<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>OSPO on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/ospo/</link><description>Recent content in OSPO on OpenChain KWG</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 10 Aug 2026 11:20:08 +0900</lastBuildDate><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/ospo/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA 2026 SBOM Minimum Elements: What to Prepare and Which Tools Fill the Gaps</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;p&gt;On July 29, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and 17 other agencies published a revised set of minimum elements for a Software Bill of Materials (SBOM)&lt;a id="a2-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/#a2"&gt;A2&lt;/a&gt;. The document states plainly that it replaces, rather than amends, the baseline established in 2021 by the National Telecommunications and Information Administration (NTIA).&lt;/p&gt;</description></item><item><title>What the US AI Executive Order (2026-06-02) Means for Enterprise Open Source Managers</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The executive order &amp;ldquo;Promoting Advanced Artificial Intelligence Innovation and Security,&amp;rdquo; signed on June 2, 2026, imposes no obligations on enterprises. Its substance is the Treasury Department-led AI Cybersecurity Clearinghouse (a relay body that pools, verifies, and distributes vulnerability information, to be established within 30 days) and a voluntary pre-disclosure framework for frontier models (to be designed within 60 days); mandatory licensing and pre-approval are explicitly excluded &lt;a id="a1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#a1"&gt;A1&lt;/a&gt;. No provision applies directly to enterprise open source managers either. Still, there is a reason to read this order: the context behind it. AI finding open source vulnerabilities faster than humans do has already become reality. Ahead of the executive order, an unreleased Anthropic model found 6,202 high- or critical-severity vulnerabilities in open source projects over two months, and patching has not kept pace &lt;a id="a6-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#a6"&gt;A6&lt;/a&gt;·&lt;a id="c1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#c1"&gt;C1&lt;/a&gt;. What open source managers need to prepare is not compliance with the executive order, but a response system that can handle a check of patch-processing capacity, cleanup of end-of-life (EOL) components, and the EU Cyber Resilience Act reporting obligation taking effect September 11, 2026, all at once.&lt;/p&gt;</description></item><item><title>The EU Open Source Strategy: Institutionalizing Open Source for Tech Sovereignty</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/09/eu-oss-strategy/</link><pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/09/eu-oss-strategy/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The European Commission&amp;rsquo;s &amp;ldquo;Communication on European Tech Sovereignty&amp;rdquo; (COM(2026) 503 final), published on June 3, 2026, comes with an EU Open Source Strategy attached. It is the first time open source has been placed at the center of EU digital policy. The strategy sets four objectives — leveraging open source for sovereignty, strengthening the ecosystem, opening up public administration, and reinforcing standards and international cooperation — and calls for roughly EUR 2 billion in public and private funding to be mobilized for open-source-related measures over the next seven years. The aim is to reduce the EU&amp;rsquo;s dependence on US proprietary IT, on which it spends an estimated EUR 264 billion annually. Civil society (FSFE) and policy analysts have welcomed the direction while flagging limits: whether the funding is sufficient, how open standards relate to open source, the light treatment of open hardware, and the practitioner skills gap. For Korean public-sector and enterprise practitioners, the points worth watching directly are the opening of EU procurement, the open-source steward regulation, and the open-source default for the EUDI Wallet.&lt;/p&gt;</description></item><item><title>What Is an OSPO?</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2021/04/18/ospo-definition/</link><pubDate>Sun, 18 Apr 2021 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2021/04/18/ospo-definition/</guid><description>&lt;div class="pageinfo pageinfo-primary"&gt;
&lt;p&gt;This paper was translated by Haksung Jang from the English version available at the &lt;a href="https://github.com/todogroup/ospodefinition.org"&gt;OSPO Definition&lt;/a&gt;. The original document is licensed under &lt;a href="https://github.com/todogroup/ospodefinition.org/blob/master/LICENSE"&gt;CC-BY-SA-4.0&lt;/a&gt;.&lt;/p&gt;

&lt;/div&gt;

&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;Hello!&lt;/p&gt;
&lt;p&gt;&lt;a href="https://todogroup.org/"&gt;TODO Group&lt;/a&gt;&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; is a &lt;a href="https://todogroup.org/members/"&gt;group&lt;/a&gt;&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; under the Linux Foundation that advocates Talk Openly, Develop Openly, aiming to build successful open source projects and programs through collaboration. TODO Group creates and publishes open source &lt;a href="https://todogroup.org/guides/"&gt;guides&lt;/a&gt;&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt;, &lt;a href="https://github.com/todogroup/repolinter"&gt;tools&lt;/a&gt;&lt;sup id="fnref:4"&gt;&lt;a href="#fn:4" class="footnote-ref" role="doc-noteref"&gt;4&lt;/a&gt;&lt;/sup&gt;, and more, making them available to anyone interested in open source.&lt;/p&gt;
&lt;p&gt;For an organization such as a company to effectively manage and use open source, it is said that establishing an OSPO&lt;sub&gt;Open Source Program Office&lt;/sub&gt; is needed for activities such as developer education, ensuring compliance, engaging with and building community, releasing open source, and code review. This article carries over the &lt;a href="https://todogroup.org/blog/ospo-definition/"&gt;article defining&lt;/a&gt;&lt;sup id="fnref:5"&gt;&lt;a href="#fn:5" class="footnote-ref" role="doc-noteref"&gt;5&lt;/a&gt;&lt;/sup&gt; what an OSPO is and what role it plays, as written by TODO Group.&lt;/p&gt;</description></item></channel></rss>