KEMBAR78
Great Open Source Compliance For Everyone (Version 3) | PPTX
Great Open Source Compliance For Everyone
Available under the CC Attribution-NoDerivatives 4.0 International license.
2
3
4
5
6
Compliance – A gateway to access
7
Let’s provide business context
8
The internal company dialogue…
9
We use Open Source and get billions of dollars of code
10
This code was created by other people
11
How we respect their rights?
12
How do we meet our legal requirements?
13
Welcome To The Stack
14
https://www.spdx.org
15
http://www.todogroup.org
16
https://www.fossology.org
17
Welcome To The Stack
18
“How do I trust my open source supply chain?”
19
OpenChain Adoption – A Story of Levels
(c)TOYOTA MOTOR CORPORATION
20
Level1
NOT understand
Importance of
OSS Compliance
Level2
NOT understand
whatto do
Level3
NOT understand
how todo
Level4
Not Understand
how toget
certification
●Join events
for Engineers/
Legalpeople/
IP people
●Workshop
●PR:
Traditional
Media/
TechMedia/
SNS
●Reference Material
(Wiki/
Handbook/
Academic
paper)
●Consultation
●Training
support
●Self
certification
support
●Third-party
certification
There are three parts to OpenChain Project:
21
1. Specification
2. Conformance
3. Curriculum
The OpenChain Specification defines the requirements
for a quality compliance program.
22
23
Training
Policy
Process
Inbound Outbound
The OpenChain Specification confirms a company has
open source processes, policies and training.
Companies have the flexibility to decide each specific
process, policies and training.
24
Common requirements for suppliers and customers
makes everything simpler.
Learn more here:
https://www.openchainproject.org/spec
25
OpenChain Conformance allows organizations to show
they meet these requirements.
26
27
If a company can answer Yes to each question they are
OpenChain Conformant.
Learn more here:
https://www.openchainproject.org/conformance
28
The OpenChain Curriculum provides reference open
source processes and solutions.
Learn more here:
https://www.openchainproject.org/curriculum
29
30
31
32
The OpenChain Curriculum can be used for any open
source training program.
Learn more here:
https://www.openchainproject.org/curriculum
33
The goal is to build trust by having organizations
conformant with the OpenChain Specification.
34
35
Scale of Platinum Members:
Over $750 Billion of Revenue
36
37
Work Teams supporting OpenChain:
38
1.Specification - Chaired by Mark Gisi (Wind River)
1.Conformance - Chaired by Miriam Ballhausen (SCA)
1.Curriculum - Chaired by Alexios Zavros (Intel)
1.Onboarding - Chaired by Nathan Kumagai (Qualcomm)
39
Progress Since Last Year
40
1. International Partners - from law firms to certification authorities
• From Moorcrofts (UK) to TÜV SÜD (Germany and Japan)
2. Significant New Board Members
• Toshiba (more announcements shortly)
3. Significant New Community Members
• Microsoft, Panasonic and more
4. A Move towards formal standardization
• The target is the PAS process for ISO - Launch ETA Q1 2020
Coming Soon
41
1.New Board Member Announcements
2.New Conformant Organization Announcements
3.New Partnership Announcements
4.Increasingly Powerful Positioning for Procurement
• Standardization
• Deployment by board members
• Deployment by community members
Be part of this
42
Join the community:
https://www.openchainproject.org/community
Self-certify your organization:
https://certification.openchainproject.org
Questions?
OpenChain Project - The Linux Foundation 43

Great Open Source Compliance For Everyone (Version 3)

  • 1.
    Great Open SourceCompliance For Everyone Available under the CC Attribution-NoDerivatives 4.0 International license.
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
    Compliance – Agateway to access 7
  • 8.
  • 9.
    The internal companydialogue… 9
  • 10.
    We use OpenSource and get billions of dollars of code 10
  • 11.
    This code wascreated by other people 11
  • 12.
    How we respecttheir rights? 12
  • 13.
    How do wemeet our legal requirements? 13
  • 14.
  • 15.
  • 16.
  • 17.
  • 18.
  • 19.
    “How do Itrust my open source supply chain?” 19
  • 20.
    OpenChain Adoption –A Story of Levels (c)TOYOTA MOTOR CORPORATION 20 Level1 NOT understand Importance of OSS Compliance Level2 NOT understand whatto do Level3 NOT understand how todo Level4 Not Understand how toget certification ●Join events for Engineers/ Legalpeople/ IP people ●Workshop ●PR: Traditional Media/ TechMedia/ SNS ●Reference Material (Wiki/ Handbook/ Academic paper) ●Consultation ●Training support ●Self certification support ●Third-party certification
  • 21.
    There are threeparts to OpenChain Project: 21 1. Specification 2. Conformance 3. Curriculum
  • 22.
    The OpenChain Specificationdefines the requirements for a quality compliance program. 22
  • 23.
  • 24.
    The OpenChain Specificationconfirms a company has open source processes, policies and training. Companies have the flexibility to decide each specific process, policies and training. 24
  • 25.
    Common requirements forsuppliers and customers makes everything simpler. Learn more here: https://www.openchainproject.org/spec 25
  • 26.
    OpenChain Conformance allowsorganizations to show they meet these requirements. 26
  • 27.
  • 28.
    If a companycan answer Yes to each question they are OpenChain Conformant. Learn more here: https://www.openchainproject.org/conformance 28
  • 29.
    The OpenChain Curriculumprovides reference open source processes and solutions. Learn more here: https://www.openchainproject.org/curriculum 29
  • 30.
  • 31.
  • 32.
  • 33.
    The OpenChain Curriculumcan be used for any open source training program. Learn more here: https://www.openchainproject.org/curriculum 33
  • 34.
    The goal isto build trust by having organizations conformant with the OpenChain Specification. 34
  • 35.
  • 36.
    Scale of PlatinumMembers: Over $750 Billion of Revenue 36
  • 37.
  • 38.
    Work Teams supportingOpenChain: 38 1.Specification - Chaired by Mark Gisi (Wind River) 1.Conformance - Chaired by Miriam Ballhausen (SCA) 1.Curriculum - Chaired by Alexios Zavros (Intel) 1.Onboarding - Chaired by Nathan Kumagai (Qualcomm)
  • 39.
  • 40.
    Progress Since LastYear 40 1. International Partners - from law firms to certification authorities • From Moorcrofts (UK) to TÜV SÜD (Germany and Japan) 2. Significant New Board Members • Toshiba (more announcements shortly) 3. Significant New Community Members • Microsoft, Panasonic and more 4. A Move towards formal standardization • The target is the PAS process for ISO - Launch ETA Q1 2020
  • 41.
    Coming Soon 41 1.New BoardMember Announcements 2.New Conformant Organization Announcements 3.New Partnership Announcements 4.Increasingly Powerful Positioning for Procurement • Standardization • Deployment by board members • Deployment by community members
  • 42.
    Be part ofthis 42 Join the community: https://www.openchainproject.org/community Self-certify your organization: https://certification.openchainproject.org
  • 43.
    Questions? OpenChain Project -The Linux Foundation 43