Information Security

Software Asset Management Policy

A software asset management policy template defining software inventory, licence compliance, approved software and removal of unsupported versions, aligned to ISO 27001, NIST SP 800-53, NIST CSF.

14-20 pages|Updated 2026-09-12|3 frameworks

What's Included

1. Purpose & Scope

Objective and software classes covered.

Policy ObjectiveSoftware in ScopeRoles and Responsibilities

2. Inventory

Knowing what is installed.

Discovery ToolingCentral RegisterOwnershipReconciliation Cadence

3. Approved Software

Controls what may be installed.

Approved ListRequest ProcessProhibited SoftwareInstallation Restrictions

4. Licence Compliance

Avoids legal and audit exposure.

Entitlement RecordsUsage ReconciliationOver-Deployment ResponseVendor Audit Readiness

5. End of Life

Removes software the vendor no longer patches.

EOL MonitoringUpgrade PlanningRemovalException Handling

6. Records & Review

Evidence and cadence.

Inventory ReportsLicence EvidenceAnnual Policy Review

Frequently Asked Questions

What should a software asset management policy include?

A comprehensive software asset management policy should include purpose & scope, inventory, approved software, licence compliance, and more. This template covers 6 key sections aligned to ISO 27001, NIST SP 800-53, NIST CSF requirements.

Which frameworks require a information security policy?

Major frameworks requiring information security policies include ISO 27001, NIST SP 800-53, NIST CSF. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a software asset management policy be reviewed?

Best practice is to review your software asset management policy at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 686+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required