About this talk
This talk covers the significance of open standards in achieving compliance within organizations, presented by Madalin Iac, a policy advisor at OpenSSF. He discusses the Linux Foundation's commitment to open source software and the vital role of open standards in facilitating compliance with regulatory requirements. The speaker highlights statistics showing the benefits of standardization, such as avoiding vendor lock-in and enhancing organizational innovation. He explains how the collaboration between open source communities and standards organizations can lead to the development of effective compliance frameworks. The session emphasizes that organizations participating in standardization efforts benefit from clearer guidelines and can better anticipate regulatory changes through proactive alignment with expected compliance standards.
Full transcript
Thank you very much. I hope you can hear me well. My name is Madalin Iac. I'm new policy advisor at OpenSSF. I have health I have also had the pleasure to represent the Linux Foundation Linux Foundation Europe in a lot of things related to open source and more importantly to cybersecurity across Europe. Yeah, I'm not the least in I'm not so interesting. So I'm the least interested
person interesting person in this room. I'll not bore you more about myself. Today I would like to talk about why open standards power compliance and I plan to split my presentation in four items. Briefly I'll introduce what is Linux Foundation OpenSSF some of our core values and why we believe in that there is value in open source. I'll talk after that about open standards, how to use
compliance or how to obtain compliance using open standards and I will with a with a couple of slides. I use this picture on purpose. If you're blocked tomorrow here due to the strike in Berlin Airport, I strongly encourage to go and visit the Museum Island in Berlin. It's amazing and yeah, I wanted to use this these pillars as a very representative image for what open standards represent
for for compliance. I suppose you all know what the Linux Foundation is. Nevertheless, I'll try to bring some numbers to you. We have more than 1,300 open source projects, more than 4 million developers trained. We see number of 89 million lines of code added weekly. And we have more than 100 standards and specifications. Yeah, we are open source, but we have also standards and specifications. About OpenSSF,
as my CTO said, we are diverse global community trying to make the world a better place through open source software. Uh we have a very simple simple mission trying to sustainably secure the development, maintenance, release, and consumption of the open source software we all depend on. As vision, we try to see a future where open source software is universally trusted, secure, and reliable by creating tools, uh
education pieces, and clear and actionable guidance for our community. We try also to enhance the security of open source software by developing tooling and processes to make secure development easier, promote a deeper understanding of best practices, and provide support to innovative technical initiatives. And yes, we want to be a catalyst for change. We want to educate and empower the modern developer, but also we want to be
an ecosystem leader in this very complex world of open We see a lot of value in open source. I have heard uh yesterday some very interesting presentations about the revenue streams for open source, but we think that there is more than that. Uh Linux Foundation research has a very nice talent to create amazing reports. And two of them, the state of global open source uh from last
year and ROI for open source software contribution, brought into our attention some very important aspects for the companies that are or for the people that are contributing to open source. We see that greater open source software engagement is linked to stronger talent attraction. Also, we see that organizations engaging in open source uh perceives that as a lever for quality and competitiveness. Believing that open source software is
valuable for to the future of the organizations, but also trying to um engage even more, believing that that will um make their organization even more competitive. The last report that I mentioned it uh return of investment for open source software contributions brought into our attention other not so tangible outcomes, but extremely important for us. we see that two out of three respondents reported return of investment has
increased since they began contributing with more than 70% expected continued increase in the future. We see that reported benefit to cost ratios from open source software contributions are two to five times on average across the engagement times. Contributors benefit from at least two months advance notice for important changes. And nearly half of respondents develop workarounds internally for features or fixes not on open source software roadmaps. An
activity that costs organizations an average of six 670,000 uh dollars annually. Talking about money, economic model reveals that uh an investment of 3.9 billion dollars from top 100 contributors between 2018 and 2025 yields 23 23.2 billion dollars in benefits. So, six times uh higher return of investment. Another value that we want to bring to our community is involvement into standards. In either as creating awareness for our
community, defending projects, defending their outcomes, avoiding conflicts with those, avoiding uh reinventing the wheel, and also trying to promote everything that we do also at the level of the standards. This is why we have tried in the past years to engage in multiple ways with software development organizations like Etsy, ITU, ANSI, CEN, CENELEC, ISO, and IEC via memorandum of understandings, liaisons, past submit past submissions, or even
membership. We truly believe that successful open collaboration ecosystems comes down to four core factors like neutrality, open governance, democracy, IP clarity, commercial support ecosystems. And we want to cascade that from what we do also into the standards world. But yeah, let's talk about more about open standards. I mentioned before the Linux Foundation research and I mentioned that they are very talented in creating very nice reports. Two
of them are related to open standards. JDF together with Linux Foundation research have this intention to publish with a cadence of two years this kind of reports. The first one was on 2023. The last one was last year. And they're reflecting extremely valuable insights related to involvement into into standards saying that 73% of perceive standards as a selling point. 85% of respondents aren't threatened by royalty-free standards.
66% of organizations primarily participate in standard development organizations with royalty-free patent policies. 78% of respondents says that royalty-free standards drive high value. And 1.6 times more respondents view adopting open models rather than filing patents as indication of innovation. noticed also that 76% of respondents agree that standardization promotes competition and innovation. And many other statistics. I will let you explore those. What And I'll come also later to
some of these graphs to to detail them more. We truly believe that standards play a role in everyone's life, instrumenting safety, enabling interoperability, reducing costs through shared technology investments, and accelerate innovation. Open standards facilitate interoperability. That's clear. We could say that some interoperability issues would be to create open source software projects everyone can use. But open source software alone will not solve all implementation challenges that open
standards can achieve. We truly believe that nowadays open standards and open source needs to coexist together. And this is why we are trying to get more and more involved and promote our values and our outcomes into into the standardization. Yeah, we we notice that standards development organizations and standards are usually formed by industry stakeholders to support the activities needed to develop a specific solution to a common
problem. The resulting solution may be a specification, a blueprint for a building and implementation, or an open source implementation specific to a set of use cases and requirements. All of those done under a neutral home to the collaboration, neutral governance model that will guard the li- guard a rail against antitrust issues and manages copyrights and other intellectual property terms safely. Going deeper into the reports that I
mentioned, we notice that a lot of organization uh strongly value the standardizations from different perspectives. First of standardization makes it easier for my organization to meet compliance or regulatory requirements. This is the point from where I started to prepare my presentation. But also we see that standardization has helped my organization avoid vendor lock-in. Standardization relies on certain standards or my organization relies on certain standards or open
source software as a selling point for products or services. And standardization may help my organization delivering more innovative products or solutions. Those are top four agreements from this report. And if we look at the bottom, we see that standards limit my ability to provide products or services represents only 10% in terms of agreement to with with that one. But also we notice that organization value open source
open standards and open source attributes. Uh I mentioned before uh some core values of open standards. Here we see we see them again. Standard is royalty free. It's final and or draft specifications are openly published and publicly accessible. It has clear, easy-to-understand IP agreements. It's extensible and or compatible with other specifications my organization uses. It was developed using a transparent process. It is managed and maintained by
multiple stakeholders. It went through a wide review or public comment processes. Those are open standards characteristics from our point of view. Because there are lots of existing definitions for open standards. We truly believe that we have five main criteria for open standard like no intentional secrets, availability, uh essential patents that must be licensed it under royalty-free terms or or covered by another assertion non-assertion promise, sorry. There
are no agreements, no requirement for license agreements, NDAs, or paperwork to deploy, and no OSR incompatible dependencies. Also, that comes from open source world, but we see also companies having simpler definitions for open standards, like IBM saying that an open standard is a standard that is freely available for adoption, implementation, and updates. And after that, we arrive at WTO definition, which puts all these concepts behind the
membership. We all agree that terms of art aren't always shared, leading many times to confusion or distrust. Standard, open contributor or contribution, open source, member, and other words often have multiple interpretations or meanings. These terms' definitions are really important to the respective groups, and there is likely nuance within the group. But, let's go one step forward, and let's focus on shared outcomes. What we are aiming to
achieve or enable. And let's try to help our communities in this direction. Because, yeah, we have noticed in the past months in our involvement with uh SDOs, that standards organizations, and open source communities want to work together. Yeah, opinions tend to vary along a continuum of features. If we look at open standards in terms of intent, we may say that it supports a frictionless open global ecosystems,
while in terms of access, we hope that we hope to have standards that are freely publicly accessible to everyone. In terms of participation, we don't want to see membership walls. We want to see everyone involved into taking into account the dimension of the companies, the same report from last year highlighted that open standards factors are important for all organizations. We see concepts like royalty-free, widely reviewed, availability
of public materials, regulatory compliance, and many others that are really important for any types of companies. Standard essential patents are not representing anymore a thing for which the companies are going to standardize the things. Filling multiple patents on our technologies represents only 32% or has answer of only 32% when it comes to what was reflected in in our report, while heavily adopting innovating innovative open source software
and or open specifications is at 53%. And we are trying to teach the people also through example. Joint Development Foundation has set up an amazing process. Streamlining streamlining standards development. We see that the traditional SDO challenge can be reflected into a lot of work and months to set up an SDO, hundreds of lawyers hours to create that, complex negotiations in terms of IPRs rules, and also significant
admin setup. While goes with a standards organization in a box. Creating faster process, default industry best terms, check the box model, flexible governance and IP choices, custom customizable for community needs. And yeah, that has resulted in more than 200 active projects. What we have tried at the level of The Linux Foundation to do through that was a global reach by becoming the interface to ISO/IEC JTC expanding
uh our specifications, our outcomes to a broader audience and alignment by transposing the specifications. Yeah. I need to speed up. Thank you. Now moving to the main topic, compliance using standards. I'm returning to one of the previous figures. And as I mentioned, we noticed an 80% agreement that standardization makes it easier for organizations to meet Yeah, organizations strongly value standardization, and we truly believe that standardization should
provide a framework and common language that simplifies demonstrating regulatory Standards in the end need to provide clear framework and common technical language defining expected behavior interop- and interoperability enabling consistent implementation across vendors that could be reflected into making compliance verifiable and repeatable. Nearly half of organizations are compelled to participate in order to engage with policy or regulations, which gives them an opportunity to shape how they will
demonstrate compliance. That's one of the main reasons why companies are getting involved into standards. We see that compliance can be connected to multiple other concepts like law, rules, governance, regulations, But we need to keep into account that a lot of these regulations are reflected through standards. Because standardization in the end facilitates compliance and regulatory requirements. Harmonized standards, where they exist, can help any organization demonstrate compliance with
new rules. In the end, the very nature of standards describes a set of rules that should be followed in order to achieve an outcome, which makes it simpler for organization to demonstrate compliance with regulatory requirements or conformance to expected behavior. Also, we see that standardization provides some kind of feedback loop. A mechanism for clarification, feedback, and review of requirements. This loop from requirement to conformance makes it
easier to spot gaps, plug holes, and modify where needed. For example, nowadays in the serial related they're not yet out, but the ISOs are already thinking about version number two. And yeah, I mentioned CRA. One of the most pleasant things that happens around us nowadays. Um in terms of compliance, we see that we ways of proving that. For depending on the product category, if we have a
product that falls under the fourth category, we do self-assessment. Modularly. If we have important products, we have two options. Important products class one, applications of standards. products class two, third-party assessment. But third-party assessment can be used also um instead of application of standards by themselves. Critical products, yeah, we hope to see UCC from ENISA out. And we hope that will be created uh very friendly to to
our community. For free and open source software, self-assessment unless categorized as critical products. I mentioned self-assessment using for important products, and I mentioned Well, third-party assessment is done usually through notified bodies or CABs. Not all CABs are notified bodies. This is why I used the code from CRA here from Annex 8. I hope you read Annex 8 from that only. They are really important. And you'll see
that I highlighted in 4.2, 4.3, and 4.4 that notified bodies are relying pretty much on harmonized standards. So, whatever path you will follow for your important products, in the end you will arrive to deal with the harmonized standards. Notified bodies evaluate compliance with your regulations. Standards translate legal requirements into the technical criteria. Harmonized standards create presumption of conformity. Open standards ensure transparent, consistent, and audit auditable And
we truly believe that standards in this context provide a technical foundation that allows the notified bodies to objectively verify regular regulatory compliance. Yeah, we have been actively engaged in standardization activities at ETSI, CEN, ITU, ISO, and ANSI, and we truly believe that uh EU's systems of developing harmonized standards is an excellent example of government and industry cooperation to achieve wide-scale societal benefits. It supports innovation and competition
in the marketplace. And but we think that there is room for improvement. That's not yet perfect. And we while we support the ideals of strong standardization framework, we truly think that there will be some things that will improve the open First of them, removing paywalls and member-only barriers for standards with legal and security implications. So, every standard that supports a regulation shall be free and not made
available only to the members or to the ones that pay for those. We need to have a clear public tracking of standardization request statuses and timelines. I think through CRA all three ESOs, CEN, CENELEC, and ETSI have done a tremendous job moving from their behind closed door activity to something much more open. At the level of ETSI, we see open consultations that have lasted for the past
5 months, and that's a very nice example on how you can have the community more engaged, how you can receive further feedback to your specifications, and how you can improve the standards relying on community coming not only from your members, but from from the whole world. we would like to see free public access to harmonized ICT standards throughout drafting and after publication, something that I mentioned before
as And we want to see an alignment of practices with open development norms familiar to software and security communities. Another thing that would be useful would be also to allow direct regulatory references to open source software technologies or releases where criteria are met. That's speeding up the things when they have to be. We notice that nowadays the processes are running very fast, and after that we hit
the deadline for OJU publication, and that's practically a black box. We do not know what happens there. That could need That could be needed to to be accelerated. And yeah, shorten consultation, revision, and citation timelines. Cite everything that makes sense. Don't reinvent the wheel. Don't create duplication of the standards. Create works that spans between open source communities and ESOs and SDOs everything much better in this context.
Yeah, we are looking to a future of collaboration. We are heartened by ASUS's progress as I mentioned, especially with regards with what has happened for the standardization request for CRA. yeah, we we noticed also that organization truly recognize the benefits of standardization to their businesses and the markets in which they operate. Even if we're talking about compliance, avoiding vendor lock-in, attracting customers, promoting market maturity and growth,
and encouraging Open standards transform compliance from the reactive regulation to proactive alignment, anticipating future regulation, aligning products with compliance expectations, reducing regulatory risk. And also we notice that open collaboration improves harmonization across industries and jurisdictions. So, creation of open standards can bring a lot of advantages as well. And two numbers to remember, 80% of the organizations really believe that standardization makes it easier for them to meet
compliance and regulatory requirements, and 50% of organizations are participating into the standardization development processes to address policy and regulatory needs as main reason. Hi, it's not a question, it's more a message of support because I work for OASIS Open that you just also showed our process. So, we've been doing open source and open standards for a long long long time and thank you for this. This was
super interesting and I think we're we're very much aligned that strategy and and kind of also contributing via past submitted process standards like Open Document Format and other standards for a long time. So, um yeah, I think we should talk. Thank you so much. The Madeline, if I'm an organization or a company that is not participating that used to participating in these kinds of standards with regard
to the CRA, is there some resource that you would recommend that can give me a better uh overview so that I can understand how it can be applicable to me. Say, if I'm a small software vendor or something like that. Thank you very much for your question. Yeah, at the level of OpenSSF, we have tried to create awareness for our community, no matter if they attend or
these processes for CRA-related standards. We have working group global cyber policy where we discuss this and standardization seek where we have, I don't know, 40 minutes out of 1 hour dedicated only to CRA-related standards, their progress, and how those are applicable to our community. I hear that working group has a really great co-chair. Yeah, both chairs are amazing. We're all amazing in here. Yeah. Please, round of
applause for Madeline Nagg.
More from this event
See all 47 talks →
Seyi Kuforiji – Bridging the Gap: Encouraging African Talent to Open Source #FOSSBack
23:57
Educating the next generation of open source contributors #FOSSBack
36:35
Jan Dittrich – Best practices and (very) small projects #FOSSBack
24:03
Johannes Näder – Let’s tackle Openwashing! #FOSSBack
24:58