Skip to content

Commit 12e456d

Browse files
committed
Update OpenChain Self-Certification Checklist 2022-10-05.md
Changed from question to statement.
1 parent d4d0824 commit 12e456d

File tree

1 file changed

+42
-61
lines changed

1 file changed

+42
-61
lines changed
Lines changed: 42 additions & 61 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
![](./media/image1.png "OpenChain logo")
22

3-
# Self-Certification Questionnaire
4-
## The Simple Way To Check OpenChain ISO/IEC 5230:2020 Conformance
3+
# OpenChain ISO/IEC 5230 Self-Certification Checklist
4+
## The Simple Way To Check Conformance
55

66
Revision 1\
7-
2021-11-26
7+
2022-10-05
88

99
# Introduction
1010

@@ -16,115 +16,96 @@ We have a lot of resources to support you if you need assistance. You can join o
1616

1717
[[https://www.openchainproject.org/community]{.underline}](https://www.openchainproject.org/community)
1818

19-
As part of our online support you can also self-certify using our web app for free here:\
20-
[[https://certification.openchainproject.org/]{.underline}](https://certification.openchainproject.org/)
21-
22-
We have a video discussing online self-certification here:\
23-
[[https://www.youtube.com/watch?v=lVM4RH8RRl0]{.underline}](https://www.youtube.com/watch?v=lVM4RH8RRl0)
24-
25-
Online self-certification is the same as this questionnaire. It is just another option.
26-
2719
Finally, if you want direct support from the project you can email
2820
[[[email protected]]{.underline}](mailto:[email protected])
2921
with questions. We provide support for free. The OpenChain Project is funded by our Platinum Members and is designed to help support the global supply chain transition to more effective and efficient open source license compliance.
3022

31-
**Our Platinum Members**
32-
33-
![](./media/image2.png "List of Platinum Members")
34-
35-
# The Self-Certification Questionnaire
23+
# The Self-Certification Checklist
3624

3725
## Section 1: Program foundation
3826

39-
- Do you have a documented policy governing the open source license compliance of the Supplied Software?
27+
- [ ] We have a policy governing the open source license compliance of Supplied Software.
4028

41-
- Do you have a documented procedure to communicate the existence of the open source policy to all Software Staff
29+
- [ ] We have a documented procedure to communicate the existence of the open source policy to all Software Staff.
4230

43-
- Have you identified the roles and responsibilities that affect the performance and effectiveness of the Program?
31+
- [ ] We have identified the roles and responsibilities that affect the performance and effectiveness of the Program.
4432

45-
- Have you identified and documented the competencies required for each role?
33+
- [ ] We have identified and documented the competencies required for each role.
4634

47-
- Have you documented the assessed competence for each Program
48-
participant?
35+
- [ ] We have documented the assessed competence for each Program participant.
4936

50-
- Have you documented the awareness of your Program participants on the following topics?
37+
- [ ] We have documented the awareness of our Program participants on the following topics:
5138

52-
- The open source policy and where to find it;
39+
- - [ ] The open source policy and where to find it;
5340

54-
- Relevant open source objectives;
41+
- - [ ] Relevant open source objectives;
5542

56-
- Contributions expected to ensure the effectiveness of the Program;
43+
- - [ ] Contributions expected to ensure the effectiveness of the Program;
5744

58-
- The implications of failing to follow the Program requirements.
45+
- - [ ] The implications of failing to follow the Program requirements.
5946

60-
- Do you have a process for determining the scope of your Program?
47+
- [ ] We have a process for determining the scope of our Program.
6148

62-
- Do you have a written statement clearly defining the scope and limits of the Program?
49+
- [ ] We have a written statement clearly defining the scope and limits of the Program.
6350

64-
- Do you have a documented procedure to review and document open source license obligations, restrictions and rights?
51+
- [ ] We have a documented procedure to review and document open source license obligations, restrictions and rights.
6552

6653
## Section 2: Relevant tasks defined and supported
6754

68-
- Have you assigned individual(s) responsibility for receiving
69-
external open source compliance inquiries?
55+
- [ ] We assigned individual(s) responsibility for receiving external open source compliance inquiries.
7056

71-
- Is the external open source compliance contact publicly identified (e.g. via an email address or the Linux Foundation Open Compliance Directory)?
57+
- [ ] The external open source compliance contact is publicly identified (e.g. via an email address or the Linux Foundation Open Compliance Directory).
7258

73-
- Do you have a documented procedure for receiving and responding to open source compliance inquiries?
59+
- [ ] We have a documented procedure for receiving and responding to open source compliance inquiries.
7460

75-
- Have you documented the persons, group or function supporting the Program role(s) identified?
61+
- [ ] We have documented the persons, group or function supporting the Program role(s) identified.
7662

77-
- Have the identified Program roles been properly staffed and
78-
adequately funded?
63+
- [ ] We have ensured identified Program roles been properly staffed and adequately funded.
7964

80-
- Has legal expertise to address internal and external open source compliance been identified?
65+
- [ ] Legal expertise to address internal and external open source compliance has been identified.
8166

82-
- Do you have a documented procedure assigning internal
83-
responsibilities for open source compliance?
67+
- [ ] We have a documented procedure assigning internal responsibilities for open source compliance.
8468

85-
- Do you have a documented procedure for handling review and
86-
remediation of non-compliant cases?
69+
- [ ] We have a documented procedure for handling review and remediation of non-compliant cases.
8770

8871
## Section 3: Open source content review and approval
8972

90-
- Do you have a documented procedure for identifying, tracking and archiving information about the open source components in a Supplied Software release?
73+
- [ ] We have a documented procedure for identifying, tracking and archiving information about the open source components in a Supplied Software release.
9174

92-
- Do you have open source component records for the Supplied Software which demonstrate the documented procedure was properly followed?
75+
- [ ] We have open source component records for the Supplied Software which demonstrate the documented procedure was properly followed.
9376

94-
- Do you have a documented procedure that covers these common open source license use cases for open source components in the Supplied Software?
77+
- [ ] We have a documented procedure that covers these common open source license use cases for open source components in the Supplied Software:
9578

96-
- Distribution in binary form;
79+
- - [ ] Distribution in binary form;
9780

98-
- Distribution in source form;
81+
- - [ ] Distribution in source form;
9982

100-
- Integration with other open source that may trigger additional obligations;
83+
- - [ ] Integration with other open source that may trigger additional obligations;
10184

102-
- Containing modified open source;
85+
- - [ ] Containing modified open source;
10386

104-
- Containing open source or other software under incompatible licenses for interaction with other components in the Supplied Software;
87+
- - [ ] Containing open source or other software under incompatible licenses for interaction with other components in the Supplied Software;
10588

106-
- Containing open source with attribution requirements.
89+
- - [ ] Containing open source with attribution requirements.
10790

10891
## Section 4: Compliance artifact creation and delivery
10992

110-
- Do you have a documented procedure describing the process for ensuring the Compliance Artifacts are distributed with Supplied Software as required by the Identified Licenses?
93+
- [ ] We have a documented procedure describing the process for ensuring the Compliance Artifacts are distributed with Supplied Software as required by the Identified Licenses.
11194

112-
- Do you have a documented procedure for archiving copies of
113-
Compliance Artifacts for the Supplied Software?
95+
- [ ] We have a documented procedure for archiving copies of Compliance Artifacts for the Supplied Software.
11496

115-
- Are the Compliance Artifacts archived at least as long as the Supplied Software is offered and as required by the Identified Licenses?
97+
- [ ] We archive the Compliance Artifacts at least as long as the Supplied Software is offered and as required by the Identified Licenses.
11698

11799
## Section 5: Understanding open source community engagements
118100

119-
- Do you have a policy for contribution to open source projects on behalf of the organization?
101+
- [ ] We have a policy for contribution to open source projects on behalf of the organization.
120102

121-
- Do you have a documented procedure governing open source
122-
contributions?
103+
- [ ] We have a documented procedure governing open source contributions.
123104

124-
- Do you have a documented procedure for making all Software Staff aware of the open source contribution policy?
105+
- [ ] We have a documented procedure for making all Software Staff aware of the open source contribution policy.
125106

126107
## Section 6: Adherence to the specification requirements
127108

128-
- Do you have documentation confirming that your Program meets all the requirements of this specification?
109+
- [ ] We have documentation confirming that your Program meets all the requirements of this specification.
129110

130-
- Do you have documentation confirming that your Program conformance was reviewed within the last 18 months?
111+
- [ ] We have documentation confirming that your Program conformance was reviewed within the last 18 months.

0 commit comments

Comments
 (0)