SlideShare a Scribd company logo
1
Open source
software licensing
2020
1
Setting the context
Open source software (OSS) is a software programme with a source code that anyone can check, modify, and
update. It is usually developed in a collaborative manner and released under a licence that allows the developer
to inspect, change, and distribute the software to anyone for any purpose.
The way an organisation can use an open source software programme depends on its licence. Hundreds of
di΍erent open source licences are available; each has its own terminologies and restrictions.
The two main categories of OSS licences are permissive and copyleft.
Open source software licensing | Setting the context
Introduction: What is open source software?
Examples
• Berkeley Software Distribution (BSD) licence
• Apache
Examples
• GNU General Public Licence
• Eclipse
•
Minimal restrictions on licence use
•
Allowed to use the source code for any purpose
•
Attribution or acknowledgement for creators /
authors is necessary
• Can be a part of proprietary software pro-
grammes
• Allowed to use the source code for any purpose
•
•
Necessary to make an open source code for
others to use it freely
•
No further restrictions can be placed on the code,
distributed to the community as received
Permissive Copyleft
Attribution or acknowledgement for creators /
authors is necessary
2
With an increase in the use of OSS in organisations, managing and optimising OSS e΍ectively
is important. This can help organisations manage risk, compliance, and security vulnerability
associated with open source components consumed internally.
Introduction: Current
situation overview
• About 80GL΍erent types of OSS licences
are available; each has its own terminolo-
gies and restrictions.
• According to Gartner, OSS is used by
more than 95% IT organisations world-
wide.
• Through 2022, the percentage of open
source within IT portfolios relative to
either homegrown or licensed third-party
solutions will increase at a compound
annual growth rate (CAGR) of 30%.
Source
What innovation leaders must know about open-source software:
https://www.gartner.com/document/3956651?ref=solrAllrefval=248155840
• After the COVID-19 crisis, most
organisations would have remote workers
who can download any software with
minimal restrictions.
• More organisations are shifting to easily
accessible OSS to reduce dependency
on paid proprietary tools.
• However, OSS has its own set of
restrictions and security issues that
need monitoring.
Did you know? Whyis it in focus now?
Open source software licensing | Introduction
Open source software come with certain requirements, which when not followed can lead to legal, operations
and security issues.
Open source software licensing requirement/rationale
IP infringement
risk: licensing
obligations by
using open source
licence for patent
provisions
Restrictions
on use as
proprietary
licence: It can
mandate the
release of the
source code as an
OSS, and provide
rights to modify
and distribute at no
charge.
Derivative
work for copyleft
licences: It needs to
be licensed under
the same OSS
licence
Copyright
notices: that are
required to be
included in the
developed code
are found in the
licence text and
source code ȴles
Security risk:
It indicates
vulnerabilities
associated with
source code
components.
Business need for OSS compliance
3
Solution overview
Deloitte leverages a tool that helps to analyse the source code and builds a standardised
and repeatable process to enhance Free and open-source software (FOSS)
inventory management.
Workȵow for the code review
Open source software licensing | Solution overview
Flavours of OSS Compliance Reviews
OSS EULA analysis
Assisting organisations in manual review of Open
Source and freeware software’s End User License
Agreement (EULA).
Platform/Application License Implication
License review to identify license implications for
open source software components that are a
part of a platform or application.
Source Code Analysis
Consistent monitoring of OSS software code during
product/application development process for
internal consumption or developing commercial
applications.
01
03
02
Acquisitions involving
OSS platform
Organisations shifting
from proprietary to OSS
software base
Software applications/
product development
organisations
OSS included as a part of
the review of entire the
SAM asset base
Carry out due diligence of
the application platforms
and identify any potential
risks posed by software
licences used in building
the platform.
Provide consulting services
on which types of OSS
licences can be used in
developing in-house and
proprietary software.
Monitor OSS software code
consistently during the
complete cycle of product/
application development
process.
Provide a view of the OSS
included in the deployment
footprint and risk
assessment of the
installed OSS.
Areas where we help organisations use OSS
How can we help
8
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company
OLPLWHGEJXDUDQWHHȊ'77/ȋ

More Related Content

PDF
Webinar–That is Not How This Works
PPTX
Automate and Enhance Application Security Analysis
PDF
Cyber Threat Intelligence: Highlights and Trends for 2020
PDF
Preventing Code Leaks & Other Critical Security Risks from Code
PDF
Webinar–Best Practices for DevSecOps at Scale
PDF
Webinar–You've Got Your Open Source Audit Report–Now What?
PDF
Webinar–What You Need To Know About Open Source Licensing
PDF
Webinar–Why All Open Source Scans Aren't Created Equal
Webinar–That is Not How This Works
Automate and Enhance Application Security Analysis
Cyber Threat Intelligence: Highlights and Trends for 2020
Preventing Code Leaks & Other Critical Security Risks from Code
Webinar–Best Practices for DevSecOps at Scale
Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–What You Need To Know About Open Source Licensing
Webinar–Why All Open Source Scans Aren't Created Equal

What's hot (20)

PDF
SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
PDF
Webinar–Using Evidence-Based Security
PDF
Webinar–The 2019 Open Source Year in Review
PDF
Beyond Security Article_Cyber Security_April_2015
PPTX
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
PPTX
Open Source Insight: Balancing Agility and Open Source Security for DevOps
PDF
How Zero Trust Makes the Mission Simple & Secure
PDF
Virtual Lunch & Learn - Netherlands
PPTX
Ivanti for msp
PDF
Securing_your_Internet_of_Things_from_the_ground_up_white_paper_EN_US
PDF
Moving Beyond Zero Trust
PDF
Tomorrow Starts Here - Security Everywhere
PDF
Ivanti Insights Podcast - FireEye Breach
PPTX
Open Source Insight: Apache Struts Exploits, Cloudera IPO Risks & the Next Cy...
PDF
Cyber Warfare e scenari di mercato
PDF
Webinar – Security Tool Misconfiguration and Abuse
PDF
The Evolution of and Need for Secure Network Access
PDF
Webinar–The State of Open Source in M&A Transactions
PDF
u10a1 Security Plan-Beji Jacob
PDF
Infonetics Network and Content Security Vendor Scorecard
SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
Webinar–Using Evidence-Based Security
Webinar–The 2019 Open Source Year in Review
Beyond Security Article_Cyber Security_April_2015
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
Open Source Insight: Balancing Agility and Open Source Security for DevOps
How Zero Trust Makes the Mission Simple & Secure
Virtual Lunch & Learn - Netherlands
Ivanti for msp
Securing_your_Internet_of_Things_from_the_ground_up_white_paper_EN_US
Moving Beyond Zero Trust
Tomorrow Starts Here - Security Everywhere
Ivanti Insights Podcast - FireEye Breach
Open Source Insight: Apache Struts Exploits, Cloudera IPO Risks & the Next Cy...
Cyber Warfare e scenari di mercato
Webinar – Security Tool Misconfiguration and Abuse
The Evolution of and Need for Secure Network Access
Webinar–The State of Open Source in M&A Transactions
u10a1 Security Plan-Beji Jacob
Infonetics Network and Content Security Vendor Scorecard
Ad

Similar to Open source software license (20)

PDF
Exploring Open Source Licensing
PPTX
Open Source Software: What Are Your Obligations?
PDF
Open source software 101: Compliance and risk management
PDF
"Open Source as a enabler for industry collaborations and innovation!" by Gaë...
PDF
The Role of Open-Source Software in Modern Development
PPTX
Zen and the Art of Organizational Open Source
PPTX
Open source software licenses
PPTX
Open source technologies
PPTX
Open source technologies
ODP
The Internet of Things & Open Data: New forms of business?
PDF
Open Source Governance in Highly Regulated Companies
PDF
Managing the Software Supply Chain: Policies that Promote Innovation While Op...
PDF
What’s Driving Open Source (for MyGOSSCon)
PPTX
OSS - enterprise adoption strategy and governance
KEY
What is "Open Source"
PDF
Open Source is eating the world...
PPTX
The New Development Organization: Embracing “Open” and “Sharing” to Deliver S...
PDF
How to Open Source an Internal Project
PPTX
The Role of In-House & External Counsel in Managing Open Source Software
PDF
Open Source In Enterprises Apache2009 Beijing Jack Cai
Exploring Open Source Licensing
Open Source Software: What Are Your Obligations?
Open source software 101: Compliance and risk management
"Open Source as a enabler for industry collaborations and innovation!" by Gaë...
The Role of Open-Source Software in Modern Development
Zen and the Art of Organizational Open Source
Open source software licenses
Open source technologies
Open source technologies
The Internet of Things & Open Data: New forms of business?
Open Source Governance in Highly Regulated Companies
Managing the Software Supply Chain: Policies that Promote Innovation While Op...
What’s Driving Open Source (for MyGOSSCon)
OSS - enterprise adoption strategy and governance
What is "Open Source"
Open Source is eating the world...
The New Development Organization: Embracing “Open” and “Sharing” to Deliver S...
How to Open Source an Internal Project
The Role of In-House & External Counsel in Managing Open Source Software
Open Source In Enterprises Apache2009 Beijing Jack Cai
Ad

More from aakash malhotra (20)

PDF
in-tax-india-budget-analysis-and-industry-impact-2025-noexp.pdf
PDF
in-fs-wealth-management-pov-final-noexp.pdf
PDF
in-ra-cscrf-for-sebi-regulated-entities-deloitte-india-20.09-noexp.pdf
PDF
in-ra-cscrf-for-sebi-regulated-entities-deloitte-india-20.09-noexp.pdf
PDF
in-ad-economics-of-energy-transition-noexp.pdf
PDF
Artificial Intelligence + Digital Public
PDF
Balancing Environmental Sustainability and Market Competition: Strategic Appr...
PDF
ISO 37008 Guidelines for Effective Internal Investigations
PDF
Women @ Work 2024 India market outlook
PDF
India Union Budget 2024 25 Impact on Tax.pdf
PDF
Union Budget 2024 Impact on Economic Growth.pdf
PDF
Union Budget 2024 25 Impact on Education Sector.pdf
PDF
Three New Criminal Laws in India 1 July 2024
PDF
India economic outlook _ Deloitte Insights.pdf
PDF
in-ad-2024-women-at-work-india-report-noexp (2).pdf
PDF
in-ad-2024-women-at-work-india-report-noexp (2).pdf
PDF
Operational Transfer Pricing (OTP) – Delivering future solutions
PDF
New criminal laws— Future of criminal justice system in India
PDF
Evolving Technology Trends Is your bank ready for tomorrow?
PDF
In-deloitte-tech-trends-2023-noexp.pdf11
in-tax-india-budget-analysis-and-industry-impact-2025-noexp.pdf
in-fs-wealth-management-pov-final-noexp.pdf
in-ra-cscrf-for-sebi-regulated-entities-deloitte-india-20.09-noexp.pdf
in-ra-cscrf-for-sebi-regulated-entities-deloitte-india-20.09-noexp.pdf
in-ad-economics-of-energy-transition-noexp.pdf
Artificial Intelligence + Digital Public
Balancing Environmental Sustainability and Market Competition: Strategic Appr...
ISO 37008 Guidelines for Effective Internal Investigations
Women @ Work 2024 India market outlook
India Union Budget 2024 25 Impact on Tax.pdf
Union Budget 2024 Impact on Economic Growth.pdf
Union Budget 2024 25 Impact on Education Sector.pdf
Three New Criminal Laws in India 1 July 2024
India economic outlook _ Deloitte Insights.pdf
in-ad-2024-women-at-work-india-report-noexp (2).pdf
in-ad-2024-women-at-work-india-report-noexp (2).pdf
Operational Transfer Pricing (OTP) – Delivering future solutions
New criminal laws— Future of criminal justice system in India
Evolving Technology Trends Is your bank ready for tomorrow?
In-deloitte-tech-trends-2023-noexp.pdf11

Recently uploaded (20)

PPTX
Type of Sentence & SaaaaaaaaaadddVA.pptx
PDF
EC290C NL EC290CNL Volvo excavator specs.pdf
PDF
Caterpillar CAT 312B L EXCAVATOR (2KW00001-UP) Operation and Maintenance Manu...
PPTX
Zeem: Transition Your Fleet, Seamlessly by Margaret Boelter
PDF
EC300D LR EC300DLR - Volvo Service Repair Manual.pdf
PDF
Caterpillar CAT 311B EXCAVATOR (8GR00001-UP) Operation and Maintenance Manual...
PDF
Todays Technician Automotive Heating & Air Conditioning Classroom Manual and ...
PDF
Physics class 12thstep down transformer project.pdf
PPTX
Materi Kuliah Umum Prof. Hsien Tsai Wu.pptx
PPTX
Lecture 3b C Library xnxjxjxjxkx_ ESP32.pptx
PDF
Renesas R-Car_Cockpit_overview210214-Gen4.pdf
PPT
Your score increases as you pick a category, fill out a long description and ...
PPT
ACCOMPLISHMENT REPOERTS AND FILE OF GRADE 12 2021.ppt
PPTX
Fire Fighting Unit IV industrial safety.pptx
PDF
intrusion control for clean steel 123.pdf
PDF
Volvo EC290C NL EC290CNL engine Manual.pdf
PPTX
Gayatri Cultural Educational Society.pptx
PDF
How Much does a Volvo EC290C NL EC290CNL Weight.pdf
PPT
Kaizen for Beginners and how to implement Kaizen
PPTX
capstoneoooooooooooooooooooooooooooooooooo
Type of Sentence & SaaaaaaaaaadddVA.pptx
EC290C NL EC290CNL Volvo excavator specs.pdf
Caterpillar CAT 312B L EXCAVATOR (2KW00001-UP) Operation and Maintenance Manu...
Zeem: Transition Your Fleet, Seamlessly by Margaret Boelter
EC300D LR EC300DLR - Volvo Service Repair Manual.pdf
Caterpillar CAT 311B EXCAVATOR (8GR00001-UP) Operation and Maintenance Manual...
Todays Technician Automotive Heating & Air Conditioning Classroom Manual and ...
Physics class 12thstep down transformer project.pdf
Materi Kuliah Umum Prof. Hsien Tsai Wu.pptx
Lecture 3b C Library xnxjxjxjxkx_ ESP32.pptx
Renesas R-Car_Cockpit_overview210214-Gen4.pdf
Your score increases as you pick a category, fill out a long description and ...
ACCOMPLISHMENT REPOERTS AND FILE OF GRADE 12 2021.ppt
Fire Fighting Unit IV industrial safety.pptx
intrusion control for clean steel 123.pdf
Volvo EC290C NL EC290CNL engine Manual.pdf
Gayatri Cultural Educational Society.pptx
How Much does a Volvo EC290C NL EC290CNL Weight.pdf
Kaizen for Beginners and how to implement Kaizen
capstoneoooooooooooooooooooooooooooooooooo

Open source software license

  • 2. 1 Setting the context Open source software (OSS) is a software programme with a source code that anyone can check, modify, and update. It is usually developed in a collaborative manner and released under a licence that allows the developer to inspect, change, and distribute the software to anyone for any purpose. The way an organisation can use an open source software programme depends on its licence. Hundreds of di΍erent open source licences are available; each has its own terminologies and restrictions. The two main categories of OSS licences are permissive and copyleft. Open source software licensing | Setting the context Introduction: What is open source software? Examples • Berkeley Software Distribution (BSD) licence • Apache Examples • GNU General Public Licence • Eclipse • Minimal restrictions on licence use • Allowed to use the source code for any purpose • Attribution or acknowledgement for creators / authors is necessary • Can be a part of proprietary software pro- grammes • Allowed to use the source code for any purpose • • Necessary to make an open source code for others to use it freely • No further restrictions can be placed on the code, distributed to the community as received Permissive Copyleft Attribution or acknowledgement for creators / authors is necessary
  • 3. 2 With an increase in the use of OSS in organisations, managing and optimising OSS e΍ectively is important. This can help organisations manage risk, compliance, and security vulnerability associated with open source components consumed internally. Introduction: Current situation overview • About 80GL΍erent types of OSS licences are available; each has its own terminolo- gies and restrictions. • According to Gartner, OSS is used by more than 95% IT organisations world- wide. • Through 2022, the percentage of open source within IT portfolios relative to either homegrown or licensed third-party solutions will increase at a compound annual growth rate (CAGR) of 30%. Source What innovation leaders must know about open-source software: https://www.gartner.com/document/3956651?ref=solrAllrefval=248155840 • After the COVID-19 crisis, most organisations would have remote workers who can download any software with minimal restrictions. • More organisations are shifting to easily accessible OSS to reduce dependency on paid proprietary tools. • However, OSS has its own set of restrictions and security issues that need monitoring. Did you know? Whyis it in focus now? Open source software licensing | Introduction Open source software come with certain requirements, which when not followed can lead to legal, operations and security issues. Open source software licensing requirement/rationale IP infringement risk: licensing obligations by using open source licence for patent provisions Restrictions on use as proprietary licence: It can mandate the release of the source code as an OSS, and provide rights to modify and distribute at no charge. Derivative work for copyleft licences: It needs to be licensed under the same OSS licence Copyright notices: that are required to be included in the developed code are found in the licence text and source code ȴles Security risk: It indicates vulnerabilities associated with source code components. Business need for OSS compliance
  • 4. 3 Solution overview Deloitte leverages a tool that helps to analyse the source code and builds a standardised and repeatable process to enhance Free and open-source software (FOSS) inventory management. Workȵow for the code review Open source software licensing | Solution overview Flavours of OSS Compliance Reviews OSS EULA analysis Assisting organisations in manual review of Open Source and freeware software’s End User License Agreement (EULA). Platform/Application License Implication License review to identify license implications for open source software components that are a part of a platform or application. Source Code Analysis Consistent monitoring of OSS software code during product/application development process for internal consumption or developing commercial applications. 01 03 02 Acquisitions involving OSS platform Organisations shifting from proprietary to OSS software base Software applications/ product development organisations OSS included as a part of the review of entire the SAM asset base Carry out due diligence of the application platforms and identify any potential risks posed by software licences used in building the platform. Provide consulting services on which types of OSS licences can be used in developing in-house and proprietary software. Monitor OSS software code consistently during the complete cycle of product/ application development process. Provide a view of the OSS included in the deployment footprint and risk assessment of the installed OSS. Areas where we help organisations use OSS How can we help
  • 5. 8 Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company OLPLWHGEJXDUDQWHHȊ'77/ȋ
  • 6. LWVQHWZRUNRIPHPEHUȴrms, and their related entities. '77/DQGHDFKRILWVPHPEHUȴrms are legally separate and independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. Please see www. GHORLWWHFRPDERXWIRUDPRUHGHWDLOHGGHVFULSWLRQRI'77/DQGLWVPHPEHUȴrms. This material is prepared by Deloitte Touche Tohmatsu India LLP (DTTILLP). This material (including any information contained in it) is intended to provide general information on a particular subject(s) and is not an exhaustive treatment of such subject(s) or a substitute to obtaining professional services or advice. This material may contain information sourced from publicly available information or other third party sources. DTTILLP does not independently verify any such sources and is not responsible for any loss whatsoever caused due to reliance placed on information sourced from such sources. None of '77Ζ//3'HORLWWH7RXFKH7RKPDWVX/LPLWHGLWVPHPEHUȴrms, or their related entities (collectively, the “Deloitte Network”) is, by means of this material, rendering any kind of LQYHVWPHQWOHJDORURWKHUSURIHVVLRQDODGYLFHRUVHUYLFHVRXVKRXOGVHHNVSHFLȴc advice of the relevant professional(s) for these kind of services. This material or information is not LQWHQGHGWREHUHOLHGXSRQDVWKHVROHEDVLVIRUDQGHFLVLRQZKLFKPDD΍ect you or your EXVLQHVV%HIRUHPDNLQJDQGHFLVLRQRUWDNLQJDQDFWLRQWKDWPLJKWD΍ect your personal ȴnDQFHVRUEXVLQHVVRXVKRXOGFRQVXOWDTXDOLȴed professional adviser. No entity in the Deloitte Network shall be responsible for any loss whatsoever sustained by any person or entity by reason of access to, use of or reliance on, this material. By using this material or any information contained in it, the user accepts this entire notice and terms of use. ©2020 Deloitte Touche Tohmatsu India LLP. Member of Deloitte Touche Tohmatsu Limited Key Contacts Rohit Mahajan President – Risk Advisory rmahajan@deloitte.com Gautam Kapoor Partner, Risk Advisory gkapoor@deloitte.com Tarun Kaura Partner, Risk Advisory tkaura@deloitte.com Gaurav Shukla Partner, Risk Advisory shuklagaurav@deloitte.com Ashish Sharma Partner, Risk Advisory sashish@deloitte.com