Protect intellectual property and respect the rights of others, including software licensing terms. This avoids both legal exposure and the misuse of your own valuable assets.
What an auditor, or Sekit's evidence engine, asks for.
Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
From the Sekit evidence catalog
In practice
IP exposure at most SMEs comes from software, not trademarks: unlicensed copies, expired subscriptions still running in production, and tools an employee signed up for on a personal card that nobody tracked. The inventory that would catch this often exists as a spreadsheet nobody updates after the initial rollout. A working control requires new software to be requested and approved before installation, keeps licence counts and renewal dates current in the register, and removes tools the moment a subscription lapses or a project ends, so a vendor audit does not surface unlicensed seats.
Common gaps
The software inventory was built once during setup and has not been updated as new tools and SaaS subscriptions were added.
Employees install software with personal credit cards and no approval step, so unlicensed or unsupported tools end up handling company data.
Licence counts in the register do not match what a vendor's true-up audit reports, exposing the company to unbudgeted licensing fees.
Questions your auditor will ask
Where is the current list of software the company uses and licenses?
In the software and SaaS inventory, which records each tool, its licence status, and the person who owns it.
How does someone get approval before installing new software?
They submit a request, the tool is checked for licensing and security fit, and only approved software gets added to the inventory.
What happens to a software licence once the tool is no longer needed?
It is removed from the inventory and the subscription is cancelled, closing off an unused entry point into company systems.
Where regulation demands it
NIS2 12.4 requires a maintained asset inventory, and ENS op.exp.1 sets the same expectation for Spanish public-sector suppliers tracking every software asset in use.
NIS2 6.9 covers protection against unauthorised software, which an enforced approval step for new tools directly addresses.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.