Adapting IT Governance Frameworks to Ensure Control and Visibility of Open Source



Similar documents
HOW TO UTILIZE OPEN SOURCE IN YOUR CODE BASE AND BUILD PROCESS Black Duck Software, Inc. All Rights Reserved.

5 Steps for a Winning Open Source Compliance Program

Driving Business Agility with the Use of Open Source Software

How To Improve Your Software

EA vs ITSM. itsmf

How To Manage An Open Source Software

Background: Business Value of Enterprise Architecture TOGAF Architectures and the Business Services Architecture

Explore the Possibilities

Module F13 The TOGAF Certification for People Program

Streamlining Open Source License Compliance with SPDX

XEROX TALKS BEST PRACTICES FOR OPEN SOURCE GOVERNANCE

From Capability-Based Planning to Competitive Advantage Assembling Your Business Transformation Value Network

Open Source Software and the impact on Mergers & Acquisitions

OSS LOGISTICS: DRIVING INNOVATIVE SOFTWARE FROM DEVELOPER TO CUSTOMER Alex Bigmore Senior Architect & Open Source Governance Programme Manager SITA

The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into

Managing Open Source Code Best Practices

Information Governance Workshop. David Zanotta, Ph.D. Vice President, Global Data Management & Governance - PMO

TOGAF and ITIL. A White Paper by: Serge Thorn Merck Serono International SA

PM Services. Portfolio Strategy, Design and Build

SOA + BPM = Agile Integrated Tax Systems. Hemant Sharma CTO, State and Local Government

Developing Business Architecture with TOGAF

How To Understand The Role Of Enterprise Architecture In The Context Of Organizational Strategy

BRIDGE. the gaps between IT, cloud service providers, and the business. IT service management for the cloud. Business white paper

TOGAF 9 Level Exam Study Guide

Migrating to the Cloud. Developing the right Cloud strategy and minimising migration risk with Logicalis Cloud Services

Setting up an Effective Enterprise Architecture capability. Simon Townson Principal Enterprise Architect SAP

OPTIMUS SBR. Optimizing Results with Business Intelligence Governance CHOICE TOOLS. PRECISION AIM. BOLD ATTITUDE.

G-Cloud 7 Service Description Document. Third Party Services. Zendesk Licences 1. Zendesk Services (Consulting) 2. Nexus Pro Licences & Services 3

Beyond Mandates: Getting to Sustainable IT Governance Best Practices. Steve Romero PMP, CISSP, CPM IT Governance Evangelist

How To Develop A Data Warehouse

The Art of Architecture Transformation. Copyright 2012, Oracle and/or its affiliates. All rights reserved.

Approach to Information Security Architecture. Kaapro Kanto Chief Architect, Security and Privacy TeliaSonera

Project Management Office Best Practices

Practical Approaches to Achieving Sustainable IT Governance

How to Ensure IT Compliance Without Compromising Innovation. Nik Teshima, IBM Phil Odence, Black Duck

Process-Based Business Transformation. Todd Lohr, Practice Director

Vermont Enterprise Architecture Framework (VEAF) Master Data Management (MDM) Abridged Strategy Level 0

ITSM 101. Patrick Connelly and Sandeep Narang. Gartner.

Data Governance Primer. A PPDM Workshop. March 2015

Table of contents. Best practices in open source governance. Managing the selection and proliferation of open source software across your enterprise

FOSSBazaar A Governance Initiative to manage Free and Open Source Software life cycle

Enterprise Architecture Roles in Delivering Business Capabilities

Managing Change Using Enterprise Architecture

AV-20 Best Practices for Effective Document and Knowledge Management

Presented By: Leah R. Smith, PMP. Ju ly, 2 011

Share the webinar Ask a question Votes (polling questions) Rate (before you leave) Attachments (you can download today s presentation)

Computing & Communications Services

White Paper Software Quality Management

Data Center is the Foundation of Carrier ICT Transformation. The challenges of building a service driven data center

DEVELOPING AN EFFECTIVE INTERNAL AUDIT TECHNOLOGY STRATEGY

Proven approaches for Legacy Systems Modernization

California Enterprise Architecture Framework

EMC PERSPECTIVE. Information Management Shared Services Framework

GRC Program Best Practices & Lessons Learned

Maximizing Your IT Value with Well-Aligned Governance August 3, 2012

EMA Service Catalog Assessment Service

E TE T R E PR P IS I E S E R ES E O S URCE E P L P A L NNIN I G

Strategic Planning. Key Initiative Overview

ENTERPRISE ARCHITECTURE AS THE CORE ENGINE FOR SUCCESSFUL BUSINESS TECHNOLOGY TRANSFORMATION

Global Headquarters: 5 Speen Street Framingham, MA USA P F

The Corporate Counsel s Guide to Open Source Software Policy Implementation

Top 10 List for Success in the Cloud

A Mission Impossible?

How IT Can Help Companies Make Better, Faster Decisions

The role of Information Governance in an Enterprise Architecture Framework

14 TRUTHS: How To Prepare For, Select, Implement And Optimize Your ERP Solution

TOGAF overview and relation

State of Michigan Department of Technology, Management & Budget

THE STATUS OF ENTERPRISE ARCHITECTURE AND INFORMATION TECHNOLOGY INVESTMENT MANAGEMENT IN THE DEPARTMENT OF JUSTICE

ITIL and IT Operations Optimization

RSA ARCHER OPERATIONAL RISK MANAGEMENT

Talousjohto muutosagenttina ja informaatiotulvan tulkkina

Fortune 500 Medical Devices Company Addresses Unique Device Identification

Mitel Professional Services Catalog for Contact Center JULY 2015 SWEDEN, DENMARK, FINLAND AND BALTICS RELEASE 1.0

SACM and CMDB Strategy and Roadmap. David Lowe ActionableITSM.com March 20, 2012

EMA CMDB Assessment Service

Module 6 Essentials of Enterprise Architecture Tools

The Open Group Architectural Framework

Global Headquarters: 5 Speen Street Framingham, MA USA P F

A Guide to Successfully Implementing the NIST Cybersecurity Framework. Jerry Beasley CISM and TraceSecurity Information Security Analyst

White Paper. Enterprise Information Governance. Date Released: September Author/s: Astral Consulting.

On Premise Vs Cloud: Selection Approach & Implementation Strategies

Begin Your BI Journey

Using the Cloud for Business Resilience

TOGAF TOGAF & Major IT Frameworks, Architecting the Family

Agenda 3/7/ ERM Symposium March 14 16, Continuous Controls Monitoring. I. Changes In Corporate Environment

FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors

[ SHERRYANNE MEYER Manage Complex SAP Implementations with Enterprise Architecture

POSITION SPECIFICATION ENTERPRISE ARCHITECT UK&I

Transcription:

Adapting IT Governance Frameworks to Ensure Control and Visibility of Open Source Dave Lounsbury, CTO & Vice President, The Open Group Peter Vescuso, EVP of Marketing & Business Development, Black Duck Black Duck 2013

Speakers Peter Vescuso EVP of Marketing & Business Development Black Duck Dave Lounsbury CTO & Vice President The Open Group 2 Black Duck 2013

Agenda Trends Open Source - Benefits and Challenges The TOGAF Standard Integrating open source processes with the TOGAF Standard Summary 3 Black Duck 2013

Open Source Technologies and Methods : Driving Major Business Trends Software is Eating the World Marc Andreessen New way to build software: Community & Co-opetition 4 Black Duck 2013

Abundance of Open Source 5000000 Open Source Projects 4500000 4000000 3500000 3000000 Projected 2500000 2000000 1500000 1000000 500000 0 2006 2008 2010 2012 2014 2016 5 Black Duck 2013

New Way to Build Software Tony McCarthy, Head of IT for Investment Banking Deutsche Bank Is our role to build software? Is our role to provide solutions? Or is our role to build frameworks that enable us to reach out to where talented people are? Source: Lodestone Foundation //lodestonefoundation.wordpress.com/ 6 Black Duck 2013

Open Source is Approaching a Tipping Point Faster release cycles Open source (Android): 3-4 months Closed source (Windows): 3 years Rate of Innovation Mobile Cloud Big Data Increasing Co-opetition Mobile - Android Automotive GENIVI Financial Lodestone 7 Black Duck 2013

How to Maintain Visibility and Control of Code? 8 Black Duck 2013

Benefits and Challenges of Open Source Key Benefits Flexibility Innovation Cost Optimization Challenges Technical Failure Security Risks IP Risks Open source is ubiquitous, it s unavoidable.having a policy against open source is impractical and places you at a competitive disadvantage Mark Driver, Gartner 9 Black Duck 2013 9

Augmenting Development Processes for Open Source Application development processes Plan Code Build Test Release Open source governance processes Acquire Approve Catalog Audit Monitor Description Version Vulnerabilities Cryptography License Maturity Black Duck KnowledgeBase 10 Black Duck 2013

Automating Compliance Manual Automated VS Cost Risk Compliance Cost Risk Compliance 11 Black Duck 2013

Architecture Methodologies and Frameworks The TOGAF Standard 12 Black Duck 2013

Why enterprise architecture? The value of having an architecture is: The primary reason to have an enterprise architecture is to provide an overall, high-level design of the enterprise Since enterprises are not designed in one step, the enterprise architecture provides the structure for all enterprise projects to conform to It expresses architectural principles of a long-term vision It communicates the system design vision and enterprise strategy to all stakeholders It helps management to plan, manage, and effectively utilize the enterprise s resources It can help ensure legal and regulatory compliance (for example, with the Clinger-Cohen Act) 13 Black Duck 2013

Background: What it is TOGAF, an Open Group Standard A proven enterprise architecture methodology and framework Used by the world's leading organizations to improve business efficiency The most prominent and reliable enterprise architecture standard Ensuring consistent standards, methods, and communication among enterprise architecture professionals 14 Black Duck 2013

The Origins of the TOGAF Framework A customer initiative A framework, not an architecture A generic framework for developing architectures to meet different business needs Not a one-size-fits-all architecture Originally based on TAFIM (U.S. DoD) 15 Black Duck 2013

Why the TOGAF Standard is Used A comprehensive general method Complementary to, not competing with, other frameworks Vendor, tool and technology neutral open standard Avoids re-inventing the wheel Widely adopted in the market Tailorable to meet an organization and industry needs Available under a free perpetual license Business IT alignment Based in best practices Possible to participate in the evolution of the framework 16 Black Duck 2013

TOGAF Capability Framework Modular Structure Content Framework Extended Guidance Architectural Styles Additional ADM detail Informs the capability Ensures Realization of Business Vision Architecture Capability Framework (Part VII) Sets targets, KPIs, budgets for architecture roles Drives need for Architecture Capability maturity Business needs feed into method Architecture Development Method (Part II) Delivers new business solutions Business Vision and Drivers Refines Understanding ADM Guidelines & Techniques (Part III) Architecture Content Framework (Part IV) TOGAF ADM & Content Framework Business Capabilities Informs the Business of the current state Enterprise Continuum & Tools (Part V) TOGAF Reference Models (Part VI) Operational changes cause updates Copyright 1999-2013 The Open Group TOGAF Enterprise Continuum & Tools 17 Black Duck 2013

TOGAF: How/Where Open Source Fits In Business architecture Application architecture Data architecture Technical architecture Defining Requirements Assessing Readiness for Change Selection Guidance Audit and Inventory Governance and Project Metadata Technology Opportunities 18 Black Duck 2013

Architecture Repository Copyright 1999-2013 The Open Group 19 Black Duck 2013

Readiness Assessment Do a Business Transformation Readiness Assessment to evaluate your organization's readiness to change Vision Desire/Willingness/ Resolve Need Business Case Funding Sponsorship and Leadership Governance Accountability Workable approach and execution model IT Capacity to execute Enterprise capacity to execute Enterprise Ability to implement and operate 20 Black Duck 2013

Prepare the organization for a ADM successful Phases architecture project Provide continual monitoring and a change management process to ensure that the architecture responds to the needs of the enterprise Provide architectural oversight for the implementation; ensure that the implementation project conforms to the architecture Analyze costs, benefits and risks; develop detailed Implementation and Migration Plan Set the scope, constraints and expectations for a TOGAF project; create the Architecture Vision; validate the business context; create the Statement of Architecture Work Develop Business Architecture Develop baseline and target architectures and analyze the gaps Develop Information Systems Architectures Develop baseline and target architectures and analyze the gaps Develop Technology Architecture Ensure that every stage of a TOGAF project is based on and validates business requirements 21 Black Duck 2013 Develop baseline and target architectures and analyze the gaps Perform initial implementation planning; identify major implementation projects

Best Practices/Recommendations Start with your vision for change and success Requirements are critical Led by business need Rigorous management watch for false requirements Assess your readiness for change Define your principles and use them Follow a strong governance process to make sure real requirements are really met 22 Black Duck 2013

Requirements for Optimal Use of Open Source Strategy Articulate the business objectives for use of OSS Policy & Process OSS policy & management processes Technology Automate governance and management of OSS Design-in compliance 23 Black Duck 2013

IT Management Maturity 24 Black Duck 2013

Open Source Adoption Open Source Management Maturity Framework Explicit Policy, Tracking & Audting Built-in Compliance Process Automation, Community Participation Strategic OSS Use, Community Leadership Informal Guidelines Ad Hoc Use Engineering driven Business strategy driven 25 Black Duck 2013

Summary Open source software and methods are changing how software gets built Architecture frameworks ensure compliance with standards, improve manageability and effectiveness The TOGAF Standard is a useful framework for defining and governing processes required for effective use of open source in the enterprise Increase visibility, control and buy-in Ensure compliance Reduce risk and exposure 26 Black Duck 2013

For More Information... Introduction to Open Source Governance and Compliance //advance.blackducksoftware.com/content/wpintroosgov The Enterprise IT Guide to Open Source Management //advance.blackducksoftware.com/content/guideeit The TOGAF Web Site //www.opengroup.org/togaf/ The Architecture Forum //www.opengroup.org/architecture/ TOGAF Version 9.1 on-line //www.opengroup.org/architecture/togaf9-doc/arch/ TOGAF Version 9.1 licensing and downloads //www.opengroup.org/togaf/ 27 Black Duck 2013