1"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[6995],{3387:(e,n,t)=>{t.r(n),t.d(n,{assets:()=>c,contentTitle:()=>u,default:()=>f,frontMatter:()=>l,metadata:()=>p,toc:()=>m});var r,o=t(8168),a=t(8587),i=(t(6540),t(5680)),s=["components"],l={title:"Organisation Metrics",tags:["OSPO (Role)","CTO/CIO (Role)","Developer","Placeholder","Organisational-Measurement"],sidebar_label:"Organisation",list_image:"/img/bok/metric.png"},u=void 0,p={unversionedId:"bok/Measurements/Organisation",id:"bok/Measurements/Organisation",title:"Organisation Metrics",description:"For an organisation engaged in open source (or inner source), consider measuring the strength of contribution, security posture and legal compliance.",source:"@site/../docs/bok/Measurements/Organisation.md",sourceDirName:"bok/Measurements",slug:"/bok/Measurements/Organisation",permalink:"/docs/bok/Measurements/Organisation",draft:!1,editUrl:"https://github.com/finos/open-source-readiness/edit/main/docs/../docs/bok/Measurements/Organisation.md",tags:[{label:"OSPO (Role)",permalink:"/docs/tags/ospo-role"},{label:"CTO/CIO (Role)",permalink:"/docs/tags/cto-cio-role"},{label:"Developer",permalink:"/docs/tags/developer"},{label:"Placeholder",permalink:"/docs/tags/placeholder"},{label:"Organisational-Measurement",permalink:"/docs/tags/organisational-measurement"}],version:"current",frontMatter:{title:"Organisation Metrics",tags:["OSPO (Role)","CTO/CIO (Role)","Developer","Placeholder","Organisational-Measurement"],sidebar_label:"Organisation",list_image:"/img/bok/metric.png"},sidebar:"defaultSidebar",previous:{title:"Code Duplication",permalink:"/docs/bok/Measurements/Code-Duplication"},next:{title:"Process",permalink:"/docs/bok/Measurements/Process"}},c={},m=[{value:"What To Measure",id:"what-to-measure",level:2}],g=(r="BoxOut",function(e){return console.warn("Component "+r+" was not imported, exported, or provided by MDXProvider as global scope"),(0,i.yg)("div",e)}),y={toc:m},d="wrapper";function f(e){var n=e.components,t=(0,a.A)(e,s);return(0,i.yg)(d,(0,o.A)({},y,t,{components:n,mdxType:"MDXLayout"}),(0,i.yg)("p",null,"For an organisation engaged in open source (or inner source), consider measuring the strength of contribution, security posture and legal compliance."),(0,i.yg)("h2",{id:"what-to-measure"},"What To Measure"),(0,i.yg)(g,{title:"Committer Strength",image:"/img/bok/metric.png",mdxType:"BoxOut"},(0,i.yg)("p",null,"Ideally, you want some measure of the pervasiveness of open source contribution within the organisation. Consider:"),(0,i.yg)("ul",null,(0,i.yg)("li",{parentName:"ul"},"Number of individual internal staff committing to open source / inner source projects"),(0,i.yg)("li",{parentName:"ul"},"Number of pull-requests merged from internal staff (either on all projects or key strategic projects)"),(0,i.yg)("li",{parentName:"ul"},"Number of inner source / open source projects being maintained."),(0,i.yg)("li",{parentName:"ul"},"Number of commits."),(0,i.yg)("li",{parentName:"ul"},"Number of CCLAs an organisation has executed/entered and maintains."))),(0,i.yg)(g,{title:"License Compliance",image:"/img/bok/metric.png",mdxType:"BoxOut"},(0,i.yg)("p",null,"Assuming your ",(0,i.yg)("a",{parentName:"p",href:"../Roles/Legal"},"Legal Team")," have created a ",(0,i.yg)("a",{parentName:"p",href:"../Activities/Level-2/License-Management"},"license allow list"),", consider scanning internal projects and producing metrics around the number of license violations. "),(0,i.yg)("p",null,"The ",(0,i.yg)("a",{parentName:"p",href:"https://github.com/finos/security-scanning"},"FINOS Security Scanning project")," shows how this can be done on a per-project basis but you are likely to want to run this across your organisation's estate. Consider applying one of the tools from the ",(0,i.yg)("a",{parentName:"p",href:"../Activities/Level-2/Software-Inventory"},"Software Inventory")," article."),(0,i.yg)("p",null,"Consider measuring:"),(0,i.yg)("ul",null,(0,i.yg)("li",{parentName:"ul"},"Violations overall, or per-project."),(0,i.yg)("li",{parentName:"ul"}
1,"Main offenders (i.e. which dependencies cause the most violations)"),(0,i.yg)("li",{parentName:"ul"},"Mean time to fix")),(0,i.yg)("p",null,(0,i.yg)("strong",{parentName:"p"},"See:")," the article on ",(0,i.yg)("a",{parentName:"p",href:"../Activities/Level-2/License-Management"},"License Management")," for more details.")),(0,i.yg)(g,{title:"Vulnerability Exposure",image:"/img/bok/metric.png",mdxType:"BoxOut"},(0,i.yg)("p",null,"Metrics around Common Vulnerabilities and Exposure (CVE) measurements in an in-house software estate."),(0,i.yg)("blockquote",null,(0,i.yg)("p",{parentName:"blockquote"},"The Common Vulnerabilities and Exposures (CVE) system provides a reference method for publicly known information-security vulnerabilities and exposures. - ",(0,i.yg)("a",{parentName:"p",href:"https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures"},"Common Vulnerabilities and Exposures, ",(0,i.yg)("em",{parentName:"a"},"Wikipedia")))),(0,i.yg)("p",null,"Consider measuring: "),(0,i.yg)("ul",null,(0,i.yg)("li",{parentName:"ul"},"Criticality of the CVEs (Using ",(0,i.yg)("a",{parentName:"li",href:"https://en.wikipedia.org/wiki/Common_Vulnerability_Scoring_System"},"CVSS Scoring"),")"),(0,i.yg)("li",{parentName:"ul"},"Time taken from reporting to patching in firm software"),(0,i.yg)("li",{parentName:"ul"},"Quantity of CVEs"),(0,i.yg)("li",{parentName:"ul"},"Amount of software being scanned vs. not scanned.")),(0,i.yg)("p",null,(0,i.yg)("strong",{parentName:"p"},"See:")," the article on ",(0,i.yg)("a",{parentName:"p",href:"../Activities/Level-2/Supply-Chain-Security"},"Supply Chain Security")," for more details.")),(0,i.yg)(g,{title:"Return On Investment (ROI)",image:"/img/bok/metric.png",mdxType:"BoxOut"},(0,i.yg)("p",null,"How can you measure the ROI of open source within the organisation, both consumption and contribution? ",(0,i.yg)("em",{parentName:"p"},"(open question - tbd)"))))}f.isMDXComponent=!0},5680:(e,n,t)=>{t.d(n,{xA:()=>p,yg:()=>y});var r=t(6540);function o(e,n,t){return n in e?Object.defineProperty(e,n,{value:t,enumerable:!0,configurable:!0,writable:!0}):e[n]=t,e}function a(e,n){var t=Object.keys(e);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(e);n&&(r=r.filter(function(n){return Object.getOwnPropertyDescriptor(e,n).enumerable})),t.push.apply(t,r)}return t}function i(e){for(var n=1;n<arguments.length;n++){var t=null!=arguments[n]?arguments[n]:{};n%2?a(Object(t),!0).forEach(function(n){o(e,n,t[n])}):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(t)):a(Object(t)).forEach(function(n){Object.defineProperty(e,n,Object.getOwnPropertyDescriptor(t,n))})}return e}function s(e,n){if(null==e)return{};var t,r,o=function(e,n){if(null==e)return{};var t,r,o={},a=Object.keys(e);for(r=0;r<a.length;r++)t=a[r],n.indexOf(t)>=0||(o[t]=e[t]);return o}(e,n);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);for(r=0;r<a.length;r++)t=a[r],n.indexOf(t)>=0||Object.prototype.propertyIsEnumerable.call(e,t)&&(o[t]=e[t])}return o}var l=r.createContext({}),u=function(e){var n=r.useContext(l),t=n;return e&&(t="function"==typeof e?e(n):i(i({},n),e)),t},p=function(e){var n=u(e.components);return r.createElement(l.Provider,{value:n},e.children)},c="mdxType",m={inlineCode:"code",wrapper:function(e){var n=e.children;return r.createElement(r.Fragment,{},n)}},g=r.forwardRef(function(e,n){var t=e.components,o=e.mdxType,a=e.originalType,l=e.parentName,p=s(e,["components","mdxType","originalType","parentName"]),c=u(t),g=o,y=c["".concat(l,".").concat(g)]||c[g]||m[g]||a;return t?r.createElement(y,i(i({ref:n},p),{},{components:t})):r.createElement(y,i({ref:n},p))});function y(e,n){var t=arguments,o=n&&n.mdxType;if("string"==typeof e||o){var a=t.length,i=new Array(a);i[0]=g;var s={};for(var l in n)hasOwnProperty.call(n,l)&&(s[l]=n[l]);s.originalType=e,s[c]="string"==typeof e?e:o,i[1]=s;for(var u=2;u<a;u++)i[u]=t[u];return r.createElement.apply(null,i)}return r.createElement.apply(null,t)}g.displayName="MDXCreateElement"}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.