By Jack M. Germain LinuxInsider Part of the ECT News Network
01/24/08 4:00 AM PT
Traditional corporate policies for managing software assets are often inadequate to address the unique characteristics of free and open source software, according to HP officials. During a recent customer engagement, for example, HP discovered three times as many FOSS licenses as the client originally thought it held, totaling 75 versus 25.
Is Your Website Killing Customer Confidence? Your Website's privacy policy can be a key factor in a customer's decision to do business with you, and it is vital to ensuring you don't run afoul of your online legal and regulatory responsibilities. Need more reasons? Read on.
HP (NYSE: HPQ) announced Thursday a three-part software governance initiative to help companies address the legal, financial and security demands associated with using free and open source software (FOSS).
The company is donating its intellectual property for monitoring open source products to a new open source community. It is also founding a new organization designed to further educate users about the licensing demands and legal issues surrounding open source software.
The third component of the governance initiative is an expansion of HP's existing consulting services. The company will provide contracted services to enterprises seeking help in identifying open source software and dealing with the license requirements.
"There is a growing need for companies to monitor their use of software containing open source elements. Some software developers ship their products without adequate disclosure of open source. Other software developers do notify their customers," Doug Small, director of marketing for HP's open source and Linux Organization, told LinuxInsider.
The problem, he said, involves both software based completely on open source and products that have open source components embedded in them. Open source is easy to obtain and often bypasses a company's regular acquisition procedures, leading to compliance issues.
Proprietary Giveaway
HP has been developing its own internal mechanisms for monitoring and regulating open source software over the last six years, said Small. That process evolved into software tools to identify open source code and licensing content.
HP is contributing these tools to a community it created around its FOSSology Web site, which went live earlier this week. FOSSology is based on the tools HP uses to effectively manage its own use of free and open source software.
This new community is designed to help users address deployment issues such as the acquisition, tracking and licensing of FOSS. FOSSology's flexible and open architecture framework, along with detection agents, can help users discover FOSS and related licenses within their own organizations. This tool set is free and downloadable from FOSSology.org for immediate use under the General Public License (GPL) version two.
"We see doing this as table stakes. It is our obligation to contribute to the open source community. That's how the open source model works," said Small. "The second reason for our donating our intellectual property is to create more demand from customers for our consulting services."
Learning Curve
FOSSBazaar is a second part of HP's new community initiatives for open source growth. It makes HP's expertise freely available to the software community as part of a collaborative effort with industry-leading software vendors and the Linux Foundation. Coverity, DLA Piper, Google (Nasdaq: GOOG), Novell (Nasdaq: NOVL), Olliance Group, OpenLogic and SourceForge have joined HP to offer online resources, educational documentation and community interaction to address FOSS business issues and promote best FOSS governance practices, said Small.
"The HP FOSS governance initiative allows HP to share the insight gained from its own experiences managing open source software with the community that made this technology possible in the first place," said Christine Martino, vice president of HP's open source and Linux organization.
HP's leadership around this open source initiative underscores its commitment to address the challenge of managing open source software proliferation while reducing barriers to adoption, she added.
Expanding Goals
Company officials view the decision to establish FOSSology and FOSSBazaar as a natural outgrowth to its interaction with existing customers. HP has been using open source code and is a major contributor to many open source projects. It is also a manufacturer of hundreds of products based on open source.
"This process has been increasing since we started seven years ago," said Small. "About two years ago we started talking to our customers about this. As a result, we realized a consulting practice opportunity."
Traditional corporate policies for managing software assets are often inadequate to address the unique characteristics of free and open source software, according to HP officials. During a recent customer engagement, for example, HP discovered three times as many FOSS licenses as the client originally thought it held, totaling 75 versus 25. This left the customer with a choice: implement governance policies to allow the safe use of FOSS or replace the software at an estimated cost of US$80 million.
Health Check
The third part of HP's open source initiative is the introduction of HP Open Source Health Check services. With these contracted services customers can extend and complement the content available from FOSSBazaar. In addition to creating a snapshot of current FOSS usage, the services assist customers with analyzing FOSS management and reducing the risk associated with it.
These services are priced on an individual basis depending on what help a customer needs, according to Small. HP is extending its existing fee structure to include the new Health Check services.
HP Open Source Heath Check offerings provide an open source management (governance) workshop that guides cross-organizational audiences through issues managing open source in the enterprise. The service also offers an open source exploration service using the HP FOSSology tool to discover open source components in legacy applications.
The open source governance assessment service provides a gap analysis of existing open source management practices and industry best practices, with recommendations to address the gaps. The open source total cost of ownership analysis service uses an HP-developed model to assess the cost benefits of moving to FOSS.
More information is available at FOSSology.org and FOSSBazaar. More information on open source and Linux at HP is available here.
Under EU Pressure, MS to Give Samba a Peek at Its Protocols December 26, 2007
"The agreement is, at its heart, a non-disclosure agreement," noted Samba Team leader Andrew Tridgell, who also negotiated for much of the agreement. "The [Protocol Freedom Information Foundation] is agreeing not to disclose certain confidential information, while Microsoft is agreeing to provide technical documentation which can be used to help build an implementation of the WSPP protocols."
Related Stories
Is Hidden Open Source Code Putting Your Apps at Risk? January 15, 2008
The most overlooked open source security vulnerabilities, according to Palamida researchers, occur in Apache Geronimo, JBoss Application Server, Libtiff, Net-SNMP and ZLIB. "The most popular projects appear in every test. This always surprises companies. There is from three to 10 times the use of open source code [in software enterprise uses] than companies realize," said Theresa Bui-Friday, cofounder of Palamida.
Coders Going Mercenary: From Community to Corporation January 11, 2008
Coders who make the transition from community to corporate software development often find little difference in the process. Software development has two main components: the code and its methodology, according to Sameer Verma, a professor of information systems at San Francisco State University.
Coverity Certifies 11 Open Source Bug Hunters January 10, 2008
With a grant from the Department of Homeland Security, security firm Coverity has been scanning open source security software for holes since 2006. In the hundreds of projects scanned, the project has fixed 7,500 holes, according to Coverity. Open source projects analyzed at the site include some of the world's most widely used applications, including the Apache Web server and Firefox.
Related News Alerts
More by Jack M. Germain
Microsoft FOSSifies .Net Micro Framework November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.