SlideShare a Scribd company logo
open source at scania
JONAS ÖBERG, chair of scania open source program
Jonas Öberg / Open Source at Scania
Always
46%
Sometimes
42%
Rarely
10%
Never
2%
How often do you try to find
open source alternatives?When we ask how often our
developers try to find open source
options over other kinds of software,
we see that 88% of our developers
sometimes or always try to use open
source.
That’s interesting, considering 43%
felt there was no policy for open
source, it was not permitted, or they
didn’t know.
Regardless of guidelines and whether
open source is encouraged or not, it
seems our developers still give some
preference to open source.
WE’re on the way, but the road is long!
Jonas Öberg / Open Source at Scania
26%
51%
18%
5%
0%
10%
20%
30%
40%
50%
60%
Very interested Somewhat interested Not too interested Not interested at all
how interested are you in contributing to open source?
Finally, we asked whether our developers
have an interest in contributing to open
source in the future. 77% are somewhat or
very interested in contributing to open
source.
This gives us some reassurance that if we
provide our developers with clear
guidelines for contributing to open source,
many will take us up on the opportunity to
do so.
supply
chain
freedrom
to operate
software
confidence in supply chain
SPDX Bill-of-
Material
Mandatory Delivery
of Required
Compliance
Artifacts
OpenChain™ or
TÜV SÜD TPS
Standard PPP
15001A certification
Q1 2020
Sure,
we can
do this!
Q1
2019
Oh, this
is
actually
hard
work…
Q4
2019
We now
deliver!??
Export control is regulations that
limit release of software,
technology, services, knowledge
to foreign countries: limiting our
freedom to operate.
Economic sanctions, trade
restrictions, barriers, tariffs,
embargoes.
Designed to protect national
security, foreign policy or
domestic economic interests.
confidence in freedom to operate
• Sensitive goods; software, technology and technical data, both physical items
and transfer of software and technology (e.g. offering as download from a
website)
− Any goods transferred to a party with the intent of being used for military purposes,
− Or, any goods which is part of the product control lists, which may be Dual Use items, i.e.
items which can have both a civilian and military purpose.
• Both require a license to export – unless they meet an exception
• Applies regardless of how it’s transferred: electronically, post, on laptop when
visiting foreign country, etc..
• Also apply to transfers within a group, e.g. Scania in Sweden to Scania in Brazil.
What is affected by Export Control?
Self classify
.. and then there are exceptions.. and exceptions to the exceptions.
Quotation marks means the word is separately defined.
Open Source at Scania
Contains Encryption? (Yes/No)
Is encryption used for User Authentication? (Yes/No)
Open-Source Encryption? (Yes/No)
Generally available to the public by being sold without restriction from
stock at retail points? (Yes/No)
Encryption Type Used? (Symmetric/Asymmetric/Elliptic-Curve)
Key-length used for the Encryption
…
Encryption Questionnaire
• The answers represent a statement of the capabilities of the software, easily
understood by the developers.
• Different organisations may interpret the answers differently.
• No need for developers to make ECCN decisions.
• Provides a way for developers to speak to export control groups.
Interpretation
Introducing EXPORT.md
Export-Declaration File v1.0
Contains-encryption: [Yes/No]
Crypto-for-user-authentication: [Yes/No]
...
Declared-ECCN: x-us:5D002
At least between Scania and FNC, we ask the same questions! And
the answers can be shared.
Export Control of Open Source Working
Group – ECOS WG
confidence in softwareavoidance of physical harm
Open Source at Scania
Open source / 3pp
libraries/code
Qualification
Evidence that the software development
process for the component is based on an
appropriate national or international
standard (e.g. ISO/IEC/IEEE 12207.
Evidence that the software complies
with its requirements, reactions to and
description of anomalities etc.
Complete code coverage including MC/DC
(ASIL-D)
26262 Requirements Abridged
No or almost no open source
fulfilling this today.
tools TCL3
Confidence from use
Evaluation of the tool
development process
Validation of the software
tool
Development according to a
safety standard
26262 Requirements
Highly recommends
“For open source developments, some of the
standards used by those communities can also be
appropriate.”
C,D
C,D
A,B
A,B
No or almost no open source fulfilling this
today.
No or almost no open source
fulfilling this today.
Tomorrow?
supply chain
OpenChain
freedrom to operate
export control of open
source working group
software
ELISA
?
Confidence
Jonas Öberg
Scania CV AB
<jonas.oberg@scania.com>

More Related Content

PPTX
Bni Connect tutoriel simplifié - BNI+
PDF
Becoming a Design Leader
PPTX
Swarming: How a new approach to support can save DevOps teams from 3rd-line t...
PDF
Boundary-Spanning Leadership
PDF
PDF
Achieving Apatheia — 7 Steps To Controlling Your Perceptions Like A Stoic
PDF
Managing for Happiness
PDF
The Secret to MLM Success
Bni Connect tutoriel simplifié - BNI+
Becoming a Design Leader
Swarming: How a new approach to support can save DevOps teams from 3rd-line t...
Boundary-Spanning Leadership
Achieving Apatheia — 7 Steps To Controlling Your Perceptions Like A Stoic
Managing for Happiness
The Secret to MLM Success

What's hot (18)

PPTX
BNI specific
PDF
Marketing - Marketing Digital - Marketing
ODP
Golden circle why
PPTX
How to Present Your MLM Opportunity to Others
PDF
Caipira Ágil 2023 - Os desafios da liderança_ como transformar dinossauros.pdf
PDF
The effective executive
PPTX
1 to 1 with members
PPTX
Start with Why: How Leaders Inspire
PDF
Deploying Automation For Manufacturing Process Improvement Powerpoint Present...
PPTX
Find your why
PPTX
Kaizen para Tecnologia da Informação
PDF
Ladder of Inference-#1
PDF
Open session management 3.0
PDF
Leadership agility
PPT
The golden circle
PPTX
3 Reasons Why People Fail in Network Marketing
PPTX
Growth hacking and marketing
PDF
50.000 orange stickies later
BNI specific
Marketing - Marketing Digital - Marketing
Golden circle why
How to Present Your MLM Opportunity to Others
Caipira Ágil 2023 - Os desafios da liderança_ como transformar dinossauros.pdf
The effective executive
1 to 1 with members
Start with Why: How Leaders Inspire
Deploying Automation For Manufacturing Process Improvement Powerpoint Present...
Find your why
Kaizen para Tecnologia da Informação
Ladder of Inference-#1
Open session management 3.0
Leadership agility
The golden circle
3 Reasons Why People Fail in Network Marketing
Growth hacking and marketing
50.000 orange stickies later
Ad

Similar to Open Source at Scania (20)

PPTX
Software
PDF
Open Source Governance in Highly Regulated Companies
PPTX
EMC World 2016 - cnaITL.01 Adopting An Open Source Strategy
PPTX
Open Source Product Management
PPTX
2016 - Safely Removing the Last Roadblock to Continuous Delivery
PPTX
Safely Removing the Last Roadblock to Continuous Delivery
PDF
Secure GitOps pipelines for Kubernetes with Snyk & Weaveworks
PPTX
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
PPTX
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
PDF
You Can’t Live Without Open Source - Results from the Open Source 360 Survey
PDF
Security that Scales with Cloud Native Development
PDF
Augmented Agile: Agile Behavior Meets Digital Engineering
PDF
Database Open Source @ Box - Percona Live 2017
PDF
Webinar–2019 Open Source Risk Analysis Report
ODP
Should I Build With Open Source Software?
PPTX
Sharing is Caring, How OSS can help embed a DevOps Culture
PDF
Infosecurity Europe - Infographic
PDF
Productivity Gains Using Open Source products
PDF
Open Source and Cloud - The Two Great Tastes...
PPTX
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
Software
Open Source Governance in Highly Regulated Companies
EMC World 2016 - cnaITL.01 Adopting An Open Source Strategy
Open Source Product Management
2016 - Safely Removing the Last Roadblock to Continuous Delivery
Safely Removing the Last Roadblock to Continuous Delivery
Secure GitOps pipelines for Kubernetes with Snyk & Weaveworks
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
You Can’t Live Without Open Source - Results from the Open Source 360 Survey
Security that Scales with Cloud Native Development
Augmented Agile: Agile Behavior Meets Digital Engineering
Database Open Source @ Box - Percona Live 2017
Webinar–2019 Open Source Risk Analysis Report
Should I Build With Open Source Software?
Sharing is Caring, How OSS can help embed a DevOps Culture
Infosecurity Europe - Infographic
Productivity Gains Using Open Source products
Open Source and Cloud - The Two Great Tastes...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
Ad

More from Shane Coughlan (20)

PPTX
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
PDF
The 3rd OSPO Summit - China (Beijing - 2025-06-12)
PPTX
OpenChain Korea Work Group Meeting - 2025-06-16
PPTX
OpenChain Tooling Work Group - 2025-07-02
PPTX
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
PPTX
In From the Cold: Open Source as Part of Mainstream Software Asset Management
PPTX
Empowering Asian Contributions: The Rise of Regional User Groups in Open Sour...
PDF
Open Chain Q2 Steering Committee Meeting - 2025-06-25
PDF
OpenChain Webinar - AboutCode - Practical Compliance in One Stack – Licensing...
PPTX
OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30
PPTX
OpenChain @ InnerSource Summit 2024 - 2024-11-20
PPTX
OpenChain Korea Work Group Meeting #24 - 2024-11-26
PDF
Compliance and Integrity in the Software Supply Chain with Software Heritage:...
PDF
Fujitsu’s OSS standards conformance and AI Management System Standardization ...
PPTX
OpenChain China Work Group Presentation @ OSCAR 2024
PPTX
OpenChain Japan Community Day - 2024-10-17
PPTX
ETRI EOST2024 Seoul Keynote - 2024-10-15
PDF
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
PDF
SBOM Implementation Reality - From Crawl to Walk, the SPDX Lite Profile for t...
PPTX
OpenChain Webinar - AI Legal Landscape - Slides
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
The 3rd OSPO Summit - China (Beijing - 2025-06-12)
OpenChain Korea Work Group Meeting - 2025-06-16
OpenChain Tooling Work Group - 2025-07-02
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
In From the Cold: Open Source as Part of Mainstream Software Asset Management
Empowering Asian Contributions: The Rise of Regional User Groups in Open Sour...
Open Chain Q2 Steering Committee Meeting - 2025-06-25
OpenChain Webinar - AboutCode - Practical Compliance in One Stack – Licensing...
OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30
OpenChain @ InnerSource Summit 2024 - 2024-11-20
OpenChain Korea Work Group Meeting #24 - 2024-11-26
Compliance and Integrity in the Software Supply Chain with Software Heritage:...
Fujitsu’s OSS standards conformance and AI Management System Standardization ...
OpenChain China Work Group Presentation @ OSCAR 2024
OpenChain Japan Community Day - 2024-10-17
ETRI EOST2024 Seoul Keynote - 2024-10-15
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
SBOM Implementation Reality - From Crawl to Walk, the SPDX Lite Profile for t...
OpenChain Webinar - AI Legal Landscape - Slides

Recently uploaded (20)

PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
top salesforce developer skills in 2025.pdf
PPTX
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
PDF
Understanding Forklifts - TECH EHS Solution
PPTX
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Cost to Outsource Software Development in 2025
PDF
Softaken Excel to vCard Converter Software.pdf
PDF
Designing Intelligence for the Shop Floor.pdf
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PDF
Nekopoi APK 2025 free lastest update
PPTX
Odoo POS Development Services by CandidRoot Solutions
PPTX
Why Generative AI is the Future of Content, Code & Creativity?
PPTX
assetexplorer- product-overview - presentation
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PPTX
Transform Your Business with a Software ERP System
wealthsignaloriginal-com-DS-text-... (1).pdf
top salesforce developer skills in 2025.pdf
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
Understanding Forklifts - TECH EHS Solution
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
Which alternative to Crystal Reports is best for small or large businesses.pdf
Cost to Outsource Software Development in 2025
Softaken Excel to vCard Converter Software.pdf
Designing Intelligence for the Shop Floor.pdf
Design an Analysis of Algorithms I-SECS-1021-03
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
Nekopoi APK 2025 free lastest update
Odoo POS Development Services by CandidRoot Solutions
Why Generative AI is the Future of Content, Code & Creativity?
assetexplorer- product-overview - presentation
Navsoft: AI-Powered Business Solutions & Custom Software Development
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
Transform Your Business with a Software ERP System

Open Source at Scania

  • 1. open source at scania JONAS ÖBERG, chair of scania open source program
  • 2. Jonas Öberg / Open Source at Scania Always 46% Sometimes 42% Rarely 10% Never 2% How often do you try to find open source alternatives?When we ask how often our developers try to find open source options over other kinds of software, we see that 88% of our developers sometimes or always try to use open source. That’s interesting, considering 43% felt there was no policy for open source, it was not permitted, or they didn’t know. Regardless of guidelines and whether open source is encouraged or not, it seems our developers still give some preference to open source. WE’re on the way, but the road is long!
  • 3. Jonas Öberg / Open Source at Scania 26% 51% 18% 5% 0% 10% 20% 30% 40% 50% 60% Very interested Somewhat interested Not too interested Not interested at all how interested are you in contributing to open source? Finally, we asked whether our developers have an interest in contributing to open source in the future. 77% are somewhat or very interested in contributing to open source. This gives us some reassurance that if we provide our developers with clear guidelines for contributing to open source, many will take us up on the opportunity to do so.
  • 5. confidence in supply chain SPDX Bill-of- Material Mandatory Delivery of Required Compliance Artifacts OpenChain™ or TÜV SÜD TPS Standard PPP 15001A certification Q1 2020
  • 6. Sure, we can do this! Q1 2019 Oh, this is actually hard work… Q4 2019 We now deliver!??
  • 7. Export control is regulations that limit release of software, technology, services, knowledge to foreign countries: limiting our freedom to operate. Economic sanctions, trade restrictions, barriers, tariffs, embargoes. Designed to protect national security, foreign policy or domestic economic interests. confidence in freedom to operate
  • 8. • Sensitive goods; software, technology and technical data, both physical items and transfer of software and technology (e.g. offering as download from a website) − Any goods transferred to a party with the intent of being used for military purposes, − Or, any goods which is part of the product control lists, which may be Dual Use items, i.e. items which can have both a civilian and military purpose. • Both require a license to export – unless they meet an exception • Applies regardless of how it’s transferred: electronically, post, on laptop when visiting foreign country, etc.. • Also apply to transfers within a group, e.g. Scania in Sweden to Scania in Brazil. What is affected by Export Control?
  • 9. Self classify .. and then there are exceptions.. and exceptions to the exceptions. Quotation marks means the word is separately defined.
  • 11. Contains Encryption? (Yes/No) Is encryption used for User Authentication? (Yes/No) Open-Source Encryption? (Yes/No) Generally available to the public by being sold without restriction from stock at retail points? (Yes/No) Encryption Type Used? (Symmetric/Asymmetric/Elliptic-Curve) Key-length used for the Encryption … Encryption Questionnaire
  • 12. • The answers represent a statement of the capabilities of the software, easily understood by the developers. • Different organisations may interpret the answers differently. • No need for developers to make ECCN decisions. • Provides a way for developers to speak to export control groups. Interpretation
  • 13. Introducing EXPORT.md Export-Declaration File v1.0 Contains-encryption: [Yes/No] Crypto-for-user-authentication: [Yes/No] ... Declared-ECCN: x-us:5D002 At least between Scania and FNC, we ask the same questions! And the answers can be shared. Export Control of Open Source Working Group – ECOS WG
  • 16. Open source / 3pp libraries/code Qualification Evidence that the software development process for the component is based on an appropriate national or international standard (e.g. ISO/IEC/IEEE 12207. Evidence that the software complies with its requirements, reactions to and description of anomalities etc. Complete code coverage including MC/DC (ASIL-D) 26262 Requirements Abridged No or almost no open source fulfilling this today.
  • 17. tools TCL3 Confidence from use Evaluation of the tool development process Validation of the software tool Development according to a safety standard 26262 Requirements Highly recommends “For open source developments, some of the standards used by those communities can also be appropriate.” C,D C,D A,B A,B No or almost no open source fulfilling this today.
  • 18. No or almost no open source fulfilling this today. Tomorrow?
  • 19. supply chain OpenChain freedrom to operate export control of open source working group software ELISA ? Confidence
  • 20. Jonas Öberg Scania CV AB <jonas.oberg@scania.com>