This document discusses strategies for software audits to identify open source software and third party components. It recommends that companies conduct regular, ongoing software audits rather than one-time audits to reduce risks and costs. A typical audit process involves scanning software to identify open source projects, licenses, vulnerabilities, and other attributes. Audits should occur at regular intervals as new code is acquired to quickly detect issues before they propagate.