OSS LOGISTICS: DRIVING INNOVATIVE SOFTWARE FROM DEVELOPER TO CUSTOMER Alex Bigmore Senior Architect & Open Source Governance Programme Manager SITA



Similar documents
Phil Marshall Black Duck Software ISACA Webinar Program ISACA. All rights reserved.

Managing Open Source Code Best Practices

XEROX TALKS BEST PRACTICES FOR OPEN SOURCE GOVERNANCE

BOM based on what they input into fossology.

Open Source Software and the impact on Mergers & Acquisitions

The Corporate Counsel s Guide to Open Source Software Policy Implementation

How To Improve Your Software

What Developers, Cars & Banks Have in Common: Best Practices for Open Source Governance

How To Manage An Open Source Software

HOW TO UTILIZE OPEN SOURCE IN YOUR CODE BASE AND BUILD PROCESS Black Duck Software, Inc. All Rights Reserved.

Intro to QualysGuard IT Risk & Asset Management. Marek Skalicky, CISM, CRISC Regional Account Manager for Central & Adriatic Eastern Europe

SecureGRC TM - Cloud based SaaS

How to Ensure IT Compliance Without Compromising Innovation. Nik Teshima, IBM Phil Odence, Black Duck

Leveraging Open Source for a Winning Enterprise Mobile Strategy

How to Avoid 5 Common Pitfalls in Open Source Utilization. July 2013

OPEN SOURCE SOFTWARE CUSTODIAN AS A SERVICE

Adapting IT Governance Frameworks to Ensure Control and Visibility of Open Source

SAP IT Infrastructure Management. Dirk Smit ALM Engagement Manager SAP Africa

Scanning Open Source Software and Managing License Obligations on IBM SmartCloud. Because code travels

SAP IT Infrastructure Management

Copyright 11/1/2010 BMC Software, Inc 1

5 Steps for a Winning Open Source Compliance Program

SpaceCode RFID for Diamond Sales Offices

7 Steps to Windows 7 Migration Best Practices. Anthony Wainman - Presales Technical Consultant Jay Lakhani Sales Director Codework Inc.

Open Source Governance in Highly Regulated Companies

IT Legacy Migration from Proprietary to Open Source Software. Bill Weinberg, Black Duck Software Jay Lyman, 451 Research

Realizing the Breakthrough Economics of Linux and Open Source through Hybrid Development. Tim Yeaton, President and CEO Black Duck Software

A 10-Minute Guide to Increasing Supply Chain Visibility

Security Compliance and Data Governance: Dual problems, single solution CON8015

Open Source and the New Software Supply Chain. Mark Tolliver, CEO Palamida Inc.

IBM Cloud Security Draft for Discussion September 12, IBM Corporation

Oracle Cloud: Enterprise Resource Planning

Business Process Services: A Value-Based Approach to Process Improvement and Delivery

Key Adoption Triggers Upgrades, Cost Reduction, Innovation

Symantec Client Management Suite 7.6 powered by Altiris technology

IBM Endpoint Manager Product Introduction and Overview

How to manage IT Risks and IT Compliance as a Service

with Managing RSA the Lifecycle of Key Manager RSA Streamlining Security Operations Data Loss Prevention Solutions RSA Solution Brief

Welcome to online seminar on. Oracle Agile PLM. Design to Release & Change Management. Presented by: Rapidflow Apps Inc.

The Power of BMC Remedy, the Simplicity of SaaS WHITE PAPER

- Cameron Haight, Gartner

Automated IT Asset Management Maximize organizational value using BMC Track-It! WHITE PAPER

CloudPassage Halo Technical Overview

Solution Briefing. Integrating the LogLogic API with NSN s Remediation & Escalation Mgmt. System

BeyondInsight Version 5.6 New and Updated Features

Open Source Drives Innovation in Financial Services

Industrial Cyber Security Risk Manager. Proactively Monitor, Measure and Manage Cyber Security Risk

Fight fire with fire when protecting sensitive data

Driving Business Agility with the Use of Open Source Software

Asset Management. Page 1 of 5. Data Sheet

DISCOVER, MONITOR AND PROTECT YOUR SENSITIVE INFORMATION Symantec Data Loss Prevention. symantec.com

Issue in Focus: Integrating Cloud PLM. Considerations for Systems Integration in the Cloud

The business owner s guide for replacing accounting software

Continuous Network Monitoring

How To Standardize Itil V3.3.5

Compliance Guide ISO Compliance Guide. September Contents. Introduction 1. Detailed Controls Mapping 2.

PIVOTAL FOR GRANT MANAGEMENT

Empowering Your Business in the Cloud Without Compromising Security

Moving beyond Virtualization as you make your Cloud journey. David Angradi

The Way to SOA Concept, Architectural Components and Organization

Vulnerability Management

Oracle Process Cloud Service Rapidly Automate & Manage Process Applications

Master Data Management Architecture

Increase insight. Reduce risk. Feel confident.

Klarna Tech Talk: Mind the Data! Jeff Pollock InfoSphere Information Integration & Governance

The Danwood Group Professional Services Offering DANWOOD

Risk & Hazard Management

Streamlining Open Source License Compliance with SPDX

Build Your Managed Services Business with ScienceLogic

Cisco Network Optimization Service

Introduction to QualysGuard IT Risk SaaS Services. Marek Skalicky, CISM, CRISC Regional Account Manager for Central & Adriatic Eastern Europe

Creating A World-Class IT Integration Strategy

RSA Data Loss Prevention (DLP) Understand business risk and mitigate it effectively

Enabling Data Quality

DOES OPEN MEAN VULNERABLE?

Cloud Technology Platform Enables Leading HR and Payroll Services Provider To Meet Solution Objectives

Welcome to the Audit, Control & Security Stream. Sponsored by:

PCI Compliance for Cloud Applications

State of Oregon. State of Oregon 1

Symantec DLP Overview. Jonathan Jesse ITS Partners

BEA BPM an integrated solution for business processes modelling. Frederik Frederiksen Principal PreSales Consultant BEA Systems

Client Technology Solutions Suresh Kumar Chief Information Officer

Oracle Fusion Cloud Service Global Price List October 9, 2014

Vulnerability management lifecycle: defining vulnerability management

Business Process Management and Cloud Computing

Microsoft Private Cloud

Service-Oriented Architecture Maturity Self-Assessment Report. by Hewlett-Packard Company. Developed for Shrinivas Yawalkar Yawalkar of CTS

Bell Techlogix looks to add business services to its BEAM-as-a-Service offering

CloudPassage Halo Technical Overview

Asset. Unicenter Management r11

CAD. Office to enterprise Product Data Management. Product Overview

White Paper. Enabling Sales and Distribution with the Cloud. Abstract. - Rafee Tarafdar, Subramanian Radhakrishnan (Subra)

Ellucian Cloud Services. Joe Street Cloud Services, Sr. Solution Consultant

Performance from the Core

Process Harmonization to address High Cost of Compliance : Insights from Implementation. Keerthana Mainkar & Jude Fernadez

CrossPoint for Managed Collaboration and Data Quality Analytics

Detecting Anomalous Behavior with the Business Data Lake. Reference Architecture and Enterprise Approaches.

3 Years of Transformation Research

nexb- Software Audit for Acquisition Due Diligence

Full-Context Forensic Analysis Using the SecureVue Unified Situational Awareness Platform

Transcription:

OSS LOGISTICS: DRIVING INNOVATIVE SOFTWARE FROM DEVELOPER TO CUSTOMER Alex Bigmore Senior Architect & Open Source Governance Programme Manager SITA Phil Granof EVP & Chief Marketing Officer Black Duck Software 2014 Black Duck Software, Inc. All Rights Reserved.

OVERVIEW Introduction Open Source Market Trends SITA Case study The OSS Logistics Framework Conclusions 2 2014 Black Duck Software, Inc. All Rights Reserved.

OSS TRENDS 3

OS CRITICAL ACROSS MANY NEW TECHNOLOGIES 63% 57% 53% 51% 49% 48% 46% 27% 26% 13% 12% 10% CLOUD/ VIRTUALIZATION CONTENT MGMT MOBILE SECURITY COLLABORATION NETWORK MGMT SOCIAL MEDIA 3D PRINTING ANALYTICS AND BUSINESS INTELLIGENCE DRONES GAMING ERP 4 2014 Black Duck Software, Inc. All Rights Reserved.

THE VIRTUOUS CYCLE Foundation Participation Proliferation Democratization 5 2014 Black Duck Software, Inc. All Rights Reserved.

OPEN SOURCE WINS ON QUALITY 80% Choose based on quality 6 2014 Black Duck Software, Inc. All Rights Reserved.

OPEN SOURCE WINS ON FEATURES 67% TCO 80% Choose based on features 7 2014 Black Duck Software, Inc. All Rights Reserved.

OPEN SOURCE WINS ON FEATURES 8 2014 Black Duck Software, Inc. All Rights Reserved.

ACCESS TO TECHNICAL FEATURES #8 Reason for adoption #4 Reason for adoption 9 2014 Black Duck Software, Inc. All Rights Reserved.

CHOOSING BASED ON SECURITY 72% Choose based on Security 10 2014 Black Duck Software, Inc. All Rights Reserved.

CHOOSING BASED ON SECURITY? 11 2014 Black Duck Software, Inc. All Rights Reserved.

CORPORATE REACTION 12 2014 Black Duck Software, Inc. All Rights Reserved.

OPEN SOURCE ADOPTION IS RISING XX%??? 30% 5% 2007 2012 2017 Source: Black Duck audit results Source: IDC Survey of G2000 13 2014 Black Duck Software, Inc. All Rights Reserved.

SITA Case Study Open Source Compliance Alex Bigmore Open Source Governance Programme Manager

15

First Steps to Compliance SITA developed an Intellectual Property software asset registry with the objective of better understanding the composition of its software in terms of IP ownership, applicable licensing terms and code used to generate SITA s revenue streams Together with developer surveys this revealed that software is mixed IP, using internally developed, outsource developed, third party proprietary and Open Source software Two questions emerged How much Open Source Software (OSS) was used as part of the code base? What were the licensing details of each OSS component? The need to answer these questions was the first step toward establishing an Open Source Governance (OSG) programme 16 Open Source Compliance Confidential SITA 2014

Creating the Governance Programme IP Asset Registry created OSS usage revealed Establish Stakeholders Pilot how much OSS is really used? Do we need OSS? Governance Programme 17 Open Source Compliance Confidential SITA 2014

Governance Objectives Ensure compliance with OSS licenses and distribution requirements Enable greater use of OSS across the organization to improve software development efficiency and quality 18 Open Source Compliance Confidential SITA 2014

Achieving Governance Objectives Strategy, policy, process License review Communication & training Approval Discovery & remediation Compliance and OSS Enablement 19 Open Source Compliance Confidential SITA 2014

Compliance and OSS Enablement Approval before use Policy requires teams to request approval before OSS is used to minimise remediation Black Duck Code Center used to manage approval process Verification scanning Determines whether there is OSS present that has not been approved Reports on licence compliance Black Duck Protex used for OSS scanning Automation wherever possible Impact the development teams as little as possible Automate responses to approval requests where possible SITA licence guidance rules implemented, others addressed manually Enable teams to trigger verification scans OSG team involved as needed 20 Open Source Compliance Confidential SITA 2014

Summary OSG and supporting tools have enabled SITA to Ensure compliance with licences of OSS used Encourage and support greater use of open source in current and future projects Notify project teams of vulnerabilities in OSS used Automate to minimise impact Self service OSS approvals Self service OSS scanning 21 Open Source Compliance Confidential SITA 2014

Thank you Alex Bigmore, OSG Programme Manager Alex.bigmore@sita.aero www.sita.aero 22 Open Source Compliance Confidential SITA 2014

OSS LOGISTICS 23

OSS SHOULD BE MANAGED, NOT FEARED 50% of companies will face challenges due to lack of FOSS policy and management FOSS Survey 24 2014 Black Duck Software, Inc. All Rights Reserved.

CHALLENGES OF THE ARCHITECT I want to know what open source I use. I want to know where I use open source. I want to eliminate the security risks associated with open source. I want more control over the open source my developers use. I want help choosing open source. I want to decrease the amount of code we need to maintain. I want to reuse code. I want to participate in the open source ecosystem. 25 2014 Black Duck Software, Inc. All Rights Reserved.

KNOWLEDGE BASE 26 2014 Black Duck Software, Inc. All Rights Reserved.

OUR VALUE We help companies manage their use of open source code in order to see enormous gains across fundamental competitive dimensions. Speed Cost Security Innovation 27 2014 Black Duck Software, Inc. All Rights Reserved.

THINK LIKE LINUX, ACT LIKE UPS, SMILE LIKE AMAZON 28 2014 Black Duck Software, Inc. All Rights Reserved.

WHAT IS OSS LOGISTICS? Choose Scan Approve Inventory Secure Deliver 29 2014 Black Duck Software, Inc. All Rights Reserved.

CHOOSE OSS Choice begins with data. The Black Duck Knowledgebase is the world s most comprehensive database of open source project information. License Version Vulnerability Maturity Cryptography Black Duck KnowledgeBase Description 30 2014 Black Duck Software, Inc. All Rights Reserved.

CHOOSE OSS The Black Duck Knowledgebase is at the heart of OSS Logistics, continually gathering data throughout the open source community: Over one million projects From 6,000 sites For over 2,200 unique software licenses. Secure Black Duck Open Hub Approve Scan Inventory Black Duck Open Source KnowledgeBase Community 31 2014 Black Duck Software, Inc. All Rights Reserved.

CHOOSE OSS The Black Duck Open Hub provides a window into the world of open source. Find reports about the composition and activity of project code bases Track the changing demographics of the FOSS world Follow developers and their contributions Search for code with Code Sight Secure Black Duck Open Hub Approve Scan Inventory Black Duck Open Source KnowledgeBase Community 32 2014 Black Duck Software, Inc. All Rights Reserved.

CHOOSE OSS 33 2014 Black Duck Software, Inc. All Rights Reserved.

APPROVE OSS Empower developers with automated approval processes built on the right policies for governing the use of open source. Eliminate uncertainty and re-work Speed identification of software components Mitigate risk without slowing developers down Collaborate seamlessly Secure Black Duck Open Hub Approve Scan Inventory Black Duck KnowledgeBase Open Source Community 34 2014 Black Duck Software, Inc. All Rights Reserved.

SCAN OSS Automatically scan, discover and identify what open source code is used within specific applications. Understand code origin Identify licenses and support compliance Eliminate manual effort Increase reliability and visibility Secure Black Duck Open Hub Approve Scan Inventory Black Duck KnowledgeBase Open Source Community 35 2014 Black Duck Software, Inc. All Rights Reserved.

INVENTORY OSS Create a company-wide intelligent catalog of approved software that grows smarter over time. Track where components are used in other applications. Encourage standardization and re-use. Secure Black Duck Open Hub Approve Scan Inventory Black Duck KnowledgeBase Open Source Community 36 2014 Black Duck Software, Inc. All Rights Reserved.

SECURE OSS Continuous monitoring ensures that future security vulnerabilities associated with a specific component are quickly flagged for resolution. Receive daily alerts Alter workflows in response to severity Quickly locate and remediate Secure Black Duck Open Hub Approve Scan Inventory Black Duck KnowledgeBase Open Source Community 37 2014 Black Duck Software, Inc. All Rights Reserved.

DELIVER We provide a license obligation report and an easily consumable bill of materials (BOM) that you can deliver to your customers or internal stakeholders. Incoming Code Automated Scanning and Built-In Approval Policies Outgoing Code 38 2014 Black Duck Software, Inc. All Rights Reserved.

DELIVER Automatically discover encryption algorithms within a code base and identify applicable export rules: Cryptography export compliance Government reporting Licensing requirements Policy management challenges Outgoing Code Approve Scan 39 2014 Black Duck Software, Inc. All Rights Reserved.

CONCLUSIONS The open source debate is over. Mostly. Complexity and quality are colliding. Reaping the benefits requires management. Logistics provides the best conceptual model for see reaping the benefits of open source. 40 2014 Black Duck Software, Inc. All Rights Reserved.

QUESTIONS? www.blackducksoftware.com 41