<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Open-source policy templates in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61741#M934</link>
    <description>Thanks for the reply. I will certainly check out this link.&lt;BR /&gt;&lt;BR /&gt;Chris</description>
    <pubDate>Wed, 16 Aug 2023 18:25:57 GMT</pubDate>
    <dc:creator>cclements</dc:creator>
    <dc:date>2023-08-16T18:25:57Z</dc:date>
    <item>
      <title>Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61693#M927</link>
      <description>&lt;P&gt;Dear ISC^2 Colleagues,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been tasked with creating a policy that governs the adoption, use, and contribution to open-source projects, libraries, and software.&amp;nbsp; I started with NIST and CSF to find their recommendations but haven't found much more than "the organization devises an open-source policy".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've identified some concerns.&amp;nbsp; Firstly, what are your suggestions?&amp;nbsp; Did I miss something? Secondly, do you have a template or actual policy you can share that will serve as a jumping off point?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;License (which open-source licenses shall we permit).&lt;/LI&gt;&lt;LI&gt;Sanctioning process - establish a process by which open-source projects, code, libraries, or software is reviewed and "sanctioned for use".&amp;nbsp; The result shall be a curated repository of projects or packages, or perhaps a list?&lt;OL&gt;&lt;LI&gt;Favor popular projects.&lt;/LI&gt;&lt;LI&gt;Observe the patch frequency.&lt;/LI&gt;&lt;LI&gt;Observe response to vulnerabilities.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Mandatory SCA for projects using third party (open source) libraries,&lt;/LI&gt;&lt;LI&gt;Create a process by which a security lead is informed of vulnerabilities in a sanctioned project.&lt;/LI&gt;&lt;LI&gt;Manual code review (this may not be practical.&lt;/LI&gt;&lt;LI&gt;Create a policy addressing contribution to open-source projects.&amp;nbsp; Consider the protection of the company's IP.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:42:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61693#M927</guid>
      <dc:creator>cclements</dc:creator>
      <dc:date>2023-10-09T10:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61696#M928</link>
      <description>&lt;P&gt;If you need it to scale, you'd need a tools to scan repos and follow dependencies, because manual code review won't scale.&amp;nbsp; You'll also need tooling to enable response to a critical vulnerability found in your code and any third party products that you use.&amp;nbsp; Google log4j and you'll find that library is in so many things.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 15:10:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61696#M928</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2023-08-15T15:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61703#M929</link>
      <description>&lt;P&gt;I'm curious, why the distinction of open-source software? Shouldn't the concerns regarding adoption, use, and contribution apply to all software? The licensing model is a bit of a red herring.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll give you a case in point that speaks to your last bullet. Many years ago I was working on a project with a large consultancy on the adoption of new enterprise-wide software for HR and financials. As part of the implementation, we collaboratively developed some code to work with this third-party proprietary software, but we never resolved who owned it (or really thought about it); we were just trying to get the job done. Had we a policy (like you are looking at), it would have been helpful, but the licensing wouldn't have mattered. I think if you go into any business today, you will find a range of licensing. I would encourage you to zoom out one level and think in terms of "enterprise software," not just open-source.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 16:33:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61703#M929</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2023-08-15T16:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61711#M930</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1138442473"&gt;@cclements&lt;/a&gt;&amp;nbsp;&amp;nbsp; See my posting under Tech Talk, you may find the website and links useful to you quest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are contacts there as well, who you can reach out too and ask further questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out:&amp;nbsp; &lt;A href="https://openssf.org/resources/guides/" target="_blank"&gt;https://openssf.org/resources/guides/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 21:34:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61711#M930</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-08-15T21:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61740#M933</link>
      <description>&lt;P&gt;Thank you for your response. I am still pondering your first question, why open-source software is any different than, COTS for instance.&amp;nbsp; Beyond there being no neck to choke, I am not sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As to the question about licenses, it was more about under which license the open-source software as released and what that obligates us, as an organization, to.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 18:25:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61740#M933</guid>
      <dc:creator>cclements</dc:creator>
      <dc:date>2023-08-16T18:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61741#M934</link>
      <description>Thanks for the reply. I will certainly check out this link.&lt;BR /&gt;&lt;BR /&gt;Chris</description>
      <pubDate>Wed, 16 Aug 2023 18:25:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61741#M934</guid>
      <dc:creator>cclements</dc:creator>
      <dc:date>2023-08-16T18:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61746#M935</link>
      <description>&lt;P&gt;I would defer the "contribution to...." part to the HR/Legal departments since that aspect is more about of use-of company time and Intellectual Property; whereas the others belong in our corner because they are more of an IT-based risk-management discussion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a big fan of white-listing software (or manufacturers or versions, depending on your paranoia level).&amp;nbsp; &amp;nbsp;From a "policy" perspective you might focus on "eligible for vendor (or 3rd party) support" instead of "current or prior version".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also have our legal department review all licenses, open-source or otherwise as part of our onboarding process.&amp;nbsp; &amp;nbsp;One good thing about open-source its habit of reusing licenses (bsd, gpl, etc) which tends to to reduce the cost/time for review.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 20:05:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61746#M935</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-08-16T20:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61748#M936</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;Yes, we do the same regularly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 20:14:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61748#M936</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-08-16T20:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61759#M937</link>
      <description>&lt;P&gt;You might also find that in many companies there is a dedicated SAM (Software Asset Management) team who could take on responsibility for compliance with license terms, audits etc. rather than push this responsibility to legal counsel.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 09:48:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61759#M937</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2023-08-17T09:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61942#M938</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1138442473"&gt;@cclements&lt;/a&gt;&amp;nbsp;&amp;nbsp; Check out the explanations on the differences between open-source types, this may help you understand.&amp;nbsp;&amp;nbsp; Within my organisation we have to undergo mandatory annual certification, on a regular basis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://snyk.io/learn/open-source-licenses/" target="_blank"&gt;https://snyk.io/learn/open-source-licenses/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 01:20:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61942#M938</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-08-18T01:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Open-source policy templates</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61967#M939</link>
      <description>Thank you for sharing this link.</description>
      <pubDate>Fri, 18 Aug 2023 14:03:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Open-source-policy-templates/m-p/61967#M939</guid>
      <dc:creator>cclements</dc:creator>
      <dc:date>2023-08-18T14:03:38Z</dc:date>
    </item>
  </channel>
</rss>

