SlideShare a Scribd company logo
1 of 44
© Black Duck 2012
It’s No Myth:
Compliance Is Good Business
Linux Collaboration Summit, 16 April 2013
Phil Odence, VP Business Development
Black Duck
@black_duck_sw
2 © Black Duck 2013
Black Duck’s Perspective
• Known for services; primarily a software company
• Not an open source company per se
• Very involved, but most products under commercial
licenses
• Serving (primarily) commercial companies
• Software, Systems, Enterprise IT Organizations
• Helping companies manage their use of open
source
@black_duck_sw
3 © Black Duck 2013
Agenda
Goal: To provide a bird’s eye view of open
source/FOSS usage and compliance in companies
• Evolving Relationship Between Commercial Companies
and FOSS
• Why open source?
• Why comply?
• Are they really?
• What’s next?
@black_duck_sw
4 © Black Duck 2013
First of all…
“Software is Eating the World.”
Marc Andreessen (Netscape Founder)
August ’11, Wall Street Journal
And there’s a growing
appetite for open source…
@black_duck_sw
5 © Black Duck 2013
…with the plate is heaping
Source: Ohloh/Black Duck KnowledgeBase
2.7 billion files
Nearly 1M de-duplicated projects
10+ million staff years of development
5000+ sites
2,200+ unique software licenses
-
500,000.00
1,000,000.00
1,500,000.00
2,000,000.00
2,500,000.00
2006 2008 2010 2012 2014
FOSS Projects
Projected
Games
UI
@black_duck_sw
6 © Black Duck 2013
OSS Adoption: Jeff Hammond circa early 2009
@black_duck_sw
7 © Black Duck 2013
Olliance Consulting* Management Maturity Framework
Developer driven Business strategy driven
Ad Hoc Use
Built-in
Compliance
Informal
Guidelines
Strategic OSS
Use, Commun
ity Leadership
Explicit
Policy, Tracking
& Audting
Process
Automation, Co
mmunity
Participation
OpenSourceAdoption
*now a division of Black Duck
@black_duck_sw
8 © Black Duck 2013
Industry OSS Adoption ala Geoff Moore
Innovators Majority
OpenSourceAdoption
@black_duck_sw
9 © Black Duck 2013
Jeff Hammond circa late 2010
• OSS goal to means
• 80% developers used
• Reduced management gap
• Don’t ask/tell to strategic
• Waned concern about
mission critical apps
@black_duck_sw
10 © Black Duck 2013
The Chasm is the Stuff of Myth
Closed
source is the
evil empire
You are a bunch
of wookies
If anyone knows
we are using open
source we’ll have
to give up all our
code
They just
want a free
ride
There’s no way to make
money if I give away my
software.
No one cares
about licenses
unless they are
getting sued Those guys
don’t get it.
• Chasm: Greek χάος means emptiness, vast
void, abyss. Same as for “chaos”
• Out of which grew the Chaoskamph myths
• Explaining the clash between order and
chaos in the world‟s creation
• paraphrasing Wikipdia
@black_duck_sw
11 © Black Duck 2012
Why open source?
Myth: You only love us cause
we’re free (as in beer)
12 © Black Duck 2013
Faster, Better, Cheaper
Jeffrey Hammond, Forrester
Open source is a „silver bullet‟ that allows simultaneous
improvement along all three dimensions of the software
„iron triangle‟ of cost, schedule, features.
Cost
FeaturesSchedule
@black_duck_sw
13 © Black Duck 2013
A bunch of good reasons…
“Open source is ubiquitous, it’s unavoidable….having a policy against open
source is impractical and places you at a competitive disadvantage”
• Key Benefits
• Flexibility
• Modify, mix, reuse code
• Innovation
• Leverage FOSS and community
• Cost Optimization
• Reduce or eliminate acquisition costs
Source: Mark Driver, Gartner Group
It’s only #3
@black_duck_sw
14 © Black Duck 2013
30%
80%
Average
Best in
class
Company Benefit: Less is More
@black_duck_sw
15 © Black Duck 2013
Real World Example
“Over 80% of the software in our handsets is open source”
Carl-Eric Mols, Head of OSS, Sony Mobile Communications
@black_duck_sw
16 © Black Duck 2013
Another:
Large Commercial UK Bank Trading Application
Delivered a new
trading app but only
had to do 28% of the
work!
@black_duck_sw
17 © Black Duck 2013
…and then there’s customer acceptance
• DoD CIO Letter…
• To effectively achieve its missions, the
Department of Defense must develop and
update its software-based capabilities faster
than ever, to anticipate new threats and
respond to continuously changing
requirements. The use of Open Source
Software (OSS) can provide advantages in
this regard.
• Unfortunately, there have been
misconceptions and misinterpretations of the
existing laws, policies and regulations that
deal with software and apply to OSS, that
have hampered effective DoD use and
development of OSS
• I have asked the Director, Enterprise Services
& Integration, to work with your staffs and
identify other barriers to the effective use of
open source software within the
Department, so we can continue to increase
the benefits from the use of OSS
FOSS
@black_duck_sw
18 © Black Duck 2013
So…
• The myth:
• It’s all about the “free beer”
• The reality:
• It’s about:
• Flexibility
• Innovation
• Co-opetition and Community
• Recruiting
• Support from customers
• And, yes, Cost
@black_duck_sw
19 © Black Duck 2012
Why Comply?
Myth: Companies don’t give a hoot
(’cept maybe when they get sued)
20 © Black Duck 2013
Software today is Multi-Source
THE ENTERPRISE – TOOLS, PROCESSES
Your Software Application
Internally
Developed
Code
Commercial
3rd-Party Code
Outsourced Code
Development
OSS Communities
Global 2000 organizations increasingly leverage code from a vast
array of sources — including internally built, open
source, outsourced, commercially built, and customized
applications.
- Melinda Ballou, IDC (sponsored by Black Duck
@black_duck_sw
21 © Black Duck 2013
The Fundamental Challenge
“How ya gonna keep ’em down on the farm…?”
@black_duck_sw
22 © Black Duck 2013
Management challenges aren’t just legal
• Key Benefits
• Flexibility
• Modify, mix, reuse
code
• Innovation
• Leverage FOSS
and community
• Cost Optimization
• Reduce or
eliminate
acquisition costs
• Challenges
• Technical Failure
• Operational
exposure
• Needs to be
audited, managed
• Security Risks
• Business exposure
• IP Risks
• Legal exposure
“Open source is ubiquitous, it’s unavoidable….having a policy against open
source is impractical and places you at a competitive disadvantage”
Source: Mark Driver, Gartner Group
It’s only #3
@black_duck_sw
23 © Black Duck 2013
Managing Open Source = Proper SW Dev Mgmt
• “There are plenty of other reasons beyond licensing
that I want to understand what’s in our code”
• CIO, Large Financial Services Firm
• Security
• Quality
• Supportability
• Community
• Sarbanes Oxley Act Section 404 says you gotta
know what software you got and who owns it
• Fortune 500 tech companies- material risk in 10Ks
@black_duck_sw
24 © Black Duck 2013
And, if they want to get bought someday…
2009 2010 2011 2012
M&A Audits
US Tech Deals
OSS Compliance have become routine question in tech M&A
Source: Black Duck / 451 Group
@black_duck_sw
25 © Black Duck 2013
Free’s not all that free
Risk
(all
sorts)
ComplianceProductivity
Phil‟s (other) iron triangle
No compliance means
productive but risky
Overly heavy compliance
reduces risk, but may
squash productivity
@black_duck_sw
26 © Black Duck 2013
So…
• The myth:
• Companies don’t care
• And only pay attention to
extreme measures
• The reality:
• Legal fear is a motivator
• But companies’ overall risk
management agendas align
reasonably with open source
governance
• It’s just not all that simple
@black_duck_sw
27 © Black Duck 2012
Who complies?
Myth: OK, but most companies don’t comply
And, they may talk the talk, but…
28 © Black Duck 2013
Companies invest heavily in compliance
@black_duck_sw
29 © Black Duck 2013
In the form of sophisticated governance processes
@black_duck_sw
30 © Black Duck 2013
…best practices, training, transformation
@black_duck_sw
31 © Black Duck 2013
..,dedicated review boards and programs
Open Source Program Office
• Responsible for all open source activities and strategy across the
company
• Provides continuous training and consulting to HP product and
project teams
• Encourages contribution to the open source community
• Sponsors numerous open source foundations (e.g. ASF, Linux
Foundation, OpenStack) and events
• Typically review 10 to 20 proposals per week from teams wanting
to use and/or contribute to open source
• Develops in-house tools to support the review and tracking of open
source across the company
• Promptly handle any compliance inquiries that come to our
attention
http://opensource.hp.com
@black_duck_sw
32 © Black Duck 2013
….correct and corresponding code infrastructure
“The Internet of objects would encode
50 to 100 trillion objects, and be able to
follow the movement of those objects.
Human beings surrounded by 1000 to
5000 trackable objects”
@black_duck_sw
33 © Black Duck 2013
OK, but do they waddle the waddle?
@black_duck_sw
34 © Black Duck 2013
Giving back is a “higher order skill”
Engineering
driven
Business strategy driven
Ad Hoc Use
Built-in
Compliance
Informal
Guidelines
Strategic OSS
Use, Commun
ity Leadership
OpenSourceAdoption
*now a division of Black Duck
@black_duck_sw
Explicit
Policy, Tracking
& Audting
Process
Automation, Co
mmunity
Participation
35 © Black Duck 2013
Companies certainly rock the Kernel
• 75% Kernel developers are paid
• 800 companies have contributed over time; 200
active as of 2012
• Red Hat, Intel, Novell, IBM, Texas
Instruments, Broadcom, Nokia, Samsung, Oracle
and Google
• Jon Corbet’s 2012 annual
report
@black_duck_sw
36 © Black Duck 2013
Financial
Services
Automotive
Mobile
Aerospace
Polarsys
Healthcare
Community and Co-opetition
Mozilla
Eclipse
Openstack
The
Foundation
The Apache Foundation
Networking
@black_duck_sw
37 © Black Duck 2013
Automotive may boast the most logos
Ford contributes AppLink code to GENIVI Alliance
GENIVI
License Review
Team
@black_duck_sw
38 © Black Duck 2013
And … I’m just sayin’
Microsoft is into open…
@black_duck_sw
39 © Black Duck 2013
Close to our hearts
@black_duck_sw
40 © Black Duck 2013
So…
• The myth:
• Companies don’t comply
• And even if they do they
don’t participate
• The reality:
• Some don’t
• Many do
• The world’s best companies
invest heavily
• And, more and more they
are walking the walk
@black_duck_sw
41 © Black Duck 2012
Looking Forward and
Conclusions
42 © Black Duck 2013
Conclusion
• The Companies/FOSS has evolved
• Corporate usage has crossed the chasm
• Companies have good business reasons to
manage/comply
• The best companies do comply
• And are finding good business reasons to give back
@black_duck_sw
43 © Black Duck 2013
There may remain a philosophical schism, but...
Software is all
about delivering
shareholder
value
Software is
all about
“free”
Rather than question motivation, focus on results
@black_duck_sw
44 © Black Duck 2013
Check out where it’s going
• Key trend toward internal OSS methods – 80%
• Open source will make up >50% deployed code –
62%
• “Lower Cost” – drops to #7 in importance
• Attracting talent – #1 reason to engage
• Company’s co-epetition will increase – 57%
• 2013 Future of Open Source
Survey Results show new
trends in OSS
• First ever webinar results panel
is now available to view on-
demand!
• #FutureOSS
@black_duck_sw

More Related Content

Similar to It’s No Myth: Compliance Is Good Business

OCITA 2012: Opening Up to Open Source Software for Government
OCITA 2012: Opening Up to Open Source Software for GovernmentOCITA 2012: Opening Up to Open Source Software for Government
OCITA 2012: Opening Up to Open Source Software for GovernmentJillmz
 
Strategies and Policies for the implementation of Free & and Open Source Soft...
Strategies and Policies for the implementation of Free & and Open Source Soft...Strategies and Policies for the implementation of Free & and Open Source Soft...
Strategies and Policies for the implementation of Free & and Open Source Soft...Frederik Questier
 
Open Source Trends and Why They Matter to Health Care
Open Source Trends and Why They Matter to Health CareOpen Source Trends and Why They Matter to Health Care
Open Source Trends and Why They Matter to Health CareBlack Duck by Synopsys
 
Corporate Open Source Anti-patterns
Corporate Open Source Anti-patternsCorporate Open Source Anti-patterns
Corporate Open Source Anti-patternsbcantrill
 
Rise of the Open Source Program Office for LinuxCon 2016
Rise of the Open Source Program Office for LinuxCon 2016Rise of the Open Source Program Office for LinuxCon 2016
Rise of the Open Source Program Office for LinuxCon 2016Gil Yehuda
 
Linux and the Open Source- D Sarkar
Linux and the Open Source- D SarkarLinux and the Open Source- D Sarkar
Linux and the Open Source- D SarkarDipayan Sarkar
 
Push To Test - Open Source Adoption in the Enterprise
Push To Test - Open Source Adoption in the EnterprisePush To Test - Open Source Adoption in the Enterprise
Push To Test - Open Source Adoption in the EnterpriseAndrew Aitken
 
Introduction to Open Source for Libraries
Introduction to Open Source for LibrariesIntroduction to Open Source for Libraries
Introduction to Open Source for LibrariesNicole C. Engard
 
Open Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated CompaniesOpen Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated Companiesiasaglobal
 
Leaping the chasm from proprietary to open: A survivor's guide
Leaping the chasm from proprietary to open: A survivor's guideLeaping the chasm from proprietary to open: A survivor's guide
Leaping the chasm from proprietary to open: A survivor's guidebcantrill
 
OSS - enterprise adoption strategy and governance
OSS -  enterprise adoption strategy and governanceOSS -  enterprise adoption strategy and governance
OSS - enterprise adoption strategy and governancePrabir Kr Sarkar
 
en-itwob-adopt-technology-faster-infographic
en-itwob-adopt-technology-faster-infographicen-itwob-adopt-technology-faster-infographic
en-itwob-adopt-technology-faster-infographicAlan Fewell
 
Open source 101
Open source 101Open source 101
Open source 101Tom Rieger
 
Getting Started in the Nonprofit Cloud
Getting Started in the Nonprofit CloudGetting Started in the Nonprofit Cloud
Getting Started in the Nonprofit CloudAbila
 
Open Source Movement
Open Source MovementOpen Source Movement
Open Source MovementMesut Yılmaz
 
Providing Services to our Remote Users: Open Source Solutions
Providing Services to our Remote Users: Open Source SolutionsProviding Services to our Remote Users: Open Source Solutions
Providing Services to our Remote Users: Open Source SolutionsNicole C. Engard
 
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing ScamOpen Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing ScamBlack Duck by Synopsys
 
(In)security in Open Source
(In)security in Open Source(In)security in Open Source
(In)security in Open SourceShane Coughlan
 
Why Open Always Trumps Closed?
Why Open Always Trumps Closed?Why Open Always Trumps Closed?
Why Open Always Trumps Closed?Exove
 

Similar to It’s No Myth: Compliance Is Good Business (20)

OCITA 2012: Opening Up to Open Source Software for Government
OCITA 2012: Opening Up to Open Source Software for GovernmentOCITA 2012: Opening Up to Open Source Software for Government
OCITA 2012: Opening Up to Open Source Software for Government
 
Strategies and Policies for the implementation of Free & and Open Source Soft...
Strategies and Policies for the implementation of Free & and Open Source Soft...Strategies and Policies for the implementation of Free & and Open Source Soft...
Strategies and Policies for the implementation of Free & and Open Source Soft...
 
Open Source Trends and Why They Matter to Health Care
Open Source Trends and Why They Matter to Health CareOpen Source Trends and Why They Matter to Health Care
Open Source Trends and Why They Matter to Health Care
 
Corporate Open Source Anti-patterns
Corporate Open Source Anti-patternsCorporate Open Source Anti-patterns
Corporate Open Source Anti-patterns
 
Rise of the Open Source Program Office for LinuxCon 2016
Rise of the Open Source Program Office for LinuxCon 2016Rise of the Open Source Program Office for LinuxCon 2016
Rise of the Open Source Program Office for LinuxCon 2016
 
Linux and the Open Source- D Sarkar
Linux and the Open Source- D SarkarLinux and the Open Source- D Sarkar
Linux and the Open Source- D Sarkar
 
Push To Test - Open Source Adoption in the Enterprise
Push To Test - Open Source Adoption in the EnterprisePush To Test - Open Source Adoption in the Enterprise
Push To Test - Open Source Adoption in the Enterprise
 
Open Source
Open Source Open Source
Open Source
 
Introduction to Open Source for Libraries
Introduction to Open Source for LibrariesIntroduction to Open Source for Libraries
Introduction to Open Source for Libraries
 
Open Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated CompaniesOpen Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated Companies
 
Leaping the chasm from proprietary to open: A survivor's guide
Leaping the chasm from proprietary to open: A survivor's guideLeaping the chasm from proprietary to open: A survivor's guide
Leaping the chasm from proprietary to open: A survivor's guide
 
OSS - enterprise adoption strategy and governance
OSS -  enterprise adoption strategy and governanceOSS -  enterprise adoption strategy and governance
OSS - enterprise adoption strategy and governance
 
en-itwob-adopt-technology-faster-infographic
en-itwob-adopt-technology-faster-infographicen-itwob-adopt-technology-faster-infographic
en-itwob-adopt-technology-faster-infographic
 
Open source 101
Open source 101Open source 101
Open source 101
 
Getting Started in the Nonprofit Cloud
Getting Started in the Nonprofit CloudGetting Started in the Nonprofit Cloud
Getting Started in the Nonprofit Cloud
 
Open Source Movement
Open Source MovementOpen Source Movement
Open Source Movement
 
Providing Services to our Remote Users: Open Source Solutions
Providing Services to our Remote Users: Open Source SolutionsProviding Services to our Remote Users: Open Source Solutions
Providing Services to our Remote Users: Open Source Solutions
 
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing ScamOpen Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
 
(In)security in Open Source
(In)security in Open Source(In)security in Open Source
(In)security in Open Source
 
Why Open Always Trumps Closed?
Why Open Always Trumps Closed?Why Open Always Trumps Closed?
Why Open Always Trumps Closed?
 

More from Black Duck by Synopsys

Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubFLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubBlack Duck by Synopsys
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...Black Duck by Synopsys
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical GuideFLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical GuideBlack Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your DealFLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your DealBlack Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub Black Duck by Synopsys
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Black Duck by Synopsys
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...Black Duck by Synopsys
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...Black Duck by Synopsys
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Black Duck by Synopsys
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...Black Duck by Synopsys
 
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...Black Duck by Synopsys
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...Black Duck by Synopsys
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating NewsOpen Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating NewsBlack Duck by Synopsys
 

More from Black Duck by Synopsys (20)

Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubFLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical GuideFLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your DealFLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
 
FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
 
Open Source Rookies and Community
Open Source Rookies and CommunityOpen Source Rookies and Community
Open Source Rookies and Community
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
 
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating NewsOpen Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
 

Recently uploaded

Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxRemote DBA Services
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfOrbitshub
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 

Recently uploaded (20)

Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 

It’s No Myth: Compliance Is Good Business

  • 1. © Black Duck 2012 It’s No Myth: Compliance Is Good Business Linux Collaboration Summit, 16 April 2013 Phil Odence, VP Business Development Black Duck @black_duck_sw
  • 2. 2 © Black Duck 2013 Black Duck’s Perspective • Known for services; primarily a software company • Not an open source company per se • Very involved, but most products under commercial licenses • Serving (primarily) commercial companies • Software, Systems, Enterprise IT Organizations • Helping companies manage their use of open source @black_duck_sw
  • 3. 3 © Black Duck 2013 Agenda Goal: To provide a bird’s eye view of open source/FOSS usage and compliance in companies • Evolving Relationship Between Commercial Companies and FOSS • Why open source? • Why comply? • Are they really? • What’s next? @black_duck_sw
  • 4. 4 © Black Duck 2013 First of all… “Software is Eating the World.” Marc Andreessen (Netscape Founder) August ’11, Wall Street Journal And there’s a growing appetite for open source… @black_duck_sw
  • 5. 5 © Black Duck 2013 …with the plate is heaping Source: Ohloh/Black Duck KnowledgeBase 2.7 billion files Nearly 1M de-duplicated projects 10+ million staff years of development 5000+ sites 2,200+ unique software licenses - 500,000.00 1,000,000.00 1,500,000.00 2,000,000.00 2,500,000.00 2006 2008 2010 2012 2014 FOSS Projects Projected Games UI @black_duck_sw
  • 6. 6 © Black Duck 2013 OSS Adoption: Jeff Hammond circa early 2009 @black_duck_sw
  • 7. 7 © Black Duck 2013 Olliance Consulting* Management Maturity Framework Developer driven Business strategy driven Ad Hoc Use Built-in Compliance Informal Guidelines Strategic OSS Use, Commun ity Leadership Explicit Policy, Tracking & Audting Process Automation, Co mmunity Participation OpenSourceAdoption *now a division of Black Duck @black_duck_sw
  • 8. 8 © Black Duck 2013 Industry OSS Adoption ala Geoff Moore Innovators Majority OpenSourceAdoption @black_duck_sw
  • 9. 9 © Black Duck 2013 Jeff Hammond circa late 2010 • OSS goal to means • 80% developers used • Reduced management gap • Don’t ask/tell to strategic • Waned concern about mission critical apps @black_duck_sw
  • 10. 10 © Black Duck 2013 The Chasm is the Stuff of Myth Closed source is the evil empire You are a bunch of wookies If anyone knows we are using open source we’ll have to give up all our code They just want a free ride There’s no way to make money if I give away my software. No one cares about licenses unless they are getting sued Those guys don’t get it. • Chasm: Greek χάος means emptiness, vast void, abyss. Same as for “chaos” • Out of which grew the Chaoskamph myths • Explaining the clash between order and chaos in the world‟s creation • paraphrasing Wikipdia @black_duck_sw
  • 11. 11 © Black Duck 2012 Why open source? Myth: You only love us cause we’re free (as in beer)
  • 12. 12 © Black Duck 2013 Faster, Better, Cheaper Jeffrey Hammond, Forrester Open source is a „silver bullet‟ that allows simultaneous improvement along all three dimensions of the software „iron triangle‟ of cost, schedule, features. Cost FeaturesSchedule @black_duck_sw
  • 13. 13 © Black Duck 2013 A bunch of good reasons… “Open source is ubiquitous, it’s unavoidable….having a policy against open source is impractical and places you at a competitive disadvantage” • Key Benefits • Flexibility • Modify, mix, reuse code • Innovation • Leverage FOSS and community • Cost Optimization • Reduce or eliminate acquisition costs Source: Mark Driver, Gartner Group It’s only #3 @black_duck_sw
  • 14. 14 © Black Duck 2013 30% 80% Average Best in class Company Benefit: Less is More @black_duck_sw
  • 15. 15 © Black Duck 2013 Real World Example “Over 80% of the software in our handsets is open source” Carl-Eric Mols, Head of OSS, Sony Mobile Communications @black_duck_sw
  • 16. 16 © Black Duck 2013 Another: Large Commercial UK Bank Trading Application Delivered a new trading app but only had to do 28% of the work! @black_duck_sw
  • 17. 17 © Black Duck 2013 …and then there’s customer acceptance • DoD CIO Letter… • To effectively achieve its missions, the Department of Defense must develop and update its software-based capabilities faster than ever, to anticipate new threats and respond to continuously changing requirements. The use of Open Source Software (OSS) can provide advantages in this regard. • Unfortunately, there have been misconceptions and misinterpretations of the existing laws, policies and regulations that deal with software and apply to OSS, that have hampered effective DoD use and development of OSS • I have asked the Director, Enterprise Services & Integration, to work with your staffs and identify other barriers to the effective use of open source software within the Department, so we can continue to increase the benefits from the use of OSS FOSS @black_duck_sw
  • 18. 18 © Black Duck 2013 So… • The myth: • It’s all about the “free beer” • The reality: • It’s about: • Flexibility • Innovation • Co-opetition and Community • Recruiting • Support from customers • And, yes, Cost @black_duck_sw
  • 19. 19 © Black Duck 2012 Why Comply? Myth: Companies don’t give a hoot (’cept maybe when they get sued)
  • 20. 20 © Black Duck 2013 Software today is Multi-Source THE ENTERPRISE – TOOLS, PROCESSES Your Software Application Internally Developed Code Commercial 3rd-Party Code Outsourced Code Development OSS Communities Global 2000 organizations increasingly leverage code from a vast array of sources — including internally built, open source, outsourced, commercially built, and customized applications. - Melinda Ballou, IDC (sponsored by Black Duck @black_duck_sw
  • 21. 21 © Black Duck 2013 The Fundamental Challenge “How ya gonna keep ’em down on the farm…?” @black_duck_sw
  • 22. 22 © Black Duck 2013 Management challenges aren’t just legal • Key Benefits • Flexibility • Modify, mix, reuse code • Innovation • Leverage FOSS and community • Cost Optimization • Reduce or eliminate acquisition costs • Challenges • Technical Failure • Operational exposure • Needs to be audited, managed • Security Risks • Business exposure • IP Risks • Legal exposure “Open source is ubiquitous, it’s unavoidable….having a policy against open source is impractical and places you at a competitive disadvantage” Source: Mark Driver, Gartner Group It’s only #3 @black_duck_sw
  • 23. 23 © Black Duck 2013 Managing Open Source = Proper SW Dev Mgmt • “There are plenty of other reasons beyond licensing that I want to understand what’s in our code” • CIO, Large Financial Services Firm • Security • Quality • Supportability • Community • Sarbanes Oxley Act Section 404 says you gotta know what software you got and who owns it • Fortune 500 tech companies- material risk in 10Ks @black_duck_sw
  • 24. 24 © Black Duck 2013 And, if they want to get bought someday… 2009 2010 2011 2012 M&A Audits US Tech Deals OSS Compliance have become routine question in tech M&A Source: Black Duck / 451 Group @black_duck_sw
  • 25. 25 © Black Duck 2013 Free’s not all that free Risk (all sorts) ComplianceProductivity Phil‟s (other) iron triangle No compliance means productive but risky Overly heavy compliance reduces risk, but may squash productivity @black_duck_sw
  • 26. 26 © Black Duck 2013 So… • The myth: • Companies don’t care • And only pay attention to extreme measures • The reality: • Legal fear is a motivator • But companies’ overall risk management agendas align reasonably with open source governance • It’s just not all that simple @black_duck_sw
  • 27. 27 © Black Duck 2012 Who complies? Myth: OK, but most companies don’t comply And, they may talk the talk, but…
  • 28. 28 © Black Duck 2013 Companies invest heavily in compliance @black_duck_sw
  • 29. 29 © Black Duck 2013 In the form of sophisticated governance processes @black_duck_sw
  • 30. 30 © Black Duck 2013 …best practices, training, transformation @black_duck_sw
  • 31. 31 © Black Duck 2013 ..,dedicated review boards and programs Open Source Program Office • Responsible for all open source activities and strategy across the company • Provides continuous training and consulting to HP product and project teams • Encourages contribution to the open source community • Sponsors numerous open source foundations (e.g. ASF, Linux Foundation, OpenStack) and events • Typically review 10 to 20 proposals per week from teams wanting to use and/or contribute to open source • Develops in-house tools to support the review and tracking of open source across the company • Promptly handle any compliance inquiries that come to our attention http://opensource.hp.com @black_duck_sw
  • 32. 32 © Black Duck 2013 ….correct and corresponding code infrastructure “The Internet of objects would encode 50 to 100 trillion objects, and be able to follow the movement of those objects. Human beings surrounded by 1000 to 5000 trackable objects” @black_duck_sw
  • 33. 33 © Black Duck 2013 OK, but do they waddle the waddle? @black_duck_sw
  • 34. 34 © Black Duck 2013 Giving back is a “higher order skill” Engineering driven Business strategy driven Ad Hoc Use Built-in Compliance Informal Guidelines Strategic OSS Use, Commun ity Leadership OpenSourceAdoption *now a division of Black Duck @black_duck_sw Explicit Policy, Tracking & Audting Process Automation, Co mmunity Participation
  • 35. 35 © Black Duck 2013 Companies certainly rock the Kernel • 75% Kernel developers are paid • 800 companies have contributed over time; 200 active as of 2012 • Red Hat, Intel, Novell, IBM, Texas Instruments, Broadcom, Nokia, Samsung, Oracle and Google • Jon Corbet’s 2012 annual report @black_duck_sw
  • 36. 36 © Black Duck 2013 Financial Services Automotive Mobile Aerospace Polarsys Healthcare Community and Co-opetition Mozilla Eclipse Openstack The Foundation The Apache Foundation Networking @black_duck_sw
  • 37. 37 © Black Duck 2013 Automotive may boast the most logos Ford contributes AppLink code to GENIVI Alliance GENIVI License Review Team @black_duck_sw
  • 38. 38 © Black Duck 2013 And … I’m just sayin’ Microsoft is into open… @black_duck_sw
  • 39. 39 © Black Duck 2013 Close to our hearts @black_duck_sw
  • 40. 40 © Black Duck 2013 So… • The myth: • Companies don’t comply • And even if they do they don’t participate • The reality: • Some don’t • Many do • The world’s best companies invest heavily • And, more and more they are walking the walk @black_duck_sw
  • 41. 41 © Black Duck 2012 Looking Forward and Conclusions
  • 42. 42 © Black Duck 2013 Conclusion • The Companies/FOSS has evolved • Corporate usage has crossed the chasm • Companies have good business reasons to manage/comply • The best companies do comply • And are finding good business reasons to give back @black_duck_sw
  • 43. 43 © Black Duck 2013 There may remain a philosophical schism, but... Software is all about delivering shareholder value Software is all about “free” Rather than question motivation, focus on results @black_duck_sw
  • 44. 44 © Black Duck 2013 Check out where it’s going • Key trend toward internal OSS methods – 80% • Open source will make up >50% deployed code – 62% • “Lower Cost” – drops to #7 in importance • Attracting talent – #1 reason to engage • Company’s co-epetition will increase – 57% • 2013 Future of Open Source Survey Results show new trends in OSS • First ever webinar results panel is now available to view on- demand! • #FutureOSS @black_duck_sw

Editor's Notes

  1. JQuery, OpenStack
  2. Geoff Moore
  3. THIRTY MINUTES
  4. 20 MINUTES
  5. 10 MINUTES
  6. Linux top 20, CodePlex, Azure: Drupal,Hadoop, LInux VMs,
  7. PsychologicalEgosim, Idealizm