Software Licensing and Technology Refresh
Within the CGEIT framework, Software Licensing and Technology Refresh fall under the Resources domain. This domain focuses on ensuring that IT resources, including applications, infrastructure, information and people, are acquired, used and retired in ways that optimize value and manage risk. Gover… Within the CGEIT framework, Software Licensing and Technology Refresh fall under the Resources domain. This domain focuses on ensuring that IT resources, including applications, infrastructure, information and people, are acquired, used and retired in ways that optimize value and manage risk. Governance professionals do not manage licenses or hardware directly. Instead, they make sure that policies, accountability structures and oversight mechanisms exist so these activities support enterprise objectives. Software Licensing governance addresses the legal, financial and operational risks of using third-party and open-source software. Key concerns include compliance with vendor terms, avoiding over-licensing (wasted spend) and under-licensing (audit penalties and reputational damage), and understanding licensing models such as perpetual, subscription, per-user, per-core and cloud consumption-based. Effective governance requires a software asset management (SAM) policy, a centralized license inventory, clear ownership, periodic true-ups and internal audits, and alignment with procurement and contract management. Boards and executives should receive meaningful metrics, such as compliance status, license utilization and cost trends. These metrics show whether licensing decisions support strategy, for example when shifting to SaaS models. Technology Refresh governance ensures that hardware, software and platforms are replaced or upgraded before they become obsolete, unsupported, insecure or too costly to maintain. A sound refresh strategy is based on lifecycle management, including defined useful lives, vendor end-of-support dates, total cost of ownership and risk assessments. Refresh decisions should be portfolio-driven and prioritized according to business value, risk exposure and capacity needs rather than ad hoc requests. Governance bodies such as IT steering committees evaluate investment business cases, balance innovation against stability, and ensure funding is planned within budgets. Together, these practices support CGEIT principles of value delivery, risk optimization and resource optimization. Frameworks such as COBIT (for example, BAI09 Managed Assets and APO06 Managed Budget and Costs) give structured guidance. They help ensure that licensing compliance and timely technology refresh reduce technical debt, strengthen security and sustain the enterprise's ability to achieve its strategic goals.
Software Licensing and Technology Refresh (CGEIT – IT Resources)
Overview
In the CGEIT (Certified in the Governance of Enterprise IT) framework, Software Licensing and Technology Refresh sits within the IT Resources domain. That domain covers how an enterprise makes sure it has the right IT capabilities to meet its strategic objectives, and it includes infrastructure, applications, information and people. Software licensing and technology refresh deal with two related problems:
• Making sure the enterprise is legally entitled to use the software it runs.
• Making sure the technology base stays current, supportable, secure and aligned with business needs over time.
Both are governance topics, not just operational ones. The board and executive management are accountable for the risks and value involved.
Why It Is Important
1. Legal and Regulatory Compliance: Using unlicensed or under-licensed software breaches copyright law and contracts. The consequences include financial penalties, audit settlements, litigation and reputational damage. Vendors and industry bodies such as the BSA (Business Software Alliance) regularly audit organizations.
2. Financial Value and Cost Optimization: Licences are a major part of IT spending.
• Over-licensing (shelfware) wastes money.
• Under-licensing creates true-up costs and penalties.
• Good licence management means the enterprise pays only for what delivers value. This supports the governance objective of value delivery and resource optimization.
3. Risk Management: Out-of-date technology increases several risks:
• Security vulnerabilities, especially once vendors stop issuing patches.
• Operational failure.
• Loss of vendor support.
• Incompatibility with newer systems.
Technology refresh is a key risk mitigation activity.
4. Strategic Alignment: Technology that is too old can stop the enterprise from adopting new business models, digital services or innovations. Refresh decisions must follow the business strategy and the enterprise architecture roadmap.
5. Business Continuity and Resilience: End-of-life hardware and software are harder to recover and maintain. Planned refresh supports availability and continuity objectives.
6. Accountability and Transparency: Governance requires management to show stakeholders that IT assets are controlled, accounted for and used responsibly.
What It Is
Software Licensing is the legal and contractual framework that defines how software may be used, distributed, copied and modified. Key concepts include:
• Licence types: perpetual, subscription (term-based), concurrent user, named user, per device, per core/processor, site licence, enterprise agreement, and SaaS (Software as a Service) subscriptions.
• Open source licences: for example GPL, MIT and Apache. These carry obligations such as attribution or making source code available, so the enterprise must understand and manage them too.
• End User License Agreement (EULA): the terms the user agrees to.
• Software Asset Management (SAM): the discipline of managing and optimizing the purchase, deployment, maintenance, use and disposal of software. ISO/IEC 19770 is the international standard for SAM.
• Licence compliance: matching installed and used software against entitlements.
• Maintenance and support agreements: these provide the right to upgrades, patches and vendor support.
• Escrow agreements: they protect the enterprise if a vendor fails by giving access to the source code.
Technology Refresh is the planned, periodic replacement or upgrade of IT assets. Its purpose is to keep them effective, efficient, secure and supportable. Key concepts include:
• Technology lifecycle: acquisition, deployment, operation, maintenance, refresh and disposal.
• End of Life (EOL) and End of Support (EOS): the vendor milestones after which products are no longer sold, patched or supported.
• Refresh cycles: for example, replacing laptops every 3 to 4 years or servers every 4 to 5 years. Cycles should be based on business need, risk and Total Cost of Ownership (TCO), not on arbitrary calendars alone.
• Technical debt: the accumulated cost of postponing upgrades.
• Obsolescence management: spotting technologies that are becoming outdated and planning their replacement.
• Secure disposal: sanitizing data and meeting environmental requirements when assets are retired.
How It Works
1. Governance Framework and Policy:
• The board and executive management set direction through policies on software acquisition, licensing compliance, acceptable use and asset lifecycle management.
• COBIT 2019 supports this through objectives such as:
– BAI09 (Managed Assets)
– APO10 (Managed Vendors)
– APO06 (Managed Budget and Costs)
– BAI03 (Managed Solutions Identification and Build)
– EDM04 (Ensured Resource Optimization)
2. Roles and Responsibilities:
• The board ensures resources are optimized.
• The CIO and IT leadership are accountable for asset management.
• Procurement and legal manage contracts.
• A SAM manager or function maintains the inventory and compliance position.
• Business owners justify needs and benefits.
3. Asset Inventory and Configuration Management: An accurate, complete inventory of hardware and software is the foundation. It is often held in a CMDB (Configuration Management Database). Discovery tools identify what is installed and used. Without an inventory, neither compliance nor refresh planning is possible.
4. Entitlement Reconciliation: Procurement records and contracts show what the enterprise owns. These are compared regularly with deployment data. Gaps are fixed by:
• Buying more licences.
• Reharvesting unused licences.
• Removing unauthorized software.
5. Vendor and Contract Management: Negotiating enterprise agreements, understanding audit clauses, tracking renewal dates and managing vendor relationships all reduce cost and risk.
6. Technology Refresh Planning:
• Refresh plans come from the IT strategy and enterprise architecture roadmap.
• Inputs include asset age, performance, vendor EOL/EOS dates, security risk, TCO analysis, business requirements and budget.
• A multi-year refresh roadmap is approved as part of the IT investment portfolio. Each refresh is justified through a business case.
7. Portfolio and Investment Management: Refresh initiatives compete for funding with other investments. Governance frameworks such as Val IT and COBIT EDM02 make sure investments are prioritized by value and risk.
8. Monitoring and Reporting: Key metrics are reported to management and the board, including:
• Licence compliance rate
• Percentage of assets beyond EOS
• Licence utilization
• Refresh budget variance
• Number of audit findings
9. Continuous Improvement: Lessons from vendor audits, incidents and post-implementation reviews feed back into policy and process.
Key Governance Principles to Remember
• Governance sets direction and monitors. Management plans, builds, runs and monitors.
• Decisions should be driven by business value, risk and alignment with strategy, not by technology preference.
• An accurate inventory is a prerequisite for effective licence and refresh management.
• Refresh is a planned, budgeted, risk-based activity, not a reaction to failures.
• Licence compliance is a legal and risk obligation owned by senior management.
Exam Tips: Answering Questions on Software Licensing and Technology Refresh
Tip 1 – Think like a governance professional, not a technician. CGEIT questions favour answers about policy, accountability, alignment, value and risk. Avoid answers that jump straight to technical fixes. For example, if asked how to address unlicensed software, establishing a software asset management policy and process is usually better than uninstalling the software.
Tip 2 – Look for the root cause or foundational step. Many questions ask for the first or most important action. Strong first steps include:
• Establishing or validating an accurate inventory.
• Understanding business requirements.
• Aligning with the IT strategy.
• Performing a risk assessment.
Tip 3 – Business alignment wins. When choosing a refresh approach, the best answer usually links the decision to business objectives, the enterprise architecture and the IT strategic plan. Answers driven by vendor pressure, the newest technology or arbitrary timelines are usually wrong.
Tip 4 – Value and TCO over purchase price. Good answers weigh Total Cost of Ownership, return on investment and benefits realization, not just upfront cost. Be cautious of answers that choose the cheapest option without considering risk or value.
Tip 5 – Risk-based decision making. Unsupported, end-of-life software creates security and compliance risk. If a scenario involves critical systems running on unsupported platforms, the best answer usually involves:
• Assessing the risk.
• Escalating it to the appropriate decision makers.
• Including remediation in the investment portfolio.
Tip 6 – Know who is accountable.
• The board is accountable for ensuring resource optimization and compliance.
• Executive management and the CIO are responsible for implementing processes.
• Business owners are accountable for business cases and benefits.
Answers that put accountability at the right level are preferred.
Tip 7 – Policies and standards come before tools. Tools such as discovery and SAM software support the process. They are not substitutes for policy, defined roles and governance oversight.
Tip 8 – Recognize contract and vendor issues. Questions may involve audit clauses, escrow, renewal terms or vendor lock-in. Key points:
• Escrow protects against vendor failure.
• Enterprise agreements can reduce cost.
• Contract terms should be reviewed by legal and procurement against business requirements.
Tip 9 – Watch for keywords. Words such as BEST, PRIMARY, MOST important, FIRST and GREATEST concern mean several options may be partly correct. Choose the one that is most strategic, most preventive and most aligned with governance principles.
Tip 10 – Monitoring and metrics. For questions about oversight, look for answers involving KPIs and KRIs reported to management and the board, such as licence compliance percentage or the proportion of assets past end of support.
Tip 11 – Open source is not free of obligations. If a scenario involves open source software, remember that licence conditions, intellectual property risk and support arrangements must still be governed.
Tip 12 – Cloud and SaaS considerations. Subscription models move spending from capital expenditure to operating expenditure. Questions may test your understanding of:
• Governing subscriptions.
• Controlling shadow IT.
• Managing data ownership.
• Planning exit strategies.
Sample Question Approach
Scenario: An internal audit finds many installations of software without valid licences across business units. What should the IT steering committee do FIRST?
Reasoning:
• Removing the software is a reactive, operational step.
• Buying licences immediately may waste money if the inventory is inaccurate.
• The governance-focused answer is to make sure there is a software asset management policy, with clear ownership and processes, and to determine the root cause. That root cause might be weak procurement controls or a lack of user awareness.
Summary
Software licensing and technology refresh are governance concerns because they affect compliance, cost, risk and strategic capability. Effective governance relies on:
• Clear policies.
• Accurate inventories.
• Defined accountability.
• Strong vendor management.
• Risk-based, value-driven refresh planning aligned with business strategy.
• Ongoing monitoring and reporting to senior management.
In the exam, prefer answers that are strategic, preventive, aligned with business objectives and focused on value and risk over tactical or purely technical responses.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!