7. Case Studies and Success Strategies

This section analyzes cases of obtaining ISO/IEC 18974 certification and presents key strategies for successful implementation. Through case studies across various company sizes, it will help readers understand real-world application methods and establish the optimal strategy for their organization.

7.1 Certification Cases by Various Company Sizes

7.1.1 Global Software Company: openEuler

openEuler is a major open source operating system project in China that obtained ISO/IEC 18974 certification in June 2024. This case shows how ISO/IEC 18974 is implemented in a large-scale open source project.

  • Background and goals of certification: openEuler aimed to build a secure, compliant, and sustainable operating system community.
  • Key challenges during implementation: The main challenge was implementing consistent security practices across a large-scale open source project.
  • Business impact and benefits after certification: openEuler’s development process, software supply chain, risk assessment, management, and developer security capabilities were recognized as meeting the highest level of standard.
  • Analysis of success factors: Community-wide cooperation and commitment, and making security a core value, were the main success factors.

Key lesson: In large-scale open source projects, community participation and cooperation are the key success factors for ISO/IEC 18974 implementation.

7.1.2 Large Enterprise: KT

KT obtained ISO/IEC 18974 certification in October 2024. This case shows how a large enterprise integrates ISO/IEC 18974 into its existing security system.

  • Background and goals of certification: KT pursued certification to strengthen its open source software security management system and increase trust within the supply chain.
  • Key challenges during implementation: It was necessary to build a systematic management system to ensure open source compliance.
  • Business impact and benefits after certification:
    • Recognized for systematic and consistent open source software security management capability.
    • Strengthened its position as a company compliant with open source security and compliance.
    • Increased trust among participants within the supply chain.
  • Analysis of success factors:
    • Building a systematic license and security check system through an open source management portal
    • Rapid resolution of legal and security issues through the formation of an in-house “OSRB” (OpenSource Review Board)
    • Establishing a culture of proper open source use through continuous employee education

Key lesson: Large enterprises can achieve efficient open source management by integrating ISO/IEC 18974 with their existing security system and leveraging an in-house expert group.

7.1.3 Financial Company: KakaoBank

In November 2023, KakaoBank became the first domestic financial company to obtain ISO/IEC 18974, the international standard for open source security assurance. This case shows how ISO/IEC 18974 is implemented at a financial company that requires a high level of security.

  • Background and goals of certification: The need to build a systematic management system emerged as the company actively used open source to provide world-class financial services quickly and efficiently.
  • Key challenges during implementation: The company had to meet more than 30 security certification requirements, including establishing open source policy and processes, building a compliance system, securing expertise in the responsible organization and personnel, and conducting in-house employee education.
  • Business impact and benefits after certification: The company’s open source use and security management capability were internationally recognized, and it was recognized as a company with systematic and consistent open source security management capability. It gave customers confidence that the company could provide safer financial services.
  • Analysis of success factors: The company formed an open source expert council (OSRB) to jointly discuss open source-related issues and built a system to manage licenses and security vulnerabilities in advance.

Key lesson: Financial companies must build a systematic open source management system and secure expertise through an expert council to meet high-level security requirements.

7.1.4 SME: (Hypothetical case) IT Solution Provider “TechSolution”

TechSolution is a small and medium-sized IT solution provider developing cloud-based services. TechSolution pursued ISO/IEC 18974 certification to safely protect customer data and secure a competitive advantage.

  • Background and goals of certification: TechSolution set a goal of obtaining ISO/IEC 18974 certification to strengthen the security of its cloud-based services, increase customer trust, and create new business opportunities.
  • Key challenges during implementation: The main challenge was meeting ISO/IEC 18974 requirements with a limited budget and personnel.
  • Business impact and benefits after certification:
    • Improved the security level of cloud-based services and was able to safely protect customer data.
    • Improved customer trust, strengthening relationships with existing customers and succeeding in attracting new customers.
    • Improved company image and secured a competitive advantage by promoting the ISO/IEC 18974 certification.
  • Analysis of success factors:
    • Strengthened cooperation between the existing development team and security team, and clarified responsibilities and roles by designating an open source security lead.
    • Reduced initial investment costs and increased management efficiency by using cloud-based SBOM generation and vulnerability scanning tools.
    • Systematically implemented ISO/IEC 18974 requirements with the help of an outside consulting firm and gained know-how for obtaining certification.

Key lesson: SMEs can efficiently use limited resources and successfully obtain ISO/IEC 18974 certification with the help of outside experts.

7.1.5 Startup: (Hypothetical case) AI-based Service Development Startup “AIBrain”

AIBrain is an early-stage startup developing AI-based services. AIBrain emphasizes innovative technology and rapid development speed as its strengths, but also has concerns about security issues.

  • Background and goals of certification: AIBrain expected ISO/IEC 18974 certification to strengthen security throughout the development process and have a positive impact on attracting investment and forming partnerships.
  • Key challenges during implementation: As an early-stage startup, it lacked security-specialized personnel, and it was difficult to meet ISO/IEC 18974 requirements without slowing down development speed.
  • Business impact and benefits after certification:
    • A security-conscious development culture took root, improving the security of the product.
    • Demonstrated security capability to investors and partners, succeeding in attracting investment and forming partnerships.
    • Improved company image and secured a competitive advantage by promoting the ISO/IEC 18974 certification.
  • Analysis of success factors:
    • Integrated security checks into the development process and actively used automated security tools to maintain development speed while strengthening security.
    • Reduced security infrastructure build costs by using a cloud-based development environment.
    • Effectively implemented ISO/IEC 18974 requirements using materials and guidelines provided by the OpenChain Project.

Key lesson: Startups can implement ISO/IEC 18974 cost-effectively by integrating security into the development process and using a cloud-based environment.

Table 7.1: Summary of ISO/IEC 18974 Certification Cases by Company Size

Company SizeCompanyKey CharacteristicsKey Success Factors
Global software companyopenEulerLarge-scale open source projectCommunity cooperation, security-centered culture
Large enterpriseKTIntegration with existing security systemUse of in-house experts, systematic management system
Financial companyKakaoBankHigh security requirementsUse of expert council, systematic management system
SME (hypothetical)TechSolutionLimited resourcesCloud-based tools, use of outside experts
Startup (hypothetical)AIBrainRapid development speedSecurity integration into the development process, cloud use

This table summarizes ISO/IEC 18974 certification cases by various company sizes. Organizations can refer to cases that match their own size and characteristics to establish an implementation strategy.

7.2 Key Strategies for Successful Implementation

The key strategies for successfully leading ISO/IEC 18974 implementation are as follows. These strategies have been validated through the case studies examined above and can be applied to an organization’s situation to maximize their effect.

7.2.1 Securing Active Support from Executive Management

  1. Presenting the ROI (Return on Investment) of security investment:
    • Quantitatively presents the positive impact of open source security management on business continuity, customer trust, and regulatory compliance.
    • Example: Uses specific figures such as “5% reduction in customer churn after obtaining ISO/IEC 18974 certification” or “30% reduction in the number of open source-related security incidents.”
  2. Regular status reporting and feedback:
    • Reports the status of open source security to executive management monthly or quarterly and receives feedback.
    • The report includes the status of the Software Bill of Materials (SBOM), the trend of vulnerability occurrence, the status of license compliance, and the results of improvement activities.
  3. Building an open source security culture:
    • Executive management leads by emphasizing the importance of open source security and raising organization-wide awareness.
    • Encourages participation in open source security-related education programs and rewards best practices.

Execution steps:

  1. Explains the importance of open source security to executive management and emphasizes the need to adopt ISO/IEC 18974.
  2. Obtains approval to establish an OSPO (Open Source Program Office) or designate an open source security lead.
  3. Secures a budget for open source security and supports securing the necessary tools and personnel.

7.2.2 Adopting a Phased Approach

  1. Gradual implementation based on priority:
    • Starts with high-risk areas (e.g., externally exposed services, core business logic) and gradually expands the scope of application.
    • Manages low-risk areas efficiently using automation tools.
  2. Maintaining momentum through quick wins:
    • Sets goals that can be achieved in the short term and shares success cases to encourage participation within the organization.
    • Example: “Build an SBOM generation and management system within 3 months,” “Complete vulnerability scanning for key projects within 6 months,” etc.
  3. Risk management and control:
    • Identifies new threats through regular risk assessments and prepares appropriate response measures.
    • Systematically manages open source-related risks using a risk management register.

Execution steps:

  1. Selects open source components related to core business logic as priority management targets.
  2. Introduces SBOM generation and vulnerability scanning tools to quickly generate initial results.
  3. Builds a regular security check and audit process to drive continuous improvement.

7.2.3 Actively Using Automation Tools

  1. Integrating the CI/CD pipeline:
    • Integrates SBOM generation, license checking, and vulnerability scanning into the Continuous Integration/Continuous Delivery (CI/CD) pipeline to perform automated security checks throughout the development process.
    • This allows developers to automatically perform security checks whenever they commit code and quickly resolve issues.
  2. Building a real-time monitoring and alert system:
    • Builds a system that provides immediate notification when a new vulnerability is found, to support a rapid response.
    • Configures notifications to be received through various channels such as Slack, email, and SMS.
  3. Minimizing repetitive tasks:
    • Automates repetitive tasks such as license checking, SBOM generation, and vulnerability scanning to allow human resources to focus on more valuable work.
    • Repetitive tasks can be minimized through script writing, API use, and automation tool configuration.

Table 7.2: Key Strategies for Successful ISO/IEC 18974 Implementation

StrategyDescriptionExecution Steps
Securing executive supportEmphasizing the need for security investment, raising organization-wide awarenessPresenting ROI, regular status reporting
Phased approachPriority-based gradual implementationStarting with high-risk areas, generating quick wins
Using automation toolsIntegrating the CI/CD pipeline, real-time monitoringMinimizing repetitive tasks, building a rapid response system

Active support from executive management, a phased approach, and the use of automation tools are essential for successful implementation.

Last modified August 9, 2026: 전체 콘텐츠 영어판 추가 (608dd718)