The State of Open Source for Software Alliance Germany 2023-04-14

Shane Coughlan
Shane CoughlanOpenChain Program Manager à The Linux Foundation
The State of Open
Source
Our Field in 2023
This talk focuses on practical
corporate use of open source
WARNING
Things Are Getting
Complex
There Are More Rules And Guidelines
● NTIA Minimum Requirements of Software Bill of Materials (SBOM)
● White House Executive Order – SBOM again
● Cyber Resiliency Act (CRA) in the European Union – Reporting and
Compliance Requirements
5.5tn
Global Cost of Cyber Crime
Source – CRA Explanatory Materials
Open Source Reality – We Need To Do Better
● The inclusion of far more support for SBOMs is inevitable
● This implies better tooling and record keeping in companies and projects
● It also implies more coordination around standards
● Enhanced reporting and other compliance requirements are still TBD
Why
Our Mental Model Of The Supply Chain
The Actual Supply Chain
67.4%
of managers monitor their supply chain with Excel spreadsheets
https://www.zippia.com/advice/supply-chain-statistics/
94%
of companies do not have full visibility of their supply chain
https://www.zippia.com/advice/supply-chain-statistics/
https://www.zippia.com/advice/supply-chain-statistics/
Context: This Is Important To Business
13
Open Source License Compliance and Security Assurance
is a key part of supply chain management.
https://www.synopsys.com/blogs/software-security/open-source-trends-ossra-report/
Open Source Reality – We Are Doing Better
● The open source supply chain is still facing many challenges
● The key thing missing for many companies are the appropriate processes to
allow implementation of better, more efficient practices
● For example, before you can have an SBOM, you need a policy and you need
processes to support implementation
Policy, Processes and Training are key
Open Source Process Management
● In Market Q4 2016~ (de facto) Q4 2020 (ISO/IEC)
OpenChain ISO/IEC 5230:2020
The International Standard for open source license compliance.
● In Market Q4 2022~ (de facto) Q3 2023 projected (ISO/IEC)
ISO/IEC DIS 18974, OpenChain Security Assurance
Specification
The de facto standard for open source security assurance compliance.
1. High level process standards;
2. Simple, effective and suitable for companies of all sizes in all markets;
3. Openly developed by a vibrant user community and freely available to all.
16
The Standards Work Company By Company
Result = A More Predictable Supply Chain
Example Adoption Of
OpenChain ISO/IEC
5230:2020
18
20%
of German companies with over 2,000 employees
already use OpenChain ISO/IEC 5230
https://www.pwc.de/en/digitale-transformation/pwc-bitkom-study-open-source-monitor-2021.pdf
Key Companies Supporting These Standards
20
Broader Community
Main Work Groups:
● Specification (Spring 2016~)
● Education (Autumn 2020~)
Community Work Groups:
● Tooling (Summer 2019~)
● Export Control (Winter 2022~)
● Public Policy (Winter 2022~)
Special Interest Groups:
● Automotive (Summer 2019~)
● Telecom (Spring 2021~)
Regional User Groups
● Japan (Dec 2017~)
● Korea (Jan 2019~)
● India (Sept 2019~)
● China (Sept 2019~)
● Taiwan (Sept 2019~)
● Germany (Jan 2020~)
● UK (June 2020~)
● USA (Dec 2020~)
1. Self-Certification
2. Independent Assessment
3. Third-Party Certification
Freedom Of Choice In Adoption
Free Self-Certification Material
23
11 Third-Party Certifiers Providing Global
Coverage
Free Online Training Courses
25
1. LFC193 - 1209 total enrollments (398 digital badges issued)
4.65 out of 5 rating by users
2. LFC194 - 579 total enrollments (138 digital badges issued)
4.55 out of 5 rating by users
Be Part Of This
https://www.openchainproject.org/participate
1 sur 26

Recommandé

2023-06-classic par
2023-06-classic2023-06-classic
2023-06-classicShane Coughlan
46 vues47 diapositives
2023-06-cute par
2023-06-cute2023-06-cute
2023-06-cuteShane Coughlan
42 vues47 diapositives
2023-06-corporate par
2023-06-corporate2023-06-corporate
2023-06-corporateShane Coughlan
45 vues47 diapositives
OpenChain @ Bitkom Forum Open Source 2022 par
OpenChain @ Bitkom Forum Open Source 2022OpenChain @ Bitkom Forum Open Source 2022
OpenChain @ Bitkom Forum Open Source 2022Shane Coughlan
25 vues27 diapositives
OpenChain Japan Work Group Meeting #28 - 2023-07-11 par
OpenChain Japan Work Group Meeting #28 - 2023-07-11OpenChain Japan Work Group Meeting #28 - 2023-07-11
OpenChain Japan Work Group Meeting #28 - 2023-07-11Shane Coughlan
50 vues32 diapositives
OpenChain Japan Work Group - Meeting 27 par
OpenChain Japan Work Group - Meeting 27OpenChain Japan Work Group - Meeting 27
OpenChain Japan Work Group - Meeting 27Shane Coughlan
109 vues35 diapositives

Contenu connexe

Similaire à The State of Open Source for Software Alliance Germany 2023-04-14

From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx par
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptxFrom One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptxShane Coughlan
46 vues15 diapositives
Assocham global conference audit data standards - 28.10.2020 par
Assocham global conference   audit data standards - 28.10.2020Assocham global conference   audit data standards - 28.10.2020
Assocham global conference audit data standards - 28.10.2020Vinod Kashyap
101 vues33 diapositives
Free and Open Source Software - Challenges for the Automotive Supply Chain par
Free and Open Source Software - Challenges for the Automotive Supply ChainFree and Open Source Software - Challenges for the Automotive Supply Chain
Free and Open Source Software - Challenges for the Automotive Supply ChainShane Coughlan
207 vues40 diapositives
SAP Leonardo Blockchain Services and Use-Cases par
SAP Leonardo Blockchain Services and Use-CasesSAP Leonardo Blockchain Services and Use-Cases
SAP Leonardo Blockchain Services and Use-CasesNagesh Caparthy
600 vues29 diapositives
Great Open Source Compliance For Everyone - Version 11 par
Great Open Source Compliance For Everyone - Version 11Great Open Source Compliance For Everyone - Version 11
Great Open Source Compliance For Everyone - Version 11Shane Coughlan
303 vues32 diapositives
OpenChain-Monthly-Meeting-2022-11-15 par
OpenChain-Monthly-Meeting-2022-11-15OpenChain-Monthly-Meeting-2022-11-15
OpenChain-Monthly-Meeting-2022-11-15Shane Coughlan
60 vues44 diapositives

Similaire à The State of Open Source for Software Alliance Germany 2023-04-14(20)

From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx par Shane Coughlan
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptxFrom One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
Shane Coughlan46 vues
Assocham global conference audit data standards - 28.10.2020 par Vinod Kashyap
Assocham global conference   audit data standards - 28.10.2020Assocham global conference   audit data standards - 28.10.2020
Assocham global conference audit data standards - 28.10.2020
Vinod Kashyap101 vues
Free and Open Source Software - Challenges for the Automotive Supply Chain par Shane Coughlan
Free and Open Source Software - Challenges for the Automotive Supply ChainFree and Open Source Software - Challenges for the Automotive Supply Chain
Free and Open Source Software - Challenges for the Automotive Supply Chain
Shane Coughlan207 vues
SAP Leonardo Blockchain Services and Use-Cases par Nagesh Caparthy
SAP Leonardo Blockchain Services and Use-CasesSAP Leonardo Blockchain Services and Use-Cases
SAP Leonardo Blockchain Services and Use-Cases
Nagesh Caparthy600 vues
Great Open Source Compliance For Everyone - Version 11 par Shane Coughlan
Great Open Source Compliance For Everyone - Version 11Great Open Source Compliance For Everyone - Version 11
Great Open Source Compliance For Everyone - Version 11
Shane Coughlan303 vues
OpenChain-Monthly-Meeting-2022-11-15 par Shane Coughlan
OpenChain-Monthly-Meeting-2022-11-15OpenChain-Monthly-Meeting-2022-11-15
OpenChain-Monthly-Meeting-2022-11-15
Shane Coughlan60 vues
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li... par Paris Open Source Summit
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
The Modern Supply Chain: Global Challenges and Best Practices par Aggregage
The Modern Supply Chain: Global Challenges and Best PracticesThe Modern Supply Chain: Global Challenges and Best Practices
The Modern Supply Chain: Global Challenges and Best Practices
Aggregage97 vues
OpenChain Monthly Meeting 2022-11-01 par Shane Coughlan
OpenChain Monthly Meeting 2022-11-01OpenChain Monthly Meeting 2022-11-01
OpenChain Monthly Meeting 2022-11-01
Shane Coughlan33 vues
Box investor presentation par box2016ir
Box investor presentationBox investor presentation
Box investor presentation
box2016ir14.4K vues
Gridforum Pierre Guisset Damien Hubaux B Ein Grid 20080402 par vrij
Gridforum Pierre Guisset Damien Hubaux B Ein Grid 20080402Gridforum Pierre Guisset Damien Hubaux B Ein Grid 20080402
Gridforum Pierre Guisset Damien Hubaux B Ein Grid 20080402
vrij1.2K vues
OpenChain Germany Work Group Meeting 2022-11-16 par Shane Coughlan
OpenChain Germany Work Group Meeting 2022-11-16OpenChain Germany Work Group Meeting 2022-11-16
OpenChain Germany Work Group Meeting 2022-11-16
Steps to Scale Internet of Things (IoT) par Rafael Maranon
Steps to Scale Internet of Things (IoT)Steps to Scale Internet of Things (IoT)
Steps to Scale Internet of Things (IoT)
Rafael Maranon2.7K vues
Rcose challenges and benefits from using software analytics in softeam par Alessandra Bagnato
Rcose  challenges and benefits from using software analytics in softeamRcose  challenges and benefits from using software analytics in softeam
Rcose challenges and benefits from using software analytics in softeam
OneAudit™ - Assess Once, Certify to Many par ControlCase
OneAudit™ - Assess Once, Certify to ManyOneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to Many
ControlCase704 vues
How to Keep SAP Projects on Schedule with B2B Managed Services par Mark Morley, MBA
How to Keep SAP Projects on Schedule with B2B Managed Services How to Keep SAP Projects on Schedule with B2B Managed Services
How to Keep SAP Projects on Schedule with B2B Managed Services
Mark Morley, MBA1.2K vues

Plus de Shane Coughlan

OpenChain Legal Work Group - 2023-06-29 par
OpenChain Legal Work Group - 2023-06-29OpenChain Legal Work Group - 2023-06-29
OpenChain Legal Work Group - 2023-06-29Shane Coughlan
134 vues7 diapositives
OpenChain Webinar #53 – OpenSCA par
OpenChain Webinar #53 – OpenSCAOpenChain Webinar #53 – OpenSCA
OpenChain Webinar #53 – OpenSCAShane Coughlan
124 vues19 diapositives
OpenChain Korea Work Group Meeting #18 par
OpenChain Korea Work Group Meeting #18OpenChain Korea Work Group Meeting #18
OpenChain Korea Work Group Meeting #18Shane Coughlan
86 vues17 diapositives
legal-work-group-2023-05-25 par
legal-work-group-2023-05-25legal-work-group-2023-05-25
legal-work-group-2023-05-25Shane Coughlan
50 vues7 diapositives
FOSSLight at the OpenChain Mini-Summit May 2023 par
FOSSLight at the OpenChain Mini-Summit May 2023FOSSLight at the OpenChain Mini-Summit May 2023
FOSSLight at the OpenChain Mini-Summit May 2023Shane Coughlan
231 vues17 diapositives
OpenChain Mini-Summit 2023 - State of Tooling in Open Source Automation par
OpenChain Mini-Summit 2023 - State of Tooling in Open Source AutomationOpenChain Mini-Summit 2023 - State of Tooling in Open Source Automation
OpenChain Mini-Summit 2023 - State of Tooling in Open Source AutomationShane Coughlan
244 vues22 diapositives

Plus de Shane Coughlan(20)

OpenChain Legal Work Group - 2023-06-29 par Shane Coughlan
OpenChain Legal Work Group - 2023-06-29OpenChain Legal Work Group - 2023-06-29
OpenChain Legal Work Group - 2023-06-29
Shane Coughlan134 vues
OpenChain Webinar #53 – OpenSCA par Shane Coughlan
OpenChain Webinar #53 – OpenSCAOpenChain Webinar #53 – OpenSCA
OpenChain Webinar #53 – OpenSCA
Shane Coughlan124 vues
OpenChain Korea Work Group Meeting #18 par Shane Coughlan
OpenChain Korea Work Group Meeting #18OpenChain Korea Work Group Meeting #18
OpenChain Korea Work Group Meeting #18
Shane Coughlan86 vues
FOSSLight at the OpenChain Mini-Summit May 2023 par Shane Coughlan
FOSSLight at the OpenChain Mini-Summit May 2023FOSSLight at the OpenChain Mini-Summit May 2023
FOSSLight at the OpenChain Mini-Summit May 2023
Shane Coughlan231 vues
OpenChain Mini-Summit 2023 - State of Tooling in Open Source Automation par Shane Coughlan
OpenChain Mini-Summit 2023 - State of Tooling in Open Source AutomationOpenChain Mini-Summit 2023 - State of Tooling in Open Source Automation
OpenChain Mini-Summit 2023 - State of Tooling in Open Source Automation
Shane Coughlan244 vues
How the Linux Foundation Standards for Compliance and Security will Fix Your ... par Shane Coughlan
How the Linux Foundation Standards for Compliance and Security will Fix Your ...How the Linux Foundation Standards for Compliance and Security will Fix Your ...
How the Linux Foundation Standards for Compliance and Security will Fix Your ...
Shane Coughlan51 vues
OpenChain Education Work Group - 2023-04-13 par Shane Coughlan
OpenChain Education Work Group - 2023-04-13OpenChain Education Work Group - 2023-04-13
OpenChain Education Work Group - 2023-04-13
Shane Coughlan33 vues
OpenChain North America and Europe Meeting - 2023-04-04 par Shane Coughlan
OpenChain North America and Europe Meeting - 2023-04-04OpenChain North America and Europe Meeting - 2023-04-04
OpenChain North America and Europe Meeting - 2023-04-04
Shane Coughlan24 vues
OpenChain Webinar #50 - An Overview of SPDX 3.0 par Shane Coughlan
OpenChain Webinar #50 - An Overview of SPDX 3.0OpenChain Webinar #50 - An Overview of SPDX 3.0
OpenChain Webinar #50 - An Overview of SPDX 3.0
Shane Coughlan388 vues
“State of the Tooling” in Open Source Automation par Shane Coughlan
“State of the Tooling” in Open Source Automation“State of the Tooling” in Open Source Automation
“State of the Tooling” in Open Source Automation
Shane Coughlan43 vues
OpenChain Monthly Meeting - North America / Asia - 2023-03-21 par Shane Coughlan
OpenChain Monthly Meeting - North America / Asia - 2023-03-21OpenChain Monthly Meeting - North America / Asia - 2023-03-21
OpenChain Monthly Meeting - North America / Asia - 2023-03-21
Shane Coughlan71 vues
OpenChain Monthly Meeting 2023-02-21 (North America and Asia) par Shane Coughlan
OpenChain Monthly Meeting 2023-02-21 (North America and Asia)OpenChain Monthly Meeting 2023-02-21 (North America and Asia)
OpenChain Monthly Meeting 2023-02-21 (North America and Asia)
Shane Coughlan62 vues
OpenChain Monthly Meeting North America - Europe - 2023-02-07 par Shane Coughlan
OpenChain Monthly Meeting North America - Europe - 2023-02-07OpenChain Monthly Meeting North America - Europe - 2023-02-07
OpenChain Monthly Meeting North America - Europe - 2023-02-07
Shane Coughlan100 vues
OpenChain-Monthly-Meeting-2023-01-17 par Shane Coughlan
OpenChain-Monthly-Meeting-2023-01-17OpenChain-Monthly-Meeting-2023-01-17
OpenChain-Monthly-Meeting-2023-01-17
Shane Coughlan46 vues
OpenChain Monthly Meeting (US / Europe) 2023-01-03 par Shane Coughlan
OpenChain Monthly Meeting (US / Europe) 2023-01-03OpenChain Monthly Meeting (US / Europe) 2023-01-03
OpenChain Monthly Meeting (US / Europe) 2023-01-03
Shane Coughlan76 vues
Open Compliance Summit - Export Control Informal Discussion par Shane Coughlan
Open Compliance Summit - Export Control Informal DiscussionOpen Compliance Summit - Export Control Informal Discussion
Open Compliance Summit - Export Control Informal Discussion
Shane Coughlan45 vues
Open Compliance Summit 2022 – State of the Union from Mike Dolan, SVP and GM ... par Shane Coughlan
Open Compliance Summit 2022 – State of the Union from Mike Dolan, SVP and GM ...Open Compliance Summit 2022 – State of the Union from Mike Dolan, SVP and GM ...
Open Compliance Summit 2022 – State of the Union from Mike Dolan, SVP and GM ...
Shane Coughlan34 vues
Open Compliance Summit 2022 - Opening Keynote par Shane Coughlan
Open Compliance Summit 2022 - Opening KeynoteOpen Compliance Summit 2022 - Opening Keynote
Open Compliance Summit 2022 - Opening Keynote
Shane Coughlan104 vues
Open Compliance Summit 2022 - Opening Keynote par Shane Coughlan
Open Compliance Summit 2022 - Opening KeynoteOpen Compliance Summit 2022 - Opening Keynote
Open Compliance Summit 2022 - Opening Keynote
Shane Coughlan26 vues

Dernier

BushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports par
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug ReportsBushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug ReportsRa'Fat Al-Msie'deen
5 vues49 diapositives
Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea... par
Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea...Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea...
Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea...Safe Software
412 vues59 diapositives
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI... par
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...Marc Müller
36 vues83 diapositives
Software testing company in India.pptx par
Software testing company in India.pptxSoftware testing company in India.pptx
Software testing company in India.pptxSakshiPatel82
7 vues9 diapositives
DSD-INT 2023 Wave-Current Interaction at Montrose Tidal Inlet System and Its ... par
DSD-INT 2023 Wave-Current Interaction at Montrose Tidal Inlet System and Its ...DSD-INT 2023 Wave-Current Interaction at Montrose Tidal Inlet System and Its ...
DSD-INT 2023 Wave-Current Interaction at Montrose Tidal Inlet System and Its ...Deltares
9 vues32 diapositives
Fleet Management Software in India par
Fleet Management Software in India Fleet Management Software in India
Fleet Management Software in India Fleetable
11 vues1 diapositive

Dernier(20)

BushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports par Ra'Fat Al-Msie'deen
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug ReportsBushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports
BushraDBR: An Automatic Approach to Retrieving Duplicate Bug Reports
Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea... par Safe Software
Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea...Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea...
Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea...
Safe Software412 vues
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI... par Marc Müller
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...
Dev-Cloud Conference 2023 - Continuous Deployment Showdown: Traditionelles CI...
Marc Müller36 vues
Software testing company in India.pptx par SakshiPatel82
Software testing company in India.pptxSoftware testing company in India.pptx
Software testing company in India.pptx
SakshiPatel827 vues
DSD-INT 2023 Wave-Current Interaction at Montrose Tidal Inlet System and Its ... par Deltares
DSD-INT 2023 Wave-Current Interaction at Montrose Tidal Inlet System and Its ...DSD-INT 2023 Wave-Current Interaction at Montrose Tidal Inlet System and Its ...
DSD-INT 2023 Wave-Current Interaction at Montrose Tidal Inlet System and Its ...
Deltares9 vues
Fleet Management Software in India par Fleetable
Fleet Management Software in India Fleet Management Software in India
Fleet Management Software in India
Fleetable11 vues
Copilot Prompting Toolkit_All Resources.pdf par Riccardo Zamana
Copilot Prompting Toolkit_All Resources.pdfCopilot Prompting Toolkit_All Resources.pdf
Copilot Prompting Toolkit_All Resources.pdf
Upgrading Incident Management with Icinga - Icinga Camp Milan 2023 par Icinga
Upgrading Incident Management with Icinga - Icinga Camp Milan 2023Upgrading Incident Management with Icinga - Icinga Camp Milan 2023
Upgrading Incident Management with Icinga - Icinga Camp Milan 2023
Icinga38 vues
Tridens DevOps par Tridens
Tridens DevOpsTridens DevOps
Tridens DevOps
Tridens9 vues
DSD-INT 2023 Simulation of Coastal Hydrodynamics and Water Quality in Hong Ko... par Deltares
DSD-INT 2023 Simulation of Coastal Hydrodynamics and Water Quality in Hong Ko...DSD-INT 2023 Simulation of Coastal Hydrodynamics and Water Quality in Hong Ko...
DSD-INT 2023 Simulation of Coastal Hydrodynamics and Water Quality in Hong Ko...
Deltares11 vues
Citi TechTalk Session 2: Kafka Deep Dive par confluent
Citi TechTalk Session 2: Kafka Deep DiveCiti TechTalk Session 2: Kafka Deep Dive
Citi TechTalk Session 2: Kafka Deep Dive
confluent17 vues
DSD-INT 2023 Simulating a falling apron in Delft3D 4 - Engineering Practice -... par Deltares
DSD-INT 2023 Simulating a falling apron in Delft3D 4 - Engineering Practice -...DSD-INT 2023 Simulating a falling apron in Delft3D 4 - Engineering Practice -...
DSD-INT 2023 Simulating a falling apron in Delft3D 4 - Engineering Practice -...
Deltares6 vues
Elevate your SAP landscape's efficiency and performance with HCL Workload Aut... par HCLSoftware
Elevate your SAP landscape's efficiency and performance with HCL Workload Aut...Elevate your SAP landscape's efficiency and performance with HCL Workload Aut...
Elevate your SAP landscape's efficiency and performance with HCL Workload Aut...
HCLSoftware6 vues
DSD-INT 2023 Baseline studies for Strategic Coastal protection for Long Islan... par Deltares
DSD-INT 2023 Baseline studies for Strategic Coastal protection for Long Islan...DSD-INT 2023 Baseline studies for Strategic Coastal protection for Long Islan...
DSD-INT 2023 Baseline studies for Strategic Coastal protection for Long Islan...
Deltares11 vues
SUGCON ANZ Presentation V2.1 Final.pptx par Jack Spektor
SUGCON ANZ Presentation V2.1 Final.pptxSUGCON ANZ Presentation V2.1 Final.pptx
SUGCON ANZ Presentation V2.1 Final.pptx
Jack Spektor22 vues
Neo4j y GenAI par Neo4j
Neo4j y GenAI Neo4j y GenAI
Neo4j y GenAI
Neo4j42 vues
.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra... par Marc Müller
.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra....NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra...
.NET Developer Conference 2023 - .NET Microservices mit Dapr – zu viel Abstra...
Marc Müller38 vues
Mark Simpson - UKOUG23 - Refactoring Monolithic Oracle Database Applications ... par marksimpsongw
Mark Simpson - UKOUG23 - Refactoring Monolithic Oracle Database Applications ...Mark Simpson - UKOUG23 - Refactoring Monolithic Oracle Database Applications ...
Mark Simpson - UKOUG23 - Refactoring Monolithic Oracle Database Applications ...
marksimpsongw76 vues

The State of Open Source for Software Alliance Germany 2023-04-14

  • 1. The State of Open Source Our Field in 2023
  • 2. This talk focuses on practical corporate use of open source WARNING
  • 4. There Are More Rules And Guidelines ● NTIA Minimum Requirements of Software Bill of Materials (SBOM) ● White House Executive Order – SBOM again ● Cyber Resiliency Act (CRA) in the European Union – Reporting and Compliance Requirements
  • 5. 5.5tn Global Cost of Cyber Crime Source – CRA Explanatory Materials
  • 6. Open Source Reality – We Need To Do Better ● The inclusion of far more support for SBOMs is inevitable ● This implies better tooling and record keeping in companies and projects ● It also implies more coordination around standards ● Enhanced reporting and other compliance requirements are still TBD
  • 7. Why
  • 8. Our Mental Model Of The Supply Chain
  • 10. 67.4% of managers monitor their supply chain with Excel spreadsheets https://www.zippia.com/advice/supply-chain-statistics/
  • 11. 94% of companies do not have full visibility of their supply chain https://www.zippia.com/advice/supply-chain-statistics/
  • 13. Context: This Is Important To Business 13 Open Source License Compliance and Security Assurance is a key part of supply chain management.
  • 15. Open Source Reality – We Are Doing Better ● The open source supply chain is still facing many challenges ● The key thing missing for many companies are the appropriate processes to allow implementation of better, more efficient practices ● For example, before you can have an SBOM, you need a policy and you need processes to support implementation Policy, Processes and Training are key
  • 16. Open Source Process Management ● In Market Q4 2016~ (de facto) Q4 2020 (ISO/IEC) OpenChain ISO/IEC 5230:2020 The International Standard for open source license compliance. ● In Market Q4 2022~ (de facto) Q3 2023 projected (ISO/IEC) ISO/IEC DIS 18974, OpenChain Security Assurance Specification The de facto standard for open source security assurance compliance. 1. High level process standards; 2. Simple, effective and suitable for companies of all sizes in all markets; 3. Openly developed by a vibrant user community and freely available to all. 16
  • 17. The Standards Work Company By Company Result = A More Predictable Supply Chain
  • 18. Example Adoption Of OpenChain ISO/IEC 5230:2020 18
  • 19. 20% of German companies with over 2,000 employees already use OpenChain ISO/IEC 5230 https://www.pwc.de/en/digitale-transformation/pwc-bitkom-study-open-source-monitor-2021.pdf
  • 20. Key Companies Supporting These Standards 20
  • 21. Broader Community Main Work Groups: ● Specification (Spring 2016~) ● Education (Autumn 2020~) Community Work Groups: ● Tooling (Summer 2019~) ● Export Control (Winter 2022~) ● Public Policy (Winter 2022~) Special Interest Groups: ● Automotive (Summer 2019~) ● Telecom (Spring 2021~) Regional User Groups ● Japan (Dec 2017~) ● Korea (Jan 2019~) ● India (Sept 2019~) ● China (Sept 2019~) ● Taiwan (Sept 2019~) ● Germany (Jan 2020~) ● UK (June 2020~) ● USA (Dec 2020~)
  • 22. 1. Self-Certification 2. Independent Assessment 3. Third-Party Certification Freedom Of Choice In Adoption
  • 24. 11 Third-Party Certifiers Providing Global Coverage
  • 25. Free Online Training Courses 25 1. LFC193 - 1209 total enrollments (398 digital badges issued) 4.65 out of 5 rating by users 2. LFC194 - 579 total enrollments (138 digital badges issued) 4.55 out of 5 rating by users
  • 26. Be Part Of This https://www.openchainproject.org/participate