TechKnowSurge
CompTIA Tech+ 3.3 CompTIA Tech+ 3.6 CompTIA A+ Core 2 1.7 CompTIA A+ Core 2 4.6 CompTIA Tech+ 6.3 CompTIA A+ Core 2 2.1 CompTIA A+ Core 2 4.2
VideoComputeFree

Software Considerations for Business

Selecting software for a business environment requires evaluating far more than basic system requirements, including impacts to device performance, network stability, operations, and company-wide policy compliance. Shadow IT — when users or departments install unauthorized software outside of IT oversight — compounds these risks and can undermine organizational consistency and security.

Complete this video to capture a CTF flag worth 1 point.

About this video

Evaluating software for a business environment demands a broader perspective than simply confirming that a device meets published system requirements. Available CPU, RAM, and storage are shared across all applications running on a machine, meaning a system that technically qualifies on paper may not have sufficient resources left to run a new application reliably alongside existing workloads. This device-level impact is just the starting point of a thorough assessment. Beyond individual devices, software decisions ripple outward to the broader network and organizational operations. A single application that introduces a security vulnerability can expose every device on the network to risk, while cloud-based tools accessed by large numbers of users simultaneously can saturate external bandwidth and degrade performance across the organization. Operationally, new software may require departments to restructure workflows, and it creates ongoing support obligations for IT teams managing diverse environments across many machines. At the highest level, software choices must align with business policies, customer requirements, and regulatory obligations. A fragmented approach — where different departments independently adopt different tools for the same function — creates coordination breakdowns, as illustrated when multiple incompatible messaging platforms prevent timely company-wide communication during an incident. Reaching a unified, leadership-supported decision and enforcing it consistently across the organization is essential to avoiding these outcomes. Shadow IT, the practice of users or departments installing and using software without going through official IT approval, is a persistent challenge that undermines these efforts. It often emerges when IT is perceived as an obstacle rather than an enabler, which points to the importance of IT functioning as a facilitator of business needs rather than simply a gatekeeper. Balancing individual and departmental requirements against organization-wide standards is critical to reducing unauthorized software adoption and maintaining a secure, manageable environment.

What you'll learn

What's covered

Business Software Considerations

Aligned to

CompTIA Tech+
3.3 Explain the purpose and proper use of software.
3.6 Compare and contrast general application concepts and uses.
6.3 Summarize behavioral security concepts.
CompTIA A+ Core 2
1.7 Given a scenario, apply application installation and configuration concepts.
4.6 Explain the importance of prohibited content/activity and privacy, licensing, and policy concepts.
2.1 Summarize various security measures and their purposes.
4.2 Explain basic change-management best practices.

Key terms

Shadow IT
The use of unauthorized software, systems, or services within an organization without IT department knowledge or approval. Shadow IT creates security blind spots because unmanaged assets fall outside standard patching, monitoring, and access controls.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Bandwidth
The maximum rate of data transfer across a network path, typically measured in bits per second.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
IT Governance
The framework of policies, processes, and oversight structures that ensure IT resources are used in alignment with organizational objectives and compliance requirements.

Topics

Software Management Shadow It It Governance Software Procurement Organizational Policy Endpoint Management

Transcript

Impact to the Device

There are some considerations about software that we're installing when it comes to us as end users, but there are even more considerations when it comes to the business and making sure that we're choosing the right software that's going to be compatible with the business.

One of the considerations when we're installing software is the impact to the device that you're installing it on. I already talked about compatibility and I talked about software requirements, so I'm not going to get more into that side of it, but there are some other considerations as well.

Just because a system meets a minimum requirement doesn't take into consideration all the other software that's installed on this machine that's utilizing those same resources. It has a limited amount of CPU, a limited amount of RAM, a limited amount of storage, and so on and so forth. So what happens is if we're using this up with some programs, then we might not meet that minimum requirement that's available to a software that we want to install. Even though overall we have enough RAM for that software, there might not be enough of it left for that software to run efficiently. So we need to consider the impact to the device itself.

Impact to Other Devices and the Network

But a device in a business doesn't just stand by itself — there are other devices that it interacts with. So we need to consider the impact to other devices on the network, because let's say some sort of software introduces a security hole. Now you're introducing that security hole, or that security impact, to all of the other devices on the network.

Or maybe what we're evaluating is some sort of software that's up in the cloud, and so it's utilizing our bandwidth going out to that resource to be able to access that. It might be just fine for a single user to access that, but now when you have many devices that are accessing that same resource, you could be saturating that link to the outside world. So now we need to consider the impact to the network by utilizing some sort of software.

Impact to Operations

There's also an impact to operations. What I mean by that is kind of twofold, really. Number one, you're installing software within a department, and so that department has to maybe change their processes to utilize that software correctly, and so now you're impacting how people do work. That could be what's meant by operations.

The other way is I think of IT operations: there are lots of different computers that we need to support, and when you're installing different software on all these different devices, that could be problematic. So how can we make sure of what the impact is to the overall, and can we support it?

Impact to the Business

And then what is the impact to the business altogether? Perhaps we have some security policies at the business level and we need to make sure that we're not breaking those policies. Or maybe our customers are demanding something and that software goes against what they're demanding, or against some sort of requirements that are out there of the business.

A good example of thinking of the big overall picture would be an instant messaging issue that I had at one point in time. With instant messaging we had a few different options. The main option that we said we were going to support across the business was this Cisco UCS system that we had installed on our network. Everybody had access to it, and so that was the official way that we were going to do instant messaging. But another department chose that they wanted to do HipChat instead, and so they started using HipChat. Yet another department wanted to use Slack, and another department wanted to use some other instant messaging. We had like four or five different instant messaging systems that were being used amongst the different departments within the company.

And then when we had an issue and tried to broadcast that out to the company through the official means, the people that were on the other systems didn't get the message about that problem, about that issue, in a timely manner. So it caused a lot of problems. Then what we said we needed to do is we needed to choose one of these and go with it. Well, the problem is that there were several departments that said, "No, we want to use our own systems," and had a lot of pushback. So we needed to make sure that the execs and the higher up in management were on board with choosing a single solution and then rolling it out companywide. So we just need to make sure that everybody's on the same page and consider the impact to the business.

Shadow IT

Which brings us to the next point: there are going to be people within your company that feel like they don't need to follow the proper channels, that they're going to want to do their own thing. We call that shadow IT. I've got the cowboy hat on because in one of the places that I worked we called it going cowboy — they're just doing their own thing, being the lone ranger, doing their thing of what they wanted to do and just ignoring what the policies were of the company and of the IT department. Where we see that being an issue is like I say, a department just chose that they wanted to use HipChat, another one just chose that they wanted to use Slack, and they didn't get approval through that.

One of the reasons why they don't come to IT for installing certain software: number one, they just don't think about it all the time. And number two, when they go to IT and say, "Hey, what we would like to do is we would like to install this software," and IT says, "Well, you can't do that because it causes these problems," so we essentially have to tell them no. Now what they've learned is don't go to IT, they're going to create problems, they're going to create hurdles — when IT is really there to facilitate the business, to help the business out, to make sure that we're enabling our users to do the best that they can, while also taking into consideration the business as a whole.

So us in an IT department, supporting all of these different users and their needs, we need to balance the needs of the company with the needs of these individual users and departments. It's a little tricky to do that and to make sure that we don't have shadow IT happening within our businesses.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →