This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

1. Organization

    First, an enterprise must establish an organization responsible for open source management.

    The following should be considered when forming the organization:

    • Roles and responsibilities of the organization
    • Competencies required for each role
    • The organization/person responsible for each role

    1. Defining the Roles and Responsibilities of the Organization

    The ISO standards commonly require a document that describes the roles and responsibilities of the various participants in the program, as follows.

    Open Source Program Manager

    To build an open source management system, an enterprise first needs someone responsible for leading and carrying it out. This person is called by titles such as Open Source Program Manager or Open Source Compliance Officer; this guide uses the term Open Source Program Manager.

    The Open Source Program Manager is in charge of the enterprise’s Open Source Program Office (OSPO). Open Source Program Office refers to the organization responsible for an enterprise’s open source management, and is also referred to by the term Open Source Secretariat.

    A person with the following competencies can be considered well-suited for the role of Open Source Program Manager.

    • Understanding of the open source ecosystem and development experience
    • Broad understanding of the enterprise’s business
    • Passion and communication skills to spread effective open source use among employees

    It is best for the Open Source Program Manager to be guaranteed the ability to perform the role full-time whenever possible.

    Global ICT enterprises are making efforts to hire capable Open Source Program Managers of this kind. Various job postings can be found at the following site: https://github.com/todogroup/job-descriptions

    Documenting Roles and Responsibilities

    An enterprise must define each role needed for the OSPO and determine what responsibilities to assign to it.

    In a small enterprise, it is possible for the Open Source Program Manager alone to perform all the roles. Depending on the size of the enterprise, an IT staff member to operate open source tools may also be needed, and a legal role may be required to provide specialized legal counsel.

    In general, the following roles are needed to build an enterprise’s open source management system.

    • Legal
    • IT
    • Security
    • Developer Relations

    Individuals and teams involved in ensuring open source compliance : https://www.linuxfoundation.org/wp-content/uploads/OpenSourceComplianceHandbook_2018_2ndEdition_DigitalEdition.pdf

    To this end, the roles and responsibilities that make up the OSPO must be documented as follows.

    NoRoleResponsibility
    1Open Source Program ManagerHolds overall responsibility for the company’s open source program.
    2LegalInterprets open source licenses and obligations. Provides advice to mitigate legal risks that may arise from open source use, including fulfilling these obligations in practice.
    3ITOperates and automates open source scanning tools, building a system so that open source analysis is performed smoothly for all software to be distributed.
    4SecurityOperates open source vulnerability scanning tools, builds a system so that vulnerability analysis is performed for all software to be distributed, and takes action to ensure that identified vulnerabilities are remediated according to defined criteria.
    5Developer RelationsSupports in-house developers in actively using open source and participating in internal and external communities to adopt advanced development practices.
    6Business UnitSoftware development/distribution organizations comply with open source policy and process to ensure proper open source use.

    2. Defining Required Competencies

    Once each role and its responsibilities have been defined, the essential competencies that the person performing that role must have need to be identified.

    The ISO standards commonly require a document that describes the competencies needed for each role, as follows.

    This is because it is necessary to assess whether the person assigned to each role has the competencies to perform it, and to provide training if needed.

    To this end, an enterprise must document the competencies needed for each role, as follows.

    NoRoleRequired Competencies
    1Open Source Program Manager1. Understanding of the software development process
    2. Understanding of intellectual property related to open source licenses, including copyright and patents
    3. Expert knowledge of open source compliance
    4. Open source development experience
    5. Communication skills
    6. Basic knowledge of open source security assurance
    2Legal1. Basic knowledge of the open source ecosystem
    2. Expert knowledge of software copyright
    3. Expert knowledge of open source licenses
    4. Ability to assess open-source-related legal risk
    3IT1. Basic knowledge of the open source compliance process
    2. Understanding of open source scanning tools
    3. Expert knowledge of IT infrastructure
    4. Understanding of automation and CI/CD pipelines
    4Security1. Broad understanding of DevSecOps
    2. Understanding of open source vulnerability scanning tools
    3. Expert knowledge of open source vulnerabilities
    4. Communication skills
    5. Risk assessment and management ability
    5Developer Relations1. Understanding of the software development process
    2. Basic knowledge of open source compliance
    3. Understanding of open source policy
    4. Ability to design education and training
    5. Experience participating in open source communities
    6Business Unit1. Understanding of the software development process
    2. Basic knowledge of open source compliance
    3. Understanding of open source policy
    4. Basic knowledge of open source licenses
    5. Understanding of the business impact of open source use

    3. Assigning Owners

    The Open Source Program Manager consults with the relevant departments to assign an owner for each role and document this. To do so, the goals and direction for building the open source compliance system must be reported to the top decision-maker, such as the CEO, in order to obtain the necessary support.

    The organization and owners related to open source do not necessarily need to work on open source full-time. It is also possible to form a virtual organization in the form of an OSRB (Open Source Review Board) to carry out the necessary roles.

    The ISO standards commonly require a document naming the persons, groups, or functions responsible for each role in the program, as follows.

    To this end, an enterprise must document the names of the persons, groups, or functions responsible for each role in the program, as follows.

    NoRoleResponsible OrganizationOwner
    1Open Source Program ManagerCTOOOO
    2LegalLegal TeamOOO
    3ITIT Infrastructure TeamOOO
    4SecuritySecurity TeamOOO
    5Developer RelationsDROOO
    6Business UnitDevelopment TeamAll members

    A documented sample of roles, responsibilities, required competencies, and owner assignments can be found on the next page. [Appendix 1] Open Source Policy (Sample) - Appendix 1. Assigned Owners

    SK telecom has formed an OSRB to create open source policies and processes within the company, and collaborates to prepare response plans when issues arise.

    https://sktelecom.github.io/about/osrb/

    4. Summary

    A documented sample of roles, responsibilities, required competencies, and owner assignments can be found in the open source policy template document: Appendix 1. Assigned Owners

    An enterprise can refer to this to organize its open source management structure to fit its own situation.

    By designating and documenting the OSPO organization in this way, an enterprise satisfies the requirements marked in red below among the ISO standard specifications.

    In fact, more important than the documentation itself is appointing an owner who will faithfully carry out the actual work, and supporting that owner in acquiring the necessary competencies.

    Taking part in systematic training, such as the Open Source License Professional Training offered by the Korea Copyright Commission or the NIPA Open Software Management Academy, is also very helpful.

    The roles of the Open Source Program Manager and the Security role are becoming increasingly important. The Open Source Program Manager must also have a basic understanding of open source security assurance, and the Security role needs an understanding of new security requirements such as SBOM (Software Bill of Materials) management.

    In addition, continuous learning and staying current with the latest trends are becoming important across every role. The open source ecosystem and related technologies and regulations are changing rapidly, so each owner must continuously update their knowledge in their own field. Participating in international communities such as OpenChain or the TODO Group, or attending domestic open source conferences, is also a good approach.