SlideShare a Scribd company logo
Organizations worldwide use Black Duck Software’s industry-leading products to automate the processes of securing and managing open source software,
eliminating the pain related to security vulnerabilities, open source license compliance and operational risk. Black Duck is headquartered in Burlington, MA,
and has offices in San Jose, CA, London, Frankfurt, Hong Kong, Tokyo, Seoul and Beijing. For more information, visit www.blackducksoftware.com
Future of Open Source Survey 2016
COMPLIANCE SPOTLIGHT
said there is no formal policy
for selecting & approving
open source code
of respondents who have
policies don’t enforce them
or allow them to be bypassed
have no list of
approved open
source licenses
never evaluate
their code quality
30%of respondents aren’t very
successful at complying
with associated licenses
OVER
NEARLY
NEARLY
NEARLY
50%
50%
are not successfully
providing information
about licenses, security
issues & software versions
NEARLY
60%
60%
90%
Compliance is Erratic
Code Reviews Are Rare
Existing Policies Rarely Enforced
Future of Open Source 2016 collaborators: Abilian, Acquia, Ant Systems, Appnovation, Appsembler, Ardent Technologies, Inc.,
Bareos GmbH & Co. KG, Black Duck Software, Capital One, Chamilo, Chef, CloudFoundry Corp, Confer, Coolan, Couchbase,
Credativ, DEIS/Engineyard, Eclipse Foundation, EnterpriseDB, Evolveum, Grid Protection Alliance, Hewlett Packard, InfoSys,
JFrog, Linux Foundation, Linux Professional Institute, MARSEC, Microsoft, MassTLC, Miracl, nexB, NGINX, North Bridge,
Open Source Business (OSB) Alliance, Open Source EHR Alliance, Open Source Initiative (OSI), OpenClinic, Open-Xchange,
Opmantek, OpusVL, Pentaho, Ravel Law, Red Hat, Rift-io, SDH Institute, Tecnisys, The Apache Software Foundation, The
Document Foundation, Ubuntu, Univention, VoltDB, Wikibon, WIPRO and WP Engine. *platinum collaborators are in bold
Growing Opportunity
for Policies & Procedures

More Related Content

PDF
Understanding Open Source
PPTX
Owasp A9 USING KNOWN VULNERABLE COMPONENTS IT 6873 presentation
PDF
Penetration testing tools and phases
PDF
The Log4Shell Vulnerability – explained: how to stay secure
PDF
CVE-2021-44228 Log4j (and Log4Shell) Executive Explainer by cje@bugcrowd
PPTX
Vulnerability and Exploit Trends: Combining behavioral analysis and OS defens...
PDF
we45 - Web Application Security Testing Case Study
PDF
10 Tips to Keep Your Software a Step Ahead of the Hackers
Understanding Open Source
Owasp A9 USING KNOWN VULNERABLE COMPONENTS IT 6873 presentation
Penetration testing tools and phases
The Log4Shell Vulnerability – explained: how to stay secure
CVE-2021-44228 Log4j (and Log4Shell) Executive Explainer by cje@bugcrowd
Vulnerability and Exploit Trends: Combining behavioral analysis and OS defens...
we45 - Web Application Security Testing Case Study
10 Tips to Keep Your Software a Step Ahead of the Hackers

What's hot (20)

PDF
SFScon 2020 - Ivan Pashchenko - Learning from Developers How to Make Dependen...
PPTX
Security misconfiguration
PPTX
Cyber Security and Open Source
PDF
Client-Side Penetration Testing Presentation
PPTX
Security testing fundamentals
PDF
Web Application Security Testing Tools
PPTX
Building your Open Source Security stack
PPTX
Machine Learning for Malware Classification and Clustering
PPTX
Intro to Network Vapt
PDF
Malware Detection - A Machine Learning Perspective
PDF
Secure Coding and Threat Modeling
PDF
Penetration testing & Ethical Hacking
PDF
Sast 2021
PPTX
Gubarevich Peter - 11-Feb-2016 - Show IT 2016 @Bratislava
PPTX
7 Reasons Your Applications are Attractive to Adversaries
PPTX
Penetration testing dont just leave it to chance
PDF
The State of Open Source Security
PPTX
MobileTechTalk - Android application troubleshooting
PPT
Mobile application security and threat modeling
PPTX
Application Whitelisting - Complementing Threat centric with Trust centric se...
SFScon 2020 - Ivan Pashchenko - Learning from Developers How to Make Dependen...
Security misconfiguration
Cyber Security and Open Source
Client-Side Penetration Testing Presentation
Security testing fundamentals
Web Application Security Testing Tools
Building your Open Source Security stack
Machine Learning for Malware Classification and Clustering
Intro to Network Vapt
Malware Detection - A Machine Learning Perspective
Secure Coding and Threat Modeling
Penetration testing & Ethical Hacking
Sast 2021
Gubarevich Peter - 11-Feb-2016 - Show IT 2016 @Bratislava
7 Reasons Your Applications are Attractive to Adversaries
Penetration testing dont just leave it to chance
The State of Open Source Security
MobileTechTalk - Android application troubleshooting
Mobile application security and threat modeling
Application Whitelisting - Complementing Threat centric with Trust centric se...
Ad

Viewers also liked (20)

PDF
Integrating Black Duck into Your Environment with Hub APIs
PDF
Integrating Black Duck into your Agile DevOps Environment
PPT
BlackDuck Suite
PDF
Collaborative Development the Gift That Keeps on Giving
PPTX
What's it like to work at Black Duck
PDF
Myths and Misperceptions of Open Source Security
PDF
Secure Application Development in the Age of Continuous Delivery
PDF
Customer Case Study: ScienceLogic - Many Paths to Compliance
PDF
Practical Steps to Scale Legal Support for Open Source
PDF
Making the Transition from Suite to the Hub
PDF
Containers for Lawyers Richard Fontana
PPTX
Litigation and Compliance in the Open Source Ecosystem
PPTX
Contain your risk: Deploy secure containers with trust and confidence
PDF
Filling your AppSec Toolbox - Which Tools, When to Use Them, and Why
PDF
Don't Let Open Source be the Deal Breaker In Your M&A
PDF
PCI and Vulnerability Assessments - What’s Missing
PPTX
Managing Open Source in Application Security and Software Development Lifecycle
PDF
Securing Docker Containers
PDF
Open Source in Application Security
PDF
The 4 Levels of Open Source Risk Management
Integrating Black Duck into Your Environment with Hub APIs
Integrating Black Duck into your Agile DevOps Environment
BlackDuck Suite
Collaborative Development the Gift That Keeps on Giving
What's it like to work at Black Duck
Myths and Misperceptions of Open Source Security
Secure Application Development in the Age of Continuous Delivery
Customer Case Study: ScienceLogic - Many Paths to Compliance
Practical Steps to Scale Legal Support for Open Source
Making the Transition from Suite to the Hub
Containers for Lawyers Richard Fontana
Litigation and Compliance in the Open Source Ecosystem
Contain your risk: Deploy secure containers with trust and confidence
Filling your AppSec Toolbox - Which Tools, When to Use Them, and Why
Don't Let Open Source be the Deal Breaker In Your M&A
PCI and Vulnerability Assessments - What’s Missing
Managing Open Source in Application Security and Software Development Lifecycle
Securing Docker Containers
Open Source in Application Security
The 4 Levels of Open Source Risk Management
Ad

Similar to Compliance in the 2016 Future of Open Source (20)

PDF
Open Source 360° Survey Key Takeaways
PPTX
Open Source 360 Survey Results
PPTX
Welcome & The State of Open Source Security
PDF
The AppSec Path to Enlightenment
PDF
Aliens in Your Apps!
PDF
14 Tips to Choose the Right Open Source Test Automation Tool.pdf
PPTX
Software Security Assurance for DevOps
PPTX
Software Security Assurance for Devops
PDF
Driving Risks Out of Embedded Automotive Software
PPTX
Live 2014 Survey Results: Open Source Development and Application Security Su...
PPTX
Aliens in Your Apps! Are You Using Components With Known Vulnerabilities?
PDF
Sonatype's 2013 OSS Software Survey
PPTX
Rana Khalil – Securing Open Source Dependencies
PDF
(In)security in Open Source
PDF
You Can’t Live Without Open Source - Results from the Open Source 360 Survey
PPTX
Shifting the conversation from active interception to proactive neutralization
PDF
Implementing and Managing Open Source Compliance Programs - A Crash Course
PDF
Implementing and Managing an Open Source Compliance Program: A Crash Course
PPTX
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
PPTX
The Top 3 Strategies To Reduce Your Open Source Security Risks - A WhiteSour...
Open Source 360° Survey Key Takeaways
Open Source 360 Survey Results
Welcome & The State of Open Source Security
The AppSec Path to Enlightenment
Aliens in Your Apps!
14 Tips to Choose the Right Open Source Test Automation Tool.pdf
Software Security Assurance for DevOps
Software Security Assurance for Devops
Driving Risks Out of Embedded Automotive Software
Live 2014 Survey Results: Open Source Development and Application Security Su...
Aliens in Your Apps! Are You Using Components With Known Vulnerabilities?
Sonatype's 2013 OSS Software Survey
Rana Khalil – Securing Open Source Dependencies
(In)security in Open Source
You Can’t Live Without Open Source - Results from the Open Source 360 Survey
Shifting the conversation from active interception to proactive neutralization
Implementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash Course
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
The Top 3 Strategies To Reduce Your Open Source Security Risks - A WhiteSour...

More from Black Duck by Synopsys (20)

PDF
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
PDF
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
PDF
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
PDF
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
PDF
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
PDF
Open-Source- Sicherheits- und Risikoanalyse 2018
PDF
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
PDF
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
PDF
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
PDF
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
PPT
FLIGHT Amsterdam Presentation - From Protex to Hub
PPTX
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
PPTX
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
PDF
Open Source Rookies and Community
PPTX
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
PPTX
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
PPTX
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
PPTX
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
PPTX
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Open-Source- Sicherheits- und Risikoanalyse 2018
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - From Protex to Hub
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Rookies and Community
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Security Breaches and Cryptocurrency Dominating News

Recently uploaded (20)

DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced IT Governance
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PDF
Electronic commerce courselecture one. Pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Modernizing your data center with Dell and AMD
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
Chapter 3 Spatial Domain Image Processing.pdf
The AUB Centre for AI in Media Proposal.docx
The Rise and Fall of 3GPP – Time for a Sabbatical?
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Spectral efficient network and resource selection model in 5G networks
Advanced IT Governance
Reach Out and Touch Someone: Haptics and Empathic Computing
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Unlocking AI with Model Context Protocol (MCP)
NewMind AI Monthly Chronicles - July 2025
GamePlan Trading System Review: Professional Trader's Honest Take
Electronic commerce courselecture one. Pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Modernizing your data center with Dell and AMD
Understanding_Digital_Forensics_Presentation.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
Mobile App Security Testing_ A Comprehensive Guide.pdf
Empathic Computing: Creating Shared Understanding
Chapter 3 Spatial Domain Image Processing.pdf

Compliance in the 2016 Future of Open Source

  • 1. Organizations worldwide use Black Duck Software’s industry-leading products to automate the processes of securing and managing open source software, eliminating the pain related to security vulnerabilities, open source license compliance and operational risk. Black Duck is headquartered in Burlington, MA, and has offices in San Jose, CA, London, Frankfurt, Hong Kong, Tokyo, Seoul and Beijing. For more information, visit www.blackducksoftware.com Future of Open Source Survey 2016 COMPLIANCE SPOTLIGHT said there is no formal policy for selecting & approving open source code of respondents who have policies don’t enforce them or allow them to be bypassed have no list of approved open source licenses never evaluate their code quality 30%of respondents aren’t very successful at complying with associated licenses OVER NEARLY NEARLY NEARLY 50% 50% are not successfully providing information about licenses, security issues & software versions NEARLY 60% 60% 90% Compliance is Erratic Code Reviews Are Rare Existing Policies Rarely Enforced Future of Open Source 2016 collaborators: Abilian, Acquia, Ant Systems, Appnovation, Appsembler, Ardent Technologies, Inc., Bareos GmbH & Co. KG, Black Duck Software, Capital One, Chamilo, Chef, CloudFoundry Corp, Confer, Coolan, Couchbase, Credativ, DEIS/Engineyard, Eclipse Foundation, EnterpriseDB, Evolveum, Grid Protection Alliance, Hewlett Packard, InfoSys, JFrog, Linux Foundation, Linux Professional Institute, MARSEC, Microsoft, MassTLC, Miracl, nexB, NGINX, North Bridge, Open Source Business (OSB) Alliance, Open Source EHR Alliance, Open Source Initiative (OSI), OpenClinic, Open-Xchange, Opmantek, OpusVL, Pentaho, Ravel Law, Red Hat, Rift-io, SDH Institute, Tecnisys, The Apache Software Foundation, The Document Foundation, Ubuntu, Univention, VoltDB, Wikibon, WIPRO and WP Engine. *platinum collaborators are in bold Growing Opportunity for Policies & Procedures