On this page
- Quick Reference: A.5.32 in 60 Seconds
- What the Standard Actually Requires
- Why This Control Matters
- Scope and Applicability
- Key Definitions and Terminology
- Relationship to Other Controls
- Detailed Implementation Guidance
- Tools, Technologies, and Solutions
- Policy and Procedure Templates
- Risk Assessment and Treatment
- Audit and Compliance Checklist
- Metrics and KPIs
- Common Pitfalls / Audit Failures & How to Avoid Them
- Illustrative Scenarios
- Multi-Framework Mapping
- Implementation Roadmap
- FAQ
- References and Further Reading
Quick Reference: A.5.32 in 60 Seconds
| Attribute | Detail |
|---|---|
| Control ID | A.5.32 |
| Control Title | Intellectual property rights |
| Objective | Ensure the organization respects and protects intellectual property (IP) rights-both its own and third-party-through documented procedures, asset tracking, licensing compliance, and enforcement. |
| Domain | Organizational controls |
| What You Must Do | Implement appropriate procedures to protect IP rights: maintain an IP register, manage software licenses, acquire from reputable sources, respect copyright/trademarks/patents, enforce employment IP clauses, monitor use, and dispose safely. |
| Typical Owner | CISO / Information Security Manager (co-owned with Legal Counsel and Procurement) |
| Maturity Level 1 | Ad-hoc awareness; no IP register; unlicensed software present; no formal policy. |
| Maturity Level 2 | Basic IP policy drafted; license tracking via spreadsheet; software purchases ad-hoc. |
| Maturity Level 3 | Documented IPR policy and procedures; asset register includes IP assets; quarterly license reconciliation; employment contracts include IP clauses. |
| Maturity Level 4 | Automated SAM/SCA tools; real-time dashboards; integration with procurement and HR; DLP controls for source code and designs. |
| Maturity Level 5 | Predictive IP risk analytics; continuous compliance monitoring; board-level IP risk reporting; automated open-source license governance. |
| Audit Red Flag | No IP policy; unlicensed software installed; missing software license records; employees using personal cracked tools; no IP assignment clauses in contracts. |
| Quick Win | Run a 48-hour software inventory and delete/unlicense any unauthorized installations; publish a one-page IP policy. |
| Time to Implement | 4–8 weeks for initial framework; ongoing monitoring forever. |
| Related Controls | A.5.1, A.5.9, A.5.12, A.5.13, A.5.30, A.5.31, A.5.33, A.5.35, A.5.36, A.5.37, A.6.1, A.6.6, A.8.1, A.8.5, A.8.12, A.8.25 |
What the Standard Actually Requires
Figure · Process
What A.5.32 asks you to do

ISO 27001:2022 A.5.32 Text
ISO 27001:2022 Annex A 5.32 asks organizations to put procedures in place to protect intellectual property rights.
ISO 27002:2022 Implementation Guidance (Section 5.32)
ISO 27002 expands the single "shall" statement into twelve practical guidance points:
- Topic-specific policy, Implement a policy on the protection of IP rights, tailored to the organization's operations and risk profile.
- Procedures for software and ICT products, Publish and communicate clear procedures defining how software and ICT products should be acquired, used, and maintained to remain compliant with IP standards.
- Reputable sources, Acquire software and digital content only from respected, reputable sources to avoid counterfeit or infringing copies.
- Asset register, Identify ICT assets that carry IP requirements in the organizational asset register.
- Proof of ownership, Be able to produce proof of ownership or license at any time, including physical and electronic licensing documents, communications, and files.
- License usage limits, Comply with agreed software usage limits, including concurrent users, virtual resources, processor/core counts, and geographic restrictions.
- Periodic reviews, Plan and implement periodic reviews to ensure the ICT estate does not contain unauthorized or unlicensed software.
- License renewal, Create operational and financial procedures that ensure licenses are kept up to date.
- Safe transfer and disposal, Establish procedures for the safe, responsible, and legally compliant transfer or disposal of software assets.
- Public-domain compliance, Ensure compliance with terms, conditions, and fair-use guidelines for any software acquired from the public domain (including open-source and freeware).
- Commercial recordings, Do not extract, copy, convert, or manipulate commercial recordings in ways not permitted by licensing or copyright law.
- Textual copyright, Respect and adhere to copyright laws and licensing terms for textual data such as standards, books, articles, and reports.
Shall / Should Analysis
| Term | Meaning for Your ISMS |
|---|---|
| Shall | Mandatory. The organization must have documented, implemented, and operating procedures that protect IP rights. |
| Should (ISO 27002) | Strongly recommended implementation guidance. Auditors treat these as the expected baseline unless you can justify an alternative. |
| Appropriate | Proportional to size, complexity, industry, and risk. A 20-person startup needs less bureaucracy than a 2,000-person bank, but both must have procedures. |
What Auditors Actually Check
| Auditor Action | What They Want to See |
|---|---|
| Review IPR policy | Documented, approved, communicated, and current |
| Inspect IP / software asset register | All software and IP assets listed with license type, owner, expiry, and proof |
| Sample software installations | Match installed products to license entitlements |
| Check procurement process | Purchase from authorized vendors; contracts include IP clauses |
| Review employment contracts | IP assignment and confidentiality clauses for employees and contractors |
| Check open-source governance | SCA reports, license whitelist, approval workflow |
| Review DLP / access controls | Restrictions on source code, design files, and other critical IP |
| Verify disposal records | Secure deletion and license transfer records |
| Test awareness | Employees can explain how to report unlicensed software |
| Review management review / audit records | IP risks discussed, findings closed |
Why This Control Matters
The Business Risk Narrative
Intellectual property is often the single most valuable asset class in a modern B2B technology company. For a SaaS startup it is the source code, product roadmap, and customer-facing algorithms. For a manufacturer it is the CAD drawings, process recipes, and tooling designs. For a media or e-commerce company it is the brand identity, product images, marketing content, and customer databases. Losing control of IP does not just mean a lawsuit-it means loss of competitive advantage, erosion of investor confidence, customer churn, and sometimes business failure.
A.5.32 sits at the intersection of information security, legal compliance, and enterprise risk management. While other Annex A controls focus on confidentiality, integrity, and availability of information, A.5.32 focuses on the legal ownership and permitted use of that information. You can have perfect encryption and still fail an audit because 30% of your laptops run unlicensed software, or because a contractor walked away with your source code.
Indian Regulatory Context
Indian organizations operate under a layered compliance environment where IP protection is reinforced by several statutes and regulators:
- The Copyright Act, 1957 (as amended) protects original literary, artistic, musical, and software works. Running unlicensed software, copying proprietary documents, or using pirated images can trigger civil and criminal penalties, including imprisonment up to three years and fines up to per offence.
- The Trade Marks Act, 1999 protects brand names, logos, and service marks. Unauthorized use of third-party trademarks in marketing or product interfaces can lead to infringement suits and takedown orders.
- The Patents Act, 1970 protects inventions and processes. Using patented algorithms or manufacturing techniques without a license can result in injunctions and damages.
- The Designs Act, 2000 protects industrial designs. Copying UI/UX layouts or product packaging can infringe registered designs.
- The Information Technology Act, 2000 (Section 43, 66, 66C, 66D) penalizes unauthorized access, theft, and fraud involving computer resources. Exfiltration of source code or confidential IP can be prosecuted as a cybercrime.
- The Digital Personal Data Protection Act, 2023 does not directly govern IP, but it governs personal data that may be embedded in proprietary datasets, model training data, and customer analytics. Mishandling such data can compound IP and privacy liabilities.
- CERT-In Directions, 2022 require organizations to report specified cyber incidents within six hours. Large-scale IP exfiltration or ransomware that destroys IP may trigger reporting obligations.
- RBI Cyber Security Framework in Banks and the Master Direction on IT Framework for NBFCs require board-approved policies, vendor risk management, and incident reporting. Banks and NBFCs must ensure that licensed software is used in regulated environments and that vendor contracts protect RBI-classified data and IP.
- SEBI cybersecurity circulars for market infrastructure institutions (MIIs) and intermediaries mandate complete policies, data protection, and periodic reporting. IP theft in capital markets can amount to market manipulation or insider trading.
- IRDAI Guidelines on Information and Cyber Security for insurers require protection of policyholder data and business-critical systems, with implicit requirements to use licensed and supported software.
Industry-Specific Consequences
| Industry | IP at Risk | Consequence of Failure |
|---|---|---|
| SaaS / Technology | Source code, algorithms, API designs, customer data models | GPL contamination, investor due-diligence failure, product shutdown |
| Banking / Fintech | Trading algorithms, customer PII, fraud models, payment interfaces | RBI/SEBI penalties, loss of license, reputational damage |
| Manufacturing | CAD files, process IP, supplier drawings, tooling designs | Production stoppage, patent infringement, loss of OEM contracts |
| Pharma / Healthcare | Formulations, clinical data, regulatory submissions, patient datasets | IP theft, regulatory rejection, litigation |
| Media / EdTech | Video content, courseware, images, music, e-books | Copyright strikes, platform bans, royalty disputes |
| E-commerce / Retail | Product photos, brand assets, licensing algorithms, seller data | Trademark suits, marketplace delisting, margin erosion |
impact of Non-Compliance: Statistics and Realities
- The Business Software Alliance (BSA) has consistently ranked India among the top countries for commercial value of unlicensed software, with historical unlicensed installation rates above 50%. Even a single license shortfall across hundreds of endpoints can result in seven-figure rupee settlements.
- Software audits by vendors such as Microsoft, Adobe, Oracle, and SAP can impose true-up overhead, back-maintenance fees, and penalties ranging from to several crores depending on deployment size.
- Open-source license violations can force an organization to release proprietary source code under copyleft terms, destroying product valuation. GPL enforcement actions have led to injunctions and product recalls.
- IP exfiltration by insiders overhead Indian companies an estimated –50 lakhs per incident in investigation, legal fees, and remediation for growing companies, and can run into crores for product companies.
- Regulatory fines under the IT Act for data theft can reach per violation. DPDP Act penalties can reach for data breaches involving personal data.
These numbers do not capture the hidden overhead: delayed funding rounds, lost enterprise deals, and the months of management distraction spent defending audits or litigation.
The Hidden impact of an IP Failure
Beyond fines and true-up payments, an IP failure creates a cascade of indirect overhead that rarely appear in the initial incident report. Smart organizations account for these overhead when building the business case for an IPR program.
Direct overhead
- Vendor audit settlements and license true-ups.
- Legal fees for defense, contract disputes, and enforcement actions.
- Remediation engineering for open-source license contamination or unauthorized asset removal.
- Forensic investigation and incident response for IP theft or suspected exfiltration.
- Regulatory fines and penalties under the Copyright Act, IT Act, and sectoral regulations.
Indirect overhead
- Customer and investor trust: A publicized IP dispute signals poor governance. Enterprise customers may terminate contracts, exclude the vendor from RFPs, or demand damaging audits.
- Management distraction: Leadership can spend 20–40% of their time for several quarters managing audits, litigation, and remediation instead of growing the business.
- Valuation impact: For startups and scale-ups, unaddressed IPR gaps can reduce valuation by 10–30% during funding or acquisition due to legal risk and uncertainty.
- Opportunity overhead: Engineering teams pulled off roadmap work to rewrite contaminated code or respond to audits delay product launches and revenue recognition.
- Employee morale: Developers may become frustrated by sudden restrictions if governance is introduced without training and communication.
- Insurance and financing: Cyber insurers may increase premiums or exclude IP-related claims. Lenders may impose covenants or reduce credit exposure.
Sample overhead Categories
| overhead Category | Typical Range (Indian Growing companies) | Notes |
|---|---|---|
| License true-up and penalties | – s | Depends on vendor, deployment scale, and negotiation |
| Legal fees | – | Higher for cross-border contractor disputes or patent cases |
| Engineering remediation | – s | OSS rewrite, code cleanup, tooling changes |
| Lost deal value | – s+ | Enterprise deals lost due to audit findings or trust erosion |
| Valuation haircut | 5–30% | Particularly damaging for SaaS and technology startups |
| Incident response and forensics | – | IP exfiltration investigations and e-discovery |
The real lesson is that IPR is not a compliance checkbox-it is a financial and strategic risk that belongs in the boardroom. Organizations that treat A.5.32 as a proactive investment rather than a reactive audit requirement consistently outperform their peers in customer trust, funding outcomes, and operational resilience. Building a strong IPR posture today prevents the emergency spending, legal exposure, and reputational damage that can derail growth tomorrow.
Scope and Applicability
What the Control Covers
A.5.32 applies to all intellectual property that the organization owns, licenses, uses, or distributes. This includes:
- Proprietary software and source code developed in-house or by contractors.
- Commercial software licenses, perpetual, subscription, SaaS, enterprise agreements, and OEM bundles.
- Open-source and free software including libraries, frameworks, fonts, icons, and tools.
- Copyrighted documents, standards, whitepapers, reports, training material, proposals, and marketing content.
- Trademarks and brand assets, logos, taglines, product names, domain names.
- Patents and patent-pending inventions including algorithms, business methods, and industrial processes.
- Industrial designs and CAD files, product designs, molds, tooling, packaging.
- Trade secrets and know-how, customer lists, licensing models, formulas, roadmaps.
- Digital media, images, videos, music, sound effects, fonts, templates.
- Datasets and model weights, training data, embeddings, ML models, analytics outputs.
Who It Applies To
The control applies to:
- All employees, interns, and trainees.
- Contractors, freelancers, and consultants.
- Outsourced development partners and Managed Service Providers (MSPs).
- Suppliers and vendors who handle the organization's IP.
- Customers and partners who receive IP under license or data-sharing agreements.
- Board members and senior leadership who approve IP strategy.
Role Categories
| Role Category | Examples | Primary IP Obligations |
|---|---|---|
| Creators | Developers, designers, researchers, architects, writers | Follow IP policy, use only approved assets, assign IP to organization, document OSS usage |
| Users | Sales, marketing, HR, finance, operations | Use only licensed software and media, no unauthorized copying, report suspected infringement |
| Custodians | IT admins, asset managers, procurement | Maintain registers, ensure license compliance, control access, manage disposal |
| Owners | CISO, Legal Counsel, CTO, Product Head | Approve policy, accept risks, enforce contracts, report to board |
| Third Parties | Vendors, contractors, cloud providers | Protect IP under contract, return/destroy IP on exit, comply with license terms |
Size-Based Applicability
| Organization Size | Focus Areas |
|---|---|
| Small (1–50 employees) | Basic software license tracking; employment IP clauses; no cracked software; approved image/font library. |
| Medium (50–500 employees) | Formal IPR policy; SAM tool; open-source license tracking; vendor IP clauses; periodic audits. |
| Large (500–5000 employees) | Enterprise SAM; DLP for source code; patent/trademark register; brand protection program; geo-license compliance. |
| Enterprise (5000+ employees) | Global IP governance; regional license optimization; AI/model IP; M&A IP due diligence; board reporting. |
Key Definitions and Terminology
| Term | Definition |
|---|---|
| Intellectual Property (IP) | Creations of the mind-such as inventions, literary and artistic works, designs, symbols, names, and images-used in commerce and protected by law. |
| Intellectual Property Rights (IPR) | Legal rights granted to creators and owners of IP, including copyright, trademarks, patents, and trade secrets. |
| Copyright | Legal protection for original works of authorship fixed in a tangible medium, including software code, documents, images, music, and videos. |
| Trademark | A recognizable sign, design, or expression that identifies products or services of a particular source and distinguishes them from others. |
| Patent | An exclusive right granted for an invention, which may be a product or a process, providing a new way of doing something or a technical solution to a problem. |
| Trade Secret | Information that derives independent economic value from not being generally known and is subject to reasonable efforts to maintain its secrecy. |
| License | A legal permission to use IP owned by another party under specified terms, scope, duration, and restrictions. |
| End-User License Agreement (EULA) | A contract between a software vendor and the user that defines permitted use, restrictions, and liabilities. |
| Open-Source Software (OSS) | Software distributed with a license that grants users the right to use, study, modify, and distribute the software and its source code. |
| Copyleft | A type of OSS license (e.g., GPL) requiring derivative works to be distributed under the same license terms, potentially affecting proprietary code. |
| Permissive License | An OSS license (e.g., MIT, Apache 2.0, BSD) with minimal restrictions, typically allowing proprietary use. |
| Software Asset Management (SAM) | The practice of managing and optimizing the purchase, deployment, maintenance, use, and disposal of software applications. |
| Software Composition Analysis (SCA) | Automated inspection of source code and binaries to identify third-party and open-source components and their licenses. |
| Digital Rights Management (DRM) | Technologies used to control the use, modification, and distribution of copyrighted works. |
| Data Loss Prevention (DLP) | Tools and processes that detect and prevent unauthorized exfiltration of sensitive information, including IP. |
| Work for Hire | A legal doctrine under which works created by employees within the scope of employment are owned by the employer. |
| IP Assignment Agreement | A contract in which a contractor or employee assigns ownership of created IP to the organization. |
| Fair Use / Fair Dealing | Limited exceptions to copyright infringement allowing use for purposes such as research, criticism, review, or news reporting, subject to local law. |
Relationship to Other Controls
Upstream Controls (Provide Input to A.5.32)
| Control | Relationship |
|---|---|
| A.5.1 Policies for information security | The IPR policy is a topic-specific policy under the master policy and must be approved, communicated, and reviewed. |
| A.5.9 Inventory of information and other associated assets | The asset register must identify IP-bearing assets such as software, source code, design files, and datasets. |
| A.5.12 Classification of information | Classification determines handling rules for IP assets (e.g., Restricted source code vs. Public marketing images). |
| A.5.31 Identification of legal, statutory, regulatory and contractual requirements | Provides the external compliance obligations that the IPR procedures must address. |
| A.5.37 Documented operating procedures | IPR procedures must be documented and available to personnel who need them. |
Parallel Controls (Operate Alongside A.5.32)
| Control | Relationship |
|---|---|
| A.5.13 Information backup | Backups of IP assets must respect license terms and protect against loss of source code or designs. |
| A.5.30 ICT readiness for business continuity | IP recovery (e.g., source code escrow, design repositories) is part of continuity planning. |
| A.6.1 Screening | Background checks reduce risk of IP theft by insiders. |
| A.6.6 Confidentiality or non-disclosure agreements | NDAs reinforce IPR protection for employees, contractors, and visitors. |
| A.8.1 User endpoint devices | Endpoint devices store IP; must be secured, inventoried, and wiped on disposal. |
| A.8.5 Secure authentication | Strong authentication protects repositories and systems containing IP. |
| A.8.12 Information transfer | Transfer of IP to third parties must be authorized, logged, and encrypted. |
| A.8.25 Secure development life cycle | SDLC must include open-source license checks and IP protection gates. |
Downstream Controls (Receive Input from A.5.32)
| Control | Relationship |
|---|---|
| A.5.33 Protection of records | License records, contracts, and IP registers must be protected from loss and falsification. |
| A.5.35 Independent review of information security | Internal audits sample IPR compliance as part of the independent review. |
| A.5.36 Compliance with policies, rules and standards | Managers verify that teams comply with the IPR policy. |
| A.8.32 Change management | Changes to software assets and repositories must be controlled to prevent IP contamination. |
Detailed Implementation Guidance
The IPR Implementation Model
We recommend a seven-phase model that moves from governance to continuous monitoring:
┌─────────────────────────────────────────────────────────────┐
│ PHASE 1: GOVERNANCE │
│ • Approve IPR policy and assign owner │
│ • Identify legal and contractual obligations │
│ • Define IP asset categories and classification │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ PHASE 2: DISCOVERY │
│ • Inventory software, source code, designs, media │
│ • Map ownership and licenses │
│ • Identify unauthorized or unlicensed items │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ PHASE 3: CONTROL DESIGN │
│ • Design procurement, access, labeling, and disposal rules │
│ • Implement SAM/SCA/DLP tooling │
│ • Draft employment and vendor IP clauses │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ PHASE 4: REMEDIATION │
│ • Remove unlicensed software │
│ • True-up license shortfalls │
│ • Resolve OSS license conflicts │
│ • Secure high-value IP repositories │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ PHASE 5: OPERATIONALIZATION │
│ • Run approval workflows for new software/media │
│ • Train employees and contractors │
│ • Acknowledge IPR policy │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ PHASE 6: MONITORING & REVIEW │
│ • Quarterly license reconciliation │
│ • Periodic unauthorized software scans │
│ • Annual IPR policy review │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ PHASE 7: CONTINUOUS IMPROVEMENT │
│ • Incident-driven policy updates │
│ • Maturity benchmarking │
│ • Board reporting and optimization │
└─────────────────────────────────────────────────────────────┘
Step-by-Step Implementation
Step 1: Establish the IPR Governance Board
Create a cross-functional IPR working group with representatives from Legal, IT/Security, Procurement, HR, R&D/Product, and Finance. The board meets quarterly to review IP risks, license spend, audit findings, and policy changes. Define RACI: Legal owns contracts and legal interpretation, CISO owns technical controls, Procurement owns vendor licensing, HR owns employment clauses, and CTO/Product owns source code and R&D IP.
Step 2: Conduct a Legal and Contractual Review
List all laws, regulations, and contractual obligations that affect IP. For Indian companies this includes the Copyright Act, Trade Marks Act, Patents Act, Designs Act, IT Act, DPDP Act, sectoral RBI/SEBI/IRDAI guidelines, and customer contracts. Document these in the legal register (A.5.31). Identify license types in use: perpetual, subscription, SaaS, enterprise, OEM, academic, open-source, freeware, trial.
Step 3: Build the IP Asset Register
Extend the information asset register (A.5.9) with an IP lens. For each asset record:
- Asset name and description
- Asset owner and custodian
- Asset classification (Public, Internal, Confidential, Restricted)
- IP category (software, source code, design, document, media, patent, trademark, dataset, trade secret)
- License type and license key / entitlement ID
- Licensor/vendor name
- Number of entitled users/devices/installations
- Actual usage count
- Purchase/order reference
- Expiry/renewal date
- Location (on-prem, cloud, endpoint)
- Restrictions (geo, concurrent, virtualization, sub-licensing)
- Open-source license (if applicable)
- Link to proof of ownership or license agreement
For software, use automated discovery tools where possible and validate with manual spot checks.
Step 4: Implement Software Asset Management (SAM)
SAM is the operational backbone of A.5.32. Key processes:
- Procurement gate: No software may be purchased or deployed without procurement and security approval. Cloud app procurement must pass through the sanctioned SaaS list.
- License entitlement management: Centralize purchase orders, EULAs, and SaaS admin consoles. Reconcile entitlements against installations monthly.
- Usage optimization: Identify shelfware and unused subscriptions; reharvest licenses before buying new ones.
- Renewal workflow: Finance receives 90/60/30-day renewal alerts; no auto-renewal without owner confirmation.
- True-up process: When audits reveal overuse, document the decision to buy more licenses or remove installations.
Step 5: Govern Open-Source Software
Open-source is not free of obligations. Implement an OSS governance program:
- Maintain an approved open-source license whitelist (e.g., MIT, Apache 2.0, BSD, PostgreSQL, LGPL with conditions) and blacklist (e.g., GPL-3.0 in proprietary products, AGPL, proprietary-style licenses with onerous terms).
- Integrate SCA into CI/CD to scan every commit and pull request.
- Require developers to declare new OSS components in a request form.
- Review copyleft and license compatibility before release.
- Maintain a Software Bill of Materials (SBOM) for every product release.
- Train engineering on license obligations and contribution policies.
Step 6: Protect Employment-Related IP
Ensure the organization owns what its people create:
- Include "work for hire" and IP assignment clauses in all employment agreements.
- For contractors and agencies, use standalone IP Assignment Agreements and NDAs before sharing confidential information.
- Define "scope of employment" clearly for creators working on side projects or open-source contributions.
- Document pre-existing IP brought by employees to avoid disputes.
- Include post-employment confidentiality and non-solicitation clauses where enforceable under Indian law.
Step 7: Control Access to High-Value IP
Apply defense-in-depth to IP repositories and endpoints:
- Enforce role-based access control (RBAC) and least privilege for source code, design, and document repositories.
- Require MFA for all access to IP-bearing systems.
- Use DLP rules to block bulk downloads of source code, CAD files, and customer lists to personal cloud storage or USB.
- Apply digital watermarks or metadata labels to confidential documents and designs.
- Log and review access to critical IP assets; flag anomalous access outside business hours or from unusual locations.
Step 8: Secure Procurement and Vendor IP Clauses
Every vendor agreement that involves IP should include:
- Clear ownership of deliverables and background IP.
- License grant scope (use, modify, sublicense, territory, duration).
- Confidentiality and data protection obligations.
- Right to audit for license compliance.
- Return or secure destruction of IP on termination.
- Indemnification for IP infringement caused by vendor deliverables.
- Sub-processor and open-source disclosure obligations.
For cloud/SaaS vendors, verify that the organization retains ownership of its data and that the vendor does not train AI models on customer data without consent.
Step 9: Manage Media and Content Use
Marketing, HR, and L&D teams frequently use images, videos, music, and fonts. Establish:
- A central, pre-approved media library with clear license terms (e.g., Shutterstock, Adobe Stock, Envato, Unsplash for limited use).
- Prohibition on downloading "free" assets from random websites.
- License tracking for stock media, including model releases and usage limits.
- Clear rules on using third-party trademarks, logos, and celebrity images.
- Accessibility and DPDP Act consent checks for images containing personal data.
Step 10: Implement Safe Transfer and Disposal
When software or IP assets are no longer needed:
- Uninstall software and revoke licenses in the SAM tool.
- Return physical media and license certificates to the vendor if required.
- For source code and design repositories, follow retention and archival policies.
- For disposal of endpoints, use secure wipe (NIST 800-88 Clear/Purge/Destroy) and record destruction.
- For trade-secret documents, use cross-cut shredding or certified e-waste destruction.
- Maintain disposal records for audit evidence.
IPR Controls by Asset Type
Different IP assets carry different risks and require tailored controls. The following matrix maps asset types to recommended controls.
| Asset Type | Key Risks | Required Controls | Evidence |
|---|---|---|---|
| Commercial software | Unlicensed use, over-deployment, expired subscriptions | SAM, procurement gate, periodic scans, renewal workflow | License register, reconciliation reports |
| Source code (proprietary) | Exfiltration, unauthorized copying, OSS contamination | RBAC, MFA, SCA, DLP, code review, SBOM | Access reviews, SCA reports, SBOMs |
| Open-source libraries | Copyleft infection, patent risk, unsupported components | License whitelist, SCA in CI/CD, Legal review | Approval records, SBOM, CI/CD logs |
| Design files / CAD | Theft by competitors or contractors, version misuse | PDM/PLM access control, watermarking, NDA | Repository logs, watermarked files, NDAs |
| Digital media (images, video, music) | Copyright infringement, unapproved use | Approved DAM, license tracking, pre-publish check | DAM records, licenses, review checklist |
| Documents and standards | Unauthorized distribution, copyright breach | Classification, DLP, controlled distribution | Classification labels, access logs |
| Trademarks and brand assets | Unauthorized use, brand dilution, infringement | Brand guidelines, trademark register, legal monitoring | Trademark certificates, usage guidelines |
| Patents and inventions | Infringement by others, accidental disclosure | Patent filings, invention disclosure process, NDAs | Patent register, NDAs, disclosure forms |
| Datasets and ML models | Data theft, model extraction, privacy overlap | Classification, encryption, access control, DLP, model watermarking | Data classification, access logs, DLP alerts |
| Trade secrets | Insider leakage, competitive use | Strict need-to-know, NDAs, DLP, exit interviews | Access lists, DLP records, exit statements |
Software and SaaS Software is the most frequently audited IP category. Treat SaaS subscriptions as licenses with renewal dates, user counts, and feature tiers. Map each SaaS application to a business owner and require re-certification before renewal. When employees leave, reclaim SaaS seats immediately-unused SaaS licenses are a common source of both waste and compliance ambiguity. Document any Bring-Your-Own-License (BYOL) arrangements with cloud providers and ensure that virtualization and container use does not exceed core-based entitlements.
Source Code Source code is the crown jewel for technology companies. Use repository branch protection, require pull-request reviews with at least one security-aware reviewer, scan for secrets and unauthorized OSS, and restrict fork/export permissions. Maintain an SBOM for every release so customers and auditors can verify license hygiene. For on-premise deployments, ensure that source code escrow agreements are in place for critical third-party components.
Digital Media Marketing teams often unintentionally infringe copyright because they assume online content is free. Provide a curated library and a simple approval path for exceptions. Include "no internet downloads" in the acceptable use policy. For user-generated content, obtain model releases and consent documentation to comply with both copyright and DPDP Act requirements.
Datasets and AI Models With the rise of generative AI and machine learning, datasets and model weights have become portable, high-value IP. Classify them as Restricted, apply encryption at rest and in transit, and include clauses in cloud vendor contracts that prohibit training on your data. If you license training data from third parties, ensure the license permits your intended use, including fine-tuning and commercial deployment.
Trade Secrets Trade secrets rely on secrecy rather than registration. Limit access to the smallest group necessary, use NDAs, conduct exit interviews reminding leavers of confidentiality obligations, and monitor for unusual access patterns. Document the "reasonable efforts" you take to maintain secrecy-this is essential if you ever need to enforce trade-secret rights in court. In India, courts look for documented confidentiality agreements, access controls, and training records when deciding whether information qualifies as a trade secret. Therefore, a strong trade-secret program is both an information security control and a legal prerequisite for enforcement.
Implementation by Organization Size
Small Organizations (1–50 employees)
- Use a simple spreadsheet for software inventory and a shared folder for license documents.
- Purchase software only through a single authorized channel.
- Include IP assignment clauses in offer letters.
- Use only approved stock-image subscriptions.
- Review quarterly.
Medium Organizations (50–500 employees)
- Adopt a lightweight SAM tool (e.g., ManageEngine AssetExplorer, Snipe-IT, or Lansweeper).
- Implement procurement workflow in the ITSM tool.
- Add SCA scanning for development teams.
- Deploy DLP for source code and design repositories.
- Conduct bi-annual IPR internal audits.
Large/Enterprise Organizations (500+ employees)
- Deploy enterprise SAM (Flexera, Snow, ServiceNow SAM) integrated with procurement and HR.
- Implement global license optimization and chargeback.
- Use dedicated brand protection and trademark monitoring services.
- Run continuous SCA, DLP, and access analytics.
- Establish an IP risk dashboard for the board.
Tools, Technologies, and Solutions
Tool Categories
| Category | Purpose | Example Tools |
|---|---|---|
| Software Asset Management (SAM) | Discover, normalize, and reconcile software installations against entitlements | Flexera, Snow Software, ServiceNow SAM, ManageEngine AssetExplorer, Lansweeper |
| Software Composition Analysis (SCA) | Identify OSS components and licenses in source code | Snyk, Black Duck, Mend (formerly WhiteSource), FOSSology, GitLab SCA, GitHub Advanced Security |
| Data Loss Prevention (DLP) | Prevent exfiltration of source code, designs, and documents | Microsoft Purview DLP, Symantec DLP, Forcepoint DLP, Digital Guardian, Trellix |
| Digital Asset Management (DAM) | Manage licensed images, videos, and brand assets | Bynder, Brandfolder, Widen, Adobe Experience Manager |
| Contract / CLM | Manage license agreements, NDAs, and vendor contracts | Icertis, Agiloft, SpotDraft, Zoho Contracts, DocuSign CLM |
| Digital Watermarking | Prove ownership and deter leakage of documents and media | Digimarc, Imatag, Vitrium, Custos |
| Source Code Protection | Secure repositories and detect secrets or unauthorized access | GitHub Advanced Security, GitLab Ultimate, Bitbucket, SonarQube, Checkmarx |
| Endpoint Protection | Detect unauthorized software and enforce USB/cloud restrictions | Microsoft Intune, CrowdStrike, SentinelOne, Sophos |
Vendor Comparison Matrix
| Vendor / Tool | Best For | Indian Availability | licensing Indication | Pros | Cons |
|---|---|---|---|---|---|
| FOSSology | Free OSS license compliance | Open source | Free | efficient, SPDX output | Requires self-hosting expertise |
| Microsoft Purview DLP | Microsoft 365 ecosystems | Direct | Bundled with E5 | Native integration | Less effective on non-MS platforms |
Build vs. Buy Guidance
| Scenario | Recommended Approach |
|---|---|
| <100 endpoints, no dedicated security team | Spreadsheet + approved vendor list + manual quarterly review |
| 100–1000 endpoints, small IT team | Cloud SAM (e.g., ManageEngine) + Snyk SCA + Microsoft Purview DLP |
| 1000+ endpoints, multi-location | Enterprise SAM + enterprise SCA + enterprise DLP + CLM |
| Regulated BFSI/Pharma | Best-of-breed with audit-grade reporting and local support |
Policy and Procedure Templates
Intellectual Property Rights (IPR) Policy Template
INTELLECTUAL PROPERTY RIGHTS POLICY
[Organization Name]
Version: 1.0
Approved by: [CISO / Legal Counsel / CEO]
Date: [Date]
Review Date: [Date + 12 months]
Classification: Internal
1. PURPOSE
This policy defines [Organization Name]'s approach to identifying, protecting,
and managing intellectual property rights in compliance with ISO 27001:2022
Annex A 5.32 and applicable Indian and international laws.
2. SCOPE
This policy applies to all employees, contractors, consultants, vendors, and
third parties who create, use, manage, or have access to [Organization Name]
intellectual property or third-party licensed materials.
3. POLICY STATEMENTS
3.1 Ownership of Work Product
All work product created by employees within the scope of employment is the
property of [Organization Name] under the "work for hire" doctrine. Contractors
must sign an IP Assignment Agreement before accessing confidential information
or creating deliverables.
3.2 Software Licensing
Only properly licensed software from approved vendors may be installed or used
on [Organization Name] assets. Unlicensed, cracked, pirated, or unauthorized
software is prohibited. All software purchases must be approved by Procurement
and IT Security.
3.3 Open-Source Software
Developers may only use open-source components that have been approved through
the OSS governance process. Copyleft licenses require Legal review before use.
All OSS components must be recorded in the SBOM.
3.4 Third-Party Content
Employees may only use images, videos, music, fonts, documents, and templates
from approved sources with valid licenses. Trademarks and logos of third
parties may not be used without written permission.
3.5 Confidentiality and Protection
High-value IP (source code, designs, customer lists, trade secrets) must be
stored in approved repositories with access limited by role. Bulk downloads,
screenshots, and transfers to personal devices or cloud storage are prohibited
unless authorized.
3.6 Procurement and Contracts
All vendor agreements must specify IP ownership, license scope,
confidentiality, return/destruction, and infringement indemnification.
3.7 Monitoring and Compliance
[Organization Name] reserves the right to scan devices and repositories for
unauthorized software and IP. Non-compliance may result in disciplinary action,
contract termination, or legal proceedings.
3.8 Reporting
Employees must immediately report suspected IP infringement, unauthorized
software, or IP exfiltration to the CISO or Legal Counsel.
4. ROLES AND RESPONSIBILITIES
- CISO / IPR Policy Owner: Maintain policy, coordinate audits, report to board.
- Legal Counsel: Interpret laws, review contracts and OSS licenses.
- Procurement: Ensure license compliance in purchases.
- IT / Security: Maintain SAM tool, enforce technical controls.
- HR: Include IP clauses in employment contracts and exit process.
- All Employees: Comply with policy, use only approved assets, report issues.
5. ENFORCEMENT
Violations of this policy may result in corrective action, disciplinary action
up to and including termination, and civil or criminal liability under
applicable law.
6. REVIEW
This policy is reviewed annually and upon significant changes in operations,
technology, or regulation.
7. ACKNOWLEDGMENT
All personnel must acknowledge this policy at onboarding and after any
material change.
IPR Procedure: Software License Compliance
PROCEDURE: SOFTWARE LICENSE COMPLIANCE
Version: 1.0
Owner: IT Asset Manager
OBJECTIVE
Ensure all software used by [Organization Name] is properly licensed and used
within entitlement limits.
PROCEDURE STEPS
1. REQUEST
a. Employee or manager submits software request via ITSM ticket.
b. Request includes business justification, number of users, and preferred
vendor.
2. APPROVE
a. Manager approves business need.
b. IT Security confirms compatibility and security posture.
c. Procurement confirms vendor is approved and negotiates license terms.
3. PURCHASE
a. Procurement issues purchase order.
b. License certificate, EULA, and proof of purchase stored in contract
repository and linked in SAM tool.
4. DEPLOY
a. IT installs software via approved package or self-service portal.
b. License key assigned to user/device in SAM tool.
5. MONITOR
a. SAM tool reconciles installations against entitlements monthly.
b. Overuse is flagged for true-up or removal.
c. Unused licenses are identified for reharvesting.
6. RENEW
a. Finance receives 90/60/30-day renewal alerts.
b. Owner confirms continued need and user count.
c. Renewal executed and records updated.
7. DISPOSE
a. On termination or replacement, software is uninstalled.
b. License is reclaimed or returned per vendor terms.
c. Disposal recorded in SAM tool and asset register.
8. AUDIT
a. Quarterly internal spot-check of 10% of endpoints.
b. Annual comprehensive license reconciliation.
c. Findings logged in corrective action register.
RECORDS
- ITSM tickets
- Purchase orders and invoices
- License certificates and EULAs
- SAM reconciliation reports
- Disposal records
IPR Procedure: Open-Source Approval
PROCEDURE: OPEN-SOURCE SOFTWARE APPROVAL
1. Developer identifies a required OSS component.
2. Developer completes OSS Request Form with component name, version, source,
license, and intended use.
3. SCA tool scans component for license, vulnerabilities, and dependencies.
4. Legal reviews license for copyleft, patent, and commercial restrictions.
5. Security reviews component for known vulnerabilities.
6. Component is added to approved SBOM or rejected with justification.
7. Developer is notified and usage is tracked.
Risk Assessment and Treatment
IP Risk Register (Sample)
| Risk ID | Risk Description | Likelihood | Impact | Risk Level | Treatment | Owner |
|---|---|---|---|---|---|---|
| R-IP-01 | Unlicensed software discovered during vendor audit | Medium | High | High | Implement SAM, quarterly reconciliation, procurement gate | CISO / Procurement |
| R-IP-02 | Open-source copyleft license contaminates proprietary product | Medium | High | High | Deploy SCA in CI/CD, maintain license whitelist, Legal review | CTO / Legal |
| R-IP-03 | Contractor walks away with source code / designs | Medium | High | High | IP assignment clauses, DLP, MFA, access revocation | CISO / HR |
| R-IP-04 | Employee uses pirated images in marketing campaign | Low | High | Medium | Approved media library, training, pre-publish review | Marketing Head |
| R-IP-05 | License renewal lapses causing operational outage | Low | Medium | Medium | Renewal alerts, Finance workflow, SAM calendar | IT Asset Manager |
| R-IP-06 | Trade secret leaked via personal email / cloud storage | Medium | High | High | DLP, labeling, awareness, access reviews | CISO |
| R-IP-07 | Vendor uses organization's data to train AI model | Low | High | Medium | Contract clause prohibiting AI training, vendor audit | Legal / Procurement |
| R-IP-08 | Patent infringement from use of third-party component | Low | High | Medium | Patent indemnification in vendor contracts, SCA | Legal |
| R-IP-09 | Disposal of equipment without secure wipe leaks IP | Low | Medium | Medium | Secure wipe procedure, certified e-waste vendor | IT / Facilities |
| R-IP-10 | Failure to document IP ownership delays M&A or funding | Low | High | Medium | Maintain IP register and assignment agreements | Legal / CFO |
Risk Treatment Options
| Treatment | When to Use | Example |
|---|---|---|
| Mitigate | Most IP risks | Deploy SAM, SCA, DLP, access controls |
| Transfer | High-value vendor risk | Require vendor indemnification and cyber insurance |
| Avoid | Unacceptable legal exposure | Prohibit copyleft OSS in commercial products |
| Accept | Low residual risk with documented justification | Accept risk of minor image reuse after legal clearance |
Residual Risk Acceptance
Any residual high-risk items must be accepted by the CISO or CEO with documented justification. Accepted risks are reviewed quarterly.
Audit and Compliance Checklist
Auditor Questions and Evidence
| # | Audit Question | Expected Evidence | Red Flag |
|---|---|---|---|
| 1 | Is there an approved IPR policy? | Signed policy, version history, approval record | No policy or policy not approved |
| 2 | Is the IPR policy communicated to relevant personnel? | Communication records, acknowledgment logs | Policy not distributed or acknowledged |
| 3 | Are software and IP assets inventoried? | Asset register, SAM tool reports | No register or incomplete inventory |
| 4 | Can you prove ownership or license for all software? | Purchase orders, EULAs, license certificates, SaaS admin records | Missing proof for critical software |
| 5 | Are all software installations within license entitlements? | Reconciliation report showing entitlement vs. usage | Over-deployment or negative compliance |
| 6 | Are software purchases made only from approved vendors? | Approved vendor list, procurement records | Evidence of gray-market or pirated software |
| 7 | Are open-source components tracked and approved? | SBOM, SCA reports, OSS approval records | Unapproved GPL/AGPL components in products |
| 8 | Do employment contracts include IP assignment clauses? | Sample contracts, HR records | No IP assignment or NDA clauses |
| 9 | Do contractor agreements include IP assignment and NDA? | Contractor contracts, IP Assignment Agreements | Contractors working without agreements |
| 10 | Are high-value IP repositories protected by access controls? | RBAC configuration, access review records | Open access to source code or designs |
| 11 | Is MFA enforced for IP-bearing systems? | IAM policy, conditional access settings | Single-factor access to source code |
| 12 | Is DLP configured to prevent IP exfiltration? | DLP policy, incident records | No DLP or unmonitored egress |
| 13 | Are devices scanned for unauthorized software? | Scan reports, remediation records | No scanning or repeated unlicensed installs |
| 14 | Is there a process for license renewal? | Renewal calendar, Finance workflow | Expired licenses causing operational risk |
| 15 | Is software disposed/returned safely? | Disposal records, license return confirmations | No disposal records |
| 16 | Are media and marketing assets used from approved sources? | DAM records, media licenses | Random images from internet in campaigns |
| 17 | Do vendor contracts include IP protection clauses? | Contract templates, executed agreements | Vendors free to use customer data/IP |
| 18 | Is there a process to report suspected IP violations? | Incident report form, training records | Employees don't know how to report |
| 19 | Are IP risks reviewed at management review? | Management review minutes | IP not discussed in governance forums |
| 20 | Are internal audits conducted for A.5.32? | Internal audit plan, findings, closure | No IPR-specific audit |
| 21 | Are exceptions to IPR policy documented and approved? | Exception register, approval records | Unauthorized exceptions |
| 22 | Is there evidence of employee awareness training? | Training records, quiz results | No training on IPR |
| 23 | Are source code and designs labeled or watermarked? | Labeling standard, sample assets | Confidential IP unlabeled |
| 24 | Is trade-secret information subject to access reviews? | Quarterly access review records | Stale access to sensitive IP |
| 25 | Are AI/model weights and datasets classified as IP? | Classification records, protection controls | AI assets unprotected |
Pre-Audit Self-Assessment
Before the certification or surveillance audit, complete this self-assessment:
- IPR policy is current, approved, and acknowledged by >95% of staff.
- Software asset register covers 100% of endpoints and servers.
- License entitlement vs. usage reconciliation completed in the last quarter.
- All unlicensed software removed or true-up completed.
- SBOM generated for the last product release.
- All employment and contractor contracts include IP clauses.
- Access reviews completed for source code and design repositories.
- DLP policies active for IP exfiltration vectors.
- Vendor contract template includes IP protection clauses.
- Disposal records available for the last 12 months.
- Management review minutes include IP risk discussion.
- Internal audit findings for A.5.32 are closed.
Metrics and KPIs
Figure · Matrix
How the options compare: Level 1–2 to Level 4–5
Figure · Measures
The measures that show A.5.32 is working
- Software license compliance rate100%Monthly
- License reconciliation coverage100%Monthly
- Open-source approval rate100%Per release
- IPR policy acknowledgment rate>98%Quarterly
- IPR training completion rate>95%Annually
IPR Governance Scorecard
| Metric | Formula | Target | Frequency |
|---|---|---|---|
| Software license compliance rate | (Compliant installations / Total installations) × 100 | 100% | Monthly |
| License reconciliation coverage | (Assets reconciled / Total software assets) × 100 | 100% | Monthly |
| Open-source approval rate | (Approved OSS components / Total OSS components) × 100 | 100% | Per release |
| IPR policy acknowledgment rate | (Acknowledged personnel / Total personnel) × 100 | >98% | Quarterly |
| IPR training completion rate | (Trained personnel / Target personnel) × 100 | >95% | Annually |
| Unauthorized software incidents | Count of unlicensed installations detected | 0 | Monthly |
| IPR audit findings | Number of findings per audit | 0 major | Per audit |
| High-value IP access review completion | (Reviews completed / Scheduled reviews) × 100 | 100% | Quarterly |
| Vendor contract IP clause coverage | (Contracts with IP clauses / Total contracts) × 100 | 100% | Per contract |
| License renewal on-time rate | (Renewals completed before expiry / Total renewals) × 100 | 100% | Monthly |
| IP exfiltration events detected/blocked | Count of DLP blocks/quarantine actions | Trend down | Monthly |
| IPR maturity score | Weighted score across policy, register, controls, monitoring | Level 3+ | Annually |
Sample IPR Dashboard
┌──────────────────────────────────────────────────────────────┐
│ IPR DASHBOARD — June 2026 │
├──────────────────────────────────────────────────────────────┤
│ Software License Compliance 99.2% ████████████████████░ │
│ OSS Approval Coverage 100% █████████████████████ │
│ IPR Policy Acknowledged 97% ███████████████████░░ │
│ High-Value IP Access Reviewed 100% █████████████████████ │
│ Renewals Due ≤30 Days 3 → Action required │
│ Unauthorized Software Detected 0 → Good │
│ Open IPR Audit Findings 1 → Due 2026-07-15 │
└──────────────────────────────────────────────────────────────┘
Target Setting by Maturity
| Maturity Level | License Compliance | Policy Acknowledgment | Audit Findings |
|---|---|---|---|
| Level 1–2 | ≥90% | ≥80% | ≤3 minor |
| Level 3 | ≥98% | ≥95% | 0 major, ≤2 minor |
| Level 4–5 | 100% | ≥98% | 0 major, ≤1 minor |
Common Pitfalls / Audit Failures & How to Avoid Them
| # | Pitfall / Audit Failure | Why It Happens | How to Avoid |
|---|---|---|---|
| 1 | No IPR policy or generic copy-paste policy | Security team treats IP as legal-only issue; policy not tailored | Assign CISO+Legal co-ownership; write organization-specific policy |
| 2 | Software inventory based on purchase records only | SAM tool not deployed; employees install freely | Use automated discovery; reconcile against entitlements |
| 3 | Unlicensed software on endpoints | Shadow IT, personal software, cracked tools | Scan quarterly; block unauthorized installs; enforce procurement gate |
| 4 | Missing IP assignment clauses in contracts | HR uses outdated templates; contractors not screened | Update templates; no work starts before signed NDA/IP assignment |
| 5 | Open-source license contamination | Developers copy code without legal review | SCA in CI/CD; whitelist/blacklist; Legal review for copyleft |
| 6 | No proof of license for SaaS | SaaS bought with corporate cards; no central record | Mandate procurement approval; centralize admin consoles and POs |
| 7 | Marketing uses unlicensed images | Teams download from Google | Provide approved DAM; pre-publish IP check |
| 8 | DLP not covering source code | DLP tuned only for PII | Add IP classification and DLP rules for code/design exfiltration |
| 9 | Vendor contracts silent on AI/data use | New AI clauses not added to templates | Update templates to prohibit training on customer data/IP |
| 10 | Disposal without license return/wipe records | IT focuses on hardware disposal, not data/IP | Add license reclaim and secure wipe steps to disposal SOP |
Illustrative Scenarios
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Illustrative Scenario 1: Mumbai Manufacturing Firm, The Unlicensed Software Audit
Background A 250-employee precision engineering company in Mumbai supplied components to automotive OEMs. The company had grown rapidly through acquisitions and had no centralized IT procurement. Each plant manager bought software independently, and the design team relied on AutoCAD, SolidWorks, and Adobe tools.
The Incident In early 2025, a major OEM customer requested evidence of license compliance as part of its supplier sustainability audit. The company could produce purchase records for only 60% of its installed design and productivity software. A follow-up scan revealed:
- 47 unlicensed installations of CAD software across three plants.
- 120 installations of Microsoft Office without sufficient Office 365 licenses.
- Multiple copies of cracked PDF and image editing tools on shop-floor PCs.
- No centralized asset register or license certificates.
The OEM placed the supplier on probation and threatened to remove them from the approved vendor list. Software vendor audit letters followed, demanding true-up payments estimated at plus penalties.
Root Cause Analysis
- Decentralized purchasing, No procurement gate or approved vendor list.
- No SAM process, License tracking was non-existent; IT did not know what was installed.
- Cultural tolerance, Shop-floor supervisors believed "everyone uses cracked tools."
- No awareness, Employees did not understand that unlicensed software was a business risk.
- Weak management oversight, IP and software compliance were never discussed at board level.
Remediation The company engaged Singahi to implement an IPR framework:
Phase 1 (Weeks 1–2): Stabilize
- Declared an immediate moratorium on new software purchases.
- Deployed an agentless discovery tool (Lansweeper) to map all installations.
- Deleted cracked tools and unauthorized software from all endpoints.
- Purchased emergency true-up licenses to close the most critical gaps.
Phase 2 (Weeks 3–6): Govern
- Approved an IPR policy co-owned by the CFO and CISO.
- Implemented a procurement gate via the ITSM system.
- Centralized license certificates and purchase orders in a contract repository.
- Trained all plant managers and designers on approved software and reporting.
Phase 3 (Weeks 7–12): Optimize
- Adopted ManageEngine AssetExplorer for ongoing SAM.
- Set up quarterly reconciliation and 90-day renewal alerts.
- Negotiated an enterprise agreement with the CAD vendor, reducing per-seat overhead by 18%.
- Added IP clauses to all supplier and contractor agreements.
Results
- License compliance improved from 60% to 99.5% within four months.
- True-up and penalty overhead reduced from to through negotiation and remediation.
- OEM supplier status restored; company won a multi-year contract that had been at risk.
- Passed a follow-up ISO 27001 surveillance audit with zero IPR findings.
- Recovered annually by identifying and reharvesting unused licenses.
Key Lessons
- Decentralized purchasing is the enemy of license compliance.
- A single discovery exercise can reveal hidden liabilities worth crores.
- Management tone matters: when the CFO treated IPR as a board-level risk, behavior changed.
- License optimization pays for itself-unused licenses are cash left on the table.
- Customer audits are becoming standard; IPR readiness is a competitive advantage.
Illustrative Scenario 2: Bengaluru Fintech Startup, Source Code Exfiltration and OSS License Contamination
Background A 90-employee Bengaluru fintech startup built a lending platform used by NBFCs. The engineering team included 25 full-time developers and 15 contractors in India and Ukraine. The company was preparing for a Series B funding round and an ISO 27001 certification.
The Incident During investor due diligence, two critical issues surfaced:
- OSS license contamination: An SCA scan commissioned by the investor found that the platform contained 18 GPL-2.0-licensed libraries linked directly into the proprietary backend. The startup's distribution model (on-premise deployment at customer data centers) triggered copyleft obligations that could force disclosure of the entire backend source code.
- Source code exfiltration: A recently terminated Ukrainian contractor had downloaded the entire Git repository to a personal cloud storage account two days before leaving. The contractor's agreement did not contain a clear IP assignment clause enforceable under Indian or Ukrainian law.
The investor made the funding contingent on resolving both issues. The estimated impact of rewriting the GPL-infected modules was and three months of engineering time. The exfiltration triggered a legal response and delayed the certification by six months.
Root Cause Analysis
- No OSS governance: Developers chose libraries based on functionality, not license. No SCA tool was in use.
- Weak contractor IP clauses: The contractor agreement was a generic service agreement with no explicit IP assignment or return/destruction obligations.
- No DLP on repositories: Bulk downloads to personal cloud were not blocked or alerted.
- No access review: The contractor retained access until the last day; offboarding was delayed by HR.
- No board-level IP risk view: The CTO believed "we own the code because we paid for it," misunderstanding contractor IP law.
Remediation The startup engaged Singahi for a full A.5.32 implementation:
Phase 1 (Weeks 1–3): Contain and Assess
- Revoked the contractor's access immediately and sent a legal notice demanding deletion and confirmation.
- Conducted a full SCA scan across all repositories.
- Quarantined GPL-infected modules and identified replacement libraries with permissive licenses.
- Reviewed all active contractor agreements and required signed IP Assignment Addendums.
Phase 2 (Weeks 4–8): Remediate
- Rewrote or replaced 14 of the 18 GPL libraries; obtained commercial licenses for the remaining 4.
- Integrated Snyk SCA into the CI/CD pipeline with a license policy.
- Created an approved OSS license whitelist and a developer approval workflow.
- Deployed Microsoft Purview DLP rules to block bulk downloads from GitHub and cloud storage.
Phase 3 (Weeks 9–16): Institutionalize
- Approved an IPR policy and trained all engineering and product staff.
- Updated employment and contractor templates with enforceable IP assignment clauses.
- Implemented quarterly access reviews and automated leaver access revocation.
- Generated an SBOM for every release and added it to customer security documentation.
Results
- Series B closed six months late but at the original valuation; the investor's security concerns were fully addressed.
- ISO 27001 certification achieved with no major findings on A.5.32.
- Customer security questionnaires now completed in two days instead of two weeks.
- Engineering velocity initially dropped 15% during remediation but recovered as the approval workflow became routine.
- The company added an "IP Risk" slide to every board deck.
Key Lessons
- Contractor agreements are not optional paperwork-they determine who owns your product.
- GPL in proprietary products is a funding and exit killer; SCA is non-negotiable.
- DLP must cover code repositories, not just endpoints.
- Funding due diligence will increasingly include IPR audits; prepare early.
- IPR is a board-level risk in technology companies.
Multi-Framework Mapping
Control Mapping Table
| ISO 27001:2022 A.5.32 | SOC 2 Type II | PCI DSS 4.0 | NIST 800-53 Rev 5 | CIS Controls v8 | COBIT 2019 | GDPR / DPDP Act 2023 |
|---|---|---|---|---|---|---|
| Intellectual property rights | CC1.2, CC1.3, CC6.1, CC6.6 | 12.3.1, 12.3.2, 12.4.1, 12.5.1 | PM-1, PM-2, CM-10, CM-11, MP-7, PS-6, PS-7, SA-4, SA-9 | Control 3 (Data Protection), Control 7 (Continuous Vulnerability Management), Control 10 (Malware Defenses), Control 13 (Network Monitoring and Defense) | APO01.01, APO01.02, APO01.03, APO04.03, APO12.01, APO12.02, APO12.03, DSS01.04, DSS05.02 | GDPR Art. 32 (Security of processing), Art. 28 (Processor obligations); DPDP Act 2023 Section 8 (Reasonable security safeguards), Section 12 (Breach notification) |
Mapping Notes
- SOC 2 Type II: CC1.2 (communication of information objectives) and CC1.3 (establishment of responsibility) support the IPR policy and governance. CC6.1 (logical access) and CC6.6 (encryption) map to access controls for IP repositories.
- PCI DSS 4.0: Requirements 12.3 (security impact analysis), 12.4 (acceptance of risk), 12.5 (maintenance of information security policy) align with IPR governance and policy maintenance.
- NIST 800-53 Rev 5: CM-10 (software usage restrictions) and CM-11 (user-installed software) are directly relevant. PS-6 (access agreements) and PS-7 (external personnel security) map to employment and contractor IP clauses. SA-4 (acquisition) and SA-9 (external system services) map to vendor IP clauses.
- CIS Controls v8: Data protection, vulnerability management, malware defenses, and network monitoring all contribute to preventing unauthorized software and IP exfiltration.
- COBIT 2019: APO01 (managed I&T management framework) and APO12 (managed risk) establish governance; DSS01 (managed operations) and DSS05 (managed security services) operationalize controls.
- GDPR / DPDP Act 2023: While focused on personal data, security of processing and breach notification obligations overlap when IP assets contain personal data or when IP theft involves data breaches.
Industry-Specific Mapping
| Industry | Additional Framework | Relevant Requirement |
|---|---|---|
| BFSI | RBI Cyber Security Framework | Board-approved cyber security policy, vendor risk management, incident reporting |
| Capital Markets | SEBI Cybersecurity Circulars | Complete policies, quarterly reporting, data protection |
| Insurance | IRDAI Cyber Security Guidelines | Protection of policyholder data, business continuity, licensed software |
| Healthcare | NABH / DPDP Act 2023 | Patient data confidentiality, consent, secure records |
| Government | MeitY / CERT-In | Data localization, incident reporting, procurement security |
Implementation Roadmap
Figure · Timeline
Rollout in order
- Phase 1: Foun…1–30
- Phase 2: Build31–60
- Phase 3: Embed61–90
Standard 8-Week Roadmap
| Week | Focus | Key Activities | Deliverables |
|---|---|---|---|
| Week 1 | Governance & Legal Review | Form IPR working group; review legal and contractual obligations; approve policy owner | IPR charter, legal register update |
| Week 2 | Discovery & Inventory | Deploy discovery tools; inventory software, code, media, designs; identify unlicensed items | IP asset register v1, gap report |
| Week 3 | Remediation, Software | Remove/delete unauthorized software; true-up critical licenses; centralize license records | Clean baseline, license records |
| Week 4 | Remediation, Contracts & OSS | Update employment/contractor templates; scan repositories; resolve OSS conflicts | New contract clauses, SCA baseline |
| Week 5 | Control Design & Tooling | Implement procurement gate; deploy SAM/SCA/DLP; configure access controls | Workflow live, tools configured |
| Week 6 | Operationalization | Train employees and contractors; launch acknowledgment campaign; run approval workflows | >95% acknowledgment, trained teams |
| Week 7 | Monitoring & Review | First monthly reconciliation; access reviews; exception register | Reconciliation report, review records |
| Week 8 | Audit Readiness | Internal audit of A.5.32; close findings; management review | Audit report, closed findings |
90-Day Sprint for New ISMS
| Phase | Days | Activities |
|---|---|---|
| Phase 1: Foundation | 1–30 | Approve IPR policy, legal register, asset inventory, remove unlicensed software |
| Phase 2: Build | 31–60 | SAM/SCA/DLP deployment, contract updates, OSS governance, training |
| Phase 3: Embed | 61–90 | First reconciliation, access reviews, internal audit, management review, continuous improvement plan |
Ongoing Cadence
| Activity | Frequency | Owner |
|---|---|---|
| License reconciliation | Monthly | IT Asset Manager |
| Open-source SBOM review | Per release | Engineering Lead |
| Access review for high-value IP | Quarterly | Data/Repository Owners |
| IPR policy review | Annually | CISO / Legal |
| Internal audit of A.5.32 | Annually | Internal Audit |
| Vendor contract IP clause review | Per contract / Annually | Legal / Procurement |
| Management review of IP risks | Quarterly | IPR Working Group |
FAQ
Does A.5.32 apply only to software?
No. While software licensing is the most common audit focus, A.5.32 covers all intellectual property: source code, patents, trademarks, designs, copyrighted documents, digital media, datasets, and trade secrets. Your procedures must address each relevant category.
Can a small company satisfy A.5.32 with just a policy?
No. ISO 27001 requires procedures that are implemented and operating. A policy alone is insufficient. You also need evidence of an asset register, license tracking, employment clauses, and periodic review.
Do we need a separate IPR policy, or can it be part of another policy?
For small organizations, IPR rules can be embedded in the Acceptable Use Policy or IT Security Policy. For medium and large organizations, a dedicated topic-specific IPR Policy is strongly recommended and expected by auditors.
How often should we review software licenses?
Reconcile license entitlements against actual usage at least monthly. Review the IPR policy annually and after any significant change such as a new product launch, merger, or regulatory update.
What is the biggest open-source license risk?
Copyleft licenses such as GPL, AGPL, and LGPL can require you to release your proprietary source code if you distribute derivative works. Always run SCA and obtain Legal review before using copyleft components in commercial products.
Can employees use free images from the internet?
Only if the image has a clear license permitting commercial use and you retain proof. The safest approach is to use an approved stock-media subscription or a vetted creative-commons library. Random search-engine images are high risk.
What should we do if we find unlicensed software?
Remove or uninstall it immediately, document the finding, determine the root cause, and decide whether to purchase licenses or discontinue use. Repeat offenders should face disciplinary action.
How do we protect IP when using contractors?
Require signed NDAs and IP Assignment Agreements before sharing any confidential information. Use least-privilege access, monitor activity, revoke access on termination, and include return/destruction clauses.
Is source code escrow relevant to A.5.32?
Yes. Source code escrow protects your continuity rights if a vendor goes out of business. It also demonstrates that you have procedures to safeguard access to critical IP. Escrow agreements should be reviewed as part of vendor IP clauses.
How does A.5.32 relate to the DPDP Act 2023?
While A.5.32 focuses on IP rights, many IP assets contain personal data. The DPDP Act requires reasonable security safeguards and breach notification. An IPR program that protects datasets, ML models, and customer analytics also supports DPDP compliance.
What evidence do auditors expect for A.5.32?
Auditors expect: an approved IPR policy, an IP/software asset register, proof of licenses, reconciliation reports, employment/contractor IP clauses, SCA reports (if applicable), DLP/access controls, disposal records, training records, and management review minutes.
How long does it take to implement A.5.32?
A focused organization can reach baseline compliance in 4–8 weeks. Achieving maturity levels 4–5 with automated SAM, SCA, and DLP typically takes 3–6 months.
References and Further Reading
Standards and Frameworks
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements
- ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection, Information security controls
- ISO/IEC 27036, Information security for supplier relationships
- ISO/IEC 19770, Information technology, IT asset management
- NIST Special Publication 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organizations
- NIST SP 800-88 Rev 1, Guidelines for Media Sanitization
- CIS Controls v8, Center for Internet Security
- COBIT 2019, ISACA
- SOC 2 Trust Services Criteria, AICPA
- PCI DSS 4.0, PCI Security Standards Council
Indian Laws and Regulations
- The Copyright Act, 1957 (as amended)
- The Trade Marks Act, 1999
- The Patents Act, 1970
- The Designs Act, 2000
- The Information Technology Act, 2000
- The Digital Personal Data Protection Act, 2023
- RBI Cyber Security Framework in Banks, 2016
- RBI Master Direction on IT Framework for NBFCs, 2017
- SEBI Circulars on Cyber Security and Cyber Resilience
- IRDAI Guidelines on Information and Cyber Security for Insurers
- CERT-In Directions, 2022
Useful Resources
- BSA | The Software Alliance, Global Software Survey
- Open Source Initiative (OSI), License list
- SPDX (Software Package Data Exchange), sbom.dev
- OWASP Dependency-Check
- Linux Foundation OpenChain Project
- MeitY, National Cyber Security Policy and Data Protection Guidance