SlideShare a Scribd company logo
LEVEL 3 – TRACKING OPEN SOURCE BY SPREADSHEET
Making Progress (Issues Remain). Developers complain
that manual tracking is impacting their productivity.
Accuracy is difficult to maintain. Provides limited insight
into security vulnerabilities.
DO YOU KNOW WHAT LICENSE OR SECURITY ISSUES
MIGHT ARISE FROM YOUR USE OF OPEN SOURCE?
BLACK DUCK CAN HELP YOU:
Automatically identify and inventory open source software used to build applications and
Docker containers
Map open source components to known vulnerabilities and license requirements with Black
Duck’s comprehensive KnowledgeBase™ of more than 1.5 million open source projects and
75,000 vulnerabilities
Streamline and secure continuous integration/deployment activities with integration with the
most popular DevOps and security tools, including IBM AppScan, HP Fortify, Docker, Red Hat
Atomic, Jenkins, and Atlassian
Help your teams set policies to govern open source security, license, and code quality risks,
enforce policies through build-tool integrations, and manage remediation efforts through IT
workflow support.
Continuously monitor for and provide alerts for new open source vulnerabilities
For more information, visit www.blackducksoftware.com
LEVEL 1 – IGNORING RISK
Code Red. You’re unaware of open source used in
your code. No policies in place to manage open
source security and licensing risks.
LEVEL 2 – MANUAL DISCOVERY OF OPEN SOURCE
Significant Trouble. Inaccurate open source invento-
ries. Processes to manage open source are incon-
sistent. No controls over open source use.
Where does your organization stand with open source risk management?
How are you identifying and securing open source used in your code?
Measure your organization against these four levels to find out…
LEVEL 4 –AUTOMATED OS RISK MANAGEMENT
Way Cool. Open source is automatically identified,
inventoried, and mapped to known vulnerabilities and
license requirements without impacting your SDLC.
Organizations worldwide use Black Duck Software’s industry-leading products to automate
the processes of securing and managing open source software, eliminating the pain related
to security vulnerabilities, open source license compliance and operational risk. Black Duck
is headquartered in Burlington, MA, and has offices in San Jose, CA, London, Frankfurt, Hong
Kong, Tokyo, Seoul and Beijing. For more information, visit www.blackducksoftware.com

More Related Content

Viewers also liked (20)

PDF
Integrating Black Duck into your Agile DevOps Environment
Black Duck by Synopsys
 
PPTX
Open Source By The Numbers
Black Duck by Synopsys
 
PDF
Securing Docker Containers
Black Duck by Synopsys
 
PPTX
Secure application deployment in the age of continuous delivery
Tim Mackey
 
PDF
PCI and Vulnerability Assessments - What’s Missing
Black Duck by Synopsys
 
PPTX
Software Security Assurance for DevOps - Hewlett Packard Enterprise + Black Duck
Black Duck by Synopsys
 
PDF
2016 Future of Open Source Study
North Bridge
 
PDF
2013 Open Source Rookies of the Year
Black Duck by Synopsys
 
PPTX
Black Duck Software’s 2014 Review
Black Duck by Synopsys
 
PPT
BlackDuck Suite
jeff cheng
 
PDF
The AppSec Path to Enlightenment
Black Duck by Synopsys
 
PDF
Myths and Misperceptions of Open Source Security
Black Duck by Synopsys
 
PDF
Secure Application Development in the Age of Continuous Delivery
Black Duck by Synopsys
 
PDF
Customer Case Study: ScienceLogic - Many Paths to Compliance
Black Duck by Synopsys
 
PDF
Containers for Lawyers Richard Fontana
Black Duck by Synopsys
 
PPTX
Litigation and Compliance in the Open Source Ecosystem
Black Duck by Synopsys
 
PDF
Understanding Open Source
Jody Garnett
 
PDF
Filling your AppSec Toolbox - Which Tools, When to Use Them, and Why
Black Duck by Synopsys
 
PPTX
2015 Future of Open Source Survey Results
Black Duck by Synopsys
 
PPTX
OPEN SOURCE SEMINAR PRESENTATION
Ritwick Halder
 
Integrating Black Duck into your Agile DevOps Environment
Black Duck by Synopsys
 
Open Source By The Numbers
Black Duck by Synopsys
 
Securing Docker Containers
Black Duck by Synopsys
 
Secure application deployment in the age of continuous delivery
Tim Mackey
 
PCI and Vulnerability Assessments - What’s Missing
Black Duck by Synopsys
 
Software Security Assurance for DevOps - Hewlett Packard Enterprise + Black Duck
Black Duck by Synopsys
 
2016 Future of Open Source Study
North Bridge
 
2013 Open Source Rookies of the Year
Black Duck by Synopsys
 
Black Duck Software’s 2014 Review
Black Duck by Synopsys
 
BlackDuck Suite
jeff cheng
 
The AppSec Path to Enlightenment
Black Duck by Synopsys
 
Myths and Misperceptions of Open Source Security
Black Duck by Synopsys
 
Secure Application Development in the Age of Continuous Delivery
Black Duck by Synopsys
 
Customer Case Study: ScienceLogic - Many Paths to Compliance
Black Duck by Synopsys
 
Containers for Lawyers Richard Fontana
Black Duck by Synopsys
 
Litigation and Compliance in the Open Source Ecosystem
Black Duck by Synopsys
 
Understanding Open Source
Jody Garnett
 
Filling your AppSec Toolbox - Which Tools, When to Use Them, and Why
Black Duck by Synopsys
 
2015 Future of Open Source Survey Results
Black Duck by Synopsys
 
OPEN SOURCE SEMINAR PRESENTATION
Ritwick Halder
 

Similar to The 4 Levels of Open Source Risk Management (20)

PDF
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
PDF
Application Security in the Age of Open Source
Black Duck by Synopsys
 
PPTX
RVAsec Bill Weinberg Open Source Hygiene Presentation
Black Duck by Synopsys
 
PDF
Q1 2016 Open Source Security Report: Glibc and Beyond
Black Duck by Synopsys
 
PDF
GDPR and Open Source: Security by the Numbers
Black Duck by Synopsys
 
PPTX
Security in the Age of Open Source
Black Duck by Synopsys
 
PDF
Security in the Age of Open Source
FINOS
 
PPTX
Open Source Insight: Global Response to COSRI 2017 Open Source Security and R...
Black Duck by Synopsys
 
PPTX
Black Duck & IBM Present: Application Security in the Age of Open Source
Black Duck by Synopsys
 
PPTX
It’s No Myth: Compliance Is Good Business
Black Duck by Synopsys
 
PPTX
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Black Duck by Synopsys
 
PDF
Open Source Insight: Struts in VMware, Law Firm Cybersecurity, Hospital Data ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
Black Duck by Synopsys
 
PPTX
DevSecCon London 2017: when good containers go bad by Tim Mackey
DevSecCon
 
PPTX
Question of trust
ssuserd8f6cf1
 
PPTX
Welcome & The State of Open Source Security
Jerika Phelps
 
PPTX
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Black Duck by Synopsys
 
PPTX
Automate and Enhance Application Security Analysis
VMware Tanzu
 
PPTX
Automate and Enhance Application Security Analysis
Carlos Andrés García
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
Application Security in the Age of Open Source
Black Duck by Synopsys
 
RVAsec Bill Weinberg Open Source Hygiene Presentation
Black Duck by Synopsys
 
Q1 2016 Open Source Security Report: Glibc and Beyond
Black Duck by Synopsys
 
GDPR and Open Source: Security by the Numbers
Black Duck by Synopsys
 
Security in the Age of Open Source
Black Duck by Synopsys
 
Security in the Age of Open Source
FINOS
 
Open Source Insight: Global Response to COSRI 2017 Open Source Security and R...
Black Duck by Synopsys
 
Black Duck & IBM Present: Application Security in the Age of Open Source
Black Duck by Synopsys
 
It’s No Myth: Compliance Is Good Business
Black Duck by Synopsys
 
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Black Duck by Synopsys
 
Open Source Insight: Struts in VMware, Law Firm Cybersecurity, Hospital Data ...
Black Duck by Synopsys
 
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
Black Duck by Synopsys
 
DevSecCon London 2017: when good containers go bad by Tim Mackey
DevSecCon
 
Question of trust
ssuserd8f6cf1
 
Welcome & The State of Open Source Security
Jerika Phelps
 
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Black Duck by Synopsys
 
Automate and Enhance Application Security Analysis
VMware Tanzu
 
Automate and Enhance Application Security Analysis
Carlos Andrés García
 
Ad

More from Black Duck by Synopsys (20)

PDF
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Black Duck by Synopsys
 
PDF
Open-Source- Sicherheits- und Risikoanalyse 2018
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
Black Duck by Synopsys
 
PPT
FLIGHT Amsterdam Presentation - From Protex to Hub
Black Duck by Synopsys
 
PPTX
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Black Duck by Synopsys
 
PPTX
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Black Duck by Synopsys
 
PDF
Open Source Rookies and Community
Black Duck by Synopsys
 
PPTX
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Black Duck by Synopsys
 
PPTX
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
PPTX
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Black Duck by Synopsys
 
PDF
20 Billion Reasons for IoT Security
Black Duck by Synopsys
 
PPTX
Open Source Insight: IoT Security, Tech Due Diligence, and Software Security ...
Black Duck by Synopsys
 
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Black Duck by Synopsys
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - From Protex to Hub
Black Duck by Synopsys
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Black Duck by Synopsys
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Black Duck by Synopsys
 
Open Source Rookies and Community
Black Duck by Synopsys
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Black Duck by Synopsys
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Black Duck by Synopsys
 
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Black Duck by Synopsys
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Black Duck by Synopsys
 
20 Billion Reasons for IoT Security
Black Duck by Synopsys
 
Open Source Insight: IoT Security, Tech Due Diligence, and Software Security ...
Black Duck by Synopsys
 
Ad

Recently uploaded (20)

PDF
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
PDF
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
PPTX
Webinar: Introduction to LF Energy EVerest
DanBrown980551
 
PDF
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
PDF
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
PDF
From Code to Challenge: Crafting Skill-Based Games That Engage and Reward
aiyshauae
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
PDF
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PDF
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
PDF
Timothy Rottach - Ramp up on AI Use Cases, from Vector Search to AI Agents wi...
AWS Chicago
 
PDF
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
PPTX
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
PDF
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
PPTX
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
PDF
Reverse Engineering of Security Products: Developing an Advanced Microsoft De...
nwbxhhcyjv
 
PDF
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
PDF
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
PPTX
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
Webinar: Introduction to LF Energy EVerest
DanBrown980551
 
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
From Code to Challenge: Crafting Skill-Based Games That Engage and Reward
aiyshauae
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
Timothy Rottach - Ramp up on AI Use Cases, from Vector Search to AI Agents wi...
AWS Chicago
 
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
Reverse Engineering of Security Products: Developing an Advanced Microsoft De...
nwbxhhcyjv
 
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 

The 4 Levels of Open Source Risk Management

  • 1. LEVEL 3 – TRACKING OPEN SOURCE BY SPREADSHEET Making Progress (Issues Remain). Developers complain that manual tracking is impacting their productivity. Accuracy is difficult to maintain. Provides limited insight into security vulnerabilities. DO YOU KNOW WHAT LICENSE OR SECURITY ISSUES MIGHT ARISE FROM YOUR USE OF OPEN SOURCE? BLACK DUCK CAN HELP YOU: Automatically identify and inventory open source software used to build applications and Docker containers Map open source components to known vulnerabilities and license requirements with Black Duck’s comprehensive KnowledgeBase™ of more than 1.5 million open source projects and 75,000 vulnerabilities Streamline and secure continuous integration/deployment activities with integration with the most popular DevOps and security tools, including IBM AppScan, HP Fortify, Docker, Red Hat Atomic, Jenkins, and Atlassian Help your teams set policies to govern open source security, license, and code quality risks, enforce policies through build-tool integrations, and manage remediation efforts through IT workflow support. Continuously monitor for and provide alerts for new open source vulnerabilities For more information, visit www.blackducksoftware.com LEVEL 1 – IGNORING RISK Code Red. You’re unaware of open source used in your code. No policies in place to manage open source security and licensing risks. LEVEL 2 – MANUAL DISCOVERY OF OPEN SOURCE Significant Trouble. Inaccurate open source invento- ries. Processes to manage open source are incon- sistent. No controls over open source use. Where does your organization stand with open source risk management? How are you identifying and securing open source used in your code? Measure your organization against these four levels to find out… LEVEL 4 –AUTOMATED OS RISK MANAGEMENT Way Cool. Open source is automatically identified, inventoried, and mapped to known vulnerabilities and license requirements without impacting your SDLC. Organizations worldwide use Black Duck Software’s industry-leading products to automate the processes of securing and managing open source software, eliminating the pain related to security vulnerabilities, open source license compliance and operational risk. Black Duck is headquartered in Burlington, MA, and has offices in San Jose, CA, London, Frankfurt, Hong Kong, Tokyo, Seoul and Beijing. For more information, visit www.blackducksoftware.com