Vladimir Slavov, Bosch

Vladimir Slavov

Across industries, more than half of the software used is now open source (OSS). This includes both OSS in a company’s own developed products, and OSS in components provided by suppliers. The shift towards OSS has led to an ever increasing demand for license compliance, security assurance, and software bills of material (SBOMs). In addition to that, the need for supply chain visibility required to address security issues will only become more crucial with the introduction of the EU’s Cyber Resilience Act.

To deal with these challenges, organizations can adopt the ISO standards developed within the OpenChain community, namely 5230:2020 for license compliance and 18974:2023 for security assurance. This talk will highlight where to start and how you can get involved in the OpenChain community.

Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)