# 7. Case Studies and Success Strategies

LLMS index: [llms.txt](/llms.txt)

---

This section analyzes cases of obtaining ISO/IEC 18974 certification and presents key strategies for successful implementation. Through case studies across various company sizes, it will help readers understand real-world application methods and establish the optimal strategy for their organization.

## 7.1 Certification Cases by Various Company Sizes

### 7.1.1 Global Software Company: openEuler

openEuler is a major open source operating system project in China that obtained ISO/IEC 18974 certification in June 2024. This case shows how ISO/IEC 18974 is implemented in a large-scale open source project.

- **Background and goals of certification**: openEuler aimed to build a secure, compliant, and sustainable operating system community.
- **Key challenges during implementation**: The main challenge was implementing consistent security practices across a large-scale open source project.
- **Business impact and benefits after certification**: openEuler's development process, software supply chain, risk assessment, management, and developer security capabilities were recognized as meeting the highest level of standard.
- **Analysis of success factors**: Community-wide cooperation and commitment, and making security a core value, were the main success factors.

**Key lesson**: In large-scale open source projects, community participation and cooperation are the key success factors for ISO/IEC 18974 implementation.

### 7.1.2 Large Enterprise: KT

KT obtained ISO/IEC 18974 certification in October 2024. This case shows how a large enterprise integrates ISO/IEC 18974 into its existing security system.

- **Background and goals of certification**: KT pursued certification to strengthen its open source software security management system and increase trust within the supply chain.
- **Key challenges during implementation**: It was necessary to build a systematic management system to ensure open source compliance.
- **Business impact and benefits after certification**:
    - Recognized for systematic and consistent open source software security management capability.
    - Strengthened its position as a company compliant with open source security and compliance.
    - Increased trust among participants within the supply chain.
- **Analysis of success factors**:
    - Building a systematic license and security check system through an open source management portal
    - Rapid resolution of legal and security issues through the formation of an in-house "OSRB" (OpenSource Review Board)
    - Establishing a culture of proper open source use through continuous employee education

**Key lesson**: Large enterprises can achieve efficient open source management by integrating ISO/IEC 18974 with their existing security system and leveraging an in-house expert group.

### 7.1.3 Financial Company: KakaoBank

In November 2023, KakaoBank became the first domestic financial company to obtain ISO/IEC 18974, the international standard for open source security assurance. This case shows how ISO/IEC 18974 is implemented at a financial company that requires a high level of security.

- **Background and goals of certification**: The need to build a systematic management system emerged as the company actively used open source to provide world-class financial services quickly and efficiently.
- **Key challenges during implementation**: The company had to meet more than 30 security certification requirements, including establishing open source policy and processes, building a compliance system, securing expertise in the responsible organization and personnel, and conducting in-house employee education.
- **Business impact and benefits after certification**: The company's open source use and security management capability were internationally recognized, and it was recognized as a company with systematic and consistent open source security management capability. It gave customers confidence that the company could provide safer financial services.
- **Analysis of success factors**: The company formed an open source expert council (OSRB) to jointly discuss open source-related issues and built a system to manage licenses and security vulnerabilities in advance.

**Key lesson**: Financial companies must build a systematic open source management system and secure expertise through an expert council to meet high-level security requirements.

### 7.1.4 SME: (Hypothetical case) IT Solution Provider "TechSolution"

TechSolution is a small and medium-sized IT solution provider developing cloud-based services. TechSolution pursued ISO/IEC 18974 certification to safely protect customer data and secure a competitive advantage.

- **Background and goals of certification**: TechSolution set a goal of obtaining ISO/IEC 18974 certification to strengthen the security of its cloud-based services, increase customer trust, and create new business opportunities.
- **Key challenges during implementation**: The main challenge was meeting ISO/IEC 18974 requirements with a limited budget and personnel.
- **Business impact and benefits after certification**:
    - Improved the security level of cloud-based services and was able to safely protect customer data.
    - Improved customer trust, strengthening relationships with existing customers and succeeding in attracting new customers.
    - Improved company image and secured a competitive advantage by promoting the ISO/IEC 18974 certification.
- **Analysis of success factors**:
    - Strengthened cooperation between the existing development team and security team, and clarified responsibilities and roles by designating an open source security lead.
    - Reduced initial investment costs and increased management efficiency by using cloud-based SBOM generation and vulnerability scanning tools.
    - Systematically implemented ISO/IEC 18974 requirements with the help of an outside consulting firm and gained know-how for obtaining certification.

**Key lesson**: SMEs can efficiently use limited resources and successfully obtain ISO/IEC 18974 certification with the help of outside experts.

### 7.1.5 Startup: (Hypothetical case) AI-based Service Development Startup "AIBrain"

AIBrain is an early-stage startup developing AI-based services. AIBrain emphasizes innovative technology and rapid development speed as its strengths, but also has concerns about security issues.

- **Background and goals of certification**: AIBrain expected ISO/IEC 18974 certification to strengthen security throughout the development process and have a positive impact on attracting investment and forming partnerships.
- **Key challenges during implementation**: As an early-stage startup, it lacked security-specialized personnel, and it was difficult to meet ISO/IEC 18974 requirements without slowing down development speed.
- **Business impact and benefits after certification**:
    - A security-conscious development culture took root, improving the security of the product.
    - Demonstrated security capability to investors and partners, succeeding in attracting investment and forming partnerships.
    - Improved company image and secured a competitive advantage by promoting the ISO/IEC 18974 certification.
- **Analysis of success factors**:
    - Integrated security checks into the development process and actively used automated security tools to maintain development speed while strengthening security.
    - Reduced security infrastructure build costs by using a cloud-based development environment.
    - Effectively implemented ISO/IEC 18974 requirements using materials and guidelines provided by the OpenChain Project.

**Key lesson**: Startups can implement ISO/IEC 18974 cost-effectively by integrating security into the development process and using a cloud-based environment.

**Table 7.1: Summary of ISO/IEC 18974 Certification Cases by Company Size**

| Company Size | Company | Key Characteristics | Key Success Factors |
| --- | --- | --- | --- |
| Global software company | openEuler | Large-scale open source project | Community cooperation, security-centered culture |
| Large enterprise | KT | Integration with existing security system | Use of in-house experts, systematic management system |
| Financial company | KakaoBank | High security requirements | Use of expert council, systematic management system |
| SME (hypothetical) | TechSolution | Limited resources | Cloud-based tools, use of outside experts |
| Startup (hypothetical) | AIBrain | Rapid development speed | Security integration into the development process, cloud use |

This table summarizes ISO/IEC 18974 certification cases by various company sizes. Organizations can refer to cases that match their own size and characteristics to establish an implementation strategy.

## 7.2 Key Strategies for Successful Implementation

The key strategies for successfully leading ISO/IEC 18974 implementation are as follows. These strategies have been validated through the case studies examined above and can be applied to an organization's situation to maximize their effect.

### 7.2.1 Securing Active Support from Executive Management

1. **Presenting the ROI (Return on Investment) of security investment**:
    - Quantitatively presents the positive impact of open source security management on business continuity, customer trust, and regulatory compliance.
    - Example: Uses specific figures such as "5% reduction in customer churn after obtaining ISO/IEC 18974 certification" or "30% reduction in the number of open source-related security incidents."
2. **Regular status reporting and feedback**:
    - Reports the status of open source security to executive management monthly or quarterly and receives feedback.
    - The report includes the status of the Software Bill of Materials (SBOM), the trend of vulnerability occurrence, the status of license compliance, and the results of improvement activities.
3. **Building an open source security culture**:
    - Executive management leads by emphasizing the importance of open source security and raising organization-wide awareness.
    - Encourages participation in open source security-related education programs and rewards best practices.

**Execution steps**:

1. Explains the importance of open source security to executive management and emphasizes the need to adopt ISO/IEC 18974.
2. Obtains approval to establish an OSPO (Open Source Program Office) or designate an open source security lead.
3. Secures a budget for open source security and supports securing the necessary tools and personnel.

### 7.2.2 Adopting a Phased Approach

1. **Gradual implementation based on priority**:
    - Starts with high-risk areas (e.g., externally exposed services, core business logic) and gradually expands the scope of application.
    - Manages low-risk areas efficiently using automation tools.
2. **Maintaining momentum through quick wins**:
    - Sets goals that can be achieved in the short term and shares success cases to encourage participation within the organization.
    - Example: "Build an SBOM generation and management system within 3 months," "Complete vulnerability scanning for key projects within 6 months," etc.
3. **Risk management and control**:
    - Identifies new threats through regular risk assessments and prepares appropriate response measures.
    - Systematically manages open source-related risks using a risk management register.

**Execution steps**:

1. Selects open source components related to core business logic as priority management targets.
2. Introduces SBOM generation and vulnerability scanning tools to quickly generate initial results.
3. Builds a regular security check and audit process to drive continuous improvement.

### 7.2.3 Actively Using Automation Tools

1. **Integrating the CI/CD pipeline**:
    - Integrates SBOM generation, license checking, and vulnerability scanning into the Continuous Integration/Continuous Delivery (CI/CD) pipeline to perform automated security checks throughout the development process.
    - This allows developers to automatically perform security checks whenever they commit code and quickly resolve issues.
2. **Building a real-time monitoring and alert system**:
    - Builds a system that provides immediate notification when a new vulnerability is found, to support a rapid response.
    - Configures notifications to be received through various channels such as Slack, email, and SMS.
3. **Minimizing repetitive tasks**:
    - Automates repetitive tasks such as license checking, SBOM generation, and vulnerability scanning to allow human resources to focus on more valuable work.
    - Repetitive tasks can be minimized through script writing, API use, and automation tool configuration.

**Table 7.2: Key Strategies for Successful ISO/IEC 18974 Implementation**

| Strategy | Description | Execution Steps |
| --- | --- | --- |
| Securing executive support | Emphasizing the need for security investment, raising organization-wide awareness | Presenting ROI, regular status reporting |
| Phased approach | Priority-based gradual implementation | Starting with high-risk areas, generating quick wins |
| Using automation tools | Integrating the CI/CD pipeline, real-time monitoring | Minimizing repetitive tasks, building a rapid response system |

Active support from executive management, a phased approach, and the use of automation tools are essential for successful implementation.
