SlideShare a Scribd company logo
© Jim Markwith 2015. All Rights Reserved.
1
Developing Mixed-Source Commercial Products:
Open Source Software Risks and Mitigation
By: Jim Markwith, Esq.
© Jim Markwith 2015. All Rights Reserved.
2
Biographical Information
Title: Developing Mixed-Source Commercial Products:
Open Source Software Risks and Mitigation
Author: Jim Markwith, Esq., Managing Partner, Symons
Markwith LLP, Seattle, WA.
Phone: +1-206-714-6003
E-Mail: Jimmarkwith@gmail.com
Jim Markwith is the Co-founder and Managing Partner of
Symons Markwith LLP’s Seattle office. His clients represent
a range of industries and offerings, including healthcare IT,
computer software, data analytics, standards development
organizations (SDOs), and other emerging technologies and
services. He specializes in technology and intellectual
property transactions, establishing end-to-end contracting
processes, supporting healthcare IT and cloud-based product
development, HIPAA and privacy compliance, open source
software use and compliance, and M&A.
Prior to private practice he served as Senior Vice President
and Chief IP Counsel for Allscripts Healthcare, and held
senior in-house legal positions with Microsoft, GE
Healthcare IT and Adobe Systems. He is an Adjunct
Professor at the Law School Graduate Program in Intellectual
Property (LLM) at the University of Washington. Prior to his
legal career Jim was a U.S. Navy Pilot.
Education: J.D., Santa Clara University School of Law;
B.S.B.A., Finance, California State University at Long
Beach.
Bar Admissions: California; Washington State; District of
Columbia.
© Jim Markwith 2015. All Rights Reserved.
3
Introduction
This paper provides an overview of open source software
(“OSS”) from a legal and developer’s perspective, discusses
risks associated with non-compliant use of OSS, including
use in the Cloud, and provides recommendations to mitigate
risks.
Using Third-party Software during Development
During the product development life cycle, developers must
decide what functionality they will develop in-house, and
what they will buy or license from third parties. That buy v.
build decision should take into account not only the cost of
the third-party code, but other important considerations as
well, including the code quality, security vulnerabilities, and
intellectual property related risks, associated with the
particular third-party code.
Open Source Software Defined
From a software developer’s perspective, OSS should be
viewed simply as a subset of third-party software. This view
is helpful because most developers know that they should not
use third-party software without permission, which is
typically in the form of a license. As with proprietary
software1, the license associated with the particular OSS
must be reviewed in order to understand the rights and
conditions that may apply to the use of that particular code.
1
“Proprietarysoftware” is software that is subject to licenses that typically restrict the
licensee’s right tocopy, redistribute, or modify the software, and normally do not grant
access to the software’s source code. These restrictions help to protect the developer’s
investment in the software by preventingthird parties from expropriating the software’s
economic value without the developer’s authorization. See also:
http://en.wikipedia.org/wiki/Proprietary_software

More Related Content

Viewers also liked

IAPA News 463
IAPA News 463IAPA News 463
IAPA News 463
Sip Sipiapa
 
Mariela Briceno HERRAMIENTAS DIGITALES
Mariela Briceno HERRAMIENTAS DIGITALESMariela Briceno HERRAMIENTAS DIGITALES
Mariela Briceno HERRAMIENTAS DIGITALES
Sip Sipiapa
 
леонтьев
леонтьевлеонтьев
леонтьев
savinovama
 
Present continuous
Present continuousPresent continuous
Present continuoustellomar
 
491
491491
Понятие педагогической направленности, Ворошилова Елена,16 группа.
 Понятие педагогической направленности, Ворошилова Елена,16 группа. Понятие педагогической направленности, Ворошилова Елена,16 группа.
Понятие педагогической направленности, Ворошилова Елена,16 группа.AlenaVoroshilova
 
AMIRA FOODS
AMIRA FOODS AMIRA FOODS
AMIRA FOODS
amirasnacks
 
New presentation
New presentationNew presentation
New presentationteejankirby
 

Viewers also liked (9)

Bvs
Bvs Bvs
Bvs
 
IAPA News 463
IAPA News 463IAPA News 463
IAPA News 463
 
Mariela Briceno HERRAMIENTAS DIGITALES
Mariela Briceno HERRAMIENTAS DIGITALESMariela Briceno HERRAMIENTAS DIGITALES
Mariela Briceno HERRAMIENTAS DIGITALES
 
леонтьев
леонтьевлеонтьев
леонтьев
 
Present continuous
Present continuousPresent continuous
Present continuous
 
491
491491
491
 
Понятие педагогической направленности, Ворошилова Елена,16 группа.
 Понятие педагогической направленности, Ворошилова Елена,16 группа. Понятие педагогической направленности, Ворошилова Елена,16 группа.
Понятие педагогической направленности, Ворошилова Елена,16 группа.
 
AMIRA FOODS
AMIRA FOODS AMIRA FOODS
AMIRA FOODS
 
New presentation
New presentationNew presentation
New presentation
 

Similar to Developing Mixed-Source Commercial Products - OSS Risks and Mitigation

SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
South Tyrol Free Software Conference
 
Security Testing for Test Professionals
Security Testing for Test ProfessionalsSecurity Testing for Test Professionals
Security Testing for Test Professionals
TechWell
 
Lawyers and Licenses in Open Source-based Development: How to Protect Your So...
Lawyers and Licenses in Open Source-based Development: How to Protect Your So...Lawyers and Licenses in Open Source-based Development: How to Protect Your So...
Lawyers and Licenses in Open Source-based Development: How to Protect Your So...
Sonatype
 
Open Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated CompaniesOpen Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated Companies
iasaglobal
 
Security Testing for Test Professionals
Security Testing for Test ProfessionalsSecurity Testing for Test Professionals
Security Testing for Test ProfessionalsTechWell
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
TechWell
 
Security Testing for Test Professionals
Security Testing for Test ProfessionalsSecurity Testing for Test Professionals
Security Testing for Test Professionals
TechWell
 
Owasp_Security_Labeling_System
Owasp_Security_Labeling_SystemOwasp_Security_Labeling_System
Owasp_Security_Labeling_SystemluisenriquezA
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
TechWell
 
Open source software license
Open source software licenseOpen source software license
Open source software license
aakash malhotra
 
I\'m Not an IT Lawyer: Why Does Open Source Matter to Me?
I\'m Not an IT Lawyer: Why Does Open Source Matter to Me?I\'m Not an IT Lawyer: Why Does Open Source Matter to Me?
I\'m Not an IT Lawyer: Why Does Open Source Matter to Me?
Jennifer O'Neill
 
Open source technology
Open source technologyOpen source technology
Open source technologyRohit Kumar
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
TechWell
 
Strategies for Commercial Software Developers Using Open Source Code in Propr...
Strategies for Commercial Software Developers Using Open Source Code in Propr...Strategies for Commercial Software Developers Using Open Source Code in Propr...
Strategies for Commercial Software Developers Using Open Source Code in Propr...
Mary Lou Wakimura
 
Open Source Software: What Are Your Obligations?
Open Source Software: What Are Your Obligations? Open Source Software: What Are Your Obligations?
Open Source Software: What Are Your Obligations?
Source Code Control Limited
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
TechWell
 
Unlocking Efficiency: Choosing the Perfect Company Secretary Software
Unlocking Efficiency: Choosing the Perfect Company Secretary SoftwareUnlocking Efficiency: Choosing the Perfect Company Secretary Software
Unlocking Efficiency: Choosing the Perfect Company Secretary Software
Smoooth Biz Limited
 
Implementing and Managing an Open Source Compliance Program: A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash CourseImplementing and Managing an Open Source Compliance Program: A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash Course
FINOS
 
Implementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing Open Source Compliance Programs - A Crash CourseImplementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing Open Source Compliance Programs - A Crash Course
Open Source Strategy Forum
 

Similar to Developing Mixed-Source Commercial Products - OSS Risks and Mitigation (20)

SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
 
Security Testing for Test Professionals
Security Testing for Test ProfessionalsSecurity Testing for Test Professionals
Security Testing for Test Professionals
 
Lawyers and Licenses in Open Source-based Development: How to Protect Your So...
Lawyers and Licenses in Open Source-based Development: How to Protect Your So...Lawyers and Licenses in Open Source-based Development: How to Protect Your So...
Lawyers and Licenses in Open Source-based Development: How to Protect Your So...
 
Open Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated CompaniesOpen Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated Companies
 
Security Testing for Test Professionals
Security Testing for Test ProfessionalsSecurity Testing for Test Professionals
Security Testing for Test Professionals
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
 
Security Testing for Test Professionals
Security Testing for Test ProfessionalsSecurity Testing for Test Professionals
Security Testing for Test Professionals
 
Owasp_Security_Labeling_System
Owasp_Security_Labeling_SystemOwasp_Security_Labeling_System
Owasp_Security_Labeling_System
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
 
Open source software license
Open source software licenseOpen source software license
Open source software license
 
I\'m Not an IT Lawyer: Why Does Open Source Matter to Me?
I\'m Not an IT Lawyer: Why Does Open Source Matter to Me?I\'m Not an IT Lawyer: Why Does Open Source Matter to Me?
I\'m Not an IT Lawyer: Why Does Open Source Matter to Me?
 
Anajli_Synopsis
Anajli_SynopsisAnajli_Synopsis
Anajli_Synopsis
 
Open source technology
Open source technologyOpen source technology
Open source technology
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
 
Strategies for Commercial Software Developers Using Open Source Code in Propr...
Strategies for Commercial Software Developers Using Open Source Code in Propr...Strategies for Commercial Software Developers Using Open Source Code in Propr...
Strategies for Commercial Software Developers Using Open Source Code in Propr...
 
Open Source Software: What Are Your Obligations?
Open Source Software: What Are Your Obligations? Open Source Software: What Are Your Obligations?
Open Source Software: What Are Your Obligations?
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
 
Unlocking Efficiency: Choosing the Perfect Company Secretary Software
Unlocking Efficiency: Choosing the Perfect Company Secretary SoftwareUnlocking Efficiency: Choosing the Perfect Company Secretary Software
Unlocking Efficiency: Choosing the Perfect Company Secretary Software
 
Implementing and Managing an Open Source Compliance Program: A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash CourseImplementing and Managing an Open Source Compliance Program: A Crash Course
Implementing and Managing an Open Source Compliance Program: A Crash Course
 
Implementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing Open Source Compliance Programs - A Crash CourseImplementing and Managing Open Source Compliance Programs - A Crash Course
Implementing and Managing Open Source Compliance Programs - A Crash Course
 

Recently uploaded

Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
Knowyourright
 
Bharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptxBharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptx
ShivkumarIyer18
 
Understanding about ITR-1 and Documentation
Understanding about ITR-1 and DocumentationUnderstanding about ITR-1 and Documentation
Understanding about ITR-1 and Documentation
CAAJAYKUMAR4
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
akbarrasyid3
 
ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.
Daffodil International University
 
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
anjalidixit21
 
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
CIkumparan
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
9ib5wiwt
 
Tax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th semTax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th sem
azizurrahaman17
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
MattGardner52
 
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Syed Muhammad Humza Hussain
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
9ib5wiwt
 
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Massimo Talia
 
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
o6ov5dqmf
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
PelayoGilbert
 
Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
Trademark Quick
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
BridgeWest.eu
 
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdfXYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
bhavenpr
 
new victimology of indonesian law. Pptx.
new victimology of indonesian law. Pptx.new victimology of indonesian law. Pptx.
new victimology of indonesian law. Pptx.
niputusriwidiasih
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
9ib5wiwt
 

Recently uploaded (20)

Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
 
Bharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptxBharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptx
 
Understanding about ITR-1 and Documentation
Understanding about ITR-1 and DocumentationUnderstanding about ITR-1 and Documentation
Understanding about ITR-1 and Documentation
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
 
ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.
 
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
 
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
 
Tax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th semTax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th sem
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
 
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
 
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
 
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
 
Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
 
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdfXYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
 
new victimology of indonesian law. Pptx.
new victimology of indonesian law. Pptx.new victimology of indonesian law. Pptx.
new victimology of indonesian law. Pptx.
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
 

Developing Mixed-Source Commercial Products - OSS Risks and Mitigation

  • 1. © Jim Markwith 2015. All Rights Reserved. 1 Developing Mixed-Source Commercial Products: Open Source Software Risks and Mitigation By: Jim Markwith, Esq.
  • 2. © Jim Markwith 2015. All Rights Reserved. 2 Biographical Information Title: Developing Mixed-Source Commercial Products: Open Source Software Risks and Mitigation Author: Jim Markwith, Esq., Managing Partner, Symons Markwith LLP, Seattle, WA. Phone: +1-206-714-6003 E-Mail: Jimmarkwith@gmail.com Jim Markwith is the Co-founder and Managing Partner of Symons Markwith LLP’s Seattle office. His clients represent a range of industries and offerings, including healthcare IT, computer software, data analytics, standards development organizations (SDOs), and other emerging technologies and services. He specializes in technology and intellectual property transactions, establishing end-to-end contracting processes, supporting healthcare IT and cloud-based product development, HIPAA and privacy compliance, open source software use and compliance, and M&A. Prior to private practice he served as Senior Vice President and Chief IP Counsel for Allscripts Healthcare, and held senior in-house legal positions with Microsoft, GE Healthcare IT and Adobe Systems. He is an Adjunct Professor at the Law School Graduate Program in Intellectual Property (LLM) at the University of Washington. Prior to his legal career Jim was a U.S. Navy Pilot. Education: J.D., Santa Clara University School of Law; B.S.B.A., Finance, California State University at Long Beach. Bar Admissions: California; Washington State; District of Columbia.
  • 3. © Jim Markwith 2015. All Rights Reserved. 3 Introduction This paper provides an overview of open source software (“OSS”) from a legal and developer’s perspective, discusses risks associated with non-compliant use of OSS, including use in the Cloud, and provides recommendations to mitigate risks. Using Third-party Software during Development During the product development life cycle, developers must decide what functionality they will develop in-house, and what they will buy or license from third parties. That buy v. build decision should take into account not only the cost of the third-party code, but other important considerations as well, including the code quality, security vulnerabilities, and intellectual property related risks, associated with the particular third-party code. Open Source Software Defined From a software developer’s perspective, OSS should be viewed simply as a subset of third-party software. This view is helpful because most developers know that they should not use third-party software without permission, which is typically in the form of a license. As with proprietary software1, the license associated with the particular OSS must be reviewed in order to understand the rights and conditions that may apply to the use of that particular code. 1 “Proprietarysoftware” is software that is subject to licenses that typically restrict the licensee’s right tocopy, redistribute, or modify the software, and normally do not grant access to the software’s source code. These restrictions help to protect the developer’s investment in the software by preventingthird parties from expropriating the software’s economic value without the developer’s authorization. See also: http://en.wikipedia.org/wiki/Proprietary_software