FOSS Compliance Certification Program

Slides:



Advertisements
Similar presentations
MONITORING OF SUBGRANTEES
Advertisements

The ISO 9002 Quality Assurance Management System
ISO 9000 Quality Management Systems Program Evaluation and Audit Verl ‘Andy’ Anders 1, Merle Pochop 2, Chad M. Laux 3 1 Industrial Specialist, Center for.
IAQG OPMT OP Assessor Training Oversight Assessment of Training Provider Approval Bodies February 2015 Module 14.
BSBPMG408A Apply Contract and Procurement Procedures Apply Contract and Procurement Procedures Unit Guide C ertificate IV in Project Management Qualification.
Purpose of the Standards
ISO 9000:2000 Quality system standards adopted in 1987 by International Organization for Standardization; revised in 1994 and 2000 Technical specifications.
Fundamentals of ISO.
Internal Auditing and Outsourcing
NVLAP Overview and Accreditation Process March 2006.
CHAPTER 5 Infrastructure Components PART I. 2 ESGD5125 SEM II 2009/2010 Dr. Samy Abu Naser 2 Learning Objectives: To discuss: The need for SQA procedures.
Verification: Quality Assurance in Assessment Verification is the main quality assurance process associated with assessment systems and practice - whether.
Roles and Responsibilities
1 CT DDS Quality Service Review Connecticut Community Providers Association Presented by Fred Balicki, DDS Quality Management Services May 27, 2008.
Understanding Meaning and Importance of Competency Based Assessment
BSBPMG405A Apply Human Resource Management Approaches Apply Human Resource Management Approaches Unit Guide C ertificate IV in Project Management
1 Thank you for visiting our site and welcome to the “Introduction to ISO 22000” Presentation that you requested. For more information.
1 Implementing a Business Management System compliant to ISO 9001:2000.
Programme Objectives Analyze the main components of a competency-based qualification system (e.g., Singapore Workforce Skills) Analyze the process and.
AET0012PPT by Dr. Anwar El-Tawil Dr. Anwar El-Tawil Director ISO Programme for Developing Countries QUALITY MANAGEMENT SYSTEM ACCORDING TO.
QUALITY MANAGEMENT STATEMENT
Michael Campe U.S. Army Aviation and Missile Command NDIA TID Technical Information Division Symposium Royal Sonesta Hotel, New Orleans, LA August 2003.
SAM-101 Standards and Evaluation. SAM-102 On security evaluations Users of secure systems need assurance that products they use are secure Users can:
Unit-5 Introduction to IS/ISO 9004:2000 – quality management systems – guidelines for performance improvements. Presented by N.Vigneshwari.
BSBPMG408A Apply Contract and Procurement Procedures Apply Contract and Procurement Procedures Unit Guide C ertificate IV in Project Management Qualification.
Employee Orientation to ISO Sygnetics, Inc. is committed to quality. ‘Quality’ is the ability to consistently produce a product or service that.
CMMI Certification - By Global Certification Consultancy.
28 June 2016 | Proprietary and confidential information. © Mphasis 2013 Audit and its classifications Mar-2016 Internal Auditor Training.
What is ISO Certification? Information is a valuable asset that can make or break your business. When properly managed it allows you to operate.
ISO Certification For Laboratory Accreditation ISO Certification For Laboratory Accreditation.
ISO 9001: 2015 BUSINESS PROCESS IMPLEMENTATION GENERAL AWARENESS
Centre for Development of Advanced Computing Chennai 103/1/12 Open Source Compliance Program Vidhyalakshmi A CDAC chennai
What is ISO? ISO is that the world’s largest developer of voluntary International Standards. International Standards provide state of the art specifications.
BSBPMG404A Apply Quality Management Techniques Apply Quality Management Techniques Unit Guide C ertificate IV in Project Management Qualification.
FOSS Compliance Certification Program The Linux Foundation.
UNDERSTANDING ISO 9001:2008.
Transitional ISO 9001:2015 Internal Audit
WRTVC INTERNATIONAL GUIDELINES Requirements for
OpenChain Meeting 2/3/15.
NIEP Evaluation PO&A “How-to” Guide and Issue Classification
Organisation Control KPI’s & an industry Review
Student Support Study Methodology Training
Data Minimization Framework
Introduction to Promoting Positive Behavior in Schools:
Data Architecture World Class Operations - Impact Workshop.
How to Survive an External Quality Assessment
MANAGING HUMAN RESOURCES
Auditor Training Module 1 – Audit Concepts and Definitions
Iowa Teaching Standards & Criteria
Service Organization Control (SOC)
Fundamentals of ISO.
UNIT V QUALITY SYSTEMS.
Построение культуры integrity в компании Aнар Каримов партнёр «ЭКВИТА»
. . . key messages for CAEs, Senior Management and the Board
Regulatory Binder: Maintaining Essential Study Documentation
[INSERT APPLICABLE REGIONAL ENTITY NAME/LOGO]
[INSERT APPLICABLE REGIONAL ENTITY NAME/LOGO]
Lockheed Martin Canada’s SMB Mentoring Program
Purpose of Ethical Standards
Introduction to CPD Quality Assurance
Ethics as Culture key elements
Introduction to ISO & The Quality Process.
Chapter # 8 Quality Management Standards
How to conduct Effective Stage-1 Audit
QA Reviews Lecture # 6.
Eloise Forster, Ed.D. Foundation for Educational Administration (FEA)
GSBPM AND ISO AS QUALITY MANAGEMENT SYSTEM TOOLS: AZERBAIJAN EXPERIENCE Yusif Yusifov, Deputy Chairman of the State Statistical Committee of the Republic.
Ethics as Culture key elements
TLQAA STANDARDS & TOOLS
HR AUDIT (An Early Evaluation System) (An Early Evaluation System) S.Jayaprakash., M.Sc (IT), PGD.HRM, DLL & AL.
Presentation transcript:

FOSS Compliance Certification Program 2018/9/7 2018/9/7 FOSS Compliance Certification Program The Linux Foundation 1

Basic elements of a certification program 2018/9/7 Basic elements of a certification program A purpose or motivation for certification Sponsors or customers that require suppliers to be certified A standard or reference model to certify against A certification or appraisal methodology and trained appraisers A certificate designating the supplier’s certification achievement 2

Certification is based on a key principle 2018/9/7 Certification is based on a key principle Process matters: A repeatable and systematic compliance process is required to achieve FOSS compliance consistently and routinely Certification appraises a supplier’s process as a predictor of eventual compliance success. Certification addresses conformance to a standard rather than business efficiency Appraisals certify that process goals have been achieved rather than that specific practices and/or tools are used The Linux Foundation Confidential 3

Open Certification Proposal 2018/9/7 Open Certification Proposal Reference model Grounded in Self-Assessment Checklist Proposes 6 compliance goals: G1. Everyone knows their FOSS responsibilities G2. Responsibility for achieving compliance is assigned G3. FOSS content (packages/licenses) is known G4. FOSS content is reviewed and approved G5. FOSS obligations are satisfied G6. Community contributions are encouraged At least two possible certification approaches , based on goals and sub-goals: Multi-level: Initial, Basic, Advanced Single level: Certified, Uncertified Community consensus will be needed about the reference model The Linux Foundation Confidential 4

Certification appraisal methodology 2018/9/7 Certification appraisal methodology On-site appraisal involving interviews and examination of evidence The Self-Assessment Checklist will provide the primary guide for interviews and data collection Responses  Goal/Sub-goal satisfaction  Certification level Other appraisers (in addition to LF) could be trained and authorized to conduct certification appraisals The Linux Foundation Confidential 5

Back-up: Reference Model 2018/9/7 Back-up: Reference Model The Linux Foundation Confidential 6

G1. Everyone knows their FOSS responsibilities 2018/9/7 Goal G1. Everyone knows their FOSS responsibilities SP1.1 FOSS policy exists SP1.2 FOSS compliance training program actively used Supporting practices

G2. Responsibility for achieving compliance is assigned 2018/9/7 Goal G2. Responsibility for achieving compliance is assigned SP2.1 FOSS Compliance Officer exists SP2.2 Compliance management activity is resourced Supporting practices SP2.3 Licensing expertise is available SP2.2.1 Processes, procedures, templates, forms, etc. are developed SP2.2.2 Compliance tool needs are identified SP2.2.3 Compliance tools are evaluated, developed or acquired, and deployed

G3. FOSS content (packages/licenses) is known 2018/9/7 Goal G3. FOSS content (packages/licenses) is known SP3.1 Code audits/scans are conducted SP3.2 Supplier compliance is managed Supporting practices SP3.3 FOSS records are maintained SP3.2.1 Supplier compliance practices are assessed SP3.2.2 Supplier FOSS disclosures are made and reviewed SP3.2.3 Supplier FOSS obligations are satisfied

G4. FOSS content is reviewed and approved 2018/9/7 Goal G4. FOSS content is reviewed and approved SP4.1 OSRB exists and is staffed appropriately SP4.2 Planned FOSS use is reviewed in context Supporting practices SP4.3 License obligations are identified, understood, and documented SP4.4 Issues are resolved and approval decisions are followed

G5. FOSS obligations are satisfied 2018/9/7 Goal G5. FOSS obligations are satisfied SP5.1 Documentation obligations are met SP5.2 Source code obligations are met Supporting practices SP5.3 Community interface exists SP5.3.1 Email and postal addresses work SP5.3.2 Web portal works SP5.3.3 Community requests and inquiries are satisfied

G6. Community contributions are encouraged 2018/9/7 Goal G6. Community contributions are encouraged SP6.1 Individual contributions are reviewed and approved SP6.2 Company contributions are reviewed and approved Supporting practices