On this webinar Tim Bird of Sony spoke on ‘Issues with Open Source License Compliance in Consumer Electronics’, a variant of a speech recently delivered at Open Source Summit Europe, and made available here for our global audience along with a great Q&A.
The full recording of our recent Education Work Group meeting is now available. Big news this time around as we lock down collaboration with LF Training to make a free online course (we get their stuff as CC-0!), how we will work, and our target release dates.
Our regular bi-weekly webinar will cover an exciting topic at 5pm Pacific today (Monday) – 8am Beijing/Taipei – 9am Seoul/Tokyo (Tuesday).
Tim Bird of Sony will cover ‘Issues with Open Source License Compliance in Consumer Electronics’, a variant of a speech recently delivered at Open Source Summit Europe, and made available live here for audiences in the USA and Asia.
The Japan Planning Sub-Work Group will host a virtual meeting on the 16th of December. The topic of the next meeting is ‘OSS training for software engineers based on the OpenChain specification.’ Our presenter is Iwata San from Hitachi.
The OpenChain Korea Work Group will hold its 8th meeting on December 2nd. The event will run from 14:00 to 16:00 Korea time. Everybody is welcome to join. Dial in details below.
Agenda
No
Agenda
Speaker
Slide
1
OpenChain Update
Shane Coughlan, Linux Foundation
–
2
현대자동차 오픈소스 거버넌스 체계 구축
현대자동차 백송하
–
3
SCA(Software Composition Analysis) Market 동향
카카오 황민호(Robin)
–
4
Olive 전격 공개
카카오 황민호(Robin)
–
5
Case Study
All
–
5
OpenChain KWG Update
SK텔레콤 장학성
–
6
Free Discussion
All
–
Case Study
주제 : 오픈소스 컴플라이언스 / 보안취약점 점검 대상 분류
폰트에 대해서도 오픈소스 컴플라이언스 활동을 수행하는지? (예: Open Font)
회사가 사내 직원용 모바일 앱(안드로이드, iOS)을 배포하는지? 그렇다면 이에 대해서도 오픈소스 컴플라이언스 활동을 수행하는지?
오픈소스 보안취약점 점검 대상은 어떻게 분류하는지? 배포하는 소프트웨어 뿐만 아니라, 인프라 용, 서버 용으로 사용 중인 소프트웨어에 대해서도 점검 대상으로 포함시키는지?
The OpenChain Project hosted a special three hour mini-summit to explain the three options for compliance to the International Standard for open source compliance. Learn about self-certification, independent assessment and third-party certification from the experts in each area.
Part 1 – Self-Certification (1 hour session)
The core of the International Standard for open source license compliance is self-certification. This is a process where a company reviews the requirements of the standard and checks whether their current processes match these requirements. If necessary, a company can make adjustments to processes. Self-certification can be accomplished in several ways. The most common are:
Part 2 – Independent Compliance Assessment (1 hour session)
Companies often want assistance in adopting an International Standard. One common form is Independent Assessment, where a knowledgable service provider reviews a company’s processes and provides objective feedback on where adjustments or improvements may be necessary. The OpenChain International Standard for open source compliance has a process called “Independent Compliance Assessment” that is provided by trusted partners of the project. These partners may be law firms or service vendors. Two of our existing partners, Source Code Control (UK) and AlektoMetis (Germany), hosted a session explaining this approach and their respective service offerings.
Part 3 – Third-Party Certification (1 hour session)
In some markets third-party certification is an important part of inter-company relationships. Examples are automotive, infrastructure and aviation, where strict regulation and regular audits are well-served by formal certification by third-parties. The OpenChain International Standard for open source compliance approaches third-party certification in the same way as other International Standards. Two of our existing partners, PwC (Germany) and Orcro (UK), hosted a session explaining this approach and their respective service offerings.
More About Our Webinars:
This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.
The OpenChain India Work Group held its third meeting on the 30th of October 2020. Check out the full recording and join our future activity via our dedicated mailing list.
Balakrishna @ Bosch led the revival of the OpenChain Education Work Group with two meetings exploring the creation of online training for the International Standard for open source license compliance. Catch up and contribute via these recordings and by subscribing to our list.
Join Our Education Mailing List and Help Make This Happen
ITAM Channel, part of the ITAMOrg international membership organization for ITAM Professionals, is hosting a webinar covering OpenChain on the 12th of November.
In this webinar you will hear about how open source is used in the supply chain, the risks associated with open source and strategies to manage this. We will also discuss the latest standards such as the new ISO standard being published from the OpenChain Project with support from many of the larger vendors incl. Arm, Microsoft, Google and Qualcomm.
Event speakers are Martin Callinan of Source Code Control and Shane Coughlan, General Manager at OpenChain
On October 28th at 19:30 GMT Shane Coughlan spoke at Open Source Summit Europe 2020. His talk explored the process of building and deploying the first Linux Foundation ISO standard in fourteen years in collaboration with the Joint Development Foundation. It explained why the evolution from de facto industry standard to formal standardization was important for open source compliance in the context of areas like sales, procurement and M&A.