| By Bill Dudney | Article Rating: |
|
| November 2, 2005 01:45 PM EST | Reads: |
12,204 |
Bill Dudney's Blog: Open Source Compliance Insurance - More Evidence of Maturing MarketI found this very interesting indeed. Basically the insurance company will underwrite you and cover various types of 'direct loss' if/when you pass their compliance audit. From the article;
In practice, OSRM has a team of five people who will carry out an open-source license compliance review on a company's software. This initial risk assessment costs between $25,000 and $50,000, according to Egger. OSRM will then report back to Hogg's Kiln on the findings of the review and after establishing the company's risk profile, the insurance policy will be drawn up. "The review firms up the facts that we've looked at it and believe in the position," Hogg said. "The buck [then] stops with the insurance company."
The team comes in and makes sure you are not currently in violation of the licenses of FOSS your company is using then provides coverage if you pass (and I would guess would give you points on how to pass if you currently don't). This makes me wonder what happens over time. Would something like Black Duck provide the on-going protection to keep your code in complainace? Not sure what the insurance company would require for the ongoing nature of development and the possibility of violations sneaking in. Later in the article though it says to get $10M worth of coverage will cost about $200K per year. Perhaps at that rate the insurance company could afford to send in someone from time to time to do a follow on assessment.
I'm not sure how I feel about insurance though. With insurance comes lawyers and with lawyers comes complexity. It will be interesting to see how many takers this type of insurance has.
Published November 2, 2005 Reads 12,204
Copyright © 2005 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Bill Dudney
Bill Dudney is Editor-in-Chief of Eclipse Developer's Journal and serves too as JDJ's Eclipse editor. He is a Practice Leader with Virtuas Solutions and has been doing Java development since late 1996 after he downloaded his first copy of the JDK. Prior to Virtuas, Bill worked for InLine Software on the UML bridge that tied UML Models in Rational Rose and later XMI to the InLine suite of tools. Prior to getting hooked on Java he built software on NeXTStep (precursor to Apple's OSX). He has roughly 15 years of distributed software development experience starting at NASA building software to manage the mass properties of the Space Shuttle.
![]() |
Eclipse Developer's Journal News Desk 11/02/05 02:51:25 PM EST | |||
Bill Dudney's Blog: Open Source Compliance Insurance - More Evidence of Maturing Market. I'm not sure how I feel about insurance though. With insurance comes lawyers and with lawyers comes complexity. It will be interesting to see how many takers this type of insurance has. |
||||
- Oracle-Sun: IBM Reportedly Behind Delay
- GITEX TECHNOLOGY WEEK 2009 Exhibitor Profiles
- IBM Puts Systems Chief on Leave of Absence
- Amazon Web Services Database in the Cloud
- SpringSource Moving to Spring 3.0
- Un-Clouding Federal Security Compliance
- United Planet offers practical portal building tips for SMBs
- Saas-Based Time and Cost Reductions in the Cloud
- Developing APIs for the Cloud
- The Bunker achieves PCI DSS Compliance
- Canonical Offers Free Cloudware
- Qt DevDays 2009 - Munich
- Oracle-Sun: IBM Reportedly Behind Delay
- The Case for Single-Purpose Services
- GITEX TECHNOLOGY WEEK 2009 Exhibitor Profiles
- Current Trends in the Data Management Market
- IBM Puts Systems Chief on Leave of Absence
- Cloud BI & Amazon VPC
- The Curious Case of Build Release Management eBook
- Cloud-Oriented Switch Start-up Valued at $230M
- Tips for Efficient PaaS Application Design
- Reporting Solutions Using Crystal Reports for Eclipse
- Amazon Web Services Database in the Cloud
- SpringSource Moving to Spring 3.0
- Java Developer's Journal Exclusive: 2006 "JDJ Editors' Choice" Awards
- The i-Technology Right Stuff
- Creating Web Applications with the Eclipse Web Tools Project
- Eclipse Special: Remote Debugging Tomcat & JBoss Apps with Eclipse
- The Next Programming Models, RIAs and Composite Applications
- Where Are RIA Technologies Headed in 2008?
- How to Bring Eclipse 3.1, J2SE 5.0, and Tomcat 5.0 Together
- SYS-CON Webcast: Eclipse IDE for Students, Useful Eclipse Tips & Tricks
- Eclipse: The Story of Web Tools Platform 0.7
- "Eclipse 3.0 is a Great Leap Forward," Says JDJ's Dudney
- Developing an Eclipse BIRT Report Item Extension
- Eclipse Special: Bill Dudney Looks at New Stuff in M9



























