Open Compliance Program

As the use of Linux and other open source software has exploded in recent years, especially in mobile and consumer electronics products, the need has arisen for a trusted, neutral, non-commercial compliance program that offers a comprehensive offering of compliance training, tools and services. To address that complexity, The Linux Foundation has developed a set of open source tools, training curricula and a new self-administered assessment checklist that will allow companies to ensure compliance in a cost-effective and efficient manner. The Open Compliance Program also includes a new data exchange standard so companies and their suppliers can easily report software information in a standard way.

The six elements of the Linux Foundation’s Open Compliance Program are:
Tools

While there are many commercial and open source scanning tools available to identify the origin and license of source code, the Linux Foundation has developed complementary tools needed to help companies improve their open source compliance due diligence. The Linux Foundation has released initial versions of these tools as open source projects and urges other developers to contribute to them. They include:

* Dependency Checker: capable of identifying code combinations at the dynamic and static link level. In addition, the tool offer a license policy framework that enables FOSS Compliance Officers to define combinations of licenses and linkage methods that are to be flagged if found as a result of running the tool.
* Bill of Material (BoM) Difference Checker: capable of reporting differences between BoMs and therefore enabling companies to identify changed source code components and to better report included open source components in updated product releases.
* The Code Janitor: This tool provides linguistic review capabilities to make sure developers did not leave comments in the source code about future products, product code names, mention of competitors, etc. The tool maintains a database of keywords that are scanned for in the source code files to ensure code released is safe and ready for public consumption.

Click here to view all of our Open Compliance tools.
Self-Assessment Checklist

The Linux Foundation has developed an extensive checklist of compliance best practices in addition to elements that must be available in an open source compliance program to ensure its success. Companies are invited to use this checklist as an internal self-administered exercise to evaluate their compliance in comparison to top tier best compliance practices. The checklist will be formally launched in q4 of 2010.

Learn more about the Self-Assessment Checklist.
The SPDX™ Standard and Workgroup

Enables companies to standardize their bills of material to ease the discovery and labeling of open source components in their products; this is especially important for consumer electronics manufacturers who assemble parts from a variety of suppliers into their shipping products. The end result is companies using free and open source software will all be following the same reporting method. More information can be found at http://www.linuxfoundation.org/workgroups/spdx/
A Compliance Directory and Rapid Alert System

The Linux Foundation has created a directory of compliance officers at companies using Linux and Open Source software in their commercial products so communication can be eased, information related to open source licenses can be easily disseminated and actions can be coordinated. This is a huge need in today’s market where it’s often times difficult for open source projects to identify the correct people at companies using their software to address issues of concern. To add contact information for compliance purposes or query the directory: http://www.linuxfoundation.org/programs/legal/compliance/directory/
Training and Education

The Linux Foundation now offers the industry’s more comprehensive compliance resource for training and informational materials. Training modules cover the fundamentals of open source licensing and compliance activities and can be tailored for audiences ranging from corporate executives to working professionals. Training will be offered live on-site or online. Information assets include free white papers, articles, and webinars available from noted compliance experts.

Learn more about our Training and Education programs.
Community

The above resources join the existing FOSSBazaar workgroup which has a thriving and informed community of software and compliance professionals. As the open source ecosystem continues to evolve with new opportunities and risks, this community will focus discussion on how the industry can best adapt to the changes. The Linux Foundation welcomes all interested companies to participate at http://www.FOSSBazaar.org.

0 comments:

Post a Comment