<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Conformance | Haksung</title><link>https://haksungjang.github.io/en/tags/conformance/</link><description>Haksung Jang — Open Source Program Manager at SK telecom</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 09 Aug 2026 17:03:59 +0900</lastBuildDate><atom:link href="https://haksungjang.github.io/en/tags/conformance/index.xml" rel="self" type="application/rss+xml"/><item><title>6. Conformance Declaration</title><link>https://haksungjang.github.io/en/docs/opensource_for_enterprise/6-conforming/</link><pubDate>Sun, 09 Aug 2026 17:03:59 +0900</pubDate><guid>https://haksungjang.github.io/en/docs/opensource_for_enterprise/6-conforming/</guid><description>An enterprise that has built an open source program (open source policy / process / tools / organization) conforming to all the requirements of ISO/IEC 5230 and ISO/IEC 18974 must document and declare the following two items.
(1) Confirming That Standard Requirements Are Met ISO/IEC 5230 and ISO/IEC 18974 require a document confirming that the program meets all requirements, as follows:
ISO/IEC 5230 - License Compliance 3.6.1.1 A document affirming the program specified in §3.1.4 satisfies all the requirements of this document.
A document affirming that the program specified in §3.1.4 satisfies all the requirements of this specification ISO/IEC 18974 - Security Assurance 3.4.1.1: Documented Evidence affirming the Program specified in §3.1.4 satisfies all the requirements of this document.
Documented evidence affirming that the Program specified in §3.1.4 satisfies all the requirements of this document. To this end, an enterprise must prepare a document containing the following content:</description><content:encoded>&lt;![CDATA[<p>An enterprise that has built an open source program (open source policy / process / tools / organization) conforming to all the requirements of ISO/IEC 5230 and ISO/IEC 18974 must document and declare the following two items.</p><h3 id="1-confirming-that-standard-requirements-are-met">(1) Confirming That Standard Requirements Are Met</h3><p>ISO/IEC 5230 and ISO/IEC 18974 require a document confirming that the program meets all requirements, as follows:</p><div class="alert alert-success" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 5230 - License Compliance</div><ul><li>3.6.1.1 A document affirming the program specified in §3.1.4 satisfies all the requirements of this document.<br><code>A document affirming that the program specified in §3.1.4 satisfies all the requirements of this specification</code></li></ul></div><div class="alert alert-warning" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 18974 - Security Assurance</div><ul><li>3.4.1.1: Documented Evidence affirming the Program specified in §3.1.4 satisfies all the requirements of this document.<br><code>Documented evidence affirming that the Program specified in §3.1.4 satisfies all the requirements of this document.</code></li></ul></div><p>To this end, an enterprise must prepare a document containing the following content:</p><pre tabindex="0"><code>The open source program of [Company Name] meets all the requirements of ISO/IEC 5230:2020 (open source license compliance) and ISO/IEC 18974 (open source security assurance).
This can be confirmed through the following documents and processes:
1. Open source policy document
2. Open source process document
3. Open source training and assessment records
4. SBOM (Software Bill of Materials) management system
5. Open source license compliance artifact generation and retention system
6. Open source security vulnerability management system
7. External inquiry response process records
[Date]
[Signature of Open Source Program Manager]</code></pre><h3 id="2-declaring-continued-conformance-assurance">(2) Declaring Continued Conformance Assurance</h3><p>ISO/IEC 5230 and ISO/IEC 18974 also require a document confirming that all requirements continue to be met for 18 months after obtaining conformance certification:</p><div class="alert alert-success" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 5230 - License Compliance</div><ul><li>3.6.2.1 A document affirming the program meets all the requirements of this document, within the past 18 months of obtaining conformance validation.<br><code>A document affirming that the program has met all the requirements of this specification version (v2.1) during the past 18 months since obtaining conformance validation</code></li></ul></div><div class="alert alert-warning" role="alert"><div class="h4 alert-heading" role="heading">ISO/IEC 18974 - Security Assurance</div><ul><li>3.4.2.1: A document affirming the Program meets all the requirements of this specification, within the past 18 months of obtaining conformance validation.<br><code>A document affirming that the program has met all the requirements of this specification during the past 18 months since obtaining conformance validation</code></li></ul></div><p>To this end, an enterprise must prepare and periodically update a document containing the following content:</p><pre tabindex="0"><code>[Company Name] guarantees that it will maintain a state of meeting all requirements for at least 18 months after obtaining conformance certification for ISO/IEC 5230:2020 (open source license compliance) and ISO/IEC 18974 (open source security assurance).
To this end, the following activities are carried out:
1. Conduct an internal audit at least every 6 months to verify that all requirements continue to be met
2. Obtain an external expert review at least once a year to assess the program's effectiveness
3. Provide ongoing training and competency assessment for program participants
4. Regularly review and update the open source policy and processes
5. Monitor and respond to changes in new technology trends and legal requirements
[Date]
[Signature of Open Source Program Manager]</code></pre><p>An enterprise can include this document in its open source policy or publish it on a publicly accessible website. For example,<a href="https://www.sktelecom.com/">SK telecom</a> publishes this content on its own open source portal site:<img src="/docs/opensource_for_enterprise/6-conforming/sktiso.png" alt=""><a href="https://sktelecom.github.io/compliance/iso5230/">https://sktelecom.github.io/compliance/iso5230/</a>
Through this documentation, an enterprise satisfies all the requirements of ISO/IEC 5230 and ISO/IEC 18974, and can guarantee ongoing management and improvement of its open source license compliance and security assurance.</p><p><img src="/docs/opensource_for_enterprise/6-conforming/totalno.png" alt=""/>
]]></content:encoded></item></channel></rss>