Skip to main content

Training Output Best Practice

These are completed examples of the three deliverables generated by the training-manager agent. Use them to compare against your own output/training/ files and spot missing items.

Reference shortcut: Training Program chapter guide


Open Source Training Curriculum

Document: curriculum.md

  • Company name: TechUnicorn
  • Version: 1.0
  • Date: 2026-03-23
  • Underlying policy: output/policy/oss-policy.md
  • Training format: Blended (online self-paced + offline group sessions)
  • Evidence level: For certification submission (OpenChain Self-Certification)
Related standards
- 5230 §3.1.2·§3.1.3
- 18974 §4.1.2·§4.1.3

Training Audience

RoleHeadcountTraining priority
Developers1,000Required (advanced)
Operations100Required (basic)
Managers10Required (policy & risk)
Total1,110

Curriculum by Role

A. Developer course (1,000 people)

Related standards
- 5230 §3.1.2.1
- 18974 §4.1.2.1

Goal: Perform license identification, SBOM generation, and vulnerability response autonomously in day-to-day work

ModuleSubjectFormatTimeRequired/Optional
M1Open source license basics (MIT·Apache·GPL·LGPL·AGPL)Online self-paced2hRequired
M2Understanding the TechUnicorn Open Source PolicyOnline self-paced1hRequired
M3Hands-on SBOM generation (Syft, CycloneDX)Offline group3hRequired
M4Hands-on vulnerability scanning and CVE responseOffline group2hRequired
M5License obligations by distribution channel (SaaS, app store, embedded)Online self-paced1.5hRequired
M6Open source contribution processOnline self-paced1hOptional
Total10.5h (required 9.5h)

Completion criteria: Complete all required modules + score 70 or higher on the online assessment Offline group sessions: Once per quarter, in groups of 50 per team


B. Manager course (10 people)

Related standards
- 5230 §3.1.2.1
- 18974 §4.1.2.1

Goal: Build competence in policy approval, risk judgment, and compliance reporting

ModuleSubjectFormatTimeRequired/Optional
M1Open source compliance overview and risksOnline self-paced1.5hRequired
M2TechUnicorn Open Source Policy and KPIsOnline self-paced1hRequired
M3ISO/IEC 5230·18974 Self-Certification procedureOffline group2hRequired
M4Risk management and incident response frameworkOffline group1.5hRequired
M5External delivery and supply chain security managementOnline self-paced1hRequired
Total7h

Completion criteria: Complete all modules + attend the offline workshop Offline group session: Once a year, for all managers


C. Operations/other course (100 people)

Related standards
- 5230 §3.1.3.1
- 18974 §4.1.3.1

Goal: Raise awareness of open source use and understand the basic rules

ModuleSubjectFormatTimeRequired/Optional
M1What is open source (awareness training)Online self-paced30minRequired
M2Summary of the company open source policyOnline self-paced20minRequired
M3Violation cases and reporting proceduresOnline self-paced10minRequired
Total1h

Completion criteria: Complete all modules (no assessment)


Training Schedule Plan

QuarterAudienceCourseNotes
2026-Q2Operations, 100 peopleCourse C (online)Opens all at once in May
2026-Q2Managers, 10 peopleCourse B (online + offline)June group session
2026-Q2~Q3Developers, 1,000 peopleCourse A M1·M2·M5·M6 (online)250 people per quarter
2026-Q3Developers, 250 people (round 1)Course A M3·M4 (offline)50 people × 5 sessions
2026-Q4Developers, 250 people (round 2)Course A M3·M4 (offline)50 people × 5 sessions
2027-Q1Developers, 500 people (rounds 3–4)Course A M3·M4 (offline)50 people × 10 sessions

Training Completion Management

  • Completion records: output/training/completion-tracker.md
  • Evidence retention: certificates and attendance sheets → kept by the Program Manager (in preparation for OpenChain certification submission)
  • Non-completers: complete a make-up session within 1 month after the quarter ends
  • Renewal cycle: retake once a year (or whenever the policy changes)

Training Completion Tracking Sheet

Document: completion-tracker.md

  • Company name: TechUnicorn
  • Version: 1.0
  • Date: 2026-03-23
  • Evidence level: For certification submission (OpenChain Self-Certification)
  • Managed by: DevOps team open source Program Manager
Related standards
- 5230 §3.1.2·§3.1.3
- 18974 §4.1.2·§4.1.3

How to Use

  • Completion date: The date the course was completed (YYYY-MM-DD)
  • Status: Completed / In progress / Not completed
  • Evidence: Record the certificate file name or attendance sheet number
  • When submitting for OpenChain certification, submit this sheet together with the evidence files
  • The Hong Gil-dong, Kim Cheol-su, Lee Young-hee, and Park Ji-su rows are sample records for illustration and are excluded from the completion status summaries

A. Developer Course (target: 1,000 people)

Sample records

The named rows in the table below are sample records and are excluded from the completion status summary. Add rows as people actually complete the course.

NameDepartmentRoleM1 Online (2h)M2 Online (1h)M3 Offline (3h)M4 Offline (2h)M5 Online (1.5h)Completion dateStatusEvidence
Hong Gil-dongPlatform Development TeamDeveloper2026-09-15CompletedCERT-DEV-001
Kim Cheol-suCloud Development TeamDeveloperIn progress
(Name)(Department)DeveloperNot completed

Completion status summary

ItemCount
Total audience1,000
Completed0
In progress0
Not completed1,000
Completion rate0%

B. Manager Course (target: 10 people)

NamePositionM1 Online (1.5h)M2 Online (1h)M3 Offline (2h)M4 Offline (1.5h)M5 Online (1h)Completion dateStatusEvidence
Lee Young-heeDevOps Team Leader2026-06-30CompletedCERT-MGR-001
(Name)(Position)Not completed

Completion status summary

ItemCount
Total audience10
Completed0
In progress0
Not completed10
Completion rate0%

C. Operations/Other Course (target: 100 people)

NameDepartmentRoleM1 Awareness (30min)M2 Policy summary (20min)M3 Reporting procedure (10min)Completion dateStatusEvidence
Park Ji-suIT Operations TeamOperations2026-05-20CompletedCERT-OPS-001
(Name)(Department)OperationsNot completed

Completion status summary

ItemCount
Total audience100
Completed0
In progress0
Not completed100
Completion rate0%

Overall Completion Status (Combined)

RoleAudienceCompletedCompletion rateTarget
Developers1,00000%100%
Managers1000%100%
Operations10000%100%
Total1,11000%100%

Policy KPI: open source–related roles must complete training at least once a year (output/policy/oss-policy.md §3)


Change History

VersionDateChangesAuthor
1.02026-03-23Initial versionDevOps team open source Program Manager

Free Training Resource List

Document: resources.md

  • Company name: TechUnicorn
  • Version: 1.0
  • Date: 2026-03-23
Related standards
- 5230 §3.1.2·§3.1.3
- 18974 §4.1.2·§4.1.3

  • Pair the free resources below with the online self-paced modules (courses A·B·C)
  • Courses that issue certificates can be submitted directly as OpenChain certification evidence

1. Official OpenChain Training Materials

ResourceAudienceFormatCertificateLink
OpenChain e-LearningAll rolesOnline self-pacedNonehttps://www.openchainproject.org/resources
OpenChain CurriculumDevelopers·ManagersSlides/documentsNonehttps://github.com/OpenChain-Project/curriculum
OpenChain Reference MaterialsManagersDocumentsNonehttps://www.openchainproject.org/resources

Curriculum mapping: supplementary materials for Developer M1·M2 and Manager M1·M2


2. Linux Foundation Courses

Course nameCourse codeAudienceTimeCertificateLink
Open Source Compliance in the EnterpriseLFC193Developers·Managers~3hAvailable (free)https://training.linuxfoundation.org/training/open-source-compliance-in-the-enterprise/
Open Source Licensing Basics for Software DevelopersLFC191Developers~3hAvailable (free)https://training.linuxfoundation.org/training/open-source-licensing-basics-for-software-developers/
Secure Software Development FundamentalsLFD121Developers~12hAvailable (free)https://training.linuxfoundation.org/training/developing-secure-software-lfd121/
Kubernetes and Cloud Native Security AssociateOperationsPaid

Curriculum mapping:

  • LFC193 → core material for Developer M2 and Manager M1·M2
  • LFC191 → core material for Developer M1
  • LFD121 → supplementary material for Developer M4

Using the certificates: LFC193 and LFC191 certificates can be used as evidence for the OpenChain Self-Certification submission


3. SPDX Training

ResourceAudienceFormatLink
SPDX Specification official documentDevelopersDocumentshttps://spdx.github.io/spdx-spec/
SPDX introductory guideDevelopersDocumentshttps://spdx.dev/learn/
SPDX Tools usageDevelopersDocuments/toolshttps://tools.spdx.org/

Curriculum mapping: reference material for Developer M3 (hands-on SBOM generation)


4. Open Source Vulnerability Resources

ResourceAudienceLink
NVD (National Vulnerability Database)Developers·Managershttps://nvd.nist.gov/
OSV (Open Source Vulnerabilities)Developershttps://osv.dev/
CISA Known Exploited VulnerabilitiesManagershttps://www.cisa.gov/known-exploited-vulnerabilities-catalog

Curriculum mapping: Developer M4, Manager M4


5. Tools and Hands-on Materials

Tool/materialPurposeLink
Syft (Anchore)Hands-on SBOM generationhttps://github.com/anchore/syft
Grype (Anchore)Hands-on vulnerability scanninghttps://github.com/anchore/grype
CycloneDX official siteUnderstanding the SBOM standardhttps://cyclonedx.org/
FOSSA blogLicense compliance case studieshttps://fossa.com/blog/
REUSE specificationSource code license annotationhttps://reuse.software/

Curriculum mapping: hands-on tools for Developer M3·M4


6. ISO/IEC 5230 · 18974 References

ResourceDescriptionLink
OpenChain ISO/IEC 5230 specificationLicense compliance standardhttps://www.openchainproject.org/license-compliance
OpenChain ISO/IEC 18974 specificationSecurity assurance standardhttps://www.openchainproject.org/security-assurance
OpenChain Self-Certification checklistCertification preparationhttps://www.openchainproject.org/conformance

Curriculum mapping: core material for Manager M3


Resource Selection Guide

RoleTop-priority resourcesCertificate use
DevelopersLFC191 → LFC193 → Syft hands-onSubmit LFC191 + LFC193 certificates
ManagersLFC193 → OpenChain Curriculum → ISO 5230/18974 specificationsSubmit LFC193 certificate
OperationsOpenChain e-LearningCompletion records suffice