• No results found

OPEN SOURCE SOFTWARE COMPLIANCE AND SECURITY Black Duck Software, Inc. All Rights Reserved.

N/A
N/A
Protected

Academic year: 2021

Share "OPEN SOURCE SOFTWARE COMPLIANCE AND SECURITY Black Duck Software, Inc. All Rights Reserved."

Copied!
22
0
0

Loading.... (view fulltext now)

Full text

(1)

© 2014 Black Duck Software, Inc. All Rights Reserved.

OPEN SOURCE SOFTWARE COMPLIANCE AND

SECURITY

(2)

2 © 2014 Black Duck Software, Inc. All Rights Reserved.

SPEAKER SLIDE

Phil Odence

Vice President & General

Manager

Danielle Sheer

General Counsel

Carbonite

(3)

15 January 2015 3

Carbonite, Inc. (Nasdaq: CARB)

Vitals

• Founded: 2005

• IPO: 2011

• Corporate HQ: Boston, MA

• Customer Support Center: Lewiston, ME

• Data centers: Multiple locations in the U.S.

• Number of employees: 500+

• Files backed up: more than 300 billion

• Files recovered: nearly 20 billion

Key Acquisitions

Phanfare (2011)

Zmanda (2012)

MailStore (2014)

(4)

4 © 2014 Black Duck Software, Inc. All Rights Reserved.

AGENDA

Trends

Open Source at Carbonite

Managing Open Source

(5)

5 © 2013 Black Duck Software, Inc. All Rights Reserved.

(6)

6 © 2014 Black Duck Software, Inc. All Rights Reserved.

INCREASING ABUNDANCE

0

500,000

1,000,000

1,500,000

2007

2009

2011

2013

2015

Open Source Projects

Black Duck KnowledgeBase

(7)

7 © 2014 Black Duck Software, Inc. All Rights Reserved.

OPEN SOURCE GROWS AS % OF CODE

2007

2012

2017

5%

30%

More % ???

Source: IDC Survey of G2000 Source: Black Duck audit results

By 2016, at least

95% of IT organizations will

leverage nontrivial elements of open-source

software

technology in their mission-critical IT

portfolios, including cases where they might not be

aware of it — an increase from 75% in 2010.

(8)

8 © 2014 Black Duck Software, Inc. All Rights Reserved.

OSS IS RELIED ON BY COMPANIES IN EVERY

SECTOR

SOFTWARE ELECTRONICS

GOVERNMENT MEDIA

FINANCIAL / SERVICES

(9)

9 © 2014 Black Duck Software, Inc. All Rights Reserved.

BUT, OSS OFTEN ENTERS A CODE BASE

UNCHECKED

Code Base

Commercial

3

rd

Party

Code

Purchasing

• Licensing?

• Security?

• Quality?

• Support?

Open Source

OPERATIONAL RISK

Which versions of code are being used, and how old are they

LEGAL RISK

Which licenses are used and do they match anticipated use of the code

SECURITY RISK

Which components have vulnerabilities and what are they

Through 2016, less than half of IT organizations will have

implemented an effective open-source governance program; that is, one that successfully minimizes risk and maximizes positive TCO and ROI opportunities”

(10)

OPEN SOURCE AT CARBONITE

Danielle Sheer, Esq.

Vice President and General Counsel

(11)

15 January 2015

What you need to know about your Open Source use

Along with the tremendous benefits of Open Source … • build better software, faster and more affordably

…Comes certain risks and obligations…. • Viral effect

• Notice and attribution

…And you can successfully manage and mitigate by implementing an Open Source Compliance Program

• Internal and external benefits

(12)

15 January 2015

Not All Licenses Are Created Equal

A significant amount of O/S can be used without restriction • MIT License

o Use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software…

o Other Examples

◦ BSD License

◦ Apache License

Some O/S could have undesirable Copyleft provisions – “Viral Risk” • GNU GPL:

o You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy

o This License will therefore apply… to the whole of the work, and all its parts, regardless of how they are packaged

o No permission to license the work in any other way

Notice and Attribution

(13)

15 January 2015

Acquiring Open Source

In October 2012, Carbonite acquired Zmanda, Inc. • Open source due diligence and audit required

o Ensure accurate valuation

o Understand the acquired technology o Quantify maintenance costs

In November 2014, Carbonite acquired MailStore Software GmbH • BlackDuck report can influence SPA negotiations

• Cultivates transparency between Buyer and Seller

Black Duck Audit

• Holistic O/S review

• Flag items to be addressed

• Practical solutions

(14)

15 January 2015

Open Source Compliance Program

Step One

• Determine where and how open source is used

• Define and assign responsibilities and processes for engineers

Step Two

• Record: o Name o Licensor o Version

o Local copy license o Business use(s) o Plans to modify? o Internal use? o Distributed? o Hosted? Step Three

• Create an approved/disapproved – white/black list for developer training tool reference

• Finalize an open source policy and review with outside counsel

Step Four

• Ongoing monitoring and maintenance

(15)

15 January 2015

Challenges and Benefits

15

Challenges

Benefits

Abundance of open source usage

Increased communication & cross-functional

teamwork

Version proliferation

Control / increased input

Fear of the unknown

Increased certainty regarding risk and

exposure

Achieving the right balance between

processes and product development

(16)

16 © 2013 Black Duck Software, Inc. All Rights Reserved.

OSS SECURITY AND

LOGISTICS

(17)

17 © 2014 Black Duck Software, Inc. All Rights Reserved.

OPEN SOURCE ADDS NEW DIMENSION TO SECURITY RISK

IT

Security

Risks

Open

Source

Challenges

Open Source

Component

Security

• What components?

• Where used?

• How secure?

• How to stay on top?

OWASP has added “Using

components with known

vulnerabilities” to Top 10

Risks.

(18)

18 © 2014 Black Duck Software, Inc. All Rights Reserved.

RISK POSED BY OPEN SOURCE

While Heartbleed, Bash & Poodle demonstrate the risk of

open source vulnerabilities, new open source vulnerabilities

outpace customers’ ability to cope.

(19)

19 © 2014 Black Duck Software, Inc. All Rights Reserved.

OSS LOGISTICS TO MANAGE ALL THE RISKS

Choose

OSS Logistics

Approve Scan Inventory Secure Deliver

Approve Scan Inventory Secure Deliver

(20)

20 © 2014 Black Duck Software, Inc. All Rights Reserved.

AUTOMATE VISIBILITY AND CONTROL – OSS LOGISTICS

Choose

OSS Logistics

Approve Scan Inventory Secure Deliver

Approve Scan Inventory Secure Deliver

Approve Scan Inventory Secure Deliver

NVD

OSVDB

(21)

21 © 2014 Black Duck Software, Inc. All Rights Reserved.

SUMMARY

Open source software is changing the world

I

But organizations need to be mindful of a range of risks

Realizing the full benefits while managing the risks requires

a comprehensive program

(22)

QUESTIONS?

References

Related documents

Franklin Oliveira, comes over to Britain in February 1998, he will have the opportunity to discuss business terms with senior figures within British Tour Operators with a view

Even though more students go to school now in Cameroon (especially female children), most of them do not study in the STEM fields after completing a third year of secondary

Drawing on the theoretical stock of literature on contracting, controlling, trust and relational signalling in inter-firm relationships, we try to provide theoretical

Movies that encourage empathy are more effective than those that objectify problems.. This is not to say that objective information isn’t needed in your DMO’s content marketing. It

Figure 5.1 Seasonal measurements of gross photosynthesis (Pg) at midday and volumetric soil water content ( θ v ) in the 0 to 15 cm profile in Kentucky bluegrass, tall fescue,

The molecular structure is shown in Figure 2.1, the bulk crystal structures of the rhombic and needle-shaped polymorphs at room temperature were determined based on single crystal

1) Negative effects of physical inactivity, described the risks of a sedentary lifestyle (cardiovascular diseases, obesity, type II diabetes, osteoporosis, etc.) and

While in-depth exploration of the secondary tools identified was beyond the scope of the current review, further exploration of the properties of the tools used to capture