SlideShare a Scribd company logo
How do I trust my open source supply chain?
Context
2
1400+
Members From
41 Countries
80%
of Fortune 100
Tech & Telecom
35,000+
Developers
Contributing Code
170+
Open Source
Projects
$16B
Shared
Value
This is the Linux Foundation
Open Compliance Program Solutions
Processes
Bill of Materials
Tooling
https://compliance.linuxfoundation.org/
SPS
SPDX Tools
OpenChain Platinum Member Companies
4
The OpenChain Project defines the key requirements of
a quality open source compliance program.
outbound
upstream downstream
inbound
Training
Policy
Process
OpenChain Defines Inflection Points
Result: Predictable B2B Compliance Activity
A Brief Introduction to OpenChain - June 2020
9
Example Conformant Organizations
• Main List (3,700+ participants)
• GitHub (105+ participants)
• Automotive (115+ participants)
• Reference Tooling (160+ participants)
• China (105+ participants)
• Japan (190+ participants)
• Korea (40+ participants)
• Taiwan (40+ participants)
• India (40+ participants)
• Germany (30+ participants)
Work Groups + Lists + GitHub
Our Online Self-Certification Questionnaire
12
Comprehensive Reference Material
13
14
Partner Program
15
Partner Program
16
Partner Program
17
Partner Program
18
Global Third-Party Certification
OpenChain in ISO – Formal Standardization
The OpenChain Project has submitted our specification to ISO via
Publicly Available Specification (PAS) in Joint Technical Committee 1
(JTC-1). The ISO submission is available at:
• https://wiki.linuxfoundation.org/_media/openchain/openchainsp
ec-2.1.draft.pdf
Working in partnership with in partnership with Joint Development
Foundation we expect to become a formal standard in Q3 2020.
The OpenChain standard can be met by:
Self-Certification
Independent Compliance Assessment
Third Party Certification
Freedom of Choice for Customers and Suppliers
Self-Certification is at the heart of the OpenChain
industry standard. Companies can access a series of
yes/no questions to determine if they have
implemented the key requirements of a quality open
source compliance program. These questions can be
found here:
https://certification.openchainproject.org
Self-Certification
Independent Compliance Assessment works in the
same was as the Independent Assessments in other
standards. An independent party such as a law firm,
consultancy or accounting firm reviews the product of
an OpenChain Self-Assessment and offers guidance on
whether they perceive it as complete.
Independent Compliance Assessment
Third-Party Certification is a process whereby a
certification authority guides a company through an
OpenChain Conformance Process. The certification
authority then issues a formal certification document.
This activity maps precisely to the forms of third-party
certification observed around automotive,
infrastructure and similar fields.
Third-Party Certification
The OpenChain industry standard has been carefully
designed by user companies to identify the inflection
points where a process, policy or training should be
implemented in an open source compliance program.
Our experience shows that self-certification is an
effective method of reducing risk and increasing
efficiency. That said, the choice of self-certification,
independent compliance assessment or third-party
certification depends on each business sector and
customer base. We seek to provide freedom of choice.
OpenChain is run by user companies for user
companies. This companies are collaborating to create
clear, shared and effective approaches to managing
open source code.
OpenChain is well positioned to support and improve
supply chain management best practices applicable to
vulnerability management. We currently have an active
dialogue on how this can be accomplished and all
parties are welcome to contribute.
Be Part of This
Join our community:
https://www.openchainproject.org/get-started
Self-Certify or Health Check an organization:
https://certification.openchainproject.org
scoughlan@linuxfoundation.org
www.openchainproject.org

More Related Content

PPTX
A Brief Introduction to OpenChain - May 2020 - Update1
PPTX
A Brief Introduction to OpenChain - May 2020
PPTX
OpenChain as a Standard
PDF
Processes Missing from OpenChain
PPTX
COAC Presentation March 26 2015
PPTX
OpenChain: Great Open Source Compliance for Everyone (Version 7)
PPTX
Great Open Source Compliance For Everyone - Version 11
PPTX
Great Open Source Compliance for Everyone - Version 6
A Brief Introduction to OpenChain - May 2020 - Update1
A Brief Introduction to OpenChain - May 2020
OpenChain as a Standard
Processes Missing from OpenChain
COAC Presentation March 26 2015
OpenChain: Great Open Source Compliance for Everyone (Version 7)
Great Open Source Compliance For Everyone - Version 11
Great Open Source Compliance for Everyone - Version 6

Similar to A Brief Introduction to OpenChain - June 2020 (20)

PPTX
Free and Open Source Software - Challenges for the Automotive Supply Chain
PPTX
Open Source in ISO Building the First LF Standard in Fourteen Years and What ...
PDF
Whitepaper For Open Gp
PPTX
A Brief Introduction to OpenChain - February 2020
PPT
451 Sugarcrm Aslett
PPTX
OpenAthens Conference 2018 - Don Thibeau - OpenID Connect
PDF
OpenChain Continual Improvement Case Studies
PPTX
Business Process Analysis and Insights COPIS
PPT
Colombia The Open Group
PPTX
ETRI EOST2024 Seoul Keynote - 2024-10-15
PPTX
OpenChain 2.0 specification in a nutshell
PDF
Top Software panies to Outsource.pdfTesting Com
PDF
An_Overview_of_FFC_Audit_Management_System_(AMS)_PDF.pdf
PDF
Robotic Process Automation
PDF
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
PDF
APP Academy: Distribute Your App Through Automation (October 13, 2014)
PDF
Ensuring Adherence to Global and Industry Standards Through Effective Softwar...
PPTX
OpenChain Legal Work Group - 2024-01-17
PDF
The Significance of Software Compliance Testing.pdf
PPTX
Agile Practices for Transitioning to SAP S/4HANA®
Free and Open Source Software - Challenges for the Automotive Supply Chain
Open Source in ISO Building the First LF Standard in Fourteen Years and What ...
Whitepaper For Open Gp
A Brief Introduction to OpenChain - February 2020
451 Sugarcrm Aslett
OpenAthens Conference 2018 - Don Thibeau - OpenID Connect
OpenChain Continual Improvement Case Studies
Business Process Analysis and Insights COPIS
Colombia The Open Group
ETRI EOST2024 Seoul Keynote - 2024-10-15
OpenChain 2.0 specification in a nutshell
Top Software panies to Outsource.pdfTesting Com
An_Overview_of_FFC_Audit_Management_System_(AMS)_PDF.pdf
Robotic Process Automation
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
APP Academy: Distribute Your App Through Automation (October 13, 2014)
Ensuring Adherence to Global and Industry Standards Through Effective Softwar...
OpenChain Legal Work Group - 2024-01-17
The Significance of Software Compliance Testing.pdf
Agile Practices for Transitioning to SAP S/4HANA®
Ad

More from Shane Coughlan (20)

PPTX
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
PDF
The 3rd OSPO Summit - China (Beijing - 2025-06-12)
PPTX
OpenChain Korea Work Group Meeting - 2025-06-16
PPTX
OpenChain Tooling Work Group - 2025-07-02
PPTX
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
PPTX
In From the Cold: Open Source as Part of Mainstream Software Asset Management
PPTX
Empowering Asian Contributions: The Rise of Regional User Groups in Open Sour...
PDF
Open Chain Q2 Steering Committee Meeting - 2025-06-25
PDF
OpenChain Webinar - AboutCode - Practical Compliance in One Stack – Licensing...
PPTX
OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30
PPTX
OpenChain @ InnerSource Summit 2024 - 2024-11-20
PPTX
OpenChain Korea Work Group Meeting #24 - 2024-11-26
PDF
Compliance and Integrity in the Software Supply Chain with Software Heritage:...
PDF
Fujitsu’s OSS standards conformance and AI Management System Standardization ...
PPTX
OpenChain China Work Group Presentation @ OSCAR 2024
PPTX
OpenChain Japan Community Day - 2024-10-17
PDF
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
PDF
SBOM Implementation Reality - From Crawl to Walk, the SPDX Lite Profile for t...
PPTX
OpenChain Webinar - AI Legal Landscape - Slides
PDF
OpenChain Telco SBOM Guide Overview - 2024-09-25
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
The 3rd OSPO Summit - China (Beijing - 2025-06-12)
OpenChain Korea Work Group Meeting - 2025-06-16
OpenChain Tooling Work Group - 2025-07-02
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
In From the Cold: Open Source as Part of Mainstream Software Asset Management
Empowering Asian Contributions: The Rise of Regional User Groups in Open Sour...
Open Chain Q2 Steering Committee Meeting - 2025-06-25
OpenChain Webinar - AboutCode - Practical Compliance in One Stack – Licensing...
OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30
OpenChain @ InnerSource Summit 2024 - 2024-11-20
OpenChain Korea Work Group Meeting #24 - 2024-11-26
Compliance and Integrity in the Software Supply Chain with Software Heritage:...
Fujitsu’s OSS standards conformance and AI Management System Standardization ...
OpenChain China Work Group Presentation @ OSCAR 2024
OpenChain Japan Community Day - 2024-10-17
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
SBOM Implementation Reality - From Crawl to Walk, the SPDX Lite Profile for t...
OpenChain Webinar - AI Legal Landscape - Slides
OpenChain Telco SBOM Guide Overview - 2024-09-25
Ad

Recently uploaded (20)

PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PDF
Digital Strategies for Manufacturing Companies
PPTX
L1 - Introduction to python Backend.pptx
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PPTX
Operating system designcfffgfgggggggvggggggggg
PPTX
assetexplorer- product-overview - presentation
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PPTX
Odoo POS Development Services by CandidRoot Solutions
PPTX
Transform Your Business with a Software ERP System
PDF
medical staffing services at VALiNTRY
PDF
top salesforce developer skills in 2025.pdf
PPTX
Why Generative AI is the Future of Content, Code & Creativity?
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
CHAPTER 2 - PM Management and IT Context
PPTX
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PDF
iTop VPN Free 5.6.0.5262 Crack latest version 2025
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Digital Strategies for Manufacturing Companies
L1 - Introduction to python Backend.pptx
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
Operating system designcfffgfgggggggvggggggggg
assetexplorer- product-overview - presentation
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Odoo POS Development Services by CandidRoot Solutions
Transform Your Business with a Software ERP System
medical staffing services at VALiNTRY
top salesforce developer skills in 2025.pdf
Why Generative AI is the Future of Content, Code & Creativity?
Wondershare Filmora 15 Crack With Activation Key [2025
CHAPTER 2 - PM Management and IT Context
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
iTop VPN Free 5.6.0.5262 Crack latest version 2025
Internet Downloader Manager (IDM) Crack 6.42 Build 41
How to Choose the Right IT Partner for Your Business in Malaysia

A Brief Introduction to OpenChain - June 2020

  • 1. How do I trust my open source supply chain?
  • 2. Context 2 1400+ Members From 41 Countries 80% of Fortune 100 Tech & Telecom 35,000+ Developers Contributing Code 170+ Open Source Projects $16B Shared Value This is the Linux Foundation
  • 3. Open Compliance Program Solutions Processes Bill of Materials Tooling https://compliance.linuxfoundation.org/ SPS SPDX Tools
  • 5. The OpenChain Project defines the key requirements of a quality open source compliance program.
  • 7. Result: Predictable B2B Compliance Activity
  • 10. • Main List (3,700+ participants) • GitHub (105+ participants) • Automotive (115+ participants) • Reference Tooling (160+ participants) • China (105+ participants) • Japan (190+ participants) • Korea (40+ participants) • Taiwan (40+ participants) • India (40+ participants) • Germany (30+ participants) Work Groups + Lists + GitHub
  • 13. 13
  • 14. 14
  • 20. OpenChain in ISO – Formal Standardization The OpenChain Project has submitted our specification to ISO via Publicly Available Specification (PAS) in Joint Technical Committee 1 (JTC-1). The ISO submission is available at: • https://wiki.linuxfoundation.org/_media/openchain/openchainsp ec-2.1.draft.pdf Working in partnership with in partnership with Joint Development Foundation we expect to become a formal standard in Q3 2020.
  • 21. The OpenChain standard can be met by: Self-Certification Independent Compliance Assessment Third Party Certification Freedom of Choice for Customers and Suppliers
  • 22. Self-Certification is at the heart of the OpenChain industry standard. Companies can access a series of yes/no questions to determine if they have implemented the key requirements of a quality open source compliance program. These questions can be found here: https://certification.openchainproject.org Self-Certification
  • 23. Independent Compliance Assessment works in the same was as the Independent Assessments in other standards. An independent party such as a law firm, consultancy or accounting firm reviews the product of an OpenChain Self-Assessment and offers guidance on whether they perceive it as complete. Independent Compliance Assessment
  • 24. Third-Party Certification is a process whereby a certification authority guides a company through an OpenChain Conformance Process. The certification authority then issues a formal certification document. This activity maps precisely to the forms of third-party certification observed around automotive, infrastructure and similar fields. Third-Party Certification
  • 25. The OpenChain industry standard has been carefully designed by user companies to identify the inflection points where a process, policy or training should be implemented in an open source compliance program. Our experience shows that self-certification is an effective method of reducing risk and increasing efficiency. That said, the choice of self-certification, independent compliance assessment or third-party certification depends on each business sector and customer base. We seek to provide freedom of choice.
  • 26. OpenChain is run by user companies for user companies. This companies are collaborating to create clear, shared and effective approaches to managing open source code.
  • 27. OpenChain is well positioned to support and improve supply chain management best practices applicable to vulnerability management. We currently have an active dialogue on how this can be accomplished and all parties are welcome to contribute.
  • 28. Be Part of This Join our community: https://www.openchainproject.org/get-started Self-Certify or Health Check an organization: https://certification.openchainproject.org