NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 CIO BlackBerry News and Tips
 CIO Research and Analysis
 CIO Microsoft
 CIO Insider
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 


Wed, Jun 4, 2008 11:49 EDT

What Risks Do Corporate Open-Source Contributions Present?

Topic: Enterprise Management

Blog: Executives Online

Current Rating: 4 Comments: 5

Enterprise IT personnel contributions to open source projects and products is becoming more common and even benefical to the enterprise. But, what risks does this open up to the enterprise?

Presumably, some of those risks can be alleviated (if not eliminated) by adopting sensible policies and creating clear guidelines. (Developers brought up some of these issues in my employee as committer article, but that wasn't its main focus.) How can an enterprise make the most out of open source involvement without triggering internal issues or risk?

You do not have flash or javascript support.
Average (2 votes)
4
 
 
Wed, Jun 4, 2008 12:55 EDT
Posted by: Bernard Golden
Rating: 90

The question was "How can an enterprise make the most out of open source involvement without triggering internal issues or risk?"

I think that perspective is poorly chosen. There's risk in contributing code to an open source project -- you might contribute valuable IP in the form of copyrighted material or trade secrets.

However, there's risk in not contributing code -- you have a suboptimal open source product or one that you have to repeatedly patch every time a new mainstream release comes out.

And even if you eschew open source, thinking that you'll avoid the IP risks in contributing code, you have a different sort of risk -- vendor lock-in, application inflexibility, and so on.

No matter which option you choose, there is risk involved. The value a specialist organization like IT brings to the table is that it can use its collective experience and knowledge to identify the path forward that best balances opportunity and risk, knowing that there is no such thing as a risk-free choice.

We do a disservice to open source if we paint it as some kind of perfect Nirvana, where all IT problems go away. They're *different* problems, and if we (meaning the people working with the open source product) do our job well, they're smaller problems (i.e., lower risk).

Contributing code is the right choice for some IT organizations, and those that do must put processes in place to track what's contributed and ensure it does not pose unacceptable IP risk.

 
Wed, Jun 4, 2008 16:26 EDT
Posted by: bobsutor
Rating: 50

When you contribute to an open source project, intellectual property is contributed to a larger community and you lose some control of it. Not all control, because contributing to open source is different from putting something in the public domain. Depending on the license, you might still be able to exercise defensive termination, for example, if someone sues you for patent infringement.

Therefore, if you contribute, know what you are giving away and know, for example, if you have a patent in the area. It also might be good to know if you've previously licensed that patent to someone because they will probably be very interested in your new found love of "free."

Make sure what you are donating is actually yours. If it is not coming from another open source project with the same license, you probably want to have certificates of originality from your developers.

Have a policy for how employees can work with open source projects in their free time. You probably don't want them to contribute your IP that happens to be in their heads to a project that they do in their off hours.

 
Thu, Jun 5, 2008 4:53 EDT
Posted by: Matthew Tomlinson
Rating: 50

Some businesses do believe that the software they create contains valuable IP, although the truth is in most cases this is not the true – unless of course you are a software vendor!

Its important to recognise that the business IP and software can be separated quite simply – business rules and data are the real business IP, software is a tool that works with the rules and data. The industry I work in is insurance, one of the most commonly used tools is Microsoft Excel. No one (except Microsoft) considers Excel as their IP, the business IP is actually the data and scripts that make up the spreadsheets created in Excel. The software is simply a tool business uses to simplify paper work and manual tasks - helping reduce mistakes and increase productivity.

If you apply this principle to open source in general, then companies have little to fear with regards to contributing to open source projects. Obviously this is a generalisation and each business needs to decide for themselves, however the principle works across most industries, be it graphic design, banking, logistics or insurance - software is a tool and usually not the business IP.

Matthew Tomlinson

Founding Member: OpenQuote
Director: Applied Industrial Logic
Sponsor: OpenSourceInsurance.org

 
Thu, Jun 5, 2008 11:24 EDT
Posted by: johnpowell
Rating: 70

Most open-source projects, and all of the top projects (Linux, Apache, etc.) require contributors to submit code as individuals, not as employees of Company X, Y, or Z. When they do so, they also generally assign copyright, while simultaneously assuming the legal burden that the code they've submitted doesn't infringe someone else's intellectual property. It's possible that a court would look past this to the company employing the developer, but I think the mechanisms in place to protect companies who contribute are quite robust.

But this is probably the wrong question to be asking, anyway. Yes, there's always a risk when contributing to an outside project, but any such risks are heavily outweighed by the following benefits:

  1. Open source reduces the risk of IT project failure. Many (most?) IT projects fail. Open source costs less and, where a company is behind the project, support is paid annually. This, coupled with open source's "try before you buy" approach, means that the likelihood and cost of a project failing go way down.
  2. Open source reduces the risk of downtime. I talk with large enterprises all the time whose biggest complaint about proprietary software (besides the cost and bloat, of course) is that it's a black box. They have no idea what is going on beneath the covers, so to speak, and so if trouble arises the customer is completely at the mercy of the vendor. This may be fine for non-critical applications, but it's a serious issue for company-critical applications and infrastructure. The employees' ability to understand and, where necessary, modify the code is of huge benefit.
  3. The way contracts are written these days, open source may also help to reduce the risk of litigation. If you've read a software license recently, or negotiated one, you know that customers increasingly are leery of any risk associated with running the software nevermind modifying it. The ability to modify the code to remove allegedly infringing code quickly is a great boon to mitigating damages.

Open source is not a legal risk waiting to happen. In my experience, it can be the exact opposite of this. Open source is a great way to reduce risk.

John Powell
CEO, Alfresco Software
http://www.alfresco.com

 
Thu, Jun 5, 2008 19:49 EDT
Anonymous user
Posted by: Rod Johnson
Rating: 50

In my experience (largely in midleware infrastructure around Spring), very few companies are concerned about giving away competitive advantage through contribution to open source infrastructure projects. The benefits of having others to help maintain the code are a clear business driver.

The obstacles are typically the difficulty of getting contributions through legal, which can be immense. Many large companies have legal departments who find it hard to understand why the company would give away any IP without compensation.

If there's any danger, I think it is to the open source projects, unless the granted IP is clean.

Post new comment

* Subject:
* Username:
* E-mail:
The content of this field is kept private and will not be shown publicly.
Homepage:
* Body:
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <img> <blockquote> <strike> <p> <br>
  • Lines and paragraphs break automatically.
More information about formatting options

* Denotes required field.

About this Blog

Our visiting guests discuss the topic of the week.

Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 113 of IT's most insightful thinkers.

  PARTNERS       WEBCASTS    
 

Windows 7 Webcast Series

There's a lot of buzz about Windows 7 out there. Each month in our webcast series, listen to analysts and customers discuss how Windows 7 and the Windows Optimized Desktop is impacting large companies around the world. Learn how they evaluated Windows 7, including the cost of deployment, deployment strategies, and tangible benefits.

Sponsored by Microsoft  Listen to on-demand Recordings »

 

Service Level Management Best Practices Life Cycle Overview - Improve Service Levels

Best practices for Service Level Management (SLM) is a process for consistently meeting customer requirements and delivering on IT's promises. See the steps required to ensure high-quality SLM.

Sponsored by Compuware  Read this White Paper »

 

Keeping Your Members Safe from Online Scams and Predators

In order to keep fraudsters out, romance sites must deploy effective solutions that look at information independent of what is supplied by users. A device fingerprinting solution such as iovation ReputationManager™ provides unique insight into the computers being used to create multiple accounts and exposes hidden device-account relationships that identity-based fraud solutions often miss.

Sponsored by iovation  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

Defend Against Blended Threats: What You Need to Know

Blended Web and email threats are becoming increasingly complex and represent a huge...  View Now »

 

Prescriptive Actions to Reduce Risk

In this Webcast, learn best practices for effective systems management in a heterogeneous environment and keep client systems cost under control.   View Now »

 

Webcast- Vantage 11: Redefining Application Performance Management

Compuware's latest release, Vantage 11, is a major advance in end-to-end application performance management--bringing together proactive issue identification, quantification of business impact and problem resolution into a single solution. Tune in to learn how Vantage 11's top-down approach helps you make better decisions and dramatically lower operations costs.  View Now »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Blogs & Discussion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

See how AT&T can help protect your network.

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

Interactive Q&A helps you discover key ways to maximize IT assets.

Ready to virtualize tier one applications? Check your virtualization maturity.

Think you can't afford a Cisco Switch? Cisco Catalyst Switches are now more affordable.

Five minute business analytics assessment. Immediate results.

The Case for Investing in Business Analytics Technology. Read white paper.

Upgrading to VMware vSphere with vWire

Top 10 Lessons Learned for Corporate 3G Mobile Broadband Deployments

CRM Built for IT: The Executive Guide to Selecting CRM that Meets IT Needs

Return on Information: Google Enterprise Search pays you back

ROI of Application Delivery Controllers

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

White Paper: Right-Sizing Your Power Infrastructure

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Top Five CIO Challenges

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

Increase UPS efficiency without sacrificing protection.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

World-class trading technology solutions from NYSE Technologies.

If You're Paying for Telecom, You're Paying Too Much. Contact Asentinel Today.

Trade-In your old printer and save up to $1,000 plus free recycling!

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community

Live Webinar: Applying Business Analytics. Click here to learn more

Removing Barriers To Better Server Virtualization Efficiency

4G Revisited. The Continued Evolution of Wireless Mobility.

What's Next for Enterprise Resource Planning?

Maximizing website Return on Information with high-quality search

Gartner Magic Quadrant, Application Delivery Controllers 2009

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths