Software ID Tags
Hi - I've been working in the SAM space for a few years now and always hear a lot about software ID tags and the ISO 19770-2 standard at conferences and in articles. In my new role, I"m trying to discover internal (non-COTS) applications and we are having difficulty coming up with accurate "signatures" to discover against. My basic knowledge of SWID tags tells me that they would be a good solution to this problem.
In my research on the topic, I cant seem to find any information on the actual usage of this standard. I'm wondering if anyone can share their experience with creating, deploying, and using SWID tags, especially for internally created applications. What tools are available? What issues did you have? We would be interested in creating the tags and deploying them to the applicaitons that are already in the environment and then making tag creation and deployment part of the process moving forward.
Just looking for any information people might have from practical usage.