SlideShare a Scribd company logo
How do I trust my open source supply chain?
Context
2
1400+
Members From
41 Countries
80%
of Fortune 100
Tech & Telecom
35,000+
Developers
Contributing Code
170+
Open Source
Projects
$16B
Shared
Value
This is the Linux Foundation
Open Compliance Program Solutions
Processes
Bill of Materials
Tooling
https://compliance.linuxfoundation.org/
4
The OpenChain Project defines the key requirements of
a quality open source compliance program.
outbound
upstream downstream
inbound
Training
Policy
Process
OpenChain Defines Inflection Points
Result: Predictable B2B Compliance Activity
Our Online Self-Certification Questionnaire
A Brief Introduction to OpenChain - February 2020
10
Big cheer for Inno3 in France!
Latest Conformant Organization
12
Comprehensive Reference Material
13
14
• This work group has membership from most major automotive
companies, Tier 1 suppliers, and a substantial number of Tier 2 and
3 companies.
• It held a face-to-face meeting beside CES in Las Vegas during
January. This meeting naturally included an excellent opportunity to
build out increased mindshare with US automotive companies.
Automotive Work Group (7月2019~)
https://groups.io/g/openchain-automotive-work-group/topics
• This work group has membership from many large companies that
use open source tooling for open source complaince in production,
such as Siemens, Bosch, Toshiba, Hitachi and Fujitsu.
• It held a face-to-face meeting beside FOSDEM in Brussels during
January. Oliver Fendt from Siemens has the details.
Reference Tooling Work Group (7月2019~)
https://groups.io/g/openchain-automotive-work-group/topics
OpenChain China – Quarterly Meetings
OpenChain Japan – Bi-Monthly Meetings
OpenChain in Korea – Quarterly Meetings
OpenChain in India – Quarterly Meetings
OpenChain Taiwan – Quarterly Meetings
OpenChain Germany – First Meeting 2月6
Siemens Nuremburg
38 People
29 Companies
Michael from Facebook has kindly offered us space at their offices in
Palo Alto for the first USA Work Group meeting.
We will be promoting the meeting this week and expect a kick-off
session with 10~20 people from various Silicon Valley companies.
OpenChain USA – First Meeting 3月13
Andrew from Moorcrofts is going to be the primary host of the first
OpenChain UK Work Group meeting. More details as the date and
venue is locked down.
OpenChain UK – First Meeting 4~5月
• Global Education Work Group
A work group focused on ensuring the OpenChain education
material is up-to-date and available across multiple languages. This
is a similar role to our original curriculum work team but more
focused on a specific work outcome.
• Global Telecommunications Work Group
A work group focused on how telecommmunication companies can
build on their leadership position to ensure smooth industry
adoption in a manner similar to the automotive work group.
New Work Groups (2月2020~)
OpenChain had its “general consumer”
debut at CES via collaboration with the
AGL Project. This saw OpenChain
volunteers manning a booth for three
days and sharing information with 100s
of people.
Shane Coughlan, OpenChain General
Advisor, has been named as an advisory
to the open source activities of the United
Nations Technology Innovation Labs.
Some Cool Stuff: CES + United Nations
OpenChain in ISO (6月2019~)
The OpenChain Project is submitting our specification to ISO via
Publicly Available Specification (PAS) in Joint Technical Committee 1
(JTC-1).
Working in partnership with in partnership with Joint Development
Foundation we expect to become a formal standard in the 1st half of
2020.
We are referring to the ISO formatted version as OpenChain 2.1.
However, it is functionally identical to OpenChain 2.0 and all
OpenChain 2.0 companies will also be ISO conformant.
OpenChain in ISO (6月2019~)
The ISO submission version is available at:
https://wiki.linuxfoundation.org/_media/openchain/openchainspec-
2.1.draft.pdf
Past readers of the spec might find the marked up version useful:
https://wiki.linuxfoundation.org/_media/openchain/OpenChainSpec-
2.1.draft.MarkUp.pdf
We are not seeking edits but we do advise everyone to review.
Partner Program (2x in 2019)
29
30
Partner Program – Newest Participant
Third Party Certification in Japan (Nov 2018~)
Global Third-Party Certification (Mar 2019~)
OpenChain Case Studies – One Example
OpenChain Services – One Example
The OpenChain standard can be met by:
Self-Certification
Independent Compliance Assessment
Third Party Certification
Freedom of Choice for Customers and Suppliers
Self-Certification is at the heart of the OpenChain
industry standard. Companies can access a series of
yes/no questions to determine if they have
implemented the key requirements of a quality open
source compliance program. These questions can be
found here:
https://certification.openchainproject.org
Self-Certification
Independent Compliance Assessment works in the
same was as the Independent Security Assessment in
ISO26262. An independent party such as a law firm,
consultancy or accounting firm reviews the product of
an OpenChain Self-Assessment and offers guidance on
whether they perceive it as complete.
Independent Compliance Assessment
Third-Party Certification is a process whereby a
certification authority guides a company through an
OpenChain Conformance Process. The certification
authority then issues a formal certification document.
This activity maps precisely to the forms of third-party
certification observed around automotive,
infrastructure and similar fields.
Third-Party Certification
The OpenChain industry standard has been carefully
designed by user companies to identify the inflection
points where a process, policy or training should be
implemented in an open source compliance program.
Our experience shows that self-certification is an
effective method of reducing risk and increasing
efficiency. That said, the choice of self-certification,
independent compliance assessment or third-party
certification depends on each business sector and
customer base. We seek to provide freedom of choice.
OpenChain is run by user companies for user
companies.
Be Part of This
Join the community:
https://www.openchainproject.org/community
Self-Certify or Health Check an organization:
https://certification.openchainproject.org
scoughlan@linuxfoundation.org
www.openchainproject.org

More Related Content

PPTX
OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17
PDF
International Cooperation Experiences: Results Achieved, Lessons Learned, and...
PPTX
OpenChain as a Standard
PPTX
OpenChain & OpenUK Future Leaders Group Presentation (Reduced)
PDF
Internationalizing a Multi-Layered Application
DOCX
Cfbi Summer Briefing 2013
PDF
PTC Launches First Global Internet of Things Certification Program
 
PDF
Who's there? A stakeholder analysis approach for hybrid OSS
OpenChain Webinar #10 - Joint Development Foundation - 2020-08-17
International Cooperation Experiences: Results Achieved, Lessons Learned, and...
OpenChain as a Standard
OpenChain & OpenUK Future Leaders Group Presentation (Reduced)
Internationalizing a Multi-Layered Application
Cfbi Summer Briefing 2013
PTC Launches First Global Internet of Things Certification Program
 
Who's there? A stakeholder analysis approach for hybrid OSS

What's hot (10)

PDF
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
PPTX
Future Cloud Action Line - EIT ICT Labs
PDF
See The Benefits Of Our Open Architectures Readiness Assessment
PPTX
ATC iLab - profile & current projects
PDF
Tai Hou-Tng - Co-Creating with Community in Technology Commercialisation, CSW...
PPTX
PCO Presentation
PDF
Open Source Journey in Moxa: Build up Open Source Office in Hardware Manufact...
PPTX
STRATEGIES FOR HELPING CO. IN THE DIGITIZATION RACE
PDF
Paulo Ribeiro - ESOP - OSL19
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Future Cloud Action Line - EIT ICT Labs
See The Benefits Of Our Open Architectures Readiness Assessment
ATC iLab - profile & current projects
Tai Hou-Tng - Co-Creating with Community in Technology Commercialisation, CSW...
PCO Presentation
Open Source Journey in Moxa: Build up Open Source Office in Hardware Manufact...
STRATEGIES FOR HELPING CO. IN THE DIGITIZATION RACE
Paulo Ribeiro - ESOP - OSL19
Ad

Similar to A Brief Introduction to OpenChain - February 2020 (20)

PPTX
OpenChain Germany Work Group Meeting 1
PPTX
Free and Open Source Software - Challenges for the Automotive Supply Chain
PPTX
OpenChain Taiwan Meeting #2: A Brief Introduction to OpenChain
PPTX
Great Open Source Compliance For Everyone - Version 11
PPTX
Great Open Source Compliance For Everyone (Version 3)
PDF
Complex Made Simple @ Bird&Birds OpenChain Seminar
PPTX
Using OpenChain for Practical Open Source Software Supply Chain Management (O...
PPTX
A Brief Introduction to OpenChain - May 2020
PPTX
Great Open Source Compliance for Everyone - Version 6
PPTX
A Brief Introduction to OpenChain - May 2020 - Update1
PPTX
Open Source in ISO Building the First LF Standard in Fourteen Years and What ...
PDF
Complex Made Simple @ LF Energy Conference in Paris
PPTX
OpenChain: Great Open Source Compliance for Everyone (Version 7)
PPTX
OpenChain Japan Work Group - Meeting 27
PPTX
A Brief Introduction to OpenChain - June 2020
PPTX
A Brief Introduction to OpenChain - July 2020
PPTX
OpenChain at ISO WG21 2020 Plenary - 9th June
PPTX
OpenChain China Workshop # 1
PPTX
OpenChain Work Team Meeting Agenda 08-19-2019
PPTX
OpenChain Korea Work Group Meeting #24 - 2024-11-26
OpenChain Germany Work Group Meeting 1
Free and Open Source Software - Challenges for the Automotive Supply Chain
OpenChain Taiwan Meeting #2: A Brief Introduction to OpenChain
Great Open Source Compliance For Everyone - Version 11
Great Open Source Compliance For Everyone (Version 3)
Complex Made Simple @ Bird&Birds OpenChain Seminar
Using OpenChain for Practical Open Source Software Supply Chain Management (O...
A Brief Introduction to OpenChain - May 2020
Great Open Source Compliance for Everyone - Version 6
A Brief Introduction to OpenChain - May 2020 - Update1
Open Source in ISO Building the First LF Standard in Fourteen Years and What ...
Complex Made Simple @ LF Energy Conference in Paris
OpenChain: Great Open Source Compliance for Everyone (Version 7)
OpenChain Japan Work Group - Meeting 27
A Brief Introduction to OpenChain - June 2020
A Brief Introduction to OpenChain - July 2020
OpenChain at ISO WG21 2020 Plenary - 9th June
OpenChain China Workshop # 1
OpenChain Work Team Meeting Agenda 08-19-2019
OpenChain Korea Work Group Meeting #24 - 2024-11-26
Ad

More from Shane Coughlan (20)

PPTX
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
PDF
The 3rd OSPO Summit - China (Beijing - 2025-06-12)
PPTX
OpenChain Korea Work Group Meeting - 2025-06-16
PPTX
OpenChain Tooling Work Group - 2025-07-02
PPTX
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
PPTX
In From the Cold: Open Source as Part of Mainstream Software Asset Management
PPTX
Empowering Asian Contributions: The Rise of Regional User Groups in Open Sour...
PDF
Open Chain Q2 Steering Committee Meeting - 2025-06-25
PDF
OpenChain Webinar - AboutCode - Practical Compliance in One Stack – Licensing...
PPTX
OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30
PPTX
OpenChain @ InnerSource Summit 2024 - 2024-11-20
PDF
Compliance and Integrity in the Software Supply Chain with Software Heritage:...
PDF
Fujitsu’s OSS standards conformance and AI Management System Standardization ...
PPTX
OpenChain China Work Group Presentation @ OSCAR 2024
PPTX
OpenChain Japan Community Day - 2024-10-17
PPTX
ETRI EOST2024 Seoul Keynote - 2024-10-15
PDF
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
PDF
SBOM Implementation Reality - From Crawl to Walk, the SPDX Lite Profile for t...
PPTX
OpenChain Webinar - AI Legal Landscape - Slides
PDF
OpenChain Telco SBOM Guide Overview - 2024-09-25
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
The 3rd OSPO Summit - China (Beijing - 2025-06-12)
OpenChain Korea Work Group Meeting - 2025-06-16
OpenChain Tooling Work Group - 2025-07-02
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
In From the Cold: Open Source as Part of Mainstream Software Asset Management
Empowering Asian Contributions: The Rise of Regional User Groups in Open Sour...
Open Chain Q2 Steering Committee Meeting - 2025-06-25
OpenChain Webinar - AboutCode - Practical Compliance in One Stack – Licensing...
OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30
OpenChain @ InnerSource Summit 2024 - 2024-11-20
Compliance and Integrity in the Software Supply Chain with Software Heritage:...
Fujitsu’s OSS standards conformance and AI Management System Standardization ...
OpenChain China Work Group Presentation @ OSCAR 2024
OpenChain Japan Community Day - 2024-10-17
ETRI EOST2024 Seoul Keynote - 2024-10-15
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
SBOM Implementation Reality - From Crawl to Walk, the SPDX Lite Profile for t...
OpenChain Webinar - AI Legal Landscape - Slides
OpenChain Telco SBOM Guide Overview - 2024-09-25

Recently uploaded (20)

PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
Cost to Outsource Software Development in 2025
PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PPTX
Computer Software and OS of computer science of grade 11.pptx
PPTX
L1 - Introduction to python Backend.pptx
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
Nekopoi APK 2025 free lastest update
PDF
Designing Intelligence for the Shop Floor.pdf
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PPTX
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Adobe Illustrator 28.6 Crack My Vision of Vector Design
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PPTX
Transform Your Business with a Software ERP System
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Softaken Excel to vCard Converter Software.pdf
wealthsignaloriginal-com-DS-text-... (1).pdf
Cost to Outsource Software Development in 2025
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
Computer Software and OS of computer science of grade 11.pptx
L1 - Introduction to python Backend.pptx
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Nekopoi APK 2025 free lastest update
Designing Intelligence for the Shop Floor.pdf
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Adobe Illustrator 28.6 Crack My Vision of Vector Design
Wondershare Filmora 15 Crack With Activation Key [2025
Odoo Companies in India – Driving Business Transformation.pdf
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Design an Analysis of Algorithms I-SECS-1021-03
Transform Your Business with a Software ERP System
Understanding Forklifts - TECH EHS Solution
Softaken Excel to vCard Converter Software.pdf

A Brief Introduction to OpenChain - February 2020

  • 1. How do I trust my open source supply chain?
  • 2. Context 2 1400+ Members From 41 Countries 80% of Fortune 100 Tech & Telecom 35,000+ Developers Contributing Code 170+ Open Source Projects $16B Shared Value This is the Linux Foundation
  • 3. Open Compliance Program Solutions Processes Bill of Materials Tooling https://compliance.linuxfoundation.org/
  • 4. 4
  • 5. The OpenChain Project defines the key requirements of a quality open source compliance program.
  • 7. Result: Predictable B2B Compliance Activity
  • 10. 10
  • 11. Big cheer for Inno3 in France! Latest Conformant Organization
  • 13. 13
  • 14. 14
  • 15. • This work group has membership from most major automotive companies, Tier 1 suppliers, and a substantial number of Tier 2 and 3 companies. • It held a face-to-face meeting beside CES in Las Vegas during January. This meeting naturally included an excellent opportunity to build out increased mindshare with US automotive companies. Automotive Work Group (7月2019~) https://groups.io/g/openchain-automotive-work-group/topics
  • 16. • This work group has membership from many large companies that use open source tooling for open source complaince in production, such as Siemens, Bosch, Toshiba, Hitachi and Fujitsu. • It held a face-to-face meeting beside FOSDEM in Brussels during January. Oliver Fendt from Siemens has the details. Reference Tooling Work Group (7月2019~) https://groups.io/g/openchain-automotive-work-group/topics
  • 17. OpenChain China – Quarterly Meetings
  • 18. OpenChain Japan – Bi-Monthly Meetings
  • 19. OpenChain in Korea – Quarterly Meetings
  • 20. OpenChain in India – Quarterly Meetings
  • 21. OpenChain Taiwan – Quarterly Meetings
  • 22. OpenChain Germany – First Meeting 2月6 Siemens Nuremburg 38 People 29 Companies
  • 23. Michael from Facebook has kindly offered us space at their offices in Palo Alto for the first USA Work Group meeting. We will be promoting the meeting this week and expect a kick-off session with 10~20 people from various Silicon Valley companies. OpenChain USA – First Meeting 3月13
  • 24. Andrew from Moorcrofts is going to be the primary host of the first OpenChain UK Work Group meeting. More details as the date and venue is locked down. OpenChain UK – First Meeting 4~5月
  • 25. • Global Education Work Group A work group focused on ensuring the OpenChain education material is up-to-date and available across multiple languages. This is a similar role to our original curriculum work team but more focused on a specific work outcome. • Global Telecommunications Work Group A work group focused on how telecommmunication companies can build on their leadership position to ensure smooth industry adoption in a manner similar to the automotive work group. New Work Groups (2月2020~)
  • 26. OpenChain had its “general consumer” debut at CES via collaboration with the AGL Project. This saw OpenChain volunteers manning a booth for three days and sharing information with 100s of people. Shane Coughlan, OpenChain General Advisor, has been named as an advisory to the open source activities of the United Nations Technology Innovation Labs. Some Cool Stuff: CES + United Nations
  • 27. OpenChain in ISO (6月2019~) The OpenChain Project is submitting our specification to ISO via Publicly Available Specification (PAS) in Joint Technical Committee 1 (JTC-1). Working in partnership with in partnership with Joint Development Foundation we expect to become a formal standard in the 1st half of 2020. We are referring to the ISO formatted version as OpenChain 2.1. However, it is functionally identical to OpenChain 2.0 and all OpenChain 2.0 companies will also be ISO conformant.
  • 28. OpenChain in ISO (6月2019~) The ISO submission version is available at: https://wiki.linuxfoundation.org/_media/openchain/openchainspec- 2.1.draft.pdf Past readers of the spec might find the marked up version useful: https://wiki.linuxfoundation.org/_media/openchain/OpenChainSpec- 2.1.draft.MarkUp.pdf We are not seeking edits but we do advise everyone to review.
  • 29. Partner Program (2x in 2019) 29
  • 30. 30 Partner Program – Newest Participant
  • 31. Third Party Certification in Japan (Nov 2018~)
  • 33. OpenChain Case Studies – One Example
  • 34. OpenChain Services – One Example
  • 35. The OpenChain standard can be met by: Self-Certification Independent Compliance Assessment Third Party Certification Freedom of Choice for Customers and Suppliers
  • 36. Self-Certification is at the heart of the OpenChain industry standard. Companies can access a series of yes/no questions to determine if they have implemented the key requirements of a quality open source compliance program. These questions can be found here: https://certification.openchainproject.org Self-Certification
  • 37. Independent Compliance Assessment works in the same was as the Independent Security Assessment in ISO26262. An independent party such as a law firm, consultancy or accounting firm reviews the product of an OpenChain Self-Assessment and offers guidance on whether they perceive it as complete. Independent Compliance Assessment
  • 38. Third-Party Certification is a process whereby a certification authority guides a company through an OpenChain Conformance Process. The certification authority then issues a formal certification document. This activity maps precisely to the forms of third-party certification observed around automotive, infrastructure and similar fields. Third-Party Certification
  • 39. The OpenChain industry standard has been carefully designed by user companies to identify the inflection points where a process, policy or training should be implemented in an open source compliance program. Our experience shows that self-certification is an effective method of reducing risk and increasing efficiency. That said, the choice of self-certification, independent compliance assessment or third-party certification depends on each business sector and customer base. We seek to provide freedom of choice.
  • 40. OpenChain is run by user companies for user companies.
  • 41. Be Part of This Join the community: https://www.openchainproject.org/community Self-Certify or Health Check an organization: https://certification.openchainproject.org