Topics Covered:
Open Source License Types
Permissive Licenses (e.g., MIT, Apache 2.0)
Copyleft Licenses (e.g., GPL, LGPL)
Dual Licensing Models
License Obligations
Attribution and credit requirements
Sharing of modified source code under copyleft licenses
Redistribution and sublicensing rules
Common Issues
License incompatibility risks
Undocumented usage of open source components
Lack of compliance artifacts (e.g., SBOMs)
Compliance Best Practices
Establishing an Open Source Program Office (OSPO)
Automated tools for license and vulnerability scanning
Internal approval processes for open source usage
Relevant Standards
ISO 5230: Open Source License Compliance Standard
SPDX: Standard for SBOM generation and management
Maturity: License and Security maturity model for open source use
Objective: Equip participants with a clear understanding of open source license obligations, potential risks, and best practices to ensure compliance and maintain software quality