<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Open Source Software and Banks in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/58023#M6135</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1420085895"&gt;@Robert956&lt;/a&gt; You both missed one important aspect "licensing" and maintaining those conditions, which can get you into a whole heap of issues.&amp;nbsp; In my organisation, we have complete courses, and mandatory education in order to allow developers to use them, produce Open Source software etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is a major aspect, as well as security &amp;amp; privacy by design controls, before anything is released etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other aspect is DevSecOps and supply chain issues too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2023 20:16:38 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2023-03-22T20:16:38Z</dc:date>
    <item>
      <title>Open Source Software and Banks</title>
      <link>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/57988#M6129</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you ever wondered why Banks and financial institutions use so much Open Source Software internally?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Open source is everywhere. Over 90% of organisations in the UK use open source components in their software, including the financial sector. FINOS’ 2022 State of Open Source in Financial Services report made it clear in particular just how rapidly open source software is proliferating in the sector.&amp;nbsp; However, recent cyberattacks demonstrate the risk these companies run of losing billions of pounds if they don’t manage their software supply chains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.finextra.com/blogposting/23919/open-source-security-is-critical-for-financial-institutions?" target="_blank" rel="noopener"&gt;https://www.finextra.com/blogposting/23919/open-source-security-is-critical-for-financial-institutions?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:28:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/57988#M6129</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Software and Banks</title>
      <link>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/57998#M6132</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Open Source Software (OSS) is becoming increasingly popular in the banking industry because it offers numerous advantages such as cost savings, flexibility, security, and innovation. Banks can use OSS to build and customize their own solutions, integrate with other systems, and collaborate with other developers and institutions. Additionally, OSS provides greater transparency, accountability, and community support, which can help banks to better serve their customers and meet regulatory requirements. However, implementing and managing OSS requires careful planning, evaluation, and monitoring to ensure compatibility, reliability, and compliance with legal and ethical standards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 08:07:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/57998#M6132</guid>
      <dc:creator>Robert956</dc:creator>
      <dc:date>2023-03-22T08:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Software and Banks</title>
      <link>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/58021#M6134</link>
      <description>&lt;P&gt;Putting on my security beanie, I do not view OSS and commercial software any differently.&amp;nbsp; The goals are the same....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Prefer popular software (to increase the odds that others find the bugs).&lt;/LI&gt;&lt;LI&gt;Try to standardize across the entire company (to minimize attack surface).&lt;/LI&gt;&lt;LI&gt;Stay current on patches.&lt;/LI&gt;&lt;LI&gt;Purchase support when Management cares about MTTR.&lt;/LI&gt;&lt;LI&gt;Judge the supplier's based on their patch cadence and vulnerability response, both current and historical.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 22 Mar 2023 17:56:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/58021#M6134</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-03-22T17:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Software and Banks</title>
      <link>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/58023#M6135</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1420085895"&gt;@Robert956&lt;/a&gt; You both missed one important aspect "licensing" and maintaining those conditions, which can get you into a whole heap of issues.&amp;nbsp; In my organisation, we have complete courses, and mandatory education in order to allow developers to use them, produce Open Source software etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is a major aspect, as well as security &amp;amp; privacy by design controls, before anything is released etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other aspect is DevSecOps and supply chain issues too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 20:16:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Open-Source-Software-and-Banks/m-p/58023#M6135</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-03-22T20:16:38Z</dc:date>
    </item>
  </channel>
</rss>

