Training Output Best Practice
These are completed examples of the three deliverables generated by the training-manager agent.
Use them to compare against your own output/training/ files and spot missing items.
Reference shortcut: Training Program chapter guide
Open Source Training Curriculum
Document: curriculum.md
- Company name: TechUnicorn
- Version: 1.0
- Date: 2026-03-23
- Underlying policy:
output/policy/oss-policy.md - Training format: Blended (online self-paced + offline group sessions)
- Evidence level: For certification submission (OpenChain Self-Certification)
Related standards
- 5230 §3.1.2·§3.1.3
- 18974 §4.1.2·§4.1.3
Training Audience
| Role | Headcount | Training priority |
|---|---|---|
| Developers | 1,000 | Required (advanced) |
| Operations | 100 | Required (basic) |
| Managers | 10 | Required (policy & risk) |
| Total | 1,110 | — |
Curriculum by Role
A. Developer course (1,000 people)
Related standards
- 5230 §3.1.2.1
- 18974 §4.1.2.1
Goal: Perform license identification, SBOM generation, and vulnerability response autonomously in day-to-day work
| Module | Subject | Format | Time | Required/Optional |
|---|---|---|---|---|
| M1 | Open source license basics (MIT·Apache·GPL·LGPL·AGPL) | Online self-paced | 2h | Required |
| M2 | Understanding the TechUnicorn Open Source Policy | Online self-paced | 1h | Required |
| M3 | Hands-on SBOM generation (Syft, CycloneDX) | Offline group | 3h | Required |
| M4 | Hands-on vulnerability scanning and CVE response | Offline group | 2h | Required |
| M5 | License obligations by distribution channel (SaaS, app store, embedded) | Online self-paced | 1.5h | Required |
| M6 | Open source contribution process | Online self-paced | 1h | Optional |
| Total | — | — | 10.5h (required 9.5h) | — |
Completion criteria: Complete all required modules + score 70 or higher on the online assessment Offline group sessions: Once per quarter, in groups of 50 per team
B. Manager course (10 people)
Related standards
- 5230 §3.1.2.1
- 18974 §4.1.2.1
Goal: Build competence in policy approval, risk judgment, and compliance reporting
| Module | Subject | Format | Time | Required/Optional |
|---|---|---|---|---|
| M1 | Open source compliance overview and risks | Online self-paced | 1.5h | Required |
| M2 | TechUnicorn Open Source Policy and KPIs | Online self-paced | 1h | Required |
| M3 | ISO/IEC 5230·18974 Self-Certification procedure | Offline group | 2h | Required |
| M4 | Risk management and incident response framework | Offline group | 1.5h | Required |
| M5 | External delivery and supply chain security management | Online self-paced | 1h | Required |
| Total | — | — | 7h | — |
Completion criteria: Complete all modules + attend the offline workshop Offline group session: Once a year, for all managers
C. Operations/other course (100 people)
Related standards
- 5230 §3.1.3.1
- 18974 §4.1.3.1
Goal: Raise awareness of open source use and understand the basic rules
| Module | Subject | Format | Time | Required/Optional |
|---|---|---|---|---|
| M1 | What is open source (awareness training) | Online self-paced | 30min | Required |
| M2 | Summary of the company open source policy | Online self-paced | 20min | Required |
| M3 | Violation cases and reporting procedures | Online self-paced | 10min | Required |
| Total | — | — | 1h | — |
Completion criteria: Complete all modules (no assessment)
Training Schedule Plan
| Quarter | Audience | Course | Notes |
|---|---|---|---|
| 2026-Q2 | Operations, 100 people | Course C (online) | Opens all at once in May |
| 2026-Q2 | Managers, 10 people | Course B (online + offline) | June group session |
| 2026-Q2~Q3 | Developers, 1,000 people | Course A M1·M2·M5·M6 (online) | 250 people per quarter |
| 2026-Q3 | Developers, 250 people (round 1) | Course A M3·M4 (offline) | 50 people × 5 sessions |
| 2026-Q4 | Developers, 250 people (round 2) | Course A M3·M4 (offline) | 50 people × 5 sessions |
| 2027-Q1 | Developers, 500 people (rounds 3–4) | Course A M3·M4 (offline) | 50 people × 10 sessions |
Training Completion Management
- Completion records:
output/training/completion-tracker.md - Evidence retention: certificates and attendance sheets → kept by the Program Manager (in preparation for OpenChain certification submission)
- Non-completers: complete a make-up session within 1 month after the quarter ends
- Renewal cycle: retake once a year (or whenever the policy changes)
Training Completion Tracking Sheet
Document: completion-tracker.md
- Company name: TechUnicorn
- Version: 1.0
- Date: 2026-03-23
- Evidence level: For certification submission (OpenChain Self-Certification)
- Managed by: DevOps team open source Program Manager
Related standards
- 5230 §3.1.2·§3.1.3
- 18974 §4.1.2·§4.1.3
How to Use
- Completion date: The date the course was completed (YYYY-MM-DD)
- Status:
Completed/In progress/Not completed - Evidence: Record the certificate file name or attendance sheet number
- When submitting for OpenChain certification, submit this sheet together with the evidence files
- The Hong Gil-dong, Kim Cheol-su, Lee Young-hee, and Park Ji-su rows are sample records for illustration and are excluded from the completion status summaries
A. Developer Course (target: 1,000 people)
The named rows in the table below are sample records and are excluded from the completion status summary. Add rows as people actually complete the course.
| Name | Department | Role | M1 Online (2h) | M2 Online (1h) | M3 Offline (3h) | M4 Offline (2h) | M5 Online (1.5h) | Completion date | Status | Evidence |
|---|---|---|---|---|---|---|---|---|---|---|
| Hong Gil-dong | Platform Development Team | Developer | ✓ | ✓ | ✓ | ✓ | ✓ | 2026-09-15 | Completed | CERT-DEV-001 |
| Kim Cheol-su | Cloud Development Team | Developer | ✓ | ✓ | — | — | ✓ | — | In progress | — |
| (Name) | (Department) | Developer | Not completed | — |
Completion status summary
| Item | Count |
|---|---|
| Total audience | 1,000 |
| Completed | 0 |
| In progress | 0 |
| Not completed | 1,000 |
| Completion rate | 0% |
B. Manager Course (target: 10 people)
| Name | Position | M1 Online (1.5h) | M2 Online (1h) | M3 Offline (2h) | M4 Offline (1.5h) | M5 Online (1h) | Completion date | Status | Evidence |
|---|---|---|---|---|---|---|---|---|---|
| Lee Young-hee | DevOps Team Leader | ✓ | ✓ | ✓ | ✓ | ✓ | 2026-06-30 | Completed | CERT-MGR-001 |
| (Name) | (Position) | Not completed | — |
Completion status summary
| Item | Count |
|---|---|
| Total audience | 10 |
| Completed | 0 |
| In progress | 0 |
| Not completed | 10 |
| Completion rate | 0% |
C. Operations/Other Course (target: 100 people)
| Name | Department | Role | M1 Awareness (30min) | M2 Policy summary (20min) | M3 Reporting procedure (10min) | Completion date | Status | Evidence |
|---|---|---|---|---|---|---|---|---|
| Park Ji-su | IT Operations Team | Operations | ✓ | ✓ | ✓ | 2026-05-20 | Completed | CERT-OPS-001 |
| (Name) | (Department) | Operations | Not completed | — |
Completion status summary
| Item | Count |
|---|---|
| Total audience | 100 |
| Completed | 0 |
| In progress | 0 |
| Not completed | 100 |
| Completion rate | 0% |
Overall Completion Status (Combined)
| Role | Audience | Completed | Completion rate | Target |
|---|---|---|---|---|
| Developers | 1,000 | 0 | 0% | 100% |
| Managers | 10 | 0 | 0% | 100% |
| Operations | 100 | 0 | 0% | 100% |
| Total | 1,110 | 0 | 0% | 100% |
Policy KPI: open source–related roles must complete training at least once a year (
output/policy/oss-policy.md§3)
Change History
| Version | Date | Changes | Author |
|---|---|---|---|
| 1.0 | 2026-03-23 | Initial version | DevOps team open source Program Manager |
Free Training Resource List
Document: resources.md
- Company name: TechUnicorn
- Version: 1.0
- Date: 2026-03-23
Related standards
- 5230 §3.1.2·§3.1.3
- 18974 §4.1.2·§4.1.3
Recommended Usage
- Pair the free resources below with the online self-paced modules (courses A·B·C)
- Courses that issue certificates can be submitted directly as OpenChain certification evidence
1. Official OpenChain Training Materials
| Resource | Audience | Format | Certificate | Link |
|---|---|---|---|---|
| OpenChain e-Learning | All roles | Online self-paced | None | https://www.openchainproject.org/resources |
| OpenChain Curriculum | Developers·Managers | Slides/documents | None | https://github.com/OpenChain-Project/curriculum |
| OpenChain Reference Materials | Managers | Documents | None | https://www.openchainproject.org/resources |
Curriculum mapping: supplementary materials for Developer M1·M2 and Manager M1·M2
2. Linux Foundation Courses
| Course name | Course code | Audience | Time | Certificate | Link |
|---|---|---|---|---|---|
| Open Source Compliance in the Enterprise | LFC193 | Developers·Managers | ~3h | Available (free) | https://training.linuxfoundation.org/training/open-source-compliance-in-the-enterprise/ |
| Open Source Licensing Basics for Software Developers | LFC191 | Developers | ~3h | Available (free) | https://training.linuxfoundation.org/training/open-source-licensing-basics-for-software-developers/ |
| Secure Software Development Fundamentals | LFD121 | Developers | ~12h | Available (free) | https://training.linuxfoundation.org/training/developing-secure-software-lfd121/ |
| Kubernetes and Cloud Native Security Associate | — | Operations | — | Paid | — |
Curriculum mapping:
- LFC193 → core material for Developer M2 and Manager M1·M2
- LFC191 → core material for Developer M1
- LFD121 → supplementary material for Developer M4
Using the certificates: LFC193 and LFC191 certificates can be used as evidence for the OpenChain Self-Certification submission
3. SPDX Training
| Resource | Audience | Format | Link |
|---|---|---|---|
| SPDX Specification official document | Developers | Documents | https://spdx.github.io/spdx-spec/ |
| SPDX introductory guide | Developers | Documents | https://spdx.dev/learn/ |
| SPDX Tools usage | Developers | Documents/tools | https://tools.spdx.org/ |
Curriculum mapping: reference material for Developer M3 (hands-on SBOM generation)
4. Open Source Vulnerability Resources
| Resource | Audience | Link |
|---|---|---|
| NVD (National Vulnerability Database) | Developers·Managers | https://nvd.nist.gov/ |
| OSV (Open Source Vulnerabilities) | Developers | https://osv.dev/ |
| CISA Known Exploited Vulnerabilities | Managers | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
Curriculum mapping: Developer M4, Manager M4
5. Tools and Hands-on Materials
| Tool/material | Purpose | Link |
|---|---|---|
| Syft (Anchore) | Hands-on SBOM generation | https://github.com/anchore/syft |
| Grype (Anchore) | Hands-on vulnerability scanning | https://github.com/anchore/grype |
| CycloneDX official site | Understanding the SBOM standard | https://cyclonedx.org/ |
| FOSSA blog | License compliance case studies | https://fossa.com/blog/ |
| REUSE specification | Source code license annotation | https://reuse.software/ |
Curriculum mapping: hands-on tools for Developer M3·M4
6. ISO/IEC 5230 · 18974 References
| Resource | Description | Link |
|---|---|---|
| OpenChain ISO/IEC 5230 specification | License compliance standard | https://www.openchainproject.org/license-compliance |
| OpenChain ISO/IEC 18974 specification | Security assurance standard | https://www.openchainproject.org/security-assurance |
| OpenChain Self-Certification checklist | Certification preparation | https://www.openchainproject.org/conformance |
Curriculum mapping: core material for Manager M3
Resource Selection Guide
| Role | Top-priority resources | Certificate use |
|---|---|---|
| Developers | LFC191 → LFC193 → Syft hands-on | Submit LFC191 + LFC193 certificates |
| Managers | LFC193 → OpenChain Curriculum → ISO 5230/18974 specifications | Submit LFC193 certificate |
| Operations | OpenChain e-Learning | Completion records suffice |