This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

3. Organization (Personnel)

    Defining Roles and Responsibilities

    To build a company’s open source governance system, a responsible person who takes charge of and carries out this task is needed first. This person may be called an Open Source Program Manager, Open Source Compliance Officer, or similar title, and is responsible for the company’s overall open source compliance.

    A person with the following competencies is well suited for this role.

    • Understanding of the open source ecosystem and development experience
    • Broad understanding of the company’s business
    • Passion and communication skills to spread effective open source use among the company’s members

    It is best to ensure that the Open Source Program Manager can perform this role full-time whenever possible.

    Global ICT companies are working to hire excellent Open Source Program Managers like this, and various job postings can be found at the following site: https://github.com/todogroup/job-descriptions

    To build an open source governance system, a company must define the necessity of each role and determine what responsibilities should be assigned. In the case of a small company, it is possible for the Open Source Program Manager alone to perform all roles. Depending on the size of the company, an infrastructure officer to operate open source tools may also be needed, and a legal officer role to provide professional legal advice may be required.

    In general, the following roles are needed to build a company’s open source governance system.

    • Legal officer
    • Infrastructure officer
    • Development culture officer
    • Security officer

    Individuals and teams involved in ensuring open source compliance : https://www.linuxfoundation.org/wp-content/uploads/OpenSourceComplianceHandbook_2018_2ndEdition_DigitalEdition.pdf

    By doing this, a company can prepare the following evidence materials required by ISO/IEC 5230.

    Self Certification 1.cHave you identified the roles and the corresponding responsibilities that affect the performance and effectiveness of the Program?
    Have you identified the roles and the corresponding responsibilities that affect the performance and effectiveness of the Program?

    Defining Required Competencies

    Once each role and its responsibilities have been defined, the required competencies that personnel performing that role must have need to be identified. This is because the person in charge of each role must be assessed for whether they have the competency to perform that role, and training must be provided if needed.

    By doing this, a company can prepare the following evidence materials required by ISO/IEC 5230.

    Self Certification 1.dHave you identified and documented the competencies required for each role?
    Have you identified and documented the competencies required for each role?

    Assigning Personnel

    The Open Source Program Manager consults with the relevant departments to assign personnel for each role and documents this. Of course, to do this, the goals and direction for building the open source compliance system must be reported to top decision-makers such as the CEO in order to receive the necessary support.

    The open source-related organization and personnel do not necessarily need to participate in open source work full-time. It is fine to form a virtual organization in the form of an OSRB (Open Source Review Board) to perform the necessary roles.

    SK telecom has formed an OSRB to create open source policies and processes within the company and to prepare response measures when issues arise.

    https://sktelecom.github.io/about/osrb/

    By doing this, a company can prepare the following evidence materials required by ISO/IEC 5230.

    Self Certification 2.dHave you documented the persons, group or function supporting the Program role(s) identified?
    Have you documented the persons, group or function supporting the Program role(s) identified?

    The table below is a sample personnel roster specifying the roles of the open source-related organization and personnel, along with the required competencies. A company can refer to this to organize and document its open source organization.

    This content can also be found on the following page. : https://haksungjang.github.io/docs/openchain/#appendix-1-담당자-현황

    Organizing in this way satisfies the following three requirements of ISO/IEC 5230.