APPS-9 Open-Source Licensing

Estimated reading: 2 minutes 1227 views

What is APPS-9 Open-Source Licensing Control about?

Open-Source Licensing Control is about making sure that your organization is keeping track of all the licenses in use and has a formal way to track them.
The use of openly developed component software has only increased, and developers around the world use open-source tools to make their lives easier and accelerate the pace of innovation.
Open-source license management is critical to safeguarding your code, software, and applications, as well as reducing financial and legal risk for your organization.
Software license management gives you transparency into your enterprise’s software assets, usage, licenses, and contracts so that you can understand what software is being used, how much, where, and by whom.
The way to track is not mandatory; it can be formal (a tool) or informal (Excel).

Available tools in the marketplace

The following listing is “crowdsourced” from our customer base or from external research. TrustCloud does not personally recommend any of the tools below, as we haven’t used them.

Tools
SnipeIT
OpenLM
Fossology

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version:

  • N/A template for this section

Control implementation

To implement this control,

  1. Tracking your organization’s open source licenses can be formal via a tool or informal via Excel.
  2. At a minimum, the following should be included in the tracking software or document:
    1. List all the vendors and the system owner.
    2. List out any license certificates and license usage purchased.
    3. Document the agreement dates.
  3. Once the inventory is in place, keep the list updated.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Provide the open-source licensing inventory export from a tool or Excel document.

Evidence example

For the suggested action, an example is provided below:

  1. Provide the open-source licensing inventory export from a tool or Excel document.
    The following screenshot shows the Open Source licensing inventory export report by snyk, here is the source.
    APPS 9 Open Source Licensing

Join the conversation

ON THIS PAGE
SHARE THIS PAGE

SUBSCRIBE
FlightSchool
OR