Tampilkan postingan dengan label Compliance. Tampilkan semua postingan
Tampilkan postingan dengan label Compliance. Tampilkan semua postingan

Rabu, 27 Juli 2011

Linux Foundation Releases New White Paper on FOSS Compliance for Suppliers

The Linux Foundation strives to provide relevant, useful guidance to organizations setting up their free and open source software (FOSS) compliance programs.  Last month, we released a white paper titled “A Five Step Compliance Process for FOSS Identification and Review.”

Now, we are releasing a freely available new white paper “FOSS Compliance Practices for Supplied Software.”  It examines compliance practices needed when software supplied by a third party vendor is brought into the code baseline of a product to be distributed externally.   The white paper discusses requirements a company should impose upon its suppliers to disclose FOSS in their deliverables and to provide what’s needed to achieve compliance.  The paper also discusses steps a company can take to review and validate the FOSS disclosures made by its suppliers.  In addition to those topics, the white paper addresses measures a company can undertake to assess its suppliers’ compliance capabilities.

Take a look!

Open Compliance Training Class Offered in Conjunction with LinuxCon North America

Once again, an onsite open compliance training course will be offered directly after a major Linux Foundation event.  We’ll deliver LF384, “Overview of Open Source Compliance End-to-End Process” right after LinuxCon North America in Vancouver, on Saturday August 20, 2011 at the conference hotel.   It’s important to The Linux Foundation to provide every opportunity to the community for learning and exchanging ideas about compliance. By hosting this one-day training course in conjunction with LinuxCon, we hope to increase access to important content on open compliance and to provide a classroom environment for collaboration on this topic.

The full-day course focuses on how to organize and manage the compliance function so that your company can benefit from FOSS while complying with all license obligations.  If you’ll be responsible for implementing your company’s compliance program, you’ll surely profit from this class.  Just go to http://www.regonline.com/Register/Checkin.aspx?EventID=923767  to register.  And, by the way, you can register for the course even if you don’t plan to attend LinuxCon.  If you have any questions about registration, please contact This e-mail address is being protected from spambots. You need JavaScript enabled to view it .  If you have questions about the course content or you’re interested in the course but can’t make the event in Vancouver and want to find out about other course offerings, please contact This e-mail address is being protected from spambots. You need JavaScript enabled to view it .

Check out the LinuxCon conference site for more info about our 20th anniversary celebration of Linux (including black tie gala(!)) and a great technical program that features a number of compliance talks by industry experts.

Comments (0)Add Comment
You must be logged in to post a comment. Please register if you do not have an account yet.
busy

View the original article here

Senin, 04 Juli 2011

Linux Foundation Releases New FOSS Compliance White Paper

The Linux Foundation continues to provide simple, straightforward guidance to organizations setting up their open source compliance programs. Last month, we released a free webinar titled “Six Tips to Getting Started With Open Source Compliance.”  Before that, we published “Keys to Managing a FOSS Compliance Program.”


Now, we’ve released a freely available new white paper, “A Five-Step Compliance Process for FOSS Identification and Review” that discusses key aspects of two compliance actions:  identifying open source in a product’s code baseline, and performing architecture and license reviews on the path to approving FOSS inclusion.  The white paper reviews inputs, outputs, and essential process elements involved in five interrelated compliance steps:  scanning source code; positively identifying FOSS, its licensing, and its provenance; reviewing licenses and license compatibility issues; reviewing architectural interactions of proprietary and open source components; and achieving final approval for FOSS use.  So, download the white paper for some useful information.


Upcoming white papers will address steps involved in satisfying license obligations, and ways to work with suppliers on their compliance responsibilities.  Feel free to provide suggestions for future white paper topics to This e-mail address is being protected from spambots. You need JavaScript enabled to view it .  For more LF resources on compliance, including white papers, webinars, self-assessment checklist, and open source tools, go to the Linux Foundation’s open compliance program webpage. 


View the original article here

Minggu, 05 Juni 2011

Six Quick Tips Get You Started with Open Compliance

More and more companies turn to Linux and other open source software for great functionality and competitive advantage in product development.  When they do so, most organizations recognize their responsibility to comply with open source license obligations.  They embrace the responsibility as part of using open source.  Unfortunately, some companies remain unaware of their obligations or choose to ignore them.  Others are simply daunted by the task of putting a compliance program in place.  They needn’t be:  There are lots of resources to turn to for guidance.  The Linux Foundation has created comprehensive training courses on compliance that are delivered confidentially onsite to help companies meet their responsibilities.  We also have instructive white papers and a great checklist of compliance actions compiled from experiences of industry-best compliance programs, and the FOSSBazaar governance community to share thoughts about compliance challenges and solutions.


But those resources may be most useful to companies that have committed themselves to compliance and understand the scope of the task before them.  What about companies that know they have to do something but haven’t even thought about where to start?  To help those companies, we’ve recorded a webinar titled “Six Tips for Getting Started with Open Source Compliance.”   It’s readily understandable, even by someone whose expertise lies outside software development.  The webinar is a great place to start with compliance and lays the groundwork for the more comprehensive Linux Foundation compliance training later.


Who should listen to the webinar?  Whoever will be responsible for establishing their company’s open source compliance program.  This could be someone in product development, or the software engineering department, or the Law Department, or Corporate Compliance, or Supplier Management, or QA.  Whoever it turns out to be, they need to get things rolling and learn enough to designate or recruit the right people to implement a compliance program.


So, check out the Six Tips webinar.  It’s well worth the 15 minutes you’ll spend.  While you’re at it, take a listen to the Introduction to SPDXTM webinar.  Phil Odence provides a great three-minute introduction to the Software Package Data Exchange project, which will transform the way companies inform their trading partners of the open source content in the software they deliver.  After listening, you’ll want to visit the SPDX webpages to learn more about the project.


It’s time to get started!


View the original article here