3 ms·
In many companies I expect at least a security review of the open source before developers can use it. This can have a lot of red tape.
by pylua 3y ago
In many companies I expect at least a security review of the open source before developers can use it.
This can have a lot of red tape.
- toomuchtodo 3y agoThis is why a SaaS offering is a must. For open source, a security review might be needed. For a SaaS, checkbox SOC2 and we’re on our way. Leverage to reduce the B2B sales cycle as you scale.
- MilStdJunkie 3y agoYes. Yes. Absolutely. This can stop adoption right in its tracks, and it depends entirely on one or two personalities. Who's at the wheel in office InfoSec. One guy had a strict "Open Source is Inherently Unstable" red line, sooooooooo . . well, we went two levels above him to get OSS signed off on, because the parent org was all about OSS. Doing that was a bad career decision, but it was the right one. This article gets it right almost exactly; transparency was a huge part of adoption, but the extensibility thing is also a big deal for a niche industry. Also, our vendor was unspeakable, disappearing for years on end, re-appearing as another company, asking fifty times the money for no reason.
- devoutsalsa 3y agoI wonder if there’s a business model around sharing the results of security reviews. Even if Company A can’t fully trust the review of Company B, you could A could provide a lot of context for B to reduce the cost of starting an evaluation from zero.
- pylua 3y agoUsually it is just rubber stamping the results of a tool like black duck, Vera code , or any scanner and the ongoing maintenance around that. Not to mention how you configure the open source also affects if you could be vulnerable to a cve.