The3nd OSPOSummit
OpenSource BusinessProcessesand
Standardsin2025
Shane Coughlan
OpenChain General Manager
CONTENTS
The 3nd OSPO Summit
1. A Year of Change
2. Standards
3. Guides
4. The Future
Part 01
1. A Year of Change
2025 is not 2020
The 3nd OSPO Summit
Business
• The question is “how do we use open platforms to save money?”
• Process Management is the future
Regulations
• Cyber Resilience Act in Europe
• Product Liability Act in Europe
• AI Act in Europe
• Minimum Requirements for SBOM in USA
Part 02
1. Standards
OpenChain and More
The 3nd OSPO Summit
OpenChain
• ISO/IEC 5230 = License Compliance Process Management
• ISO/IEC 18974 = Security Assurance Process Management
SPDX
• ISO/IEC 5962 = A Format For SBOM
Software Heritage
• ISO/IEC 18670 = A Long-Term Software Identifier
Part 03
1. Guides
SBOM Quality
AI Compliance
The 3nd OSPO Summit
New Areas
• What is an SBOM that helps me with all the regulations? SBOM Quality.
• How do I deal with all the AI in the supply chain? AI Compliance.
New Solutions
• OpenChain Telco SBOM Guide – SBOM Quality
• OpenChain Cross-Industry SBOM Quality Guide (draft)
• OpenChain AI BOM Compliance in the Supply Chain (draft)
The 3nd OSPO Summit
SBOM Quality AI Compliance
Part 04
1. The Future
More Processes?
The 3nd OSPO Summit
Business Strategy Focus
• Everything needs to show reduced cost or increased revenue.
All Business Departments
• Ownership is company-wide
• Less special teams
• More company culture
The 3nd OSPO Summit
Thank you for
watching

The 3rd OSPO Summit - China (Beijing - 2025-06-12)

  • 1.
  • 2.
    CONTENTS The 3nd OSPOSummit 1. A Year of Change 2. Standards 3. Guides 4. The Future
  • 3.
    Part 01 1. AYear of Change 2025 is not 2020
  • 4.
    The 3nd OSPOSummit Business • The question is “how do we use open platforms to save money?” • Process Management is the future Regulations • Cyber Resilience Act in Europe • Product Liability Act in Europe • AI Act in Europe • Minimum Requirements for SBOM in USA
  • 5.
  • 6.
    The 3nd OSPOSummit OpenChain • ISO/IEC 5230 = License Compliance Process Management • ISO/IEC 18974 = Security Assurance Process Management SPDX • ISO/IEC 5962 = A Format For SBOM Software Heritage • ISO/IEC 18670 = A Long-Term Software Identifier
  • 7.
    Part 03 1. Guides SBOMQuality AI Compliance
  • 8.
    The 3nd OSPOSummit New Areas • What is an SBOM that helps me with all the regulations? SBOM Quality. • How do I deal with all the AI in the supply chain? AI Compliance. New Solutions • OpenChain Telco SBOM Guide – SBOM Quality • OpenChain Cross-Industry SBOM Quality Guide (draft) • OpenChain AI BOM Compliance in the Supply Chain (draft)
  • 9.
    The 3nd OSPOSummit SBOM Quality AI Compliance
  • 10.
    Part 04 1. TheFuture More Processes?
  • 11.
    The 3nd OSPOSummit Business Strategy Focus • Everything needs to show reduced cost or increased revenue. All Business Departments • Ownership is company-wide • Less special teams • More company culture
  • 12.
    The 3nd OSPOSummit Thank you for watching