How are organizations managing Software Asset Management for software installed within containers?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 hours ago
I'm interested in hearing how other organizations are approaching Software Asset Management (SAM) and software visibility within containerized environments.
Historically, most software inventory has come from traditional discovery sources such as SCCM, Tanium, Jamf, ServiceNow Discovery, cloud inventory sources, etc. However, as more workloads move to Kubernetes and containers, it feels like there is an increasing visibility gap when it comes to understanding what software is actually running inside container images.
While ServiceNow provides visibility into Kubernetes resources, container images, and cloud infrastructure, I'm struggling to understand how organizations are managing software inventory and licensing for the software packages, libraries, and dependencies that exist within those containers. Recent ServiceNow discussions around Kubernetes Visibility Agent (KVA), SBOMs, and software composition visibility suggest that container software intelligence is becoming more important, but I'm curious how others are handling this.
A few questions for the community:
- Are you tracking software installed within containers as part of your SAM program?
- If so, what tooling are you using to identify software packages and dependencies inside container images?
- Are you leveraging SBOM data?
- Have you integrated any container security platforms (Wiz, Prisma Cloud, Aqua, Syft/Anchore, etc.) with ServiceNow for software inventory purposes?
- Are you bringing any container package information into SAM Pro, discovery models, or software installations?
- How are you handling licensing considerations for software distributed within container images?
- Do you consider container-based software part of your compliance position today, or are you treating it separately from traditional software discovery?
I'm particularly interested in hearing from organizations that have successfully bridged the gap between container security/SBOM tooling and Software Asset Management, as well as any lessons learned along the way.
Looking forward to hearing how others are addressing this challenge.
