provides software and services that enable enterprises
Live Chat 1-888-673-6564
The Enterprise Open Source Blog
  • Home
  • Search
  • Source Code Scanning Tools
  • Products and Support
  • Services
  • Cloud Services
  • Open Source Training
  • Enterprise OSS Blog
  • Wazi Technical Blog
  • Resources Library
  • Partners
  • Customers
  • Community
  • Company
  • Careers
  • News and Events
  • Contact Us

Subscribe by Email

Your email:

Most Popular Posts

  • Enterprise Apache Tomcat 7 Clustering - Designing an Efficient, Reliable and Productive Application Server Cluster
  • Open Source Virtual Whiteboards and Dimdim Review
  • An Enterprise Apache Tomcat Clustering Guide
  • Supporting CentOS In The Cloud With Windows Azure
  • Why Closed Source is Better Than Open Source
  • JBoss AS7 Clustering Using mod_cluster and http 2.4 (Part 1)
  • An In-Depth Look at Tomcat’s Clustering Mechanisms
  • VLC License Change: A lesson in perseverance
  • Apache HTTP Server: New Features for Version 2.4
  • Where is JBoss 7.2.0.Final?

Connect With Us!

Current Articles | RSS Feed RSS Feed

Open Source Software 101: Understanding Compliance

Posted by Jon Stroker on Fri, Jul 27, 2012
  
Email This Email Article  
Tweet  
  

Open source software and open source risk management have been widely adopted on the enterprise level since the open source concept’s inception in the 1970s and 80s. In fact, open source has been so widely adopted that many organizations, including yours, may be using it unknowingly. It is not uncommon for organizations of any size to be using open source without any notice, whatsoever.

Take OSS in the mobile arena for example. The data in OpenLogic’s Predictions and Trends Presentation shows that 71% of mobile apps licensed under GPL, Apache, and LGPL (the three most chosen licenses by developers) are not in compliance.

Usage of OSS may be as widespread as it is unknown, but that does not necessarily make its usage ok. This should not be interpreted as a great concern for your organization, but rather recognized as a need for compliance.

What is open source software compliance?

Software compliance is essentially the ability to display that you, or your organization, have met the license terms and requirements of a given software package that were agreed upon at the time of installation. In other words, if you, or your organization, are using more licenses than have been purchased or agreed upon, whether it be unknowingly or in an effort to cut costs, you may be susceptible to legal liability and a court case. It does not necessarily matter if licensed open source software is being physically shipped or not. If you are using it, the open source licenses are legally enforceable and are being enforced. The bottom line is, every organization must be prepared to explain their use of open source software.

It is important to know that open source software is licensed software; the open source licenses are what make the software “open source”. The open source definition, as maintained by the Open Source Initiative, is actually an umbrella idea that encompasses many different licenses. Currently, there are 69 OSI-approved open source licenses, and there are hundreds of other licenses in existence today. A list of the OSI-approved licenses can be found here.

Most Popular Licenses in the Enterprise

Fortunately, there are convenient solutions available to organizations to ensure that they are in compliance with the open source licenses of their software. Source code scanners such as OpenLogic’s free and open source tool OSS Discovery can find the open source software included in internal applications and installed on corporate workstations and servers. OSS Discovery does not require access to source code, so it's ideal for taking inventory of open source in deployed applications or on servers and desktops.

Compliance could be thought of as something that has been required and expected of companies, or it could be thought of differently. There are advantages of compliance. Companies are increasingly using compliance to differentiate themselves from their competitors from a marketing standpoint.

Regardless of your motives, compliance is a great move for any organization.  Take the time to learn more about how your organization is using open source and how you can take steps to begin to comply.  I think you will find that the benefits far outweigh the consequences.

Follow @JonRStroker
Follow @openlogic
Follow @OSCloudServices

This work is licensed under a Creative Commons Attribution 3.0 Unported License
Creative Commons License.
Tags: Legal & Compliance, Scanning & Governance

Comments

Spot on. Subject very much needs engagement and vetting. Lawyers are good folks but sometimes they get in the way of a more organized and open process. Format and website is a great start.Thanks Jon Stroker for sending this out through MIL-OSS which is how I got it. I don't have much time to do blogs and emails but will chime in when I can.
Posted @ Friday, September 14, 2012 9:45 AM by Harley Garrett
I'm glad you enjoyed my article, Harley. Thanks for the kind words.
Posted @ Friday, September 14, 2012 3:08 PM by Jon Stroker
Post Comment
Name
 *
Email
 *
Website (optional)
Comment
 *

Allowed tags: <a> link, <b> bold, <i> italics

Loading...
Error sending email
Email sent successfully

Email article
Email To : 
Your name : 
Message : (maximum 200 characters)

Enterprise OSS Blog Policy

If you read a post on The Enterprise OSS Blog, please leave a comment. Let us know what you think, even if it's just a few words. Comments do not require approval, but they are moderated.OpenLogic reserves the right to remove any comments it deems inappropriate.

 

click-to-chat-with-a-live-open-source-expert

get-a-quote-on-support

download-the-support-evaluation-kit

Browse by Tag

  • 2013 (2)
  • Agile (1)
  • Apache (4)
  • apache tomcat (1)
  • AS 7 (1)
  • as7 (1)
  • Auditing (5)
  • Azure (3)
  • Budget (1)
  • BusyBox (1)
  • CentOS (4)
  • Closed Source Software (1)
  • cloud (5)
  • clustering (1)
  • CMS (1)
  • code (1)
  • Code Scanning (1)
  • commercial distribution (1)
  • Community (6)
  • compliance (41)
  • contribute (2)
  • C-Suite (1)
  • Database (1)
  • developers (2)
  • DevOps (15)
  • diploma (1)
  • Drupal (1)
  • enterprise (2)
  • enterprise software (2)
  • Federation (1)
  • FOSS (5)
  • Gitbhub (1)
  • GNU-Bash (1)
  • Governance (36)
  • guide (1)
  • Hadoop (2)
  • HBase (2)
  • http 2.4 (1)
  • httpd 2.4 (1)
  • Java (1)
  • javascript (1)
  • jboss (3)
  • JBoss Cluster (1)
  • Joomla (1)
  • legal (21)
  • Legal & Compliance (62)
  • Legal and Compliance (2)
  • license compliance (1)
  • Licenses (12)
  • Linux (4)
  • lisp code (1)
  • M&A (1)
  • martin fowler (1)
  • Mobile (3)
  • mod_cluster (2)
  • MySQL (2)
  • Neal Ford (1)
  • Open Source (26)
  • open source compliance (1)
  • open source components (1)
  • open source events (1)
  • Open Source Governance (2)
  • open source legal issues (1)
  • Open Source Licensing (3)
  • Open Source Management (38)
  • Open Source Policy (3)
  • open source software (15)
  • Open Source Software Adoption (4)
  • open source software policy (1)
  • Open Source Training (1)
  • Open Source Trends (337)
  • Open Source vs. Commercial Software (3)
  • OSS (6)
  • OSS Packages (2)
  • PaaS (1)
  • paredit (1)
  • patches (1)
  • picketlink (1)
  • Policy (4)
  • PostgreSQL (1)
  • Presentations (1)
  • Programming (2)
  • red hat (1)
  • RHEL (1)
  • Ruby (1)
  • SAML (1)
  • scanning (28)
  • Scanning & Governance (12)
  • Scanning & Provisioning (30)
  • Security (15)
  • Shibboleth (1)
  • software compliance (1)
  • Software Development (2)
  • Software Development Lifecycle (7)
  • software infrastructure (1)
  • Solr (1)
  • struts (1)
  • support (50)
  • Support & Services (2)
  • SUSE (1)
  • Technical Governance (1)
  • The Cloud (35)
  • The C-Suite (2)
  • tomcat (5)
  • training (10)
  • Ubuntu (1)
  • Uncategorized (69)
  • Windows (2)
  • Windows Azure (1)
  • Wordpress (1)
  • Zookeeper (1)
Home | Search | Source Code Scanning Tools | Products and Support | Services | Cloud Services | Open Source Training | Enterprise OSS Blog | Wazi Technical Blog | Resources Library | Partners | Customers | Community | Company | Careers | News and Events | Contact Us
Products
OpenLogic Exchange (OLEX)
License Compliance Module
OSS Discovery
OSS Deep Discovery
OpenUpdate
Services
Open Source Support
CentOS Support
Scanning & Compliance
Open Source Training
Professional Services
Solutions
Support & Indemnification
Open Source Governance
Open Source Scanning
Open Source Provisioning
Consulting & Training
Contact Us
1-888-673-6564


© 2013 OpenLogic, Inc. All rights reserved.
Site Map  |  Privacy Policy