Awareness Session - Open Source Compliance

Prashant Singh Baghel

profile
Awareness Session - Open Source Compliance
profile
4,8996,300
60 mins

Awareness Session: Open Source Compliance

Topics Covered:

Open Source License Types

Permissive Licenses (e.g., MIT, Apache 2.0)

Copyleft Licenses (e.g., GPL, LGPL)

Dual Licensing Models

License Obligations

Attribution and credit requirements

Sharing of modified source code under copyleft licenses

Redistribution and sublicensing rules

Common Issues

License incompatibility risks

Undocumented usage of open source components

Lack of compliance artifacts (e.g., SBOMs)

Compliance Best Practices

Establishing an Open Source Program Office (OSPO)

Automated tools for license and vulnerability scanning

Internal approval processes for open source usage

Relevant Standards

ISO 5230: Open Source License Compliance Standard

SPDX: Standard for SBOM generation and management

Maturity: License and Security maturity model for open source use


Objective: Equip participants with a clear understanding of open source license obligations, potential risks, and best practices to ensure compliance and maintain software quality