You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Updated as per the Call 2023-06-29 with restructuring of the supplier information pack material at the top, and the optional issues below, plus formatting fixes.
Copy file name to clipboardExpand all lines: Adoption-Preparation/Model-Provisions/openchain-standards-model-provisions.0.4.md
+23-23Lines changed: 23 additions & 23 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -89,7 +89,7 @@ The goal of this document is to ensure people can understand options. We will no
89
89
90
90
#### 1.8.5. [usual indemnity wording]
91
91
92
-
# Optional Issue Structure:
92
+
# Below is a Series of Optional Model Language Issues in Original Risk Grid Format:
93
93
94
94
Each issue is formatted as follows:
95
95
@@ -101,23 +101,23 @@ Each issue is formatted as follows:
101
101
- Supplier's Arguments
102
102
- Customer's Arguments
103
103
104
-
# Overarching Topics
104
+
##Overarching Topics
105
105
106
-
## Issue - Inclusion of OpenChain ISO/IEC 5230
106
+
###Issue - Inclusion of OpenChain ISO/IEC 5230
107
107
108
-
### Commentary
108
+
####Commentary
109
109
110
110
None listed.
111
111
112
-
### Who is best placed to bear risk?
112
+
####Who is best placed to bear risk?
113
113
114
114
Supplier.
115
115
116
-
### Best mechanism to tackle risk
116
+
####Best mechanism to tackle risk
117
117
118
118
None listed.
119
119
120
-
### Sample Wording
120
+
####Sample Wording
121
121
122
122
The Supplier warrants that the [Software][defined components of the Software] originate[s] from an OpenChain ISO/IEC 5230:2000 Conformant Program [or Programs][, with the OpenChain ISO/IEC 5230:2000 Conformant Program being specified in the Supplier Information Pack].
123
123
@@ -129,29 +129,29 @@ and
129
129
130
130
[The Supplier does not warrant that use, modification or further distribution by the Customer of the Software constitutes a continuation of adherence to an OpenChain ISO/IEC 5230:2000 Conformant Program].
131
131
132
-
### Supplier's Arguments
132
+
####Supplier's Arguments
133
133
134
134
The Supplier may argue that the inclusion of these requirements or the extent of the requirements included introduce a cost-burden that need to be offset.
135
135
136
-
### Customer's Arguments
136
+
####Customer's Arguments
137
137
138
138
The Customer is receiving a potential liability regarding third-party intellectual property along with the Software deliverable from the Supplier. As such, it is reasonable to request that the Supplier adheres to international standards related to the licensing of this third-party intellectual property.
139
139
140
-
## Issue - Inclusion of OpenChain ISO/IEC DIS 18974
140
+
###Issue - Inclusion of OpenChain ISO/IEC DIS 18974
141
141
142
-
### Commentary
142
+
####Commentary
143
143
144
144
None listed.
145
145
146
-
### Who is best placed to bear risk?
146
+
####Who is best placed to bear risk?
147
147
148
148
Supplier.
149
149
150
-
### Best mechanism to tackle risk
150
+
####Best mechanism to tackle risk
151
151
152
152
None listed.
153
153
154
-
### Sample Wording
154
+
####Sample Wording
155
155
156
156
The Supplier warrants that the [Software][defined components of the Software] originate[s] from an OpenChain ISO/IEC DIS 18974 Conformant Program [or Programs][, with the OpenChain ISO/IEC DIS 18974 Conformant Program being specified in the Supplier Information Pack].
157
157
@@ -163,29 +163,29 @@ and
163
163
164
164
[The Supplier does not warrant that use, modification or further distribution by the Customer of the Software constitutes a continuation of adherence to an OpenChain ISO/IEC DIS 18974 Conformant Program].
165
165
166
-
### Supplier's Arguments
166
+
####Supplier's Arguments
167
167
168
168
The Supplier may argue that the inclusion of these requirements or the extent of the requirements included introduce a cost-burden that need to be offset.
169
169
170
-
### Customer's Arguments
170
+
####Customer's Arguments
171
171
172
172
The Customer is receiving a potential liability regarding security along with the Software deliverable from the Supplier. As such, it is reasonable to request that the Supplier adheres to international standards related to the managing of security assurance related to the Software.
173
173
174
-
## Issue - Determining if the OpenChain Conformant Program is self-certified or third-party certified
174
+
###Issue - Determining if the OpenChain Conformant Program is self-certified or third-party certified
175
175
176
-
### Commentary
176
+
####Commentary
177
177
178
178
None listed.
179
179
180
-
### Who is best placed to bear risk?
180
+
####Who is best placed to bear risk?
181
181
182
182
Supplier
183
183
184
-
### Best mechanism to tackle risk
184
+
####Best mechanism to tackle risk
185
185
186
186
None listed.
187
187
188
-
### Sample Wording
188
+
####Sample Wording
189
189
190
190
The Supplier warrants that the OpenChain [ISO/IEC 5230:2000][ISO/IEC DIS 18974] Conformant Program [or Programs] referenced in the relevant [purchasing agreement[s]][contract[s]] is self-certified as per the checklists or questionnaires provided by the OpenChain Project.
191
191
@@ -197,11 +197,11 @@ and
197
197
198
198
[The Supplier will produce documentation to verify that the OpenChain [ISO/IEC 5230:2000][ISO/IEC DIS 18974] Conformant Program [or Programs] has undergone the disclosed certification process.]
199
199
200
-
### Supplier's Arguments
200
+
####Supplier's Arguments
201
201
202
202
None.
203
203
204
-
### Customer's Arguments
204
+
####Customer's Arguments
205
205
206
206
The Customer requires clarity regarding the type of certification that the Supplier has undergone to contextualize their risk. A Customer may regard third-party certification as preferable due to the inherent audit involved. Alternatively, a Customer may be satisfied that self-certification is sufficient given that OpenChain ISO/IEC 5230:2000 or ISO/IEC DIS 18974 both require the party with a conformant program to maintain documentation on how they accomplished their conformance.
0 commit comments