Due Diligence and Ongoing Monitoring

 View Only

Opensource/Community third parties and tools

  • 1.  Opensource/Community third parties and tools

    This message was posted by a user wishing to remain anonymous
    Posted 02-20-2025 01:08 PM
    This message was posted by a user wishing to remain anonymous

    Hello,

    I am reaching out to this community for any guidance you may have regarding the onboarding and tracking of Opensource/community tools. These tools are categorized by having some form of open license (MIT, Apache, GNU, etc) and not direct contract with an entity. 

    1. What documentation do you collect?
    2. How do you verify the tool is secure to use?
    3. Is this part of your TPRM program or managed in your IT dept?
    4. What sort of continuous monitor procedure do you utilize?
    5. How does your legal dept get comfortable with the license and lack of other agreement protections?