After the Log4j security incident, the U.S. government decided to get more involved cybersecurity and particularly open source software security. In this video, learn about the OSS Security Mobilization Plan, which includes 10 key initiatives to keep open source software secure.
This video is from the webinar, “Open Source Security and Compliance: What Organizations Need to Know” that took place on March 23, 2023. It features Javier Perez, Chief OSS Evangelist and Senior Director of Product Management at Perforce Software.
Watch the complete webinar here: https://ter.li/xc2d7h
- -
About OpenLogic by Perforce:
OpenLogic offers end-to-end enterprise support for organizations using open source software in their infrastructure. With support for over 400 open source packages, guaranteed SLAs, and direct access to highly experienced Enterprise Architects, OpenLogic customers benefit from 24x7 ticket-based technical support, professional services, and training.
Follow OpenLogic on LinkedIn, Twitter, and don’t forget to subscribe to our YouTube channel for more videos on all things open source!
- -
Transcript (lightly edited for clarity):
So I said, as a result of those initiatives and the working groups that came from the White House meeting and then the executive order, they came up with a plan with 10 streams of work, 10 initiatives. These are the first five, what you see there on the screen. This was driven by the Linux Foundation, and the OpenSSF, Open Software Security Foundation, with input from representatives from some of the top technology companies, the likes of Google and Microsoft and IBM and others. And for each one of these initiatives, they actually are getting funded. These large organizations and also the government are putting money there to go and address these issues, which means hiring developers, hiring engineers to work on it, assigning resources to it, to do it right, to focus on this.
I recommend reading the complete document, which is called the OSS Security Mobilization Plan, which gives you details on all these initiatives. This was published last year and we're starting to see some good results. We're starting to see some deliveries, some releases on some of these things. So just to mention a couple of them really quickly:
Digital signatures. There's the open source technology to address that and this is about encouraging open source software contributors to use digital signatures.
Assessing the risk of the top 10,000 Open Source projects. That's something that is ongoing.
Coordinated public disclosure and code reviews of the 200 most critical Open Source software. First they identified which ones are the most critical, and then they are going through those reviews.
SBOMs: Software Bill of Materials. This stream of work is to make sure that we are consistent on those formats and most importantly, for everyone to adopt the generation of SBOMs as standard practice.