# 7. Training/Assessment

LLMS index: [llms.txt](/llms.txt)

---

## Training

No matter how excellent a policy and process a company has built, it will be useless if none of the company's members pay attention to it. For the open source policy and open source compliance process to work effectively in a company, training its members is important.

A company must provide practical means, such as training and an internal wiki, so that all Program participants are aware that the organization has an open source policy and can carry out the necessary activities. Here, Program participants refers to all employees involved in the company's software development, distribution, and contribution, including software developers, deployment engineers, and quality engineers.

Many companies publish their open source policy document on an internal wiki site so that any employee can check what is needed. In addition, they make training on the open source policy mandatory during new employee orientation and provide periodic training to Program participants annually or once every two years, so that all Program participants are aware of the existence of the open source policy. That is, a company should include such methods in its open source policy document, written as in the example below.

```
1. Training and Assessment

All Software Distribution participants must complete the mandatory open source
training provided on the [Learning Portal] every year.
This ensures familiarity with the open source policy, related training policy, and
how to look it up. Training records are retained on the [Learning Portal].

```

Building such a training environment allows a company to prepare the following evidence materials required by ISO/IEC 5230.

<div class="alert alert-success" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 5230</div>



* <b>3.1.1.2 A documented procedure that makes Program participants aware of the existence of the open source policy (e.g., training, internal wiki, or other practical communication methods)</b>

</div>


| Self Certification 1.b  | Do you have a documented procedure that communicates the existence of the open source policy to all Software Staff? (e.g., via training, internal wiki, or other practical communication method) |
|---|:---|
|  | Do you have a documented procedure that communicates the existence of the open source policy to all Software Staff? (e.g., via training, internal wiki, or other practical communication method) |

In addition, a company must make Program participants aware of the company's open source policy, open source-related objectives, how participants can contribute to an effective open source program, and the implications of failing to comply with Program requirements. To do this, a company provides training and conducts an assessment to confirm that Program participants have understood correctly. The assessment results are documented and retained.

A company can include content such as the example below in its open source policy for this purpose.

```
1. Purpose
  (1) Purpose of the policy
    This policy provides the following principles so that the entire organization
    involved in the company's software development, service, and distribution can
    make proper use of open source.

    1) Principles for performing compliance in consideration of open source licenses
    2) Principles for contributing to external open source projects
    3) Principles for releasing internal projects as open source

   These principles provide a way for all members of the company to understand the
   value of open source, use open source correctly, and contribute to the open
   source community.

  (2) Impact of non-compliance
   Failure to comply with this policy may result in the following situations.
   * Receiving demands from external parties for open source license compliance.
   * Being forced to disclose company-developed source code against its wishes.
   * Facing legal action from open source copyright holders.
   * Being fined or receiving a product sales suspension order for copyright
     infringement and breach of contract.
   * Loss of company reputation.
   * Breach of contract with suppliers, resulting in claims for damages.
  For these reasons, the company takes violations of the open source policy
  seriously, and members or organizations that violate it may be subject to
  disciplinary action.

  (3) How members can contribute
    All members can contribute to the effectiveness of the policy and the
    improvement of the company's compliance level by understanding the basis
    and content of this policy and faithfully carrying out the necessary
    activities.
```

Assessment is explained in more detail below.


Including such training content in the policy allows a company to prepare the following evidence materials required by ISO/IEC 5230.

<div class="alert alert-success" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 5230</div>



* <b>3.1.3.1 Documented evidence indicating that the awareness of Program participants was assessed regarding: the objectives of the Program, how participants contribute within the Program, and the implications of failing to comply with the Program</b>

</div>


| Self Certification 1.f  | Do you have evidence documenting the awareness of your personnel of the following topics? <br> i. The open source policy and where to find it <br> ii. The relevant open source objectives <br>iii. The contributions expected to ensure the effectiveness of the Program <br>iv. The implications of failing to follow the Program requirements |
|---|:---|
|  | Do you have evidence documenting the awareness of your personnel of the following topics? <br>i - The open source policy and where to find it;<br>ii - The relevant open source objectives;<br>iii - The contributions expected to ensure the effectiveness of the Program;<br>iv - The implications of failing to follow the Program requirements. |

Open source training also includes content about the open source contribution policy. Even if an open source contribution policy has been created, if internal members are unaware of its existence, there is a risk that indiscriminate contribution activities could cause harm to individuals and the company. Open source training is provided so that all internal developers are aware of the existence of the open source contribution policy.

Providing training on the contribution policy in this way allows a company to prepare the following evidence materials required by ISO/IEC 5230.

<div class="alert alert-success" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 5230</div>



* <b>3.5.1.3 A documented procedure that makes all Program participants aware of the existence of the Open Source contribution policy (e.g., training, internal wiki, or other practical communication methods)</b>

</div>


| Self Certification 5.c  | Do you have a documented procedure that makes all Software Staff aware of the existence of the Open Source contribution policy? |
|---|:---|
|  | Do you have a documented procedure that makes all Software Staff aware of the existence of the Open Source contribution policy? |

Creating new training materials from scratch can also be a difficult task for someone just starting this role. To help with this difficulty, NCSOFT published its internal open source training materials, including the lecture slides (PPT) and lecture script, on GitHub so anyone can use them.

<figure class="card rounded p-2 td-post-card mb-4 mt-4" style="max-width: 910px">
<img class="card-img-top" src="/docs/governance_iso5230/7-training/ncsofttraining_hu_99d8b656159f9e27.png" width="900" height="483">
<figcaption class="card-body px-0 pt-2 pb-0">
<p class="card-text">


<center><i>https://github.com/ncsoft/oss-basic-training</i></center>

</p>
</figcaption>
</figure>


In addition, Kakao, a leading domestic platform company, has also released its open source training materials for internal developers so that anyone can view them.


<figure class="card rounded p-2 td-post-card mb-4 mt-4" style="max-width: 910px">
<img class="card-img-top" src="/docs/governance_iso5230/7-training/kakaotraining_hu_2f60a795ba2987ca.png" width="900" height="507">
<figcaption class="card-body px-0 pt-2 pb-0">
<p class="card-text">


<center><i>http://t1.kakaocdn.net/olive/assets/opensource_guide_kakao.pdf</i></center>

</p>
</figcaption>
</figure>


If training materials have not yet been created, using the open source training materials of these companies with excellent open source management practices is also a good option.

## Assessment

Once a company has assigned personnel to each role, it must confirm that the assigned personnel are qualified to perform the role based on education, training, and experience. Training must also be provided to Program participants with insufficient competency so they can acquire sufficient competency. The company must also assess whether each participant has the necessary competency and retain the results.

1. The company provides training so that each participant can acquire the required competency.
2. An assessment is conducted based on the training content.
3. The assessment results are retained by the company's training system or HR department.

When there are several hundred or more Program participants, making training difficult to provide, using the company's online training and assessment system is also a good option.

Such content can be included in a company's open source policy as follows.

```
4. Roles, Responsibilities, and Competencies
To ensure the effectiveness of this policy, the roles, responsibilities, and the
competencies required of the person in charge of each role are defined as follows.
The organization/person in charge of each role and the required competency level
are defined in "Appendix 1. Personnel Roster".

5. Training and Assessment
All members responsible for each role defined in Chapter 4 must complete the
open source training provided on the [Learning Portal].
Training records and assessment results are retained on the [Learning Portal]
for at least three years.

```

Having such a training and assessment system in place allows a company to prepare the following evidence materials required by ISO/IEC 5230.

<div class="alert alert-success" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 5230</div>



* <b>3.1.2.3 Documented evidence of assessed competence for each Program participant</b>

</div>


| Self Certification 1.e  | Have you documented evidence of assessed competence for each Program participant? |
|---|:---|
|  | Have you documented evidence of assessed competence for each Program participant? |

## Open Source License Guide

To properly comply with open source licenses, one must accurately know the requirements of each open source license. However, since it is difficult for individual software developers to grasp all of this, it is advisable for the Open Source Program Manager to organize the requirements and precautions for common use cases of frequently used open source licenses and share them internally within the company.

The open source license guide should include the requirements for common open source license use cases, enabling the development department to correctly comply with license obligations while using open source.

For general guidance on open source licenses and summarized license obligation materials, the [License Guide](https://www.olis.or.kr/license/licenseGuide.do) provided by the Korea Copyright Commission can be referenced.

The [License Obligations](https://sktelecom.github.io/guide/use/obligation/) document in SK telecom's open source guide is also a good resource.

![](sktlicenseguide.png)
[https://sktelecom.github.io/guide/use/obligation/gpl-2.0/](https://sktelecom.github.io/guide/use/obligation/gpl-2.0/)


Providing such an open source license guide allows a company to prepare the following evidence materials required by ISO/IEC 5230.

<div class="alert alert-success" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 5230</div>



* <b>3.3.2.1 A documented procedure for handling common open source license use cases for open source components within Supplied Software</b>

</div>


| Self Certification 3.c  | Have you implemented a procedure that handles at least the following common open source license use cases for the open source components within each Supplied Software release? <br>i - distributed in binary form;<br>ii - distributed in source form;<br>iii - integrated with other open source such that it may trigger copyleft obligations;<br>iv - contains modified open source;<br>v - contains open source or other software under an incompatible license interacting with other components within the Supplied Software |
|---|:---|
|  | Have you implemented a procedure that handles at least the following common open source license use cases for the open source components of each supplied Supplied Software release?<br>i - distributed in binary form;<br>ii - distributed in source form;<br>iii - integrated with other open source such that it may trigger copyleft obligations;<br>iv - contains modified open source;<br>v - contains open source or other software under an incompatible license interacting with other components within the Supplied Software;<br>vi - contains open source with attribution requirements. |


Building the environment for training, assessment, and guide provision up to this point results in compliance with the ISO/IEC 5230 requirements as shown below.

![](trainingno.png)
