Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Overview of Open Source Software (OSS) Governance for Government
- Defining open source software and its function within federal enterprise architectures
- Advantages and associated risks of adopting OSS solutions
- Analytical review of successful and unsuccessful OSS implementations
Formulating an OSS Governance Policy
- Essential elements of a robust OSS governance framework
- Defined roles and accountability in OSS management
- Reconciling technological innovation with necessary risk controls
Licensing Requirements and Regulatory Compliance
- Prevalent open source license types and corresponding compliance obligations
- Strategies for managing license compatibility
- Mitigation techniques to prevent licensing violations
Software Bill of Materials (SBOM)
- Definition and strategic importance of the SBOM
- Procedures for generating and sustaining an accurate SBOM
- Alignment with industry standards and federal regulatory mandates
Software Composition Analysis (SCA) Tools
- Functional overview of SCA technologies and capabilities
- Incorporating SCA processes into Continuous Integration/Continuous Deployment (CI/CD) workflows
- Detection and remediation of software vulnerabilities
Security Protocols and Risk Management for OSS
- Surveillance of the OSS supply chain against potential threats
- Incident response procedures for identified OSS vulnerabilities
- Recommended practices for effective patch management
Implementing Operational OSS Management
- Synchronization of OSS management protocols with federal IT operations
- Implementation of continuous monitoring and compliance reporting mechanisms
- Fostering organizational accountability and responsible OSS utilization for government
Conclusion and Strategic Next Steps
Requirements
- Demonstrated knowledge of software development lifecycles
- Practical experience in project or IT management
- Awareness of security protocols and regulatory compliance requirements
Target Audience
- Information technology managers
- Security and compliance officials
- Leaders of software development teams
14 Hours
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Speed of response and communication