SlideShare ist ein Scribd-Unternehmen logo
1 von 26
5 STEPS TO ENSURING COMPLIANCE IN THE SOFTWARE 
SUPPLY CHAIN: THE HARMAN CASE STUDY 
© 2014 Black Duck Software, Inc. All Rights Reserved. 
Black Duck Software 
@black_duck_sw
SPEAKERS 
Matthew Jacobs 
General Counsel 
Black Duck Software 
Alyssa Harvey Dawson 
Vice President, Global Intellectual Property & Licensing 
Harman International Industries 
2 © 2014 Black Duck Software, Inc. All Rights Reserved.
AGENDA 
• Open Source Trends 
• License Review 
• OSS Compliance – Harman’s point of view 
• Q&A 
3 © 2014 Black Duck Software, Inc. All Rights Reserved.
FIRST OF ALL… 
“Software is Eating the World.” 
Marc Andreessen (Netscape Founder) 
August ’11, Wall Street Journal 
“Open Source is ubiquitous… having a policy against open source [use] 
is impractical and places you at a competitive disadvantage.” 
4 © 2014 Black Duck Software, Inc. All Rights Reserved. 
Mark Driver, Gartner
…AND THERE IS A GROWING APPETITE FOR OPEN 
SOURCE 
• 4.0 billion files 
• Nearly 1M de-duplicated projects 
• 10+ million staff years of development 
• Billions of $s of development 
• 2,300+ unique software licenses 
2,000,000 
1,500,000 
1,000,000 
500,000 
0 
2007 2009 2011 2013 2015 
5 © 2014 Black Duck Software, Inc. All Rights Reserved. 
Black Duck 
KnowledgeBase 
Open Source Projects
WHAT IS OPEN SOURCE SOFTWARE 
(OSS)? 
• It’s third party software 
• No single “official” 
definition 
Third-Party 
Software 
6 © 2014 Black Duck Software, Inc. All Rights Reserved. 
Open 
Source 
Software
PRIMARY OSS LICENSE CATEGORIES 
• Permissive Licenses 
• Licensee can use, copy, modify and distribute the 
software 
• Licensee is allowed to combine the source with open 
source or proprietary software 
• Licensee is NOT obligated to distribute the source code 
of derivative works 
• Copyleft Licenses 
• Any Licensee modifications to the software must be 
distributed under the same reciprocal OSS license 
• Copyleft licenses are substantially more complex than 
permissive licenses 
7 © 2014 Black Duck Software, Inc. All Rights Reserved. 
Permissive: 
• BSD 
• MIT 
Copyleft: 
• GPL 
• MPL
TOP 20 OPEN SOURCE LICENSES 
Ranked according to number of 
open source projects using the 
license: 
 Top 10 licenses account for 94% 
 Top 20 licenses account for 97% 
 GPL family of licenses account 
for 46% 
Rank License 
1. GNU General Public License (GPL) 2.0 
2. MIT License 
3. Apache License 2.0 
4. GNU General Public License (GPL) 3.0 
5. BSD License 2.0 (3-clause, New or Revised) 
6. Artistic License (Perl) 
7. GNU Lesser General Public License (LGPL) 2.1 
8. GNU Lesser General Public License (LGPL) 3.0 
9. Microsoft Public License (MS-PL) 
10. Eclipse Public License (EPL) 
11. Code Project Open License 1.02 
12. Mozilla Public License (MPL) 1.1 
13. Simplified BSD License (BSD) 
14. Common Development and Distribution License (CDDL) 
15. Microsoft Reciprocal License 
16. GNU Affero General Public License v3 or later 
17. Sun GPL With Classpath Exception v2.0 
18. CDDL-1.1 
19. zlib/libpng License 
20. Common Public License (CPL) 
Source: https://www.blackducksoftware.com/resources/data/top-20- 
open-source-licenses October 2014 
8 © 2014 Black Duck Software, Inc. All Rights Reserved.
IDC ON OPEN SOURCE USE 
“Open source makes up 
30% or more of the 
code at G2000 
organizations” 
“ ‘Next generation’ companies 
such as Amazon, Google, 
Netflix, etc., handle 
development in fundamentally 
different ways leveraging open 
source software” 
9 © 2014 Black Duck Software, Inc. All Rights Reserved.
BLACK DUCK’S EXPERIENCE ANALYZING 
CODE 
• 99% of code audits find open 
source. 
• 95% of audits find unknown open 
source 
• 75% of audits contain unknown 
licenses. 
• 50% of code audits contain GPL. 
• Audits on average contain 33% 
open source. 
10 © 2014 Black Duck Software, Inc. All Rights Reserved.
TODAY DEVELOPMENT IS MULTI-SOURCE 
11 © 2014 Black Duck Software, Inc. All Rights Reserved.
…BUT OFTEN OSS ENTERS A CODE BASE 
UNCHECKED 
Open Source 
Code Base 
Commercial 
3rd Party 
Code 
Purchasing 
• Licensing? 
• Security? 
• Quality? 
• Support? 
12 © 2014 Black Duck Software, Inc. All Rights Reserved. 
SECURITY RISK 
Which components 
have vulnerabilities 
and what are they 
LEGAL RISK 
Which licenses are 
used and do they 
match anticipated 
use of the code 
OPERATIONAL RISK 
Which versions of 
code are being used, 
and how old are they
HARMAN CASE STUDY 
A Real-World Perspective on Open Source 
13 © 2013 Black Duck Software, Inc. All Rights Reserved.
HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2013. ON STAGE, 
AT HOME, 
IN THE CAR, OR 
ON THE GO 
LEGENDARY, DISCIPLINED, 
VISIONARY 
14 
TECHNOLOGY 
INNOVATION 
GLOBAL 
GROWTH 
PREMIUM 
BRANDS 
HARMAN BRINGS YOUR CONNECTED LIFESTYLE AND 
ENTERTAINMENT EXPERIENCES TOGETHER THROUGH PREMIUM 
INFOTAINMENT AND AUDIO SOLUTIONS FOR THE STAGE, AT HOME, 
IN THE CAR, OR ON THE GO.
FY14 REV $5.3B 
~16,000 FTEs 
NUMBER ONE 
IN ALL MARKETS 
L I FESTYLE 
BRANDED AUDIO PRODUCTS 
FOR HOME, CAR, ON THE GO 
LTM REVENUE $1,580M 
LTM EBITDA 14.3% 
PROFESSIONAL 
PRO AUDIO & LIGHTING 
FOR CINEMA, BROADCAST, 
TOUR & INSTALLED SOUND 
LTM REVENUE $826M 
LTM EBITDA 16.3% 
HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2014. 15 
INFOTAINMENT 
NAVIGATION, MULTIMEDIA, 
CONNECTIVITY, & SAFETY 
SOLUTIONS 
LTM REVENUE $2,680M 
LTM EBITDA 10.5% 
LTM = Last Twelve Months, ending Mar. 31, 2014, and exclude non-recurring expense
R&D LEADER 
IN INFOTAINMENT & AUDIO 
HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2013. 16 
STRONGEST GLOBAL R&D 
FOOTPRINT 
• IN-HOUSE DEVELOPMENT OF CORE 
TECHNOLOGIES 
POWERFUL INNOVATION 
PIPELINE 
• 4,900+ PATENTS & PATENTS PENDING 
• SOLUTION ORIENTED TECHNOLOGY ROADMAP 
DISRUPTIVE INNOVATION 
CULTURE 
• SCALABLE PLATFORM REDEFINED INDUSTRY 
LANDSCAPE 
• REVERSE INNOVATION PIONEER IN AUTO 
• RE-INVENTOR OF SURROUND SOUND
EXPAND TECHNOLOGY 
LEADERSHIP 
ACCELERATING 
THE PACE OF 
INNOVATION 
PATENT GROWTH TREND 
1,800+ 
2,700+ 
3,600+ 
4,900+ 
FY ‘07 FY ‘09 FY ‘11 FY ‘13 
HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2013. 17 
4,900+ 
PATENTS
CONNECTED, 
SAFE, GREEN 
AND 
INTELLIGENT 
INNOVATION = 
PASSION + TECHNOLOGY 
DIGITAL SIGNAL 
PROCESSING 
USER EXPERIENCE 
NETWORK 
INTEL L IGENCE 
HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2013. 18 
CONNECTIVITY 
HARMAN CLOUD PLATFORM 
ADVANCED SAFETY 
ENERGY 
EF F ICIENCY 
2XP E R F O R M A N C E @ 5 0 % E N E R G Y
OPEN SOURCE AT HARMAN 
APPRECIATE THE BENEFITS 
• Simplified and rapid development opportunities 
• Many projects offer reliable and well supported code 
• Open standards and vendor independence 
TECHNOLOGY LEADERSHIP 
• OS has moved from margins to the mainstream 
• Key part of any development process 
COMPLIANCE 
• Respect third party rights 
• Protect IP position 
• Minimize adverse product impact 
19 © 2014 Black Duck Software, Inc. All Rights Reserved.
FIVE STEPS TO OPEN SOURCE COMPLIANCE: 
STEP 1: UNDERSTAND PRODUCT DEVELOPMENT 
PROCESSES 
COLLABORATE WITH 
PRODUCT DEVELOPMENT 
OBTAIN MANAGEMENT BUY-IN 
CREATE A TEAM WITH KEY PRODUCT 
DEVELOPMENT PROFESSIONALS 
ENABLE TEAM OWNERSHIP OF REVIEW 
SEEK TO LEARN AND UNDERSTAND FIRST 
20 © 2014 Black Duck Software, Inc. All Rights Reserved.
FIVE STEPS TO OPEN SOURCE COMPLIANCE 
STEP 2: OPEN SOURCE USAGE EVALUATION 
EVALUATE KEY OPEN 
SOURCE USAGE 
DIFFERENTIATE INTERNAL VS. EXTERNAL USAGE 
UNDERSTAND PRODUCT/SERVICES USAGE 
PAY ATTENTION TO DISTRIBUTION 
UNDERSTAND CONTRIBUTIONS 
ASCERTAIN KEY STAKEHOLDERS 
21 © 2014 Black Duck Software, Inc. All Rights Reserved.
FIVE STEPS TO OPEN SOURCE COMPLIANCE: 
STEP 3: TRANSLATE REVIEWS INTO POLICY 
DEVELOP AN OPEN 
SOURCE POLICY 
ESTABLISH A POLICY THAT WORKS WITH YOUR PRODUCT 
DEVELOPMENT PROCESSES 
POLICY SHOULD FILL IN THE GAPS UNCOVERED BY YOUR 
PROCESS REVIEW 
SET UP OPEN SOURCE GOVERNANCE COMMITTEE APPROPRIATE 
FOR YOUR ORGANIZATION 
OBTAIN BUY-IN FROM KEY STAKEHOLDERS 
DESIGN A PROCESS WITH YOUR CUSTOMERS IN MIND 
MAKE SURE KEY COMPONENTS ARE ADDRESSED 
22 © 2014 Black Duck Software, Inc. All Rights Reserved.
FIVE STEPS TO OPEN SOURCE COMPLIANCE: 
STEP 4: IMPLEMENT THE POLICY 
IMPLEMENT THE POLICY 
EDUCATE KEY GROUPS ON OPEN SOURCE 
TRAIN KEY GROUPS ON THE POLICY 
OBTAIN FEEDBACK 
CREATE DOCUMENTATION TO SPEED UP REVIEWS 
BE TRANSPARENT WITH KEY CONSTITUENCIES SUCH AS 
CUSTOMERS, SUPPLIERS 
23 © 2014 Black Duck Software, Inc. All Rights Reserved.
FIVE STEPS TO OPEN SOURCE COMPLIANCE: 
STEP 5: AUDIT THE POLICY AND PROCESS 
REGULARLY REVIEW 
POLICY 
ANNUAL REVIEWS 
UPDATE AS ORGANIZATION CHANGES 
• DIVISION REORGS 
• NEW PERSONNEL 
• ACQUISITIONS 
LISTEN TO FEEDBACK 
KEEP WHAT WORKS, CHANGE WHAT DOESN’T 
ONE SIZE DOES NOT FIT ALL; TAILOR FOR YOUR COMPANY 
24 © 2014 Black Duck Software, Inc. All Rights Reserved.
CONCLUSION 
• Software development has changed 
• Componentization and re-use 
• Open source is ubiquitous and an important element of 
software strategy 
• Open source has significant benefits, but needs to be 
managed properly 
• An effective compliance program includes policy, 
process and automation technology 
25 © 2014 Black Duck Software, Inc. All Rights Reserved.
VIEW THIS WEBINAR PRESENTATION AT: 
WWW.BLACKDUCKSOFTWARE.COM/RESOURCE 
S/WEBINAR/5-STEPS-ENSURING-OPEN-SOURCE-COMPLIANCE- 
SOFTWARE-SUPPLY-CHAIN-HARMAN- 
CASE-STUDY 
@black_duck_sw

Weitere ähnliche Inhalte

Was ist angesagt?

OMA Open Source Industry Survey Results
OMA Open Source Industry Survey ResultsOMA Open Source Industry Survey Results
OMA Open Source Industry Survey ResultsOpen Mobile Alliance
 
PCI and Vulnerability Assessments - What’s Missing?
PCI and Vulnerability Assessments - What’s Missing?PCI and Vulnerability Assessments - What’s Missing?
PCI and Vulnerability Assessments - What’s Missing?Black Duck by Synopsys
 
Q1 2016 Open Source Security Report: Glibc and Beyond
Q1 2016 Open Source Security Report: Glibc and BeyondQ1 2016 Open Source Security Report: Glibc and Beyond
Q1 2016 Open Source Security Report: Glibc and BeyondBlack Duck by Synopsys
 
Rise of the Open Source Program Office for LinuxCon 2016
Rise of the Open Source Program Office for LinuxCon 2016Rise of the Open Source Program Office for LinuxCon 2016
Rise of the Open Source Program Office for LinuxCon 2016Gil Yehuda
 
Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–You've Got Your Open Source Audit Report–Now What? Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–You've Got Your Open Source Audit Report–Now What? Synopsys Software Integrity Group
 
Open Source 360 Survey Results
Open Source 360 Survey ResultsOpen Source 360 Survey Results
Open Source 360 Survey ResultsTim Mackey
 
Morpheus Drive – A Simple File Sharing UI for Alfresco that Solves the Dropbo...
Morpheus Drive – A Simple File Sharing UI for Alfresco that Solves the Dropbo...Morpheus Drive – A Simple File Sharing UI for Alfresco that Solves the Dropbo...
Morpheus Drive – A Simple File Sharing UI for Alfresco that Solves the Dropbo...rivetlogic
 
Open Source: The Legal & Security Implications for the Connected Car
Open Source: The Legal & Security Implications for the Connected CarOpen Source: The Legal & Security Implications for the Connected Car
Open Source: The Legal & Security Implications for the Connected CarJerika Phelps
 
Do Design Quality and Code Quality Matter in Merger and Acquisition Tech Due ...
Do Design Quality and Code Quality Matter in Merger and Acquisition Tech Due ...Do Design Quality and Code Quality Matter in Merger and Acquisition Tech Due ...
Do Design Quality and Code Quality Matter in Merger and Acquisition Tech Due ...Synopsys Software Integrity Group
 
Going Open: How to Make a Project Open Source
Going Open: How to Make a Project Open SourceGoing Open: How to Make a Project Open Source
Going Open: How to Make a Project Open SourceBlack Duck by Synopsys
 
Open Source: The Legal & Security Implications for the Connected Car
Open Source: The Legal & Security Implications for the Connected CarOpen Source: The Legal & Security Implications for the Connected Car
Open Source: The Legal & Security Implications for the Connected CarBlack Duck by Synopsys
 
Web Engagement for the Mobile Era
Web Engagement for the Mobile EraWeb Engagement for the Mobile Era
Web Engagement for the Mobile Erarivetlogic
 
Managing IP for OSS and Open Technology Programs
Managing IP for OSS and Open Technology ProgramsManaging IP for OSS and Open Technology Programs
Managing IP for OSS and Open Technology ProgramsMarcus A. Streips
 

Was ist angesagt? (19)

OMA Open Source Industry Survey Results
OMA Open Source Industry Survey ResultsOMA Open Source Industry Survey Results
OMA Open Source Industry Survey Results
 
PCI and Vulnerability Assessments - What’s Missing?
PCI and Vulnerability Assessments - What’s Missing?PCI and Vulnerability Assessments - What’s Missing?
PCI and Vulnerability Assessments - What’s Missing?
 
Q1 2016 Open Source Security Report: Glibc and Beyond
Q1 2016 Open Source Security Report: Glibc and BeyondQ1 2016 Open Source Security Report: Glibc and Beyond
Q1 2016 Open Source Security Report: Glibc and Beyond
 
Webinar–That is Not How This Works
Webinar–That is Not How This WorksWebinar–That is Not How This Works
Webinar–That is Not How This Works
 
Rise of the Open Source Program Office for LinuxCon 2016
Rise of the Open Source Program Office for LinuxCon 2016Rise of the Open Source Program Office for LinuxCon 2016
Rise of the Open Source Program Office for LinuxCon 2016
 
Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–You've Got Your Open Source Audit Report–Now What? Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–You've Got Your Open Source Audit Report–Now What?
 
Open Source 360 Survey Results
Open Source 360 Survey ResultsOpen Source 360 Survey Results
Open Source 360 Survey Results
 
Webinar–5 ways to risk rank your vulnerabilities
Webinar–5 ways to risk rank your vulnerabilitiesWebinar–5 ways to risk rank your vulnerabilities
Webinar–5 ways to risk rank your vulnerabilities
 
Webinar–The State of Open Source in M&A Transactions
Webinar–The State of Open Source in M&A Transactions Webinar–The State of Open Source in M&A Transactions
Webinar–The State of Open Source in M&A Transactions
 
Morpheus Drive – A Simple File Sharing UI for Alfresco that Solves the Dropbo...
Morpheus Drive – A Simple File Sharing UI for Alfresco that Solves the Dropbo...Morpheus Drive – A Simple File Sharing UI for Alfresco that Solves the Dropbo...
Morpheus Drive – A Simple File Sharing UI for Alfresco that Solves the Dropbo...
 
Zero-Trust SASE DevSecOps
Zero-Trust SASE DevSecOpsZero-Trust SASE DevSecOps
Zero-Trust SASE DevSecOps
 
Open Source: The Legal & Security Implications for the Connected Car
Open Source: The Legal & Security Implications for the Connected CarOpen Source: The Legal & Security Implications for the Connected Car
Open Source: The Legal & Security Implications for the Connected Car
 
Making Network Security Relevant
Making Network Security RelevantMaking Network Security Relevant
Making Network Security Relevant
 
Do Design Quality and Code Quality Matter in Merger and Acquisition Tech Due ...
Do Design Quality and Code Quality Matter in Merger and Acquisition Tech Due ...Do Design Quality and Code Quality Matter in Merger and Acquisition Tech Due ...
Do Design Quality and Code Quality Matter in Merger and Acquisition Tech Due ...
 
Webinar–The 2019 Open Source Year in Review
Webinar–The 2019 Open Source Year in ReviewWebinar–The 2019 Open Source Year in Review
Webinar–The 2019 Open Source Year in Review
 
Going Open: How to Make a Project Open Source
Going Open: How to Make a Project Open SourceGoing Open: How to Make a Project Open Source
Going Open: How to Make a Project Open Source
 
Open Source: The Legal & Security Implications for the Connected Car
Open Source: The Legal & Security Implications for the Connected CarOpen Source: The Legal & Security Implications for the Connected Car
Open Source: The Legal & Security Implications for the Connected Car
 
Web Engagement for the Mobile Era
Web Engagement for the Mobile EraWeb Engagement for the Mobile Era
Web Engagement for the Mobile Era
 
Managing IP for OSS and Open Technology Programs
Managing IP for OSS and Open Technology ProgramsManaging IP for OSS and Open Technology Programs
Managing IP for OSS and Open Technology Programs
 

Ähnlich wie 5 Steps to Ensuring Compliance in the Software Supply Chain: The Harman Case Study

OSS has taken over the enterprise: The top five OSS trends of 2015
OSS has taken over the enterprise: The top five OSS trends of 2015OSS has taken over the enterprise: The top five OSS trends of 2015
OSS has taken over the enterprise: The top five OSS trends of 2015Rogue Wave Software
 
Welcome & The State of Open Source Security
Welcome & The State of Open Source SecurityWelcome & The State of Open Source Security
Welcome & The State of Open Source SecurityJerika Phelps
 
Open source software 101: Compliance and risk management
Open source software 101: Compliance and risk managementOpen source software 101: Compliance and risk management
Open source software 101: Compliance and risk managementOsler, Hoskin & Harcourt LLP
 
Building the Open Developer Platform with OpenShift & WhiteSource
Building the Open Developer Platform with OpenShift & WhiteSourceBuilding the Open Developer Platform with OpenShift & WhiteSource
Building the Open Developer Platform with OpenShift & WhiteSourceOpen Source Strategy Forum
 
Open soucre(cut shrt)
Open soucre(cut shrt)Open soucre(cut shrt)
Open soucre(cut shrt)Shivani Rai
 
Open Source All The Things
Open Source All The ThingsOpen Source All The Things
Open Source All The ThingsAll Things Open
 
Implementing and Managing an Open Source Compliance Program: A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash CourseImplementing and Managing an Open Source Compliance Program: A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash CourseFINOS
 
Implementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing Open Source Compliance Programs - A Crash CourseImplementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing Open Source Compliance Programs - A Crash CourseOpen Source Strategy Forum
 
Establishing an Open Source Program Office
Establishing an Open Source Program OfficeEstablishing an Open Source Program Office
Establishing an Open Source Program OfficeLee Calcote
 
Create a Unified View of Your Application Security Program – Black Duck Hub a...
Create a Unified View of Your Application Security Program – Black Duck Hub a...Create a Unified View of Your Application Security Program – Black Duck Hub a...
Create a Unified View of Your Application Security Program – Black Duck Hub a...Denim Group
 
Why open source is good for your economy
Why open source is good for your economyWhy open source is good for your economy
Why open source is good for your economyDirk Riehle
 
Identifying and managing the risks of open source software for PHP developers
Identifying and managing the risks of open source software for PHP developersIdentifying and managing the risks of open source software for PHP developers
Identifying and managing the risks of open source software for PHP developersRogue Wave Software
 
How enterprises learned to stop worrying and love open source
How enterprises learned to stop worrying and love open sourceHow enterprises learned to stop worrying and love open source
How enterprises learned to stop worrying and love open sourceRogue Wave Software
 
The Role of Legal Counsels in Focusing Compliance on Scaling and Execution
The Role of Legal Counsels in Focusing Compliance on Scaling and ExecutionThe Role of Legal Counsels in Focusing Compliance on Scaling and Execution
The Role of Legal Counsels in Focusing Compliance on Scaling and ExecutionSamsung Open Source Group
 
Understanding Open Source
Understanding Open SourceUnderstanding Open Source
Understanding Open SourceJody Garnett
 
Inner-Source: The Lesson of Linux for Enterprises
Inner-Source: The Lesson of Linux for EnterprisesInner-Source: The Lesson of Linux for Enterprises
Inner-Source: The Lesson of Linux for EnterprisesSamsung Open Source Group
 

Ähnlich wie 5 Steps to Ensuring Compliance in the Software Supply Chain: The Harman Case Study (20)

OSS has taken over the enterprise: The top five OSS trends of 2015
OSS has taken over the enterprise: The top five OSS trends of 2015OSS has taken over the enterprise: The top five OSS trends of 2015
OSS has taken over the enterprise: The top five OSS trends of 2015
 
Open Source vs Proprietary
Open Source vs ProprietaryOpen Source vs Proprietary
Open Source vs Proprietary
 
Welcome & The State of Open Source Security
Welcome & The State of Open Source SecurityWelcome & The State of Open Source Security
Welcome & The State of Open Source Security
 
Open source
Open source Open source
Open source
 
Open source software 101: Compliance and risk management
Open source software 101: Compliance and risk managementOpen source software 101: Compliance and risk management
Open source software 101: Compliance and risk management
 
Open Source
Open SourceOpen Source
Open Source
 
Building the Open Developer Platform with OpenShift & WhiteSource
Building the Open Developer Platform with OpenShift & WhiteSourceBuilding the Open Developer Platform with OpenShift & WhiteSource
Building the Open Developer Platform with OpenShift & WhiteSource
 
Open soucre(cut shrt)
Open soucre(cut shrt)Open soucre(cut shrt)
Open soucre(cut shrt)
 
Open Source All The Things
Open Source All The ThingsOpen Source All The Things
Open Source All The Things
 
Implementing and Managing an Open Source Compliance Program: A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash CourseImplementing and Managing an Open Source Compliance Program: A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash Course
 
Implementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing Open Source Compliance Programs - A Crash CourseImplementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing Open Source Compliance Programs - A Crash Course
 
Establishing an Open Source Program Office
Establishing an Open Source Program OfficeEstablishing an Open Source Program Office
Establishing an Open Source Program Office
 
Create a Unified View of Your Application Security Program – Black Duck Hub a...
Create a Unified View of Your Application Security Program – Black Duck Hub a...Create a Unified View of Your Application Security Program – Black Duck Hub a...
Create a Unified View of Your Application Security Program – Black Duck Hub a...
 
Why open source is good for your economy
Why open source is good for your economyWhy open source is good for your economy
Why open source is good for your economy
 
Identifying and managing the risks of open source software for PHP developers
Identifying and managing the risks of open source software for PHP developersIdentifying and managing the risks of open source software for PHP developers
Identifying and managing the risks of open source software for PHP developers
 
How enterprises learned to stop worrying and love open source
How enterprises learned to stop worrying and love open sourceHow enterprises learned to stop worrying and love open source
How enterprises learned to stop worrying and love open source
 
open source
open sourceopen source
open source
 
The Role of Legal Counsels in Focusing Compliance on Scaling and Execution
The Role of Legal Counsels in Focusing Compliance on Scaling and ExecutionThe Role of Legal Counsels in Focusing Compliance on Scaling and Execution
The Role of Legal Counsels in Focusing Compliance on Scaling and Execution
 
Understanding Open Source
Understanding Open SourceUnderstanding Open Source
Understanding Open Source
 
Inner-Source: The Lesson of Linux for Enterprises
Inner-Source: The Lesson of Linux for EnterprisesInner-Source: The Lesson of Linux for Enterprises
Inner-Source: The Lesson of Linux for Enterprises
 

Mehr von Black Duck by Synopsys

Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubFLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubBlack Duck by Synopsys
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...Black Duck by Synopsys
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical GuideFLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical GuideBlack Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your DealFLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your DealBlack Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub Black Duck by Synopsys
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Black Duck by Synopsys
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...Black Duck by Synopsys
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...Black Duck by Synopsys
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Black Duck by Synopsys
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...Black Duck by Synopsys
 
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...Black Duck by Synopsys
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...Black Duck by Synopsys
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating NewsOpen Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating NewsBlack Duck by Synopsys
 

Mehr von Black Duck by Synopsys (20)

Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubFLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical GuideFLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your DealFLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
 
FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
 
Open Source Rookies and Community
Open Source Rookies and CommunityOpen Source Rookies and Community
Open Source Rookies and Community
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
 
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating NewsOpen Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
 

Kürzlich hochgeladen

Authentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxAuthentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxGregory DeShields
 
It’s Time Get Refresh Travel Around The World
It’s Time Get Refresh Travel Around The WorldIt’s Time Get Refresh Travel Around The World
It’s Time Get Refresh Travel Around The WorldParagliding Billing Bir
 
Top Five Best Places to Visit in India.pdf
Top Five Best Places to Visit in India.pdfTop Five Best Places to Visit in India.pdf
Top Five Best Places to Visit in India.pdfonlinevisaindia
 
How Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersHow Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersMakena Coast Charters
 
a presentation for foreigners about how to travel in Germany.
a presentation for foreigners about how to travel in Germany.a presentation for foreigners about how to travel in Germany.
a presentation for foreigners about how to travel in Germany.moritzmieg
 
Lucknow to Sitapur Cab | Lucknow to Sitapur Taxi
Lucknow to Sitapur Cab | Lucknow to Sitapur TaxiLucknow to Sitapur Cab | Lucknow to Sitapur Taxi
Lucknow to Sitapur Cab | Lucknow to Sitapur TaxiCab Bazar
 
Sicily Holidays Guide Book: Unveiling the Treasures of Italy's Jewel
Sicily Holidays Guide Book: Unveiling the Treasures of Italy's JewelSicily Holidays Guide Book: Unveiling the Treasures of Italy's Jewel
Sicily Holidays Guide Book: Unveiling the Treasures of Italy's JewelTime for Sicily
 
Story Of Neem Karoli Baba -Kainchi Dham Yatra
Story Of Neem Karoli Baba -Kainchi Dham YatraStory Of Neem Karoli Baba -Kainchi Dham Yatra
Story Of Neem Karoli Baba -Kainchi Dham YatraSuYatra
 
What Unwritten Rules Of Surfing Etiquette Are Crucial For Beginners To Grasp
What Unwritten Rules Of Surfing Etiquette Are Crucial For Beginners To GraspWhat Unwritten Rules Of Surfing Etiquette Are Crucial For Beginners To Grasp
What Unwritten Rules Of Surfing Etiquette Are Crucial For Beginners To GraspHanalei Surf School
 
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)Mazie Garcia
 
Canada PR - Eligibility, Steps to apply and Visa processing fees
Canada PR - Eligibility, Steps to apply and Visa processing feesCanada PR - Eligibility, Steps to apply and Visa processing fees
Canada PR - Eligibility, Steps to apply and Visa processing feesY-Axis Overseas Careers
 
Phil....National-Capital-Region-NCR.pptx
Phil....National-Capital-Region-NCR.pptxPhil....National-Capital-Region-NCR.pptx
Phil....National-Capital-Region-NCR.pptxDitasDelaCruz
 
Disney Dreams in Europe: A Guide to Disneyland Paris
Disney Dreams in Europe: A Guide to Disneyland ParisDisney Dreams in Europe: A Guide to Disneyland Paris
Disney Dreams in Europe: A Guide to Disneyland ParisisangoTravel
 
Inspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodInspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodKasia Chojecki
 
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)Escort Service
 
Paragliding Billing Bir at Himachal Pardesh
Paragliding Billing Bir at Himachal PardeshParagliding Billing Bir at Himachal Pardesh
Paragliding Billing Bir at Himachal PardeshParagliding Billing Bir
 
Solbello Sun Shade Umbrella for Beach 2024
Solbello Sun Shade Umbrella for Beach 2024Solbello Sun Shade Umbrella for Beach 2024
Solbello Sun Shade Umbrella for Beach 2024Solbello
 
Revolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI UpdateRevolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI Updatejoymorrison10
 

Kürzlich hochgeladen (18)

Authentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxAuthentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptx
 
It’s Time Get Refresh Travel Around The World
It’s Time Get Refresh Travel Around The WorldIt’s Time Get Refresh Travel Around The World
It’s Time Get Refresh Travel Around The World
 
Top Five Best Places to Visit in India.pdf
Top Five Best Places to Visit in India.pdfTop Five Best Places to Visit in India.pdf
Top Five Best Places to Visit in India.pdf
 
How Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersHow Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s Waters
 
a presentation for foreigners about how to travel in Germany.
a presentation for foreigners about how to travel in Germany.a presentation for foreigners about how to travel in Germany.
a presentation for foreigners about how to travel in Germany.
 
Lucknow to Sitapur Cab | Lucknow to Sitapur Taxi
Lucknow to Sitapur Cab | Lucknow to Sitapur TaxiLucknow to Sitapur Cab | Lucknow to Sitapur Taxi
Lucknow to Sitapur Cab | Lucknow to Sitapur Taxi
 
Sicily Holidays Guide Book: Unveiling the Treasures of Italy's Jewel
Sicily Holidays Guide Book: Unveiling the Treasures of Italy's JewelSicily Holidays Guide Book: Unveiling the Treasures of Italy's Jewel
Sicily Holidays Guide Book: Unveiling the Treasures of Italy's Jewel
 
Story Of Neem Karoli Baba -Kainchi Dham Yatra
Story Of Neem Karoli Baba -Kainchi Dham YatraStory Of Neem Karoli Baba -Kainchi Dham Yatra
Story Of Neem Karoli Baba -Kainchi Dham Yatra
 
What Unwritten Rules Of Surfing Etiquette Are Crucial For Beginners To Grasp
What Unwritten Rules Of Surfing Etiquette Are Crucial For Beginners To GraspWhat Unwritten Rules Of Surfing Etiquette Are Crucial For Beginners To Grasp
What Unwritten Rules Of Surfing Etiquette Are Crucial For Beginners To Grasp
 
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
 
Canada PR - Eligibility, Steps to apply and Visa processing fees
Canada PR - Eligibility, Steps to apply and Visa processing feesCanada PR - Eligibility, Steps to apply and Visa processing fees
Canada PR - Eligibility, Steps to apply and Visa processing fees
 
Phil....National-Capital-Region-NCR.pptx
Phil....National-Capital-Region-NCR.pptxPhil....National-Capital-Region-NCR.pptx
Phil....National-Capital-Region-NCR.pptx
 
Disney Dreams in Europe: A Guide to Disneyland Paris
Disney Dreams in Europe: A Guide to Disneyland ParisDisney Dreams in Europe: A Guide to Disneyland Paris
Disney Dreams in Europe: A Guide to Disneyland Paris
 
Inspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodInspirational Quotes About Italy and Food
Inspirational Quotes About Italy and Food
 
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
 
Paragliding Billing Bir at Himachal Pardesh
Paragliding Billing Bir at Himachal PardeshParagliding Billing Bir at Himachal Pardesh
Paragliding Billing Bir at Himachal Pardesh
 
Solbello Sun Shade Umbrella for Beach 2024
Solbello Sun Shade Umbrella for Beach 2024Solbello Sun Shade Umbrella for Beach 2024
Solbello Sun Shade Umbrella for Beach 2024
 
Revolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI UpdateRevolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI Update
 

5 Steps to Ensuring Compliance in the Software Supply Chain: The Harman Case Study

  • 1. 5 STEPS TO ENSURING COMPLIANCE IN THE SOFTWARE SUPPLY CHAIN: THE HARMAN CASE STUDY © 2014 Black Duck Software, Inc. All Rights Reserved. Black Duck Software @black_duck_sw
  • 2. SPEAKERS Matthew Jacobs General Counsel Black Duck Software Alyssa Harvey Dawson Vice President, Global Intellectual Property & Licensing Harman International Industries 2 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 3. AGENDA • Open Source Trends • License Review • OSS Compliance – Harman’s point of view • Q&A 3 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 4. FIRST OF ALL… “Software is Eating the World.” Marc Andreessen (Netscape Founder) August ’11, Wall Street Journal “Open Source is ubiquitous… having a policy against open source [use] is impractical and places you at a competitive disadvantage.” 4 © 2014 Black Duck Software, Inc. All Rights Reserved. Mark Driver, Gartner
  • 5. …AND THERE IS A GROWING APPETITE FOR OPEN SOURCE • 4.0 billion files • Nearly 1M de-duplicated projects • 10+ million staff years of development • Billions of $s of development • 2,300+ unique software licenses 2,000,000 1,500,000 1,000,000 500,000 0 2007 2009 2011 2013 2015 5 © 2014 Black Duck Software, Inc. All Rights Reserved. Black Duck KnowledgeBase Open Source Projects
  • 6. WHAT IS OPEN SOURCE SOFTWARE (OSS)? • It’s third party software • No single “official” definition Third-Party Software 6 © 2014 Black Duck Software, Inc. All Rights Reserved. Open Source Software
  • 7. PRIMARY OSS LICENSE CATEGORIES • Permissive Licenses • Licensee can use, copy, modify and distribute the software • Licensee is allowed to combine the source with open source or proprietary software • Licensee is NOT obligated to distribute the source code of derivative works • Copyleft Licenses • Any Licensee modifications to the software must be distributed under the same reciprocal OSS license • Copyleft licenses are substantially more complex than permissive licenses 7 © 2014 Black Duck Software, Inc. All Rights Reserved. Permissive: • BSD • MIT Copyleft: • GPL • MPL
  • 8. TOP 20 OPEN SOURCE LICENSES Ranked according to number of open source projects using the license:  Top 10 licenses account for 94%  Top 20 licenses account for 97%  GPL family of licenses account for 46% Rank License 1. GNU General Public License (GPL) 2.0 2. MIT License 3. Apache License 2.0 4. GNU General Public License (GPL) 3.0 5. BSD License 2.0 (3-clause, New or Revised) 6. Artistic License (Perl) 7. GNU Lesser General Public License (LGPL) 2.1 8. GNU Lesser General Public License (LGPL) 3.0 9. Microsoft Public License (MS-PL) 10. Eclipse Public License (EPL) 11. Code Project Open License 1.02 12. Mozilla Public License (MPL) 1.1 13. Simplified BSD License (BSD) 14. Common Development and Distribution License (CDDL) 15. Microsoft Reciprocal License 16. GNU Affero General Public License v3 or later 17. Sun GPL With Classpath Exception v2.0 18. CDDL-1.1 19. zlib/libpng License 20. Common Public License (CPL) Source: https://www.blackducksoftware.com/resources/data/top-20- open-source-licenses October 2014 8 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 9. IDC ON OPEN SOURCE USE “Open source makes up 30% or more of the code at G2000 organizations” “ ‘Next generation’ companies such as Amazon, Google, Netflix, etc., handle development in fundamentally different ways leveraging open source software” 9 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 10. BLACK DUCK’S EXPERIENCE ANALYZING CODE • 99% of code audits find open source. • 95% of audits find unknown open source • 75% of audits contain unknown licenses. • 50% of code audits contain GPL. • Audits on average contain 33% open source. 10 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 11. TODAY DEVELOPMENT IS MULTI-SOURCE 11 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 12. …BUT OFTEN OSS ENTERS A CODE BASE UNCHECKED Open Source Code Base Commercial 3rd Party Code Purchasing • Licensing? • Security? • Quality? • Support? 12 © 2014 Black Duck Software, Inc. All Rights Reserved. SECURITY RISK Which components have vulnerabilities and what are they LEGAL RISK Which licenses are used and do they match anticipated use of the code OPERATIONAL RISK Which versions of code are being used, and how old are they
  • 13. HARMAN CASE STUDY A Real-World Perspective on Open Source 13 © 2013 Black Duck Software, Inc. All Rights Reserved.
  • 14. HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2013. ON STAGE, AT HOME, IN THE CAR, OR ON THE GO LEGENDARY, DISCIPLINED, VISIONARY 14 TECHNOLOGY INNOVATION GLOBAL GROWTH PREMIUM BRANDS HARMAN BRINGS YOUR CONNECTED LIFESTYLE AND ENTERTAINMENT EXPERIENCES TOGETHER THROUGH PREMIUM INFOTAINMENT AND AUDIO SOLUTIONS FOR THE STAGE, AT HOME, IN THE CAR, OR ON THE GO.
  • 15. FY14 REV $5.3B ~16,000 FTEs NUMBER ONE IN ALL MARKETS L I FESTYLE BRANDED AUDIO PRODUCTS FOR HOME, CAR, ON THE GO LTM REVENUE $1,580M LTM EBITDA 14.3% PROFESSIONAL PRO AUDIO & LIGHTING FOR CINEMA, BROADCAST, TOUR & INSTALLED SOUND LTM REVENUE $826M LTM EBITDA 16.3% HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2014. 15 INFOTAINMENT NAVIGATION, MULTIMEDIA, CONNECTIVITY, & SAFETY SOLUTIONS LTM REVENUE $2,680M LTM EBITDA 10.5% LTM = Last Twelve Months, ending Mar. 31, 2014, and exclude non-recurring expense
  • 16. R&D LEADER IN INFOTAINMENT & AUDIO HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2013. 16 STRONGEST GLOBAL R&D FOOTPRINT • IN-HOUSE DEVELOPMENT OF CORE TECHNOLOGIES POWERFUL INNOVATION PIPELINE • 4,900+ PATENTS & PATENTS PENDING • SOLUTION ORIENTED TECHNOLOGY ROADMAP DISRUPTIVE INNOVATION CULTURE • SCALABLE PLATFORM REDEFINED INDUSTRY LANDSCAPE • REVERSE INNOVATION PIONEER IN AUTO • RE-INVENTOR OF SURROUND SOUND
  • 17. EXPAND TECHNOLOGY LEADERSHIP ACCELERATING THE PACE OF INNOVATION PATENT GROWTH TREND 1,800+ 2,700+ 3,600+ 4,900+ FY ‘07 FY ‘09 FY ‘11 FY ‘13 HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2013. 17 4,900+ PATENTS
  • 18. CONNECTED, SAFE, GREEN AND INTELLIGENT INNOVATION = PASSION + TECHNOLOGY DIGITAL SIGNAL PROCESSING USER EXPERIENCE NETWORK INTEL L IGENCE HARMAN INTERNATIONAL. CONFIDENTIAL. COPYRIGHT 2013. 18 CONNECTIVITY HARMAN CLOUD PLATFORM ADVANCED SAFETY ENERGY EF F ICIENCY 2XP E R F O R M A N C E @ 5 0 % E N E R G Y
  • 19. OPEN SOURCE AT HARMAN APPRECIATE THE BENEFITS • Simplified and rapid development opportunities • Many projects offer reliable and well supported code • Open standards and vendor independence TECHNOLOGY LEADERSHIP • OS has moved from margins to the mainstream • Key part of any development process COMPLIANCE • Respect third party rights • Protect IP position • Minimize adverse product impact 19 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 20. FIVE STEPS TO OPEN SOURCE COMPLIANCE: STEP 1: UNDERSTAND PRODUCT DEVELOPMENT PROCESSES COLLABORATE WITH PRODUCT DEVELOPMENT OBTAIN MANAGEMENT BUY-IN CREATE A TEAM WITH KEY PRODUCT DEVELOPMENT PROFESSIONALS ENABLE TEAM OWNERSHIP OF REVIEW SEEK TO LEARN AND UNDERSTAND FIRST 20 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 21. FIVE STEPS TO OPEN SOURCE COMPLIANCE STEP 2: OPEN SOURCE USAGE EVALUATION EVALUATE KEY OPEN SOURCE USAGE DIFFERENTIATE INTERNAL VS. EXTERNAL USAGE UNDERSTAND PRODUCT/SERVICES USAGE PAY ATTENTION TO DISTRIBUTION UNDERSTAND CONTRIBUTIONS ASCERTAIN KEY STAKEHOLDERS 21 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 22. FIVE STEPS TO OPEN SOURCE COMPLIANCE: STEP 3: TRANSLATE REVIEWS INTO POLICY DEVELOP AN OPEN SOURCE POLICY ESTABLISH A POLICY THAT WORKS WITH YOUR PRODUCT DEVELOPMENT PROCESSES POLICY SHOULD FILL IN THE GAPS UNCOVERED BY YOUR PROCESS REVIEW SET UP OPEN SOURCE GOVERNANCE COMMITTEE APPROPRIATE FOR YOUR ORGANIZATION OBTAIN BUY-IN FROM KEY STAKEHOLDERS DESIGN A PROCESS WITH YOUR CUSTOMERS IN MIND MAKE SURE KEY COMPONENTS ARE ADDRESSED 22 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 23. FIVE STEPS TO OPEN SOURCE COMPLIANCE: STEP 4: IMPLEMENT THE POLICY IMPLEMENT THE POLICY EDUCATE KEY GROUPS ON OPEN SOURCE TRAIN KEY GROUPS ON THE POLICY OBTAIN FEEDBACK CREATE DOCUMENTATION TO SPEED UP REVIEWS BE TRANSPARENT WITH KEY CONSTITUENCIES SUCH AS CUSTOMERS, SUPPLIERS 23 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 24. FIVE STEPS TO OPEN SOURCE COMPLIANCE: STEP 5: AUDIT THE POLICY AND PROCESS REGULARLY REVIEW POLICY ANNUAL REVIEWS UPDATE AS ORGANIZATION CHANGES • DIVISION REORGS • NEW PERSONNEL • ACQUISITIONS LISTEN TO FEEDBACK KEEP WHAT WORKS, CHANGE WHAT DOESN’T ONE SIZE DOES NOT FIT ALL; TAILOR FOR YOUR COMPANY 24 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 25. CONCLUSION • Software development has changed • Componentization and re-use • Open source is ubiquitous and an important element of software strategy • Open source has significant benefits, but needs to be managed properly • An effective compliance program includes policy, process and automation technology 25 © 2014 Black Duck Software, Inc. All Rights Reserved.
  • 26. VIEW THIS WEBINAR PRESENTATION AT: WWW.BLACKDUCKSOFTWARE.COM/RESOURCE S/WEBINAR/5-STEPS-ENSURING-OPEN-SOURCE-COMPLIANCE- SOFTWARE-SUPPLY-CHAIN-HARMAN- CASE-STUDY @black_duck_sw