I am reviewing the EATO controls framework (2025-03-03) and ran across AIS - Software License Inventory.
Why are software licenses considered a security control in EATO?
I am not saying that software licenses aren't important. For example, incorporating GPL into one's application can have unintended consequences and compliance with EO 14028 will require a machine readable SBOM (which isn't mentioned in this control at all). But what does a cloud service customer care whether or not you have an enterprise or named-user license to Microsoft Visual Studio or IBM Rational Rose?
------------------------------
Bryon Nevis
Unknown
Unknown
------------------------------