3.4 Adherence to the specification requirements
For an organization to claim that it operates an open source security assurance program, that program must comply with all the requirements of the ISO/IEC 18974 standard. This chapter provides guidance on how an organization can confirm and maintain compliance with the standard.
4.4.1 Completeness
To declare that a program complies with the ISO/IEC 18974 standard, the organization must formally confirm that the program satisfies all the requirements set out in the standard. Satisfying only some of the requirements is not sufficient.
4.4.1.1 Evidence of Requirement Satisfaction
ISO/IEC 18974
- 4.4.1.1: Documented evidence affirming the program specified in 4.1.4 satisfies all the requirements of this document.
- 4.4.1.1: Documented evidence confirming that the program specified in 4.1.4 satisfies all requirements of this document.
Self-Certification Checklist
- We have documentation confirming that the Program meets all the requirements of this specification.
- We have documented confirmation that the Program satisfies all requirements of this standard.
The organization must present documented evidence demonstrating that the program satisfies all the requirements of the ISO/IEC 18974 standard. This evidence must cover every aspect of the program’s operation and must be objective and reliable.
Implementation Methods and Considerations
- Requirement mapping:
- Map each requirement of the ISO/IEC 18974 standard to a specific policy, procedure, or activity of the organization’s program.
- Document the mapping results and make them easily accessible to program participants.
- Collecting compliance evidence:
- Collect evidence demonstrating compliance with each requirement.
- Evidence can take various forms, such as documents, records, logs, and test results.
- Evidence must be objective and reliable, and must reflect up-to-date information.
- Internal audit:
- An independent audit team assesses the actual state of the program’s operation and confirms compliance with the ISO/IEC 18974 standard.
- Audit results are documented and reported to management.
- Necessary corrective actions are taken based on the audit results.
- Management review:
- Management reviews the operational status of the program and the audit results, and gives final confirmation of compliance with the ISO/IEC 18974 standard.
- Management provides guidance for the program’s continuous improvement.
Example Evidence Materials
- Policy documents:
- Open source policy, security policy, license management policy, etc.
- Procedure documents:
- Vulnerability management procedure, incident response procedure, SBOM management procedure, etc.
- Records:
- Vulnerability scan results, code review results, security test results, etc.
- Logs:
- System access logs, change logs, audit logs, etc.
- Test results:
- Functional test results, security test results, performance test results, etc.
Implementation Considerations
- Evidence must be objective and reliable.
- Evidence must reflect up-to-date information.
- Evidence must be managed systematically, with access rights appropriately controlled.
Documentation Approach
Include the following content within the open source policy. (Reference: Open Source Policy Template)
11.1 ISO Standard Compliance Declaration
- Compliance declaration:
- Through this policy, the company declares that it satisfies all the requirements of ISO/IEC 5230 (Open Source License Compliance) and ISO/IEC 18974 (Open Source Security Assurance).
- The declaration date and validity period (18 months) are stated clearly.
- The compliance declaration may be made through Self Certification under the Linux Foundation’s OpenChain project.
- Documenting evidence:
- The Open Source Program Manager (OSPM) documents and maintains evidence of satisfaction for each requirement.
- Evidence documents include policy documents, process descriptions, training records, compliance deliverables, and security vulnerability management records.
- All evidence documents are kept in a central repository and retained for at least 3 years.
- This document must be prepared within 18 months of obtaining conformance validation, and updated at least once a year.
- Periodic review and renewal:
- The OSRB reviews requirement satisfaction at least once a year and improves policies and processes as needed.
- Review results and improvements are documented and retained.
- Preparing for external verification:
- The organization prepares to provide evidence documents to external auditors or certification bodies upon request.
Through this approach, the organization can demonstrate that the program satisfies all the requirements of the ISO/IEC 18974 standard and build external trust.
4.4.2 Duration
ISO/IEC 18974
- 4.4.2.1: A document affirming the program meets all the requirements of this specification, within the past 18 months of obtaining conformance validation.
- 4.4.2.1: A document confirming that, within the past 18 months since the program obtained conformance validation, it satisfies all requirements of this specification.
Self-Certification Checklist
- We have documentation confirming that Program conformance was reviewed within the last 18 months.
- We have a record confirming that the Program’s compliance was reviewed within the past 18 months.
Compliance with the ISO/IEC 18974 standard is not a one-time event but an ongoing process. Therefore, even after obtaining compliance with the standard, an organization must make continuous efforts to maintain that status. This section explains the requirements related to the compliance period.
4.4.2.1 Documentation Confirming the Compliance Period
A program that complies with the ISO/IEC 18974 standard is valid for 18 months from the date it received compliance validation. Therefore, within 18 months after the program receives compliance validation, the organization must present a document confirming that the program still satisfies all the requirements of the standard. This is important for demonstrating that the program has not drifted from the standard over time and is being continuously improved.
Implementation Methods and Considerations
- Recording the compliance validation date:
- Accurately record the date on which the program received ISO/IEC 18974 compliance validation.
- Keep the compliance validation certificate or related documents as evidence.
- Establishing a compliance renewal plan:
- Before the compliance period expires, establish a plan to revalidate compliance status and renew it if necessary.
- The plan may include activities such as a self-assessment of compliance status, internal audits, and external reviews.
- Periodic review of compliance status:
- During the compliance period, periodically review whether the program still satisfies all the requirements of the ISO/IEC 18974 standard.
- Perform the review at least once every 6 months, and document the review results.
- If the review finds a part that does not comply with the standard, take corrective action immediately.
- Reviewing all requirements again before renewal:
- Before the compliance period expires, conduct a full review of whether the program once again satisfies all the requirements of the ISO/IEC 18974 standard.
- This review may be performed by an independent audit team or external experts.
- Document the review results and report them to management.
Example Evidence Materials
- Compliance validation certificate: An official document certifying that ISO/IEC 18974 compliance validation was obtained.
- Compliance renewal plan: A document describing the concrete plan for maintaining and renewing compliance status.
- Periodic review report: A report recording the results of periodically reviewing compliance status.
- Full requirement re-review report: A report recording the results of re-reviewing, before compliance renewal, whether the program satisfies all requirements of the standard.
Implementation Considerations
- Maintaining compliance status requires continuous effort and investment of resources.
- The organization must monitor changes to the ISO/IEC 18974 standard and make the adjustments the program needs.
- The importance of standard compliance must be emphasized to program participants, and responsibility must be assigned to them.
Documentation Approach
Include the following content within the open source policy. (Reference: Open Source Policy Template)
11.2 Maintaining Compliance Status
- Periodic review:
- The OSRB performs an internal review of all requirements of ISO/IEC 5230 and ISO/IEC 18974 at least once a year.
- Review results are documented and retained, and an improvement plan is established for any items not satisfied.
- Periodic internal audit:
- The internal audit assesses whether program participants are performing their roles, the conformity of compliance deliverables, and the effectiveness of security assurance activities.
- Areas for improvement are identified based on audit results, and necessary actions are taken.
- Providing education and training:
- Regular education and training are provided to continuously improve the competency and awareness of program participants.
- The training content reflects the latest open source trends and the organization’s requirements, and emphasizes compliance with the ISO standards.
- Preparing to respond to external inquiries:
- A system is maintained to respond quickly and effectively when there are external inquiries related to ISO standard compliance.
- The Open Source Program Manager handles inquiry responses, cooperating with the legal team as needed.
- Periodic policy renewal:
- The policy is reviewed at least once a year and is updated to reflect the latest open source trends and the organization’s requirements.
- The updated policy is shared with all program participants.
Through this approach, the organization can continuously maintain compliance with the ISO/IEC 18974 standard and provide customers with safe and trustworthy open source software.