TWM646838U - Information asset management system for automatic software compliance analysis - Google Patents

Information asset management system for automatic software compliance analysis Download PDF

Info

Publication number
TWM646838U
TWM646838U TW112206054U TW112206054U TWM646838U TW M646838 U TWM646838 U TW M646838U TW 112206054 U TW112206054 U TW 112206054U TW 112206054 U TW112206054 U TW 112206054U TW M646838 U TWM646838 U TW M646838U
Authority
TW
Taiwan
Prior art keywords
information
data
module
compliance
asset
Prior art date
Application number
TW112206054U
Other languages
Chinese (zh)
Inventor
劉姍姍
陳盈嘉
Original Assignee
精誠軟體服務股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 精誠軟體服務股份有限公司 filed Critical 精誠軟體服務股份有限公司
Priority to TW112206054U priority Critical patent/TWM646838U/en
Publication of TWM646838U publication Critical patent/TWM646838U/en

Links

Landscapes

  • Stored Programmes (AREA)

Abstract

本新型提供一種自動軟體合規分析之資訊資產管理系統,供包含一資料管理模組、一合規分析模組及一介面呈現模組,該資料管理模組電訊連接該合規分析模組,且該介面呈現模組電訊連接該資料管理組及該合規分析模組。該資料管理模組供建置至少一單位基本資料及對應該單位基本資料之一資產資料。該合規分析模組匯整並統計該資產資料之金額後輸出一資產價值統整表,且統計該資產資料之硬體資訊之ESG狀態而形成一第一或第二綠色採購績效表;匯整該資產資料之軟體資訊之版權狀態而形成一授權取得資料,且運算該等軟體資訊之部署狀態而形成一安裝部署資料,據此利用一合規對照資料比對該授權取得資料及該安裝部署資料中各該軟體資訊之產品名稱及產品版本而形成一合規分析表,以供自動合規及管控軟硬體資產。 The present invention provides an information asset management system for automatic software compliance analysis, which includes a data management module, a compliance analysis module and an interface presentation module. The data management module is connected to the compliance analysis module via telecommunications. And the interface presentation module is electrically connected to the data management group and the compliance analysis module. The data management module is used to create at least one unit's basic data and one asset data corresponding to the unit's basic data. The compliance analysis module compiles and counts the amount of the asset data and then outputs an asset value summary table, and counts the ESG status of the hardware information of the asset data to form a first or second green procurement performance table; The copyright status of the software information of the asset data is adjusted to form an authorized acquisition data, and the deployment status of the software information is calculated to form an installation deployment data. Accordingly, a compliance comparison data is used to compare the authorized acquisition data and the installation. Deploy the product name and product version of each software information in the data to form a compliance analysis table for automatic compliance and management of software and hardware assets.

Description

自動軟體合規分析之資訊資產管理系統Information asset management system for automatic software compliance analysis

本新型係與資訊資產管理系統有關,尤其是一種自動軟體合規分析之資訊資產管理系統。The present invention relates to an information asset management system, particularly an information asset management system for automatic software compliance analysis.

資訊合規管理(Compliance Management)係包含營業許可證、綠色執照、合約義務、產業標準及企業章程等內外規則、標準或義務要求,以防止並管控諸如企業或政府組織等單位使用盜版軟體、以次充好或偽造資產等違規行為,同時亦可避免單位因違規而遭受財務損失、商譽損失,甚或停止執業等風險。傳統上,企業或政府組織等單位普遍由其各部門自行對其所採購的軟硬體等資訊資產進行管理及自行對其營運業務所需面對的法令遵循、產業標準或合約義務等進行管控,因此常見各單位存在有管控制度不一致與整體合規風險控管成效低落的現象,導致常有單位中某一部門使用無版權軟體而造成整體單位資訊安全防線崩塌的情事發生。簡言之,不論是企業或政府組織,係皆由於其治理階層或管理階層未全面掌握整體資產的部署狀況與合規風險防控程度等,且未能確保單位營運所遵循的法規或標準皆已為最新正確版本,故而一旦某一部門的資安受危害,單位整體便只能以亡羊補牢收場。Information compliance management (Compliance Management) includes internal and external rules, standards or obligations such as business licenses, green licenses, contractual obligations, industry standards and corporate articles of association to prevent and control the use of pirated software by entities such as enterprises or government organizations. Violations such as substandard goods or counterfeit assets can also avoid risks such as financial losses, loss of goodwill, or even cessation of practice due to violations. Traditionally, units such as enterprises or government organizations generally have their respective departments manage the information assets such as software and hardware they purchase and control the legal compliance, industry standards or contractual obligations required to operate their business. Therefore, it is common for various units to have inconsistent management systems and low overall compliance risk control effectiveness, which often leads to the use of non-copyrighted software by a certain department in the unit, causing the entire unit's information security defense line to collapse. In short, whether it is an enterprise or a government organization, the reason is that its governance or management does not fully understand the deployment status of the overall assets and the degree of compliance risk prevention and control, and fails to ensure that the regulations or standards followed by the unit's operations are all in compliance. It is the latest and correct version, so once the information security of a certain department is compromised, the entire organization can only make amends.

為此,目前全球企業或政府組織係逐漸傾向由治理視角出發來發展合規管理,以由上而下地監督整體資產及營運業務等的合規情形。只是,目前市場上所提供的資訊資產管理系統,卻並不具有全面且自動的合規檢驗程序,其係因系統無內置有符合諸如Microsoft、Autodesk、Adobe等原廠認證的比對資料,且系統缺代系統性與邏輯性的資料匯整與運算程序,故而造成系統未能提供有效且精確的合規管控作業。換言之,單位雖耗費大筆經費建置該資訊資產管理系統,卻仍需人工進行諸如法規合對、合約檢視、採購預算擬制等合規作業而無端耗費諸多人力與成本,於現時代下,實不符單位營運績效的需求。For this reason, global enterprises or government organizations are currently gradually tending to develop compliance management from a governance perspective to supervise the compliance of overall assets and operating businesses from top to bottom. However, the information asset management systems currently provided on the market do not have comprehensive and automatic compliance inspection procedures. This is because the system does not have built-in comparison data that meets the original certifications of Microsoft, Autodesk, Adobe, etc., and The system lacks systematic and logical data collection and calculation procedures, resulting in the system being unable to provide effective and accurate compliance control operations. In other words, although the company spends a large amount of money to build the information asset management system, it still needs to manually perform compliance operations such as regulatory compliance, contract review, procurement budget preparation and so on, which consumes a lot of manpower and cost for no reason. In the current era, it is difficult to implement Does not meet the needs of the unit's operational performance.

有感於此,如何提供一種具自動合規功能之資訊資產管理系統,藉以確保單位營運合規而改善上述習知技術之缺失,並避免因違規而遭受法律制裁、監管處罰、重大財務損失或聲譽損失等風險,進而對外展現良好治理形象,即為本新型所欲探究之課題。In view of this, how to provide an information asset management system with automatic compliance functions to ensure the compliance of unit operations and improve the shortcomings of the above-mentioned conventional technologies, and avoid suffering legal sanctions, regulatory penalties, major financial losses or due to violations. Risks such as reputational loss, and then externally displaying a good governance image, are the topics that this new model intends to explore.

有鑑於上述問題,本新型之目的旨在提供一種具自動軟體合規分析功能之資訊資產管理系統,其透過後台系統性建置及維護一產品名稱對照表、一盤點產品對照表及一產品終止對照表,並透過合規分析模組邏輯性地統合及運算資產部署狀況及版權狀況而實現自動且精準的系統合規功能,據此以協助一單位充分掌握涵括實體端及雲端之軟硬體資產的運用實況,進而實現最佳化採購預算擬制的目的。In view of the above problems, the purpose of this new model is to provide an information asset management system with automatic software compliance analysis function, which systematically builds and maintains a product name comparison table, an inventory product comparison table and a product termination through the background Comparison table, and through the compliance analysis module, the asset deployment status and copyright status are logically integrated and calculated to achieve automatic and accurate system compliance functions, thereby helping an organization to fully understand the software and hardware including the physical end and the cloud. Real-time utilization of physical assets, thereby achieving the purpose of optimal procurement budget preparation.

為達上述目的,本新型係揭露一種自動軟體合規分析之資訊資產管理系統,係供自動合規及管控一單位之軟硬體資產而執行於一單位主機及一後台伺服器中,其包含:一資料管理模組,係供建置至少一單位基本資料及對應該單位基本資料之一資產資料,且該單位基本資料包含一綠色採購廠商資訊、一企業社會責任驗證、一第一單位屬性或一第二單位屬性、及至少一單位聯絡人之設定,該資產資料包含複數個硬體資訊、複數個軟體資訊及複數個服務資訊;其中,各該硬體資訊、各該軟體資訊及該服務資訊分別設有一部署狀態、一版權狀態、一ESG(Environmental、Social、Governance, 環境保護、社會責任、公司治理)狀態之其中至少一者;一合規分析模組 ,內存有一合規對照資料並電訊連接該資料管理模組,且該合規對照資料設有產品名稱、產品版本、授權方案、採購數量、有效授權數量及軟體部署量;該合規分析模組匯整並統計該資產資料之金額而輸出一資產價值統整表,同時,統計該等硬體資訊之ESG狀態而依據該第一單位屬性形成一第一綠色採購績效表或依據該第二單位屬性形成一第二綠色採購績效表;該合規分析模組匯整該等軟體資訊之該版權狀態而形成一授權取得資料,且運算該等軟體資訊之各該部署狀態而形成一安裝部署資料,據此並利用該合規對照資料比對該授權取得資料及該安裝部署資料中各該軟體資訊之產品名稱及產品版本而形成一合規分析表,以供獲知未達法令遵循標準、授權不足或偽授權之軟體使用狀況而降低資安風險;及一介面呈現模組,係設有一資訊資產合規儀表板,該介面呈現模組利用該資訊資產合規儀表板之一側顯示該資產價值統整表而另一側顯示該第一綠色採購績效表或該第二綠色採購績效表。In order to achieve the above purpose, the present invention discloses an information asset management system for automatic software compliance analysis, which is used to automatically comply with and control the software and hardware assets of a unit and is executed on a unit host and a backend server, which includes : A data management module for constructing at least one unit's basic information and one asset data corresponding to the unit's basic information, and the unit's basic information includes a green purchasing manufacturer information, a corporate social responsibility verification, and a first unit attribute Or a second unit attribute, and the setting of at least one unit contact person. The asset data includes a plurality of hardware information, a plurality of software information and a plurality of service information; among which, each of the hardware information, each of the software information and the The service information is respectively provided with at least one of a deployment status, a copyright status, and an ESG (Environmental, Social, Governance, Environmental Protection, Social Responsibility, Corporate Governance) status; a compliance analysis module, which stores a compliance comparison data The data management module is connected via telecommunications, and the compliance comparison data includes product name, product version, authorization plan, purchase quantity, valid authorization quantity and software deployment quantity; the compliance analysis module compiles and counts the asset data The amount is output to an asset value summary table, and at the same time, the ESG status of the hardware information is counted to form a first green procurement performance table based on the first unit attributes or a second green procurement based on the second unit attributes. Performance table; the compliance analysis module aggregates the copyright status of the software information to form an authorized acquisition data, and calculates the deployment status of the software information to form an installation deployment data, and uses the compliance data accordingly. The regulatory comparison data compares the product name and product version of each software information in the authorization acquisition data and the installation and deployment data to form a compliance analysis table for use in identifying software that does not meet legal compliance standards, is insufficiently authorized, or is falsely authorized. status to reduce information security risks; and an interface presentation module is provided with an information asset compliance dashboard, and the interface presentation module uses one side of the information asset compliance dashboard to display the asset value summary table and the other side of the information asset compliance dashboard. The first green procurement performance table or the second green procurement performance table is displayed on the side.

其中,該合規對照資料係包含一產品名稱對照表、一盤點產品對照表及一產品終止對照表,該產品名稱對照表係將原廠每個軟體的產品類別、對應名稱、產品名稱、產品版本、授權採購方案、支援週期終止(End-of-Support, EOS)及生命週期終止(End-of-Life, EOL)之資訊表列清單;該盤點產品對照表係將對應一盤點工具內的產品名稱、產品版本、授權版本、有效授權數量及軟體部署量之資訊表列清單;該產品終止對照表係將供裝載軟體之硬體的名稱、型號、支援週期終止及生命週期終止之資訊表列清單。該合規分析模組係比對該授權取得資料中各該軟體資訊之產品類別、對應名稱、產品名稱及產品版本與該產品名稱對照表所對應的名稱是否一致;及比對該安裝部署資料中各該軟體資訊之產品名稱及產品版本與該盤點產品對照表所對應的名稱是否一致而形成該合規分析表,且該合規分析表包含一授權EOS版權提醒表及一安裝EOS版權提醒表。Among them, the compliance comparison information includes a product name comparison table, an inventory product comparison table and a product termination comparison table. The product name comparison table is the product category, corresponding name, product name, product A list of versions, authorized purchase plans, end-of-Support (EOS) and end-of-life (EOL) information; this inventory product comparison table will correspond to the inventory in an inventory tool A list of information on product name, product version, authorized version, number of valid licenses, and software deployment volume; the product termination comparison table is an information table of the name, model, end of support period, and end of life cycle of the hardware that will be used to load the software. Make lists. The compliance analysis module compares the product category, corresponding name, product name and product version of each software information in the authorization obtained data with the name corresponding to the product name comparison table; and compares the installation and deployment data The compliance analysis table is formed by checking whether the product name and product version of each software information in the software information are consistent with the names corresponding to the inventory product comparison table, and the compliance analysis table includes an authorized EOS copyright reminder table and an installed EOS copyright reminder table. surface.

該資訊資產管理系統更包含一授權模組及一後台管理模組,該授權模組電訊連接該資料管理模組及該後台管理模組,且該後台管理模組電訊連接該合規分析模組;該授權模組產生一啟動金鑰予該資料管理模組,以供該單位啟動該資訊資產管理系統時作為憑證之用,且該後台管理模組則供建置並定期維護該合規對照資料,以供該合規分析模組下載並定期更新該合規對照資料。該資產價值統整表係包含該單位之硬體資產總金額,且該合規分析模組統計該等硬體資訊之ESG狀態而形成該第一或第二綠色採購績效表時,係獲知該單位之綠色採購總金額、各項目類別綠色採購金額及非綠色採購項目原因之數據,並進一步計算綠色採購總金額佔硬體資產總金額之百分比而形成一綠色採購績效值,而於該第一綠色採購績效表設有該第一單位屬性時,該資訊資產合規儀表板利用一五葉草圖示元件之葉片多寡及一第一燈號元件顯示該單位綠色採購績效之百分比級數;當該第二綠色採購績效表設有該第二單位屬性時,該合規分析模組係更以一指定比率評比該百分比而輸出一評等,以利用一四葉草圖示元件之葉片多寡顯示該單位綠色採購績效之百分比級數的同時,利用一第二燈號元件顯示該評等。The information asset management system further includes an authorization module and a backend management module. The authorization module is electrically connected to the data management module and the backend management module, and the backend management module is electrically connected to the compliance analysis module. ; The authorization module generates an activation key to the data management module for use as a certificate when the unit starts the information asset management system, and the backend management module is used to build and regularly maintain the compliance control Data for the compliance analysis module to download and regularly update the compliance comparison data. The asset value integration table includes the total amount of hardware assets of the unit, and the compliance analysis module calculates the ESG status of the hardware information to form the first or second green procurement performance table. The data of the unit's total green procurement amount, the green procurement amount of each project category and the reasons for non-green procurement projects are further calculated as a percentage of the total green procurement amount to the total amount of hardware assets to form a green procurement performance value, and in the first When the green procurement performance table has the first unit attribute, the information asset compliance dashboard uses the number of leaves of a five-leaf clover icon component and a first light component to display the percentage level of the unit's green procurement performance; when When the second green procurement performance table is provided with the second unit attribute, the compliance analysis module further evaluates the percentage with a specified ratio and outputs a rating to display the number of leaves of a four-leaf clover icon element. Along with the percentage grade of the unit's green procurement performance, a second light component is used to display the rating.

並且,該合規分析模組匯整並分析該資產資料而獲知複數筆重複數據,比對該等重複數據而輸出一異動訊息予對應之該單位聯絡人,以通知該單位聯絡人修正該等重複數據。該介面呈現模組係設有一總覽頁面,以供於系統開啟時顯示複數個總覽資訊,且該總覽頁面設有一小幫手元件,以供自行增訂一待辦事項及至少一提醒事項之其中至少一者。該資料管理模組係設有一對象建置元件及一資訊匯入元件,該對象建置元件供該單位建置該單位基本資料,該資訊匯入元件供該單位匯入一現有設備資料並自動轉換形成該資產資料,以協助該單位快速建置該資產資料。Moreover, the compliance analysis module collects and analyzes the asset data and obtains multiple duplicate data, compares the duplicate data and outputs a change message to the corresponding unit contact person to notify the unit contact person to correct the data. Duplicate data. The interface presentation module is provided with an overview page for displaying a plurality of overview information when the system is started, and the overview page is provided with a small helper component for self-adding at least one of a to-do item and at least one reminder item By. The data management module is provided with an object construction component and an information import component. The object construction component is used for the unit to build basic data of the unit. The information import component is used for the unit to import an existing equipment data and automatically The asset data is converted into data to assist the unit in quickly establishing the asset data.

該資訊資產管理系統更包含一專案管理模組,係電訊連接該資料管理模組及該介面呈現模組,該專案管理模組供建置至少一採購專案,該採購專案設有採購之至少一該硬體資訊、至少一該軟體資訊、至少一該服務資訊及至少一合約資訊之其中之一或其組合,且該合約資訊設有合約起迄日、簽約期數及每期驗收條件;該專案管理模組依據該合約資訊匯整對應之該資產資料並檢驗合約起迄日,以於合約臨近迄日時輸出附有該合約資訊之一續約資訊。該資訊資產管理系統更包含一報表輸出模組、一查詢處理模組及一報修處理模組,該報表輸出模組電訊連接該合規分析模組及該介面呈現模組,該查詢處理模組電訊連接該資料管理模組及該介面呈現模組,且該報修處理模組電訊連接該資料管理模組;該報表輸出模組解析該合規分析表形成一授權EOS版權提醒表及一安裝EOS版權提醒表,同時,匯整該資產價值統整表、該綠色採購績效表及該合規分析表並運算形成一ESG面向報表及一綠色採購政策符合性報表;該查詢處理模組供一使用者依權限查詢資料,且欲報修該硬體資訊、該軟體資訊或該服務資訊時,係利用該報修處理模組輸出一報修請求予對應之該單位聯絡人而進行線上報修作業。The information asset management system further includes a project management module, which is connected by telecommunications to the data management module and the interface presentation module. The project management module is used to build at least one procurement project, and the procurement project has at least one procurement One or a combination of the hardware information, at least one piece of software information, at least one piece of service information, and at least one contract information, and the contract information has a contract start and end date, the number of contract periods and the acceptance conditions for each period; the The project management module compiles the corresponding asset data based on the contract information and checks the contract start and end dates, so as to output renewal information with the contract information when the contract is approaching the expiration date. The information asset management system further includes a report output module, a query processing module and a repair processing module. The report output module is electrically connected to the compliance analysis module and the interface presentation module. The query processing module The data management module and the interface presentation module are connected by telecommunications, and the repair processing module is connected by telecommunications to the data management module; the report output module parses the compliance analysis table to form an authorized EOS copyright reminder table and an installed EOS Copyright reminder table, at the same time, the asset value summary table, the green procurement performance table and the compliance analysis table are compiled and calculated to form an ESG-oriented report and a green procurement policy compliance report; the query processing module is for one use When the user inquires information according to the authority and wants to report the hardware information, the software information or the service information, the repair request processing module is used to output a repair request to the corresponding contact person of the unit to perform the online repair operation.

綜上所述,本新型係透過該後台管理模組建置並定期維該產品名稱對照表、該盤點產品對照表及該產品終止對照表,以將對應原廠的每個軟體及每個硬體的產品名稱、產品版本、EOS及EOL等資訊匯整列表後,供該合規分析模組比對該授權取得資料、該安裝部署資料與該合規對照資料而完成對無論是裝載於硬體中或置放於雲端上的軟體進行版權合規作業,據此使降低資安風險的同時,協助該單位全面掌控所有有形與無形的資訊資產實際運用現況,進而得以擬制最合理的採購策略並提升整體單位營運績效。並且,本新型透過該專案管理模組系統性地匯整對應該合約資訊之該資產資料係可協助該單位快速且正確地進行合約歸檔作業,使避免日後該單位發生耗時耗力查找合約相關資料的狀況,同時,透過該專案管理模組邏輯性地運算對應該合約資訊之續約日期及續約條件等並自動輸出該續約資訊的作動功能,係可協助對應之該單位聯絡人高效率地控管合約義務,以減少諸如銷售、生產及服務等該單位營運活動因於無合約保障而暴露於違法風險下的狀況發生。To sum up, the system of the present invention configures and regularly maintains the product name comparison table, the inventory product comparison table and the product termination comparison table through the backend management module, so as to store each software and each hardware corresponding to the original manufacturer. After the product name, product version, EOS and EOL and other information of the entity are compiled into a list, the compliance analysis module can compare the authorization acquisition data, the installation deployment data and the compliance comparison data to complete the analysis of whether it is loaded on the hard drive. Conduct copyright compliance operations on software in the system or placed on the cloud, thereby reducing information security risks while assisting the unit to fully control the actual use status of all tangible and intangible information assets, thereby formulating the most reasonable procurement strategy and improve overall unit operating performance. Moreover, this new model systematically collects the asset data corresponding to the contract information through the project management module, which can help the unit quickly and accurately perform contract archiving operations, so as to avoid the unit's time-consuming and labor-intensive search for contract-related matters in the future. At the same time, through the project management module, the action function of logically calculating the renewal date and renewal conditions corresponding to the contract information and automatically outputting the renewal information can assist the corresponding contact person of the unit. Efficiently control contractual obligations to reduce the exposure of the unit's operating activities, such as sales, production and services, to illegal risks due to the absence of contractual protection.

為使本領域具有通常知識者能清楚了解本新型之內容,謹以下列說明搭配圖式,敬請參閱。In order to enable those with ordinary knowledge in the field to clearly understand the contents of the present invention, the following description is accompanied by the drawings, please refer to them.

請參閱第1圖,其係為本新型一較佳實施例之架構圖。如圖所示,該自動軟體合規分析之資訊資產管理系統1係包含一資料管理模組10、一合規分析模組12及一介面呈現模組14,以供自動合規及管控一單位之軟硬體資產而執行於一單位主機及一後台伺服器中。該資料管理模組10電訊連接該合規分析模組12及該介面呈現模組14,且該合規分析模組12電訊連接該介面呈現模組14,該合規分析模組12內存有一合規對照資料310,該合規對照資料310設有產品名稱、產品版本、授權方案、採購數量、有效授權數量及軟體部署量。該資料管理模組10供建置至少一單位基本資料1000及對應該單位基本資料1000之一資產資料101,且該單位基本資料1000包含一綠色採購廠商資訊、一企業社會責任驗證、一第一單位屬性或一第二單位屬性、及至少一單位聯絡人之設定,該資產資料101包含複數個硬體資訊、複數個軟體資訊及複數個服務資訊;其中,各該硬體資訊、各該軟體資訊及各該服務資訊分別設有一部署狀態、一版權狀態及一ESG(Environmental、Social、Governance, 環境保護、社會責任、公司治理)狀態之其中至少一者。Please refer to Figure 1, which is a structural diagram of a preferred embodiment of the present invention. As shown in the figure, the automatic software compliance analysis information asset management system 1 includes a data management module 10, a compliance analysis module 12 and an interface presentation module 14 for automatic compliance and control of a unit. The software and hardware assets are executed on a host and a backend server. The data management module 10 is electrically connected to the compliance analysis module 12 and the interface presentation module 14, and the compliance analysis module 12 is electrically connected to the interface presentation module 14. The compliance analysis module 12 stores a Compliance comparison data 310 includes product name, product version, authorization plan, purchase quantity, valid authorization quantity and software deployment quantity. The data management module 10 is used to establish at least one unit basic data 1000 and one asset data 101 corresponding to the unit's basic data 1000, and the unit's basic data 1000 includes a green procurement manufacturer information, a corporate social responsibility verification, a first The unit attribute or a second unit attribute, and the setting of at least one unit contact person, the asset data 101 includes a plurality of hardware information, a plurality of software information and a plurality of service information; wherein, each of the hardware information, each of the software Information and each service information are respectively provided with at least one of a deployment status, a copyright status and an ESG (Environmental, Social, Governance, Environmental Protection, Social Responsibility, Corporate Governance) status.

該合規分析模組12匯整並統計該資產資料101之金額而輸出一資產價值統整表120,同時,該合規分析模組12統計該等硬體資訊之ESG狀態而依據該第一單位屬性形成一第一綠色採購績效表121或依據該第二單位屬性形成一第二綠色採購績效表122。並且,該合規分析模組12匯整該等軟體資訊之版權狀態而形成一授權取得資料,且運算該等軟體資訊之部署狀態而形成一安裝部署資料,據此並利用該合規對照資料310比對該授權取得資料及該安裝部署資料中各該軟體資訊之產品名稱及產品版本而形成一合規分析表123,以供獲知未達法令遵循標準、授權不足或偽授權之軟體使用狀況而降低資安風險,達確保資訊使用安全的效果。並且,該介面呈現模組14設有一資訊資產合規儀表板141,以供利用該資訊資產合規儀表板141之一側顯示該資產價值統整表120,而另一側顯示該第一綠色採購績效表121或該第二綠色採購績效表122。The compliance analysis module 12 compiles and counts the amount of the asset data 101 and outputs an asset value summary table 120. At the same time, the compliance analysis module 12 counts the ESG status of the hardware information and based on the first The unit attributes form a first green procurement performance table 121 or a second green procurement performance table 122 is formed based on the second unit attributes. Moreover, the compliance analysis module 12 aggregates the copyright status of the software information to form an authorization acquisition data, and calculates the deployment status of the software information to form an installation deployment data, and uses the compliance comparison data accordingly. 310 Compare the product name and product version of each software information in the authorization acquisition data and the installation and deployment data to form a compliance analysis table 123 to learn the usage status of software that does not meet legal compliance standards, is insufficiently authorized, or is falsely authorized. This reduces information security risks and ensures the security of information use. Moreover, the interface presentation module 14 is provided with an information asset compliance dashboard 141 for use. One side of the information asset compliance dashboard 141 displays the asset value summary table 120, and the other side displays the first green Procurement performance table 121 or the second green procurement performance table 122.

請參閱第2~7圖,其係分別為本新型二較佳實施例之架構圖、流程圖及各示意圖。如圖所示,該自動軟體合規分析之資訊資產管理系統1係執行於一單位主機2及一後台伺服器3中而包含一資料管理模組10、一專案管理模組11、一合規分析模組12、一報表輸出模組13、一介面呈現模組14、一查詢處理模組15、一報修處理模組16、一授權模組30及一後台管理模組31,以供自動合規諸如企業或政府組織之一單位之軟體資產及邏輯管控該單位之硬體資產,而協助該單位之管理人員清楚掌控所有硬體資產之使用狀態及軟體資產之授權狀態,使避免該單位承受因硬體停產無法提供後續服務或誤用盜版軟體等情事而損害單位形象及利益的風險。該資料管理模組10電訊連接該專案管理模組11、該合規分析模組12、該介面呈現模組14、該查詢處理模組15、該報修處理模組16及該授權模組30;該專案管理模組11電訊連接該介面呈現模組14及該查詢處理模組15;該合規分析模組12電訊連接該報表輸出模組13、該介面呈現模組14及該後台管理模組31;該介面呈現模組14電訊連接該報表輸出模組13及該查詢處理模組15,且該授權模組30電訊連接該後台管理模組31。該資料管理模組10設有一對象建置元件100及一資訊匯入元件102,該介面呈現模組14設有一總覽頁面140及一資訊資產合規儀表板141,該總覽頁面140供於系統開啟時顯示複數個總覽資訊,且該總覽頁面140設有一小幫手元件1400,以供該單位之管理人員自行增訂至少一待辦事項及至少一提醒事項之其中至少一者。該查詢處理模組15供該單位之管理人員、單位聯絡人、資產保管者或資產使用者等依權限查詢資料,且該資訊資產管理系統1之運作方式可包含下列步驟。Please refer to Figures 2 to 7, which are respectively the architecture diagram, flow chart and schematic diagrams of the second preferred embodiment of the present invention. As shown in the figure, the automatic software compliance analysis information asset management system 1 is executed on a unit host 2 and a backend server 3 and includes a data management module 10, a project management module 11, and a compliance Analysis module 12, a report output module 13, an interface presentation module 14, a query processing module 15, a repair processing module 16, an authorization module 30 and a backend management module 31 for automatic integration Regulate the software assets and logical control of the unit's hardware assets, such as an enterprise or a government organization, and assist the unit's managers to clearly control the usage status of all hardware assets and the authorization status of the software assets, so as to avoid the unit's suffering The risk of damage to the company's image and interests due to hardware discontinuation, inability to provide follow-up services or misuse of pirated software. The data management module 10 is connected to the project management module 11, the compliance analysis module 12, the interface presentation module 14, the query processing module 15, the repair processing module 16 and the authorization module 30; The project management module 11 is electrically connected to the interface presentation module 14 and the query processing module 15; the compliance analysis module 12 is electrically connected to the report output module 13, the interface presentation module 14 and the backend management module 31; The interface presentation module 14 is electrically connected to the report output module 13 and the query processing module 15, and the authorization module 30 is electrically connected to the backend management module 31. The data management module 10 is provided with an object construction component 100 and an information import component 102. The interface presentation module 14 is provided with an overview page 140 and an information asset compliance dashboard 141. The overview page 140 is provided for system opening. A plurality of overview information is displayed at the same time, and the overview page 140 is provided with a small helper component 1400 for managers of the unit to add at least one of at least one to-do item and at least one reminder item. The query processing module 15 allows the unit's managers, unit liaisons, asset custodians or asset users to query data according to their authority, and the operation method of the information asset management system 1 may include the following steps.

該單位主機2可裝設有一盤點工具,例如Lansweeper軟體,該授權模組30及該後台管理模組31可裝置於該後台伺服器3中,且於步驟S1中,該後台伺服器3之管理員利用該後台管理模組31建置並定期維護一合規對照資料310,以供該合規分析模組12下載儲存並定期更新。其中,該合規對照資料310可包含一產品名稱對照表、一盤點產品對照表及一產品終止對照表,該產品名稱對照表係將原廠每個軟體的產品類別、對應名稱、產品名稱、產品版本、授權採購方案、支援週期終止(End-of-Support, EOS)及生命週期終止(End-of-Life, EOL)等資訊表列清單;該盤點產品對照表係將對應該盤點工具,例如Lansweeper軟體或廠商盤點表單,內的產品名稱、產品版本、授權版本、有效授權數量及軟體部署量等資訊表列清單;該產品終止對照表係將供裝載軟體之硬體的名稱、型號、EOS及EOL等資訊表列清單。步驟S10,當該單位主機2初始化建置該資訊資產管理系統1時,該資料管理模組10係輸出一啟動授權請求予該授權模組30,使該授權模組30產生對應之一啟動金鑰300並反饋予該資料管理模組10,以供為後續該單位啟動該資訊資產管理系統1時作為憑證之用。值得注意的是,該後台管理模組31更可電訊連接至少一原廠伺服設備4而定期掃描諸如Microsoft、Autodesk及Adobe等的原廠產品資料,以檢核該產品名稱對照表及該產品終止對照表之精準性而確保系統合規的運算準確率。The unit host 2 can be installed with an inventory tool, such as Lansweeper software. The authorization module 30 and the backend management module 31 can be installed in the backend server 3, and in step S1, the backend server 3 is managed The operator uses the backend management module 31 to build and regularly maintain a compliance comparison data 310 for the compliance analysis module 12 to download, store and regularly update. Among them, the compliance comparison data 310 may include a product name comparison table, an inventory product comparison table and a product termination comparison table. The product name comparison table is the product category, corresponding name, product name, A list of information such as product versions, authorized purchasing plans, End-of-Support (EOS) and End-of-Life (EOL); this inventory product comparison table will be compared to the corresponding inventory tool. For example, the Lansweeper software or manufacturer inventory form lists information such as product name, product version, authorized version, number of valid licenses, and software deployment volume; the product termination comparison table is the name, model, and number of the hardware that will be used to load the software. List of information such as EOS and EOL. Step S10, when the unit host 2 initializes the establishment of the information asset management system 1, the data management module 10 outputs a startup authorization request to the authorization module 30, causing the authorization module 30 to generate a corresponding startup fee. The key 300 is fed back to the data management module 10 for use as a certificate when the unit subsequently starts the information asset management system 1 . It is worth noting that the backend management module 31 can also connect to at least one original server device 4 by telecommunications and regularly scan original product information such as Microsoft, Autodesk and Adobe to check the product name comparison table and product termination. The accuracy of the comparison table ensures the operational accuracy of the system's compliance.

步驟S2,該單位之管理人員利用該對象建置元件100建置至少一單位基本資料1000,例如單位自身、廠商、客戶及顧問等的基本資料,且該單位基本資料1000係包含一綠色採購廠商資訊、一企業社會責任驗證、一第一單位屬性或一第二單位屬性、及至少一單位聯絡人,例如單位管理人、資產保管人、廠商窗口、客戶及顧問等聯絡人訊息之設定。步驟S20,該管理人員利用該資料管理模組10手動建置對應該單位基本資料1000之一資產資料101,該資產資料101包含複數個硬體資訊、複數個軟體資訊及複數個服務資訊,且各該硬體資訊、各該軟體資訊及各該服務資訊分別設有包含實體設置及雲端設置之一部署狀態、一版權狀態、一ESG狀態及一憑證資料之其中至少一者;或者,若該單位既有一現有設備資料,則步驟S21,該管理人員利用該資訊匯入元件102匯入並自動轉換該現有設備資料形成該資產資料101,以協助該單位快速完成該資產資料101的建置作業而大幅減輕人力的無謂耗費。步驟S22,利用該專案管理模組11建置至少一採購專案,例如虛擬化系統設備、軟體授權與網路設備汰舊換新暨維護一年期、微軟授權乙批或3E採購案等各式軟硬體或服務之購買事件,該採購專案設有採購之至少一該硬體資訊、至少一該軟體資訊、至少一該服務資訊及至少一合約資訊110之其中之一或其組合,且該合約資訊110,例如買賣合約、授權合約及委外合約等分別設有合約起迄日、簽約期數及每期驗收條件。接著,該專案管理模組11將該採購專案中各資訊新增入或更新至該資產資料101中,據此以完善該資產資料101之全面性及系統系,使供後續利用該查詢處理模組15查詢資產資料時,即可一併獲知對應之該採購專案及該合約資訊,進而獲知採購此資產之採購人員及簽約人員等相關訊息。In step S2, the management personnel of the unit use the object construction component 100 to build at least one unit basic information 1000, such as the basic information of the unit itself, manufacturers, customers, consultants, etc., and the unit basic information 1000 includes a green procurement manufacturer. Information, a corporate social responsibility verification, a first unit attribute or a second unit attribute, and the setting of at least one unit contact person, such as unit manager, asset custodian, manufacturer window, customer and consultant, and other contact information. Step S20, the manager uses the data management module 10 to manually create an asset data 101 corresponding to the unit's basic data 1000. The asset data 101 includes a plurality of hardware information, a plurality of software information and a plurality of service information, and Each of the hardware information, each of the software information and each of the service information respectively has at least one of a deployment status, a copyright status, an ESG status and a certificate information including physical settings and cloud settings; or, if the The unit already has existing equipment data, then in step S21, the manager uses the information import component 102 to import and automatically convert the existing equipment data to form the asset data 101 to assist the unit in quickly completing the establishment of the asset data 101. And significantly reduce the unnecessary consumption of manpower. Step S22, use the project management module 11 to create at least one procurement project, such as virtualization system equipment, software authorization and network equipment replacement and maintenance for one year, Microsoft authorization batch B or 3E procurement projects, etc. For a purchase event of software, hardware or services, the procurement project includes purchasing one or a combination of at least one of the hardware information, at least one of the software information, at least one of the service information and at least one of the contract information 110, and the Contract information 110, such as sales and purchase contracts, authorization contracts, and outsourcing contracts, respectively have contract start and end dates, number of contract periods, and acceptance conditions for each period. Then, the project management module 11 adds or updates each information in the procurement project to the asset data 101, thereby improving the comprehensiveness and system of the asset data 101 for subsequent use of the query processing module. When Group 15 queries asset information, it can obtain the corresponding procurement project and contract information together, and further obtain relevant information such as the purchasing personnel and contracting personnel who purchased this asset.

步驟S3,該合規分析模組12匯整並統計該資產資料101之金額而輸出一資產價值統整表120,該資產價值統整表120包含軟硬體資產總金額、硬體資產總金額、軟體資產總金額、租賃總金額、逾N年硬體資產、逾N年軟體資產等數據,以供該單位充分掌握所以有形無形之該等硬體資訊、該等軟體資訊及該等服務資訊等資源的運用狀況,進而允許該單位後續可用最適當的成本規畫採購策略。步驟S4,該合規分析模組12統計該等硬體資訊之ESG狀態而獲得該單位之綠色採購總金額、各項目類別綠色採購金額及非綠色採購項目原因等數據,並計算綠色採購總金額佔硬體資產總金額的百分比而形成一綠色採購績效值,以供於步驟S40中,依據該等硬體資訊中該第一單位屬性,例如企業,形成一第一綠色採購績效表121;或於步驟S41中,依據該第二單位屬性,例如政府組織,形成一第二綠色採購績效表122,且該合規分析模組12係更以一指定比率,例如政府公告的指定綠色採購比率來評比該百分比而輸出一評等,例如優等、甲等、乙等及丙等。In step S3, the compliance analysis module 12 compiles and counts the amount of the asset data 101 and outputs an asset value integration table 120. The asset value integration table 120 includes the total amount of software and hardware assets and the total amount of hardware assets. , the total amount of software assets, the total amount of leases, hardware assets over N years, software assets over N years and other data, so that the unit can fully grasp all tangible and intangible hardware information, software information and service information. and other resource utilization status, thereby allowing the unit to use the most appropriate cost planning procurement strategy in the future. In step S4, the compliance analysis module 12 counts the ESG status of the hardware information to obtain the total green procurement amount of the unit, the green procurement amount of each project category, and the reasons for non-green procurement projects, and calculates the total green procurement amount. A green procurement performance value is formed as a percentage of the total amount of hardware assets, for use in step S40 to form a first green procurement performance table 121 based on the attributes of the first unit in the hardware information, such as the enterprise; or In step S41, a second green procurement performance table 122 is formed based on the attributes of the second unit, such as a government organization, and the compliance analysis module 12 further uses a specified ratio, such as the specified green procurement ratio announced by the government. The percentage is evaluated and a grade is output, such as excellent, first grade, second grade, and third grade.

並且,該資訊資產合規儀表板141對應該第一單位屬性及該第二單位屬性係至少設有兩板模,其中一板模設有一五葉草圖示元件1210及一第一燈號元件1211,而另一板模設有一四葉草圖示元件1220及一第二燈號元件1221。步驟S5,該介面呈現模組14接收該資產價值統整表120並利用該資訊資產合規儀表板141之一側顯示其軟硬體資產總金額、硬體資產總金額、軟體資產總金額、租賃總金額、逾N年硬體資產、逾N年軟體資產等數據,且步驟S50,該介面呈現模組14判斷所接收之綠色採購績效表為該第一綠色採購績效表121或該第二綠色採購績效表122?若為設有該第一單位屬性之該第一綠色採購績效表121時,步驟S51,該資訊資產合規儀表板141顯示該第一綠色採購績效表121中該綠色採購績效值,如圖6中該五葉草圖示元件旁的88%數值,並利用該五葉草圖示元件1210之葉片多寡及該第一燈號元件1211顯示該單位綠色採購績效之百分比級數,以供透過該五葉草圖示元件1210及該第一燈號元件1211圖形化視覺呈現該單位綠色採購績效,同時,亦顯示非綠色採購項目原因,例如執行業務需要、產品規格不符、目前無環保產品等而加速該管理人員對非綠色採購績效不足的理解度。反之,若為設有該第二單位屬性之該第二綠色採購績效表122時,步驟S52,該資訊資產合規儀表板141顯示該第二綠色採購績效表122中該綠色採購績效值,如圖7中該四葉草圖示元件旁的96.4數值,並利用該四葉草圖示元件1220之葉片多寡顯示該單位綠色採購績效之百分比級數的同時,利用該第二燈號元件1221顯示該評等,據此以透過該四葉草圖示元件1220及該第二燈號元件1221圖形化視覺呈現該單位綠色採購績效,同時,亦顯示非綠色採購項目原因而加速該管理人員對非綠色採購績效不足的理解度。當然,該資訊資產合規儀表板141於呈現該綠色採購績效值時,除顯示88%或96.4等數值外,亦可同步顯示該評等或進一步整合顯示全產品類別採購績效級別等資訊,於此不另舉例贅述。Moreover, the information asset compliance dashboard 141 is provided with at least two templates corresponding to the first unit attribute and the second unit attribute, one of which is provided with a five-leaf clover icon component 1210 and a first light signal component 1211 , and another template is provided with a four-leaf clover icon component 1220 and a second light signal component 1221. In step S5, the interface presentation module 14 receives the asset value summary table 120 and uses one side of the information asset compliance dashboard 141 to display the total amount of software and hardware assets, the total amount of hardware assets, the total amount of software assets, The total amount of lease, hardware assets over N years, software assets over N years and other data, and in step S50, the interface presentation module 14 determines that the received green procurement performance table is the first green procurement performance table 121 or the second Green Procurement Performance Table 122? If the first green procurement performance table 121 is provided with the first unit attribute, in step S51, the information asset compliance dashboard 141 displays the green procurement performance value in the first green procurement performance table 121, as shown in Figure 6 The 88% value next to the five-leaf clover icon element is used, and the number of leaves of the five-leaf clover icon element 1210 and the first light signal element 1211 are used to display the percentage level of the unit's green procurement performance, so as to use the five-leaf clover The graphical component 1210 and the first light component 1211 graphically and visually present the green procurement performance of the unit. At the same time, they also display the reasons for non-green procurement projects, such as business execution needs, product specifications incompatible, and currently no environmentally friendly products, etc. to speed up the management. Personnel understanding of non-green procurement performance deficiencies. On the contrary, if the second green procurement performance table 122 is provided with the second unit attribute, in step S52, the information asset compliance dashboard 141 displays the green procurement performance value in the second green procurement performance table 122, such as The 96.4 value next to the four-leaf clover graphic component in Figure 7 uses the number of leaves of the four-leaf clover graphic component 1220 to display the percentage level of the unit's green procurement performance, and at the same time uses the second light component 1221 to display the evaluation. etc. Accordingly, the green procurement performance of the unit is graphically presented through the four-leaf clover graphic component 1220 and the second light component 1221. At the same time, the reasons for the non-green procurement projects are also displayed to accelerate the management personnel's assessment of the non-green procurement performance. Insufficient understanding. Of course, when the information asset compliance dashboard 141 presents the green procurement performance value, in addition to displaying values such as 88% or 96.4, it can also simultaneously display the rating or further integrate and display information such as the procurement performance level of the entire product category. No further examples will be given here.

步驟S6,該合規分析模組12匯整該等軟體資訊之版權狀態而形成一授權取得資料,且無論該單位主機2是否裝設有該盤點工具,該合規分析模組12皆運算該等軟體資訊之部署狀態而形成一安裝部署資料,且該安裝部署資料包含裝設於一該硬體資訊中或置放於雲端網路中之各該軟體資訊使用狀態,據此以達全面的資產合規作業而大幅提升資安防範級數。步驟S60,該合規分析模組12比對該授權取得資料中各該軟體資訊之產品類別、對應名稱、產品名稱及產品版本與該產品名稱對照表所對應的名稱是否一致;及比對該安裝部署資料中各該軟體資訊之產品名稱及產品版本與該盤點產品對照表所對應的名稱是否一致?若是,步驟S61,形成一合規分析表123,以供該單位獲知未達法令遵循標準、授權不足或偽授權之軟體使用狀況而達大幅降低資安風險的效果。In step S6, the compliance analysis module 12 aggregates the copyright status of the software information to form an authorized acquisition data, and regardless of whether the unit host 2 is equipped with the inventory tool, the compliance analysis module 12 calculates the The deployment status of the software information forms an installation deployment data, and the installation deployment data includes the usage status of each software information installed in the hardware information or placed in the cloud network, thereby achieving a comprehensive Asset compliance operations significantly improve the level of information security prevention. Step S60, the compliance analysis module 12 compares the product category, corresponding name, product name and product version of each software information in the authorization acquisition data with the name corresponding to the product name comparison table; and compares the Are the product names and product versions of the software information in the installation and deployment data consistent with the names corresponding to the inventory product comparison table? If so, in step S61, a compliance analysis table 123 is formed so that the unit can learn the usage status of the software that does not meet legal compliance standards, is insufficiently authorized or has false authorization, thereby achieving the effect of significantly reducing information security risks.

步驟S7,該報表輸出模組13解析該合規分析表123形成一授權EOS版權提醒表及一安裝EOS版權提醒表,同時,匯整該資產價值統整表120、該第一或第二綠色採購績效表121或122及該合規分析表123並自動運算形成一ESG面向報表及一綠色採購政策符合性報表後,定期透過E-mail或即時訊息傳送此等報表予對應之管理人員或該單位聯絡人,其中,該ESG面向報表可包含如圖6、7中利用柱狀圖呈現之綠色採購項目分類、及供應商分析數據等,該綠色採購政府符合性報表可包含如圖6、7中利用柱狀圖呈現之非綠色採購項目原因、及舒鉰治理分析數據等。進一步地,如圖5所示,該報表輸出模組13更自動利用該介面呈現模組14於系統開啟時所呈現之該總覽頁面140中顯示對應該授權EOS版權提醒表或該安裝EOS版權提醒表之一提醒訊號130。順帶一提的是,該管理人員或該單位聯絡人於接收上述任何報表時,皆可隨時利用該小幫手元件1400以一附件形式新增形成一該待辦事項或一該提醒事項,以協助輕鬆進行資訊資產管理作業而提升作業效率及管理成效。Step S7, the report output module 13 parses the compliance analysis table 123 to form an authorized EOS copyright reminder table and an installed EOS copyright reminder table, and at the same time, compiles the asset value integration table 120, the first or second green After the procurement performance table 121 or 122 and the compliance analysis table 123 are automatically calculated to form an ESG-oriented report and a green procurement policy compliance report, these reports are regularly sent to the corresponding management personnel or the corresponding management personnel through e-mail or instant messaging. Unit contact person, among which, the ESG-oriented report can include green procurement project classification and supplier analysis data presented using bar charts as shown in Figures 6 and 7, and the green procurement government compliance report can include Figures 6 and 7 The reasons for non-green procurement projects and the analysis data of Shuxing governance are presented using bar charts. Further, as shown in FIG. 5 , the report output module 13 automatically uses the interface presentation module 14 to display the corresponding authorized EOS copyright reminder table or the installed EOS copyright reminder in the overview page 140 presented when the system is started. Table 1 Reminder Signal 130. By the way, when receiving any of the above reports, the manager or the contact person of the unit can use the helper component 1400 to add a to-do item or a reminder item in the form of an attachment at any time to assist Easily perform information asset management operations to improve operational efficiency and management effectiveness.

於本實施例中,步驟S8,該合規分析模組12匯整並分析該資產資料101而獲知對應一該硬體資訊記錄有複數筆重複數據時,比對該等重複數據而輸出一異動訊息予對應之該單位聯絡人,以即時通知該單位聯絡人確認該硬體資訊中組件異動異常的狀況並獲得盡速修正該等重複數據的效果,進而降低資料錯誤率並提升資產管理的正確性。步驟S9,該專案管理模組11依據該合約資訊110匯整對應之該資產資料並檢驗合約起迄日,以於合約臨近迄日時輸出附有該合約資訊之一續約資訊111,使透過該介面呈現模組顯示,並通知對應之該單位聯絡人進行續約作業。當該管理人員、該單位聯絡人、該資產保管者或該資產使用者欲報修該硬體資訊、該軟體資訊或該服務資訊時,步驟S10,利用該報修處理模組16輸出一報修請求160予對應之該單位聯絡人而進行線上報修作業,使一次提供正確且充份的報修需求資訊而提升資產維護效率。In this embodiment, in step S8, the compliance analysis module 12 compiles and analyzes the asset data 101 and learns that there are a plurality of duplicate data corresponding to the hardware information record, and compares the duplicate data and outputs a change. Send a message to the corresponding contact person of the unit to immediately notify the contact person of the unit to confirm the abnormal component movement in the hardware information and obtain the effect of correcting the duplicate data as soon as possible, thus reducing the data error rate and improving the accuracy of asset management. sex. In step S9, the project management module 11 compiles the corresponding asset data based on the contract information 110 and checks the contract start and end dates, so as to output the renewal information 111 with the contract information when the contract is approaching the end date, so that through the The interface displays the module display and notifies the corresponding contact person of the unit to perform the contract renewal operation. When the manager, the unit contact person, the asset custodian or the asset user wants to report the hardware information, the software information or the service information, step S10 uses the repair processing module 16 to output a repair request 160 Conduct online repair reports to the corresponding contact person of the unit, so as to provide correct and sufficient repair request information at one time and improve asset maintenance efficiency.

其中,當利用該查詢管理模組15查詢資料時,係可任意依據資產資訊、專案資訊、合約資訊、單位聯絡人、資產保管者及資產使用者等查知相關資產使用狀況、部署狀態及合規狀況等,且該報表輸出模組亦可依據該單位需求不同而自動輸出客製化的分析報告,系統可供進行之資料查詢及資訊呈現方式實族繁不及備載,於此不另贅述。並且,本新型所述之模組,係透過硬體或軟體輔以硬體之方式予以實現,例如該資料管理模組10、該專案管理模組11、該合規分析模組12、該報表輸出模組13、該介面呈現模組14、該查詢處理模組15、該報修處理模組16、該授權模組30及該後台管理模組31等之定義本質上即指為諸如CPU、微型處理器、記憶體、訊號傳輸器或顯示處理器等各種硬體設備之集成,並輔以軟體程序予以實現之技術特徵。Among them, when the query management module 15 is used to query data, the system can arbitrarily check the usage status, deployment status and contract status of relevant assets based on asset information, project information, contract information, unit contacts, asset custodians, asset users, etc. Regulation status, etc., and the report output module can also automatically output customized analysis reports according to the different needs of the unit. The data query and information presentation methods available for the system are extremely complicated and will not be elaborated here. . Moreover, the modules described in this model are implemented through hardware or software supplemented by hardware, such as the data management module 10, the project management module 11, the compliance analysis module 12, and the report The definitions of the output module 13, the interface presentation module 14, the query processing module 15, the repair processing module 16, the authorization module 30 and the background management module 31 essentially refer to components such as CPU, micro The integration of various hardware devices such as processors, memories, signal transmitters or display processors, and the technical characteristics of implementation with software programs.

惟,以上所述者,僅為本新型之較佳實施例而已,並非用以限定本新型實施之範圍;故在不脫離本新型之精神與範圍下所作之均等變化與修飾,皆應涵蓋於本新型之專利範圍內。However, the above are only preferred embodiments of the present invention and are not intended to limit the scope of implementation of the present invention; therefore, equal changes and modifications made without departing from the spirit and scope of the present invention should be included in Within the patent scope of this new model.

1:資訊資產管理系統1: Information asset management system

10:資料管理模組10:Data management module

100:對象建置元件100:Object construction component

1000:單位基本資料1000: Basic information of the unit

101:資產資料101:Asset information

102:資訊匯入元件102:Information import component

11:專案管理模組11:Project management module

110:合約資訊110:Contract information

111:續約資訊111:Contract renewal information

12:合規分析模組12: Compliance analysis module

120:資產價值統整表120: Asset value summary table

121:第一綠色採購績效表121:First Green Procurement Performance Table

1210:五葉草圖示元件1210: Five-leaf clover icon component

1211:第一燈號元件1211: The first signal component

122:第二綠色採購績效表122:Second Green Procurement Performance Table

1220:四葉草圖示元件1220: Four-leaf clover icon component

1221:第二燈號元件1221: Second light component

123:合規分析表123: Compliance Analysis Form

13:報表輸出模組13: Report output module

130:提醒訊號130: Reminder signal

14:介面呈現模組14:Interface rendering module

140:總覽頁面140:Overview page

1400:小幫手元件1400: little helper component

141:資訊資產合規儀表板141: Information Asset Compliance Dashboard

15:查詢處理模組15: Query processing module

16:報修處理模組16:Repair processing module

160:報修請求160:Repair request

2:單位主機2: Unit host

3:後台伺服器3:Backend server

30:授權模組30: Authorized module

300:啟動金鑰300:Startup key

31:後台管理模組31:Backend management module

310:合規對照資料310: Compliance control information

4:原廠伺服設備4:Original servo equipment

S1~S9、S90:步驟S1~S9, S90: steps

第1圖,為本新型一較佳實施例之架構圖。 第2圖,為本新型二較佳實施例之架構圖。 第3圖,為本新型二較佳實施例之系統架構示意圖。 第4A、4B、4C、4D、4E圖,為本新型二較佳實施例之流程圖。 第5圖,為本新型二較佳實施例之總覽頁面示意圖。 第6圖,為本新型二較佳實施例之資訊資產合規儀表板示意圖。 第7圖,為本新型二較佳實施例之四葉草圖示元件之示意圖。 第8圖,為本新型二較佳實施例之報修請求之示意圖。Figure 1 is a structural diagram of a preferred embodiment of the present invention. Figure 2 is a structural diagram of the second preferred embodiment of the present invention. Figure 3 is a schematic diagram of the system architecture of the second preferred embodiment of the present invention. Figures 4A, 4B, 4C, 4D, and 4E are flow charts of the second preferred embodiment of the present invention. Figure 5 is a schematic diagram of the overview page of the second preferred embodiment of the present invention. Figure 6 is a schematic diagram of the information asset compliance dashboard of the second preferred embodiment of the present invention. Figure 7 is a schematic diagram of the four-leaf clover graphic element of the second preferred embodiment of the present invention. Figure 8 is a schematic diagram of a repair request according to the second preferred embodiment of the present invention.

1:資訊資產管理系統 1: Information asset management system

10:資料管理模組 10:Data management module

1000:單位基本資料 1000: Basic information of the unit

101:資產資料 101:Asset information

12:合規分析模組 12: Compliance analysis module

120:資產價值統整表 120: Asset value summary table

121:第一綠色採購績效表 121:First Green Procurement Performance Table

122:第二綠色採購績效表 122:Second Green Procurement Performance Table

123:合規分析表 123: Compliance Analysis Form

14:介面呈現模組 14:Interface rendering module

141:資訊資產合規儀表板 141: Information Asset Compliance Dashboard

310:合規對照資料 310: Compliance control information

Claims (10)

一種自動軟體合規分析之資訊資產管理系統,係供自動合規及管控一單位之軟硬體資產而執行於一單位主機及一後台伺服器中,其包含:一資料管理模組,係供建置至少一單位基本資料及對應該單位基本資料之一資產資料,且該單位基本資料包含一綠色採購廠商資訊、一企業社會責任驗證、一第一單位屬性或一第二單位屬性、及至少一單位聯絡人之設定,該資產資料包含複數個硬體資訊、複數個軟體資訊及複數個服務資訊;其中,各該硬體資訊、各該軟體資訊及各該服務資訊分別設有一部署狀態、一版權狀態、一ESG狀態之其中至少一者;一合規分析模組,內存有一合規對照資料並電訊連接該資料管理模組,且該合規對照資料設有產品名稱、產品版本、授權方案、採購數量、有效授權數量及軟體部署量;該合規分析模組匯整並統計該資產資料之金額而輸出一資產價值統整表,同時,統計該等硬體資訊之ESG狀態而依據該第一單位屬性形成一第一綠色採購績效表或依據該第二單位屬性形成一第二綠色採購績效表;該合規分析模組匯整該等軟體資訊之版權狀態而形成一授權取得資料,且運算該等軟體資訊之部署狀態而形成一安裝部署資料,據此並利用該合規對照資料比對該授權取得資料及該安裝部署資料中各該軟體資訊之產品名稱及產品版本而形成一合規分析表,以供獲知未達法令遵循標準、授權不足或偽授權之軟體使用狀況而降低資安風險;及一介面呈現模組,係電訊連接該資料管理模組及該合規分析模組並設有一資訊資產合規儀表板,該介面呈現模組利用該資訊資產合規儀表板之一側顯 示該資產價值統整表而另一側顯示該第一綠色採購績效表或該第二綠色採購績效表。 An information asset management system for automatic software compliance analysis, which is used for automatic compliance and management of a unit's software and hardware assets and is executed on a unit's host computer and a backend server. It includes: a data management module for Create at least one unit basic information and one asset data corresponding to the unit's basic information, and the unit's basic information includes a green procurement manufacturer information, a corporate social responsibility verification, a first unit attribute or a second unit attribute, and at least For the setting of a unit contact person, the asset data includes a plurality of hardware information, a plurality of software information, and a plurality of service information; among which, each hardware information, each software information, and each service information have a deployment status, At least one of a copyright status and an ESG status; a compliance analysis module that stores a compliance comparison data and is connected to the data management module via telecommunications, and the compliance comparison data is provided with product name, product version, authorization plan, purchase quantity, valid authorization quantity and software deployment quantity; the compliance analysis module compiles and counts the amount of the asset data and outputs an asset value summary table, and at the same time, counts the ESG status of the hardware information based on The first unit attribute forms a first green procurement performance table or a second green procurement performance table is formed based on the second unit attribute; the compliance analysis module aggregates the copyright status of the software information to form an authorized acquisition data , and calculate the deployment status of the software information to form an installation deployment data, and use the compliance comparison data to compare the authorization acquisition data with the product name and product version of each software information in the installation deployment data. a compliance analysis table for understanding the usage status of software that does not meet legal compliance standards, insufficient authorization or false authorization to reduce information security risks; and an interface presentation module that is a telecommunications connection between the data management module and the compliance analysis The module also has an information asset compliance dashboard, and the interface presents the module using one of the side displays of the information asset compliance dashboard. The asset value summary table is displayed and the other side displays the first green procurement performance table or the second green procurement performance table. 如請求項1所述之自動軟體合規分析之資訊資產管理系統,其中,該合規對照資料係包含一產品名稱對照表、一盤點產品對照表及一產品終止對照表,該產品名稱對照表係將原廠每個軟體的產品類別、對應名稱、產品名稱、產品版本、授權採購方案、支援週期終止及生命週期終止之資訊表列清單;該盤點產品對照表係將對應一盤點工具內的產品名稱、產品版本、授權版本、有效授權數量及軟體部署量之資訊表列清單;該產品終止對照表係將供裝載軟體之硬體的名稱、型號、支援週期終止及生命週期終止之資訊表列清單。 The information asset management system for automatic software compliance analysis as described in request item 1, wherein the compliance comparison data includes a product name comparison table, an inventory product comparison table and a product termination comparison table, and the product name comparison table It is a list of the product category, corresponding name, product name, product version, authorized purchase plan, end of support cycle and end of life cycle of each software from the original manufacturer; the inventory product comparison table will correspond to the information in an inventory tool A list of information on product name, product version, authorized version, number of valid licenses, and software deployment volume; the product termination comparison table is an information table of the name, model, end of support period, and end of life cycle of the hardware that will be used to load the software. Make lists. 如請求項2所述之自動軟體合規分析之資訊資產管理系統,其中,該合規分析模組係比對該授權取得資料中各該軟體資訊之產品類別、對應名稱、產品名稱及產品版本與該產品名稱對照表所對應的名稱是否一致;及比對該安裝部署資料中各該軟體資訊之產品名稱及產品版本與該盤點產品對照表所對應的名稱是否一致而形成該合規分析表,且該合規分析表包含一授權EOS版權提醒表及一安裝EOS版權提醒表。 An information asset management system for automatic software compliance analysis as described in request item 2, wherein the compliance analysis module compares the product category, corresponding name, product name and product version of each software information in the authorized data. Whether the name corresponding to the product name comparison table is consistent; and whether the product name and product version of each software information in the installation and deployment data are consistent with the name corresponding to the inventory product comparison table to form the compliance analysis table , and the compliance analysis table includes an authorized EOS copyright reminder table and an installed EOS copyright reminder table. 如請求項1所述之自動軟體合規分析之資訊資產管理系統,其中,該資產價值統整表係包含該單位之硬體資產總金額,且該合規分析模組統計該等硬體資訊之ESG狀態而形成該第一或第二綠色採購績效表時,係獲知該單位之綠色採購總金額、各項目類別綠色採購金額及非綠色採購項目原因之數據,並進一步計算綠色採購總金額佔硬體資產總金額之百分比而形成一綠色採購績效值,而於該第一綠色採購績效表設有該第一單位屬性時,該資訊資產合規儀表板利用一五葉草圖示元件之葉片多寡及一第一燈號元件顯示該單位綠色 採購績效之百分比級數;當該第二綠色採購績效表設有該第二單位屬性時,該合規分析模組係更以一指定比率評比該百分比而輸出一評等,以利用一四葉草圖示元件之葉片多寡顯示該單位綠色採購績效之百分比級數的同時,利用一第二燈號元件顯示該評等。 An information asset management system for automatic software compliance analysis as described in request item 1, wherein the asset value integration table contains the total amount of hardware assets of the unit, and the compliance analysis module counts the hardware information When forming the first or second green procurement performance table according to the ESG status of the unit, the data on the total amount of green procurement, the amount of green procurement of each project category, and the reasons for non-green procurement items are obtained, and the proportion of the total amount of green procurement to the total amount is further calculated. A green procurement performance value is formed as a percentage of the total amount of hardware assets, and when the first green procurement performance table is provided with the first unit attribute, the information asset compliance dashboard uses the leaves of a five-leaf clover icon element The quantity and a first light element show the unit green The percentage level of procurement performance; when the second green procurement performance table is provided with the second unit attribute, the compliance analysis module further evaluates the percentage with a specified ratio and outputs a rating to utilize a four-leaf The number of blades of the sketch display component displays the percentage level of the unit's green procurement performance, and at the same time, a second light component is used to display the rating. 如請求項1所述之自動軟體合規分析之資訊資產管理系統,其中,該合規分析模組匯整並分析該資產資料而獲知對應一該硬體資訊記錄有複數筆重複數據時,比對該等重複數據而輸出一異動訊息予對應之該單位聯絡人,以即時通知該單位聯絡人確認該硬體資訊中組件異動異常的狀況並獲得盡速修正該等重複數據的效果。 The information asset management system for automatic software compliance analysis as described in request item 1, wherein the compliance analysis module collects and analyzes the asset data and learns that there are multiple pieces of duplicate data corresponding to the hardware information record. For the duplicate data, a change message is output to the corresponding contact person of the unit, so as to immediately notify the contact person of the unit to confirm the abnormal status of component changes in the hardware information and obtain the effect of correcting the duplicate data as soon as possible. 如請求項1所述之自動軟體合規分析之資訊資產管理系統,其中,該介面呈現模組係設有一總覽頁面,以供於系統開啟時顯示複數個總覽資訊,且該總覽頁面設有一小幫手元件,以供自行增訂一待辦事項及至少一提醒事項之其中至少一者。 An information asset management system for automatic software compliance analysis as described in request item 1, wherein the interface presentation module is provided with an overview page for displaying a plurality of overview information when the system is started, and the overview page is provided with a small The helper component is used to add at least one of a to-do item and at least one reminder item by oneself. 如請求項1所述之自動軟體合規分析之資訊資產管理系統,其中,該資料管理模組係設有一對象建置元件及一資訊匯入元件,該對象建置元件供該單位建置該單位基本資料,該資訊匯入元件供該單位匯入一現有設備資料並自動轉換形成該資產資料,以協助該單位快速建置該資產資料。 The information asset management system for automatic software compliance analysis as described in request item 1, wherein the data management module is provided with an object construction component and an information import component, and the object construction component is used by the unit to build the Basic data of the unit. This information import component allows the unit to import an existing equipment data and automatically convert it into the asset data to help the unit quickly build the asset data. 如請求項1所述之自動軟體合規分析之資訊資產管理系統,更包含一專案管理模組,係電訊連接該資料管理模組及該介面呈現模組,該專案管理模組供建置至少一採購專案,該採購專案設有採購之至少一該硬體資訊、至少一該軟體資訊、至少一該服務資訊及至少一合約資訊之其中之一或其組合,且該合約資訊設有合約起迄日、簽約期數及每期驗收條件;該專案管理模組依據 該合約資訊匯整對應之該資產資料並檢驗合約起迄日,以於合約臨近迄日時輸出附有該合約資訊之一續約資訊。 The information asset management system for automatic software compliance analysis as described in claim 1 further includes a project management module that is connected to the data management module and the interface presentation module via telecommunications. The project management module is used to build at least A procurement project, the procurement project includes one or a combination of at least one of the hardware information, at least one of the software information, at least one of the service information and at least one of the contract information, and the contract information has a contract starting point Expiry date, number of contract phases and acceptance conditions for each phase; the project management module is based on The contract information compiles the corresponding asset data and checks the contract start and end dates, so as to output renewal information with the contract information when the contract is approaching the expiration date. 如請求項1所述之自動軟體合規分析之資訊資產管理系統,更包含一報表輸出模組、一查詢處理模組及一報修處理模組,該報表輸出模組電訊連接該合規分析模組及該介面呈現模組,該查詢處理模組電訊連接該資料管理模組及該介面呈現模組,且該報修處理模組電訊連接該資料管理模組;該報表輸出模組解析該合規分析表形成一授權EOS版權提醒表及一安裝EOS版權提醒表,同時,匯整該資產價值統整表、該綠色採購績效表及該合規分析表並運算形成一ESG面向報表及一綠色採購政策符合性報表;該查詢處理模組供一使用者依權限查詢資料,且欲報修該硬體資訊、該軟體資訊或該服務資訊時,係利用該報修處理模組輸出一報修請求予對應之該單位聯絡人而進行線上報修作業。 The information asset management system for automatic software compliance analysis as described in claim 1 further includes a report output module, a query processing module and a repair processing module. The report output module is connected to the compliance analysis module via telecommunications. The group and the interface presentation module are electrically connected to the data management module and the interface presentation module, and the repair processing module is electrically connected to the data management module; the report output module parses the compliance The analysis table forms an authorized EOS copyright reminder table and an installed EOS copyright reminder table. At the same time, the asset value summary table, the green procurement performance table and the compliance analysis table are compiled and calculated to form an ESG-oriented report and a green procurement Policy compliance report; the query processing module allows a user to query data according to authority, and when he wants to report the hardware information, the software information or the service information, the repair processing module is used to output a repair request to the corresponding user. Contact the unit to conduct online repair reporting. 如請求項1所述之自動軟體合規分析之資訊資產管理系統,更包含一授權模組及一後台管理模組,該授權模組電訊連接該資料管理模組及該後台管理模組,且該後台管理模組電訊連接該合規分析模組;該授權模組產生一啟動金鑰予該資料管理模組,以供該單位啟動該資訊資產管理系統時作為憑證之用,且該後台管理模組則供建置並定期維護該合規對照資料,以供該合規分析模組下載並定期更新該合規對照資料。 The information asset management system for automatic software compliance analysis as described in request item 1 further includes an authorization module and a backend management module, the authorization module is electrically connected to the data management module and the backend management module, and The backend management module is connected to the compliance analysis module via telecommunications; the authorization module generates an activation key to the data management module for use as a certificate when the unit activates the information asset management system, and the backend management The module is used to build and regularly maintain the compliance comparison data, so that the compliance analysis module can download and regularly update the compliance comparison data.
TW112206054U 2022-09-30 2022-09-30 Information asset management system for automatic software compliance analysis TWM646838U (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW112206054U TWM646838U (en) 2022-09-30 2022-09-30 Information asset management system for automatic software compliance analysis

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW112206054U TWM646838U (en) 2022-09-30 2022-09-30 Information asset management system for automatic software compliance analysis

Publications (1)

Publication Number Publication Date
TWM646838U true TWM646838U (en) 2023-10-01

Family

ID=89856657

Family Applications (1)

Application Number Title Priority Date Filing Date
TW112206054U TWM646838U (en) 2022-09-30 2022-09-30 Information asset management system for automatic software compliance analysis

Country Status (1)

Country Link
TW (1) TWM646838U (en)

Similar Documents

Publication Publication Date Title
Sabbaghi et al. The current status of the consumer electronics repair industry in the US: A survey-based study
Talamo et al. Knowledge management and information tools for building maintenance and facility management
Haug et al. The costs of poor data quality
US20030135481A1 (en) Rules based method and system for project performance monitoring
US20020099638A1 (en) Method and system for electronically communicating with suppliers, such as under an electronic auction
CA2894046A1 (en) Method and system for technology risk and control
Koronios et al. A data quality model for asset management in engineering organisations
AU2020100138A4 (en) System and Method for Identifying, Analysing and Managing Risk for Products in the supply network
US20080091676A1 (en) System and method of automatic data search to determine compliance with an international standard
US20220084044A1 (en) Contract management, compliance and financial reporting system and method
CA3208723A1 (en) System and method for managing remote assets with data aggregation
Kajba et al. Business process reengineering–process optimization of boutique production SME
US20080027834A1 (en) Systems and methods for inventory management
JP2004021602A (en) Product recycle management system and method
KR20070104493A (en) Audit information system based on erp, and method of management the same
TWM646838U (en) Information asset management system for automatic software compliance analysis
US20110276362A1 (en) Auditing client - service provider relationships with reference to internal controls assessments
Zu et al. An empirical model of supplier relation and management for better quality
CN113806391A (en) Method and device for constructing topic model based on data warehouse and storage medium
TW202113734A (en) Industrial waste cleaning platform and service integration method of platform which can quickly match the suitable cleaning treatment industry through the cleaning platform to increase the willingness of the business organization to legally clean waste
US20110276912A1 (en) Automating internal controls assessments for outsourced operations
Suciu et al. LCC criteria for procurement of ITC goods and services: The need for a flexible approach
Abbaszadegan Instantaneous project controls: Current status, state of the art, benefits, and strategies
AU2007100428A4 (en) Ipro LiVe On-line Compliance and Verification system
JP2003296475A (en) Equipment management information provision system and its method