Skip to main content

reference

#Reference

This section contains reference materials needed to build an open source management system.

Output Best Practice

This is a complete example of the output produced by the agent at each stage. We provide 3 profiles by size (startup / small business / large company). Check the missing items by comparing them with the results of your output/ folder.

outputResponse AgentGo to
Organization (role-definition, raci-matrix, appointment-template)organization-designerOrganizational Output
policy (oss-policy, license-allowlist)policy-generatorPolicy Output
process (usage-approval, distribution-checklist, vulnerability-response)process-designerProcess Output
Education (curriculum, completion-tracker, resources)training-managerEducation output
Certification (gap-analysis, declaration-draft, submission-guide)conformance-preparerCertification Output

Contents to be covered (in preparation)

Tool Guide

This is an in-depth guide to free open source tools.

toolsContentstatus
syftSBOM Creation AdvancedPreparing
cdxgenCycloneDX Conversion AdvancedPreparing
Dependency Trackvulnerability management detailed settingsPreparing
OSV APIHow to use vulnerability searchPreparing

License

documentContentstatus
License Compatibility MatrixCompatibility between major licensesPreparing
SKT Open Source License GuideDetailed ObligationsShortcut
regulationContentstatus
EU CRACyber ​​Resilience Act SummaryPreparing
US EO 14028SBOM Mandatory Executive OrderPreparing
Domestic trendsStatus of government guidelinesPreparing