SlideShare a Scribd company logo
Bob Sutor – VP, Open Systems Strategy
29 March, 2011




Open Source Governance
for your Organization




                                        © 2011 IBM Corporation
Before we get started
! Per my website:

             The content on this site is my own and does not necessarily
              represent my employer’s positions, strategies or opinions.



! http://www.sutor.com
! This discussion does not constitute legal advice.
! I’m not an attorney, and certainly not an intellectual property
  attorney, and you should consult one as necessary.



2   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
The key question




                    Do you have proper legal controls and business
                     processes in place to deal with open source
                                      software?




3   29 March 2011     Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
Your open source governance strategy
! Five years ago, it was not uncommon for that strategy to be
  defined as “you shall use no open source software.”
! You need to understand the legal risks and responsibilities for
  any software you use, and weigh those against the business
  value.
! Work out a plan that specifies what business and legal
  controls are in place to approve use of open source in your
  organization or in your products, and make sure you have a
  well defined escalation path.




4   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
What you need to know
! All projects to which your employees or organizational
  members contribute, the free and open source licenses being
  used, and the intellectual property commitments those
  contributions make upon your company or organization.
! All use of open source code within internal processes,
  product development, and services engagements.




5   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
What you need to know
! All open source code that goes into your hardware products,
  software products, web-delivered services, or are given to
  your customers as part of consulting and services
  engagements.
! The location of all open source code repositories used in
  development, with strict rules about what code with which
  licenses can be combined (or not).




6   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
What you then need to put in place
! Uniform cross-organizational rules and policies about the use
  of open source, with the ability to audit adherence.
! Tools to determine code provenance: from which original
  bodies of open source code did your current codebase
  derive?
! Balanced policies to weigh the business and legal benefits
  and risks in using open source code.




7   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
What you then need to put in place
! Education for all employees and contractors, with special
  sections appropriate for users, contributors, developers, and
  distributors of open source code.
! Clear processes defining when decisions about open source
  can be made locally and when they must be made centrally,
  with paths for escalating decisions going up both the
  executive and legal chains.
! An aggressive policy for contributing to the various open
  source communities from which you benefit in your company
  or organization.



8   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
The IBM experience
! Ten+ years contributing to and leading hundreds of open
  source projects in efforts such as Linux, Eclipse, and Apache.
! An internal governance process embodied within the Open
  Source Steering Committee (OSSC), with the set of rules now
  in their third generation in the last decade.
! The OSSC reviews all IBM external activities involving Open
  Source including
    – Starting a new OSS community/project
    – Contributing to an existing OSS community
    – Using OSS in IBM products or services
    – Distributing reference implementations or OSS modifications
    – Redistributing (OEM or Resell) vendor products containing OSS


9   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
Use of open source has grown
! We have seen proposals to the OSSC grow steadily.
! The proposals fall into 3 categories
     – Already evaluated and approved for use
     – Meets well-defined criteria and a centralized committee can handle
     – Complex or original scenarios that are best decided by top of the
       business

! The governance process continues to evolve
     – Scalability: handle increase in the number proposals
     – Delegation: allow business units to drive majority of decisions
     – Economy: don’t spend money on people and resources to answer
       questions to which you already know the answers.




10   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
Some lessons learned

! We were worried about code quality but we shouldn’t have
  been.
! We gained a better understanding of the open source domain
     – Copyright and patent complexities
     – License terms and conditions
     – Usual lack of warranty
! We learned to balanced open and proprietary.




11   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
Some lessons learned

! We gained a better understanding of the value of open source
     – How to leverage it in what we do
     – How and where to contribute
     – How to work well in open source communities
! We learned to manage the risks.
! We learned it is important to have clear business and strategic
  reasons for using open source




12   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation
Final thoughts
! Develop your open source policy collaboratively among your
  business, technical, and legal experts, don’t dictate it.
! Education is key for employee and contractor compliance.
! Establish clear policy for what employees can and cannot do
  with open source in their spare time.
! Consider using code pedigree and scanning services from
  companies such as Black Duck, OpenLogic, and Palamida.
! Know where handling open source needs to be the same as
  closed source, and where it needs to be different.
! Plan to iterate on and refine your policy yearly for the first few
  years.
13   29 March 2011   Bob Sutor - Open Source Governance for your Organization   © 2011 IBM Corporation

More Related Content

PPT
5 mistakes to avoid when creating a mobile app
PDF
IBM Mobile Strategy - Mobile World Congress 2012
KEY
How technology can enhance the non-profit organization: What it can do for y...
PPT
How Open Source Can Help Your Startup
PPTX
Grass Roots Developer Evangelism by Paul Pajo | DevCon Summit 2015 #GoOpenSou...
PDF
Video on demand for worship
PDF
Career in Software Development
PDF
From Eureka to Successful Innovation
5 mistakes to avoid when creating a mobile app
IBM Mobile Strategy - Mobile World Congress 2012
How technology can enhance the non-profit organization: What it can do for y...
How Open Source Can Help Your Startup
Grass Roots Developer Evangelism by Paul Pajo | DevCon Summit 2015 #GoOpenSou...
Video on demand for worship
Career in Software Development
From Eureka to Successful Innovation

What's hot (18)

PDF
Mobile Testing: Challenges and Solutions
PPTX
Creativity & Innovation
PDF
Adventures on the Road to Enterprise Virtual Assistants
PPTX
Mobile Web Performance Optimization 1-7-14
PPTX
UXPA2019 Enhancing the User Experience for People with Disabilities: Top 10 ...
PPT
Senscape for mo mo bj 530
DOCX
4th blog post
PDF
Using Technology to Make People More Powerful
PDF
Top10 techno
PDF
Embedded Development - to Fit the Unique Needs of Enterprises Around the Globe
PPTX
What is new about javaspace?
PPTX
Kaspars Petersons - BYOD - more like BYOP
PPTX
Future of IT preso
PDF
10 Reasons To Use Open Source Software-Defined Networking
PDF
"Work like a startup!" a.k.a. building an internal venture in a big company
PDF
Can a lean startup be built inside a large company?
PPTX
The future of technology final project
PDF
Apple Study: 8 easy steps to beat Microsoft (and Google)
Mobile Testing: Challenges and Solutions
Creativity & Innovation
Adventures on the Road to Enterprise Virtual Assistants
Mobile Web Performance Optimization 1-7-14
UXPA2019 Enhancing the User Experience for People with Disabilities: Top 10 ...
Senscape for mo mo bj 530
4th blog post
Using Technology to Make People More Powerful
Top10 techno
Embedded Development - to Fit the Unique Needs of Enterprises Around the Globe
What is new about javaspace?
Kaspars Petersons - BYOD - more like BYOP
Future of IT preso
10 Reasons To Use Open Source Software-Defined Networking
"Work like a startup!" a.k.a. building an internal venture in a big company
Can a lean startup be built inside a large company?
The future of technology final project
Apple Study: 8 easy steps to beat Microsoft (and Google)
Ad

Similar to Open Source Governance for your Organization (20)

PDF
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
PDF
Breaking Free from Proprietary Gravitational Pull
PDF
Practical Trademark Law for FOSS Projects
ODP
Managing Community Open Source Brands
PDF
Managing the Software Supply Chain: Policies that Promote Innovation While Op...
PPTX
Open soucre(cut shrt)
PPTX
Four Steps to Creating an Effective Open Source Policy
PPT
Intellectual Primer For Small Business oct 2011
PDF
Four Steps to Creating an Effective Open Source Policy
PDF
Open Source Governance at HP
PDF
Open Source BI (OSBI)
PDF
Methods about Open Source Governance v2.5
PDF
Open Source Governance v2.5
PDF
Osbi Sesame?
ODP
Fundamentals of Free and Open Source Software
PDF
Why choose-liferay
PPTX
How to keep developers happy and lawyers calm
PDF
Open Source Contribution Policies That Don't Suck
PPTX
Open source softwares, 2011
PPT
Ten Elements of Open Source Governance
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
Breaking Free from Proprietary Gravitational Pull
Practical Trademark Law for FOSS Projects
Managing Community Open Source Brands
Managing the Software Supply Chain: Policies that Promote Innovation While Op...
Open soucre(cut shrt)
Four Steps to Creating an Effective Open Source Policy
Intellectual Primer For Small Business oct 2011
Four Steps to Creating an Effective Open Source Policy
Open Source Governance at HP
Open Source BI (OSBI)
Methods about Open Source Governance v2.5
Open Source Governance v2.5
Osbi Sesame?
Fundamentals of Free and Open Source Software
Why choose-liferay
How to keep developers happy and lawyers calm
Open Source Contribution Policies That Don't Suck
Open source softwares, 2011
Ten Elements of Open Source Governance
Ad

More from Robert Sutor (12)

PPTX
Considering New Data Sources
PPT
For the Love of Big Data
PDF
Lotusphere 2012 - Harnessing the Power of Enterprise Mobility
PDF
Landmines for Open Source in the Mobile Space
PDF
ApacheCon 2010 Keynote: Problems, Data, and Languages
PDF
Regarding Clouds, Mainframes, and Desktops … and Linux
PDF
Linux Everywhere? Matching the Workload to the Computer
PDF
Linux, Virtualisation, and Clouds
PDF
The Intersection of Ideas in Open Source and Open Standards
PDF
IBM Standards Principles
ODP
Information Technology Supporting the Development of International Standards
PDF
Smaller, Flatter, Smarter
Considering New Data Sources
For the Love of Big Data
Lotusphere 2012 - Harnessing the Power of Enterprise Mobility
Landmines for Open Source in the Mobile Space
ApacheCon 2010 Keynote: Problems, Data, and Languages
Regarding Clouds, Mainframes, and Desktops … and Linux
Linux Everywhere? Matching the Workload to the Computer
Linux, Virtualisation, and Clouds
The Intersection of Ideas in Open Source and Open Standards
IBM Standards Principles
Information Technology Supporting the Development of International Standards
Smaller, Flatter, Smarter

Recently uploaded (20)

PPTX
Cloud computing and distributed systems.
PDF
Electronic commerce courselecture one. Pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Approach and Philosophy of On baking technology
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
Spectroscopy.pptx food analysis technology
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
KodekX | Application Modernization Development
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Cloud computing and distributed systems.
Electronic commerce courselecture one. Pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Unlocking AI with Model Context Protocol (MCP)
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
NewMind AI Weekly Chronicles - August'25 Week I
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Chapter 3 Spatial Domain Image Processing.pdf
Approach and Philosophy of On baking technology
sap open course for s4hana steps from ECC to s4
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Review of recent advances in non-invasive hemoglobin estimation
Spectral efficient network and resource selection model in 5G networks
Spectroscopy.pptx food analysis technology
Network Security Unit 5.pdf for BCA BBA.
KodekX | Application Modernization Development
Digital-Transformation-Roadmap-for-Companies.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx

Open Source Governance for your Organization

  • 1. Bob Sutor – VP, Open Systems Strategy 29 March, 2011 Open Source Governance for your Organization © 2011 IBM Corporation
  • 2. Before we get started ! Per my website: The content on this site is my own and does not necessarily represent my employer’s positions, strategies or opinions. ! http://www.sutor.com ! This discussion does not constitute legal advice. ! I’m not an attorney, and certainly not an intellectual property attorney, and you should consult one as necessary. 2 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 3. The key question Do you have proper legal controls and business processes in place to deal with open source software? 3 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 4. Your open source governance strategy ! Five years ago, it was not uncommon for that strategy to be defined as “you shall use no open source software.” ! You need to understand the legal risks and responsibilities for any software you use, and weigh those against the business value. ! Work out a plan that specifies what business and legal controls are in place to approve use of open source in your organization or in your products, and make sure you have a well defined escalation path. 4 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 5. What you need to know ! All projects to which your employees or organizational members contribute, the free and open source licenses being used, and the intellectual property commitments those contributions make upon your company or organization. ! All use of open source code within internal processes, product development, and services engagements. 5 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 6. What you need to know ! All open source code that goes into your hardware products, software products, web-delivered services, or are given to your customers as part of consulting and services engagements. ! The location of all open source code repositories used in development, with strict rules about what code with which licenses can be combined (or not). 6 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 7. What you then need to put in place ! Uniform cross-organizational rules and policies about the use of open source, with the ability to audit adherence. ! Tools to determine code provenance: from which original bodies of open source code did your current codebase derive? ! Balanced policies to weigh the business and legal benefits and risks in using open source code. 7 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 8. What you then need to put in place ! Education for all employees and contractors, with special sections appropriate for users, contributors, developers, and distributors of open source code. ! Clear processes defining when decisions about open source can be made locally and when they must be made centrally, with paths for escalating decisions going up both the executive and legal chains. ! An aggressive policy for contributing to the various open source communities from which you benefit in your company or organization. 8 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 9. The IBM experience ! Ten+ years contributing to and leading hundreds of open source projects in efforts such as Linux, Eclipse, and Apache. ! An internal governance process embodied within the Open Source Steering Committee (OSSC), with the set of rules now in their third generation in the last decade. ! The OSSC reviews all IBM external activities involving Open Source including – Starting a new OSS community/project – Contributing to an existing OSS community – Using OSS in IBM products or services – Distributing reference implementations or OSS modifications – Redistributing (OEM or Resell) vendor products containing OSS 9 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 10. Use of open source has grown ! We have seen proposals to the OSSC grow steadily. ! The proposals fall into 3 categories – Already evaluated and approved for use – Meets well-defined criteria and a centralized committee can handle – Complex or original scenarios that are best decided by top of the business ! The governance process continues to evolve – Scalability: handle increase in the number proposals – Delegation: allow business units to drive majority of decisions – Economy: don’t spend money on people and resources to answer questions to which you already know the answers. 10 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 11. Some lessons learned ! We were worried about code quality but we shouldn’t have been. ! We gained a better understanding of the open source domain – Copyright and patent complexities – License terms and conditions – Usual lack of warranty ! We learned to balanced open and proprietary. 11 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 12. Some lessons learned ! We gained a better understanding of the value of open source – How to leverage it in what we do – How and where to contribute – How to work well in open source communities ! We learned to manage the risks. ! We learned it is important to have clear business and strategic reasons for using open source 12 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation
  • 13. Final thoughts ! Develop your open source policy collaboratively among your business, technical, and legal experts, don’t dictate it. ! Education is key for employee and contractor compliance. ! Establish clear policy for what employees can and cannot do with open source in their spare time. ! Consider using code pedigree and scanning services from companies such as Black Duck, OpenLogic, and Palamida. ! Know where handling open source needs to be the same as closed source, and where it needs to be different. ! Plan to iterate on and refine your policy yearly for the first few years. 13 29 March 2011 Bob Sutor - Open Source Governance for your Organization © 2011 IBM Corporation