Course Outline
Introduction to Open Source Software (OSS) Management
- Defining OSS and its role in enterprise environments
- Benefits and risks of OSS adoption
- Case studies of OSS successes and failures
Establishing an OSS Policy
- Key components of an OSS governance framework
- Roles and responsibilities in OSS management
- Balancing innovation with risk mitigation
Understanding Licensing and Compliance
- Common open-source licenses and obligations
- Managing license compatibility
- Avoiding license violations
Software Bill of Materials (SBOM)
- What is an SBOM and why it matters
- Creating and maintaining an SBOM
- Industry standards and regulatory requirements
Software Composition Analysis (SCA) Tools
- Overview of SCA tools and features
- Integrating SCA into CI/CD pipelines
- Identifying and mitigating vulnerabilities
Security and Risk Management in OSS
- Monitoring OSS supply chains for threats
- Responding to OSS vulnerabilities
- Best practices for patch management
Operationalizing OSS Management
- Integrating OSS management into IT operations
- Establishing ongoing monitoring and reporting
- Building a culture of responsible OSS use
Summary and Next Steps
Requirements
- An understanding of software development processes
- Experience with project or IT management
- Familiarity with security and compliance considerations
Audience
- IT managers
- Security and compliance officers
- Software development team leads
Testimonials (5)
The fact that there were practical examples with the content
Smita Hanuman - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Speed of response and communication
Bader Bin rubayan - Lean Business Services
Course - ISO/IEC 27001 Lead Implementer
The trainer was extremely clear and concise. Very easy to understand and absorb the information.
Paul Clancy - Rowan Dartington
Course - CGEIT – Certified in the Governance of Enterprise IT
The trainer was very motivated and knowledgeable. The trainer was not only capable of information transfer, she also brought it with humor to lighten the dry theoretical training subject.
Marco van den Berg - ZiuZ Medical B.V.
Course - HIPAA Compliance for Developers
I genuinely enjoyed the real examples of the trainer.