Open Source Software Institute

Last updated
Open Source Software Institute
Type Nonprofit
Industry Open-source software
Founded2000
FounderJohn Farrell
Andrew Murren
Headquarters
Area served
United States
Website www.ossinstitute.org

The Open Source Software Institute (OSSI) is a U.S.-based 501(c)(6), non-profit organization whose mission is to promote the development and implementation of open-source software solutions within US Federal, state and municipal government agencies.

Contents

History

OSSI was established in 2000 and has focused on strategic initiatives to promote the adoption of open source within US Department of Defense and Department of Homeland Security.

Projects

Efforts include securing the Federal Information Processing Standards FIPS 140-2 validation for the OpenSSL cryptographic module library, participation in development of the U.S. Navy's Open Source Guidance Document, [1] securing the Open Source Corporate Management Information System (OSCMIS) with the Defense Information Systems Agency, [2] [3] and working with the Department of Homeland Security's Science and Technology Directorate to establish and implement the Homeland Open Security Technology (HOST) program, which promotes open security. [4]

See also

Related Research Articles

<span class="mw-page-title-main">DARPA</span> Agency of the U.S. Department of Defense

The Defense Advanced Research Projects Agency (DARPA) is a research and development agency of the United States Department of Defense responsible for the development of emerging technologies for use by the military.

<span class="mw-page-title-main">Defense Information Systems Agency</span> US Department of Defense combat support agency

The Defense Information Systems Agency (DISA), known as the Defense Communications Agency (DCA) until 1991, is a United States Department of Defense (DoD) combat support agency composed of military, federal civilians, and contractors. DISA provides information technology (IT) and communications support to the President, Vice President, Secretary of Defense, the military services, the combatant commands, and any individual or system contributing to the defense of the United States.

<span class="mw-page-title-main">Mitre Corporation</span> American not-for-profit corporation

The Mitre Corporation is an American not-for-profit organization with dual headquarters in Bedford, Massachusetts, and McLean, Virginia. It manages federally funded research and development centers (FFRDCs) supporting various U.S. government agencies in the aviation, defense, healthcare, homeland security, and cybersecurity fields, among others.

<span class="mw-page-title-main">National Cyber Security Division</span>

The National Cyber Security Division (NCSD) is a division of the Office of Cyber Security & Communications, within the United States Department of Homeland Security's Cybersecurity and Infrastructure Security Agency. Formed from the Critical Infrastructure Assurance Office, the National Infrastructure Protection Center, the Federal Computer Incident Response Center, and the National Communications System, NCSD opened on June 6, 2003. The NCSD mission is to collaborate with the private sector, government, military, and intelligence stakeholders to conduct risk assessments and mitigate vulnerabilities and threats to information technology assets and activities affecting the operation of the civilian government and private sector critical cyber infrastructures. NCSD also provides cyber threat and vulnerability analysis, early warning, and incident response assistance for public and private sector constituents. NCSD carries out the majority of DHS’ responsibilities under the Comprehensive National Cybersecurity Initiative. The FY 2011 budget request for NCSD is $378.744 million and includes 342 federal positions. The current director of the NCSD is John Streufert, former chief information security officer (CISO) for the United States Department of State, who assumed the position in January 2012.

<span class="mw-page-title-main">Terry Bollinger</span> American computer scientist

Terry Benton Bollinger is an American computer scientist who works at the MITRE Corporation. In 2003 he wrote an influential report for the U.S. Department of Defense in which he showed that free and open source software (FOSS) had already become a vital part of the United States Department of Defense software infrastructure, and that banning or restricting its use would have had serious detrimental impacts on DoD security, research capabilities, operational capabilities, and long-term cost efficiency. His report ended a debate about whether FOSS should be banned from U.S. DoD systems, and in time helped lead to the current official U.S. DoD policy of treating FOSS and proprietary software as equals. The report is referenced on the DoD CIO web site and has been influential in promoting broader recognition of the importance of free and open source software in government circles. Bollinger is also known for his activity in the IEEE Computer Society, where he was an editor for IEEE Software for six years, wrote the founding charter for IEEE Security & Privacy Magazine, and received an IEEE Third Millennium Medal for lifetime contributions to IEEE. He has written about a wide range of software issues including effective development processes, cyber security, and distributed intelligence.

Commercial off-the-shelf or commercially available off-the-shelf (COTS) products are packaged or canned (ready-made) hardware or software, which are adapted aftermarket to the needs of the purchasing organization, rather than the commissioning of custom-made, or bespoke, solutions. A related term, Mil-COTS, refers to COTS products for use by the U.S. military.

<span class="mw-page-title-main">Enterprise architecture framework</span> Frame in which the architecture of a company is defined

An enterprise architecture framework defines how to create and use an enterprise architecture. An architecture framework provides principles and practices for creating and using the architecture description of a system. It structures architects' thinking by dividing the architecture description into domains, layers, or views, and offers models – typically matrices and diagrams – for documenting each view. This allows for making systemic design decisions on all the components of the system and making long-term decisions around new design requirements, sustainability, and support.

<span class="mw-page-title-main">Intellipedia</span> US Intelligence Community encyclopedia

Intellipedia is an online system for collaborative data sharing used by the United States Intelligence Community (IC). It was established as a pilot project in late 2005 and formally announced in April 2006. Intellipedia consists of three wikis running on the separate JWICS (Intellipedia-TS), SIPRNet (Intellipedia-S), and DNI-U (Intellipedia-U) networks. The levels of classification allowed for information on the three wikis are Top Secret Sensitive Compartmented Information, Secret (S), and Sensitive But Unclassified information, respectively. Each of the wikis is used by individuals with appropriate clearances from the 18 agencies of the US intelligence community and other national-security related organizations, including Combatant Commands and other federal departments. The wikis are not open to the public.

A cross-domain solution (CDS) is an integrated information assurance system composed of specialized software, and sometimes hardware, that provides a controlled interface to manually or automatically enable and/or restrict the access or transfer of information between two or more security domains based on a predetermined security policy. CDSs are designed to enforce domain separation and typically include some form of content filtering, which is used to designate information that is unauthorized for transfer between security domains or levels of classification, such as between different military divisions, intelligence agencies, or other operations which depend on the timely sharing of potentially sensitive information.

<span class="mw-page-title-main">Linux Foundation</span> Non-profit technology consortium to develop the Linux operating system

The Linux Foundation (LF) is a non-profit organization established in 2000 to support Linux development and open-source software projects. In addition to providing a neutral home where Linux kernel development can be fostered and accelerated, the LF is dedicated to building sustainable ecosystems around open-source projects to accelerate technology development and encourage commercial adoption.

<span class="mw-page-title-main">DHS Science and Technology Directorate</span> U.S. Dept. of Homeland Security Research and Development units

The Science and Technology Directorate (S&T) is a component within the United States Department of Homeland Security. DHS-S&T serves as the research and development arm of the Department as it fulfills its national security mission.

ManTech International Corporation is an American defense contracting firm based in Herndon, Virginia. It was co-founded in 1968 by Franc Wertheimer and George J. Pedersen. The company uses technology to help government and industry clients. The company name "ManTech" is a portmanteau formed through the combination of "management" and "technology."

The Analysis Corporation (TAC) was the Intelligence Solutions business of Global Defense Technology & Systems, Inc. (GTEC), now Sotera Defense Solutions, a defense contracting company. Based in McLean, Virginia, it is a wholly owned subsidiary of Global Strategies Group Inc., the operating company of GTEC. From its inception in 1990 to its dissolution in 2012, TAC worked on projects in the counterterrorism and national security realm by supporting national watchlisting activities as well as other counterterrorism requirements.

<span class="mw-page-title-main">Department of Defense Cyber Crime Center</span>

The Department of Defense Cyber Crime Center (DC3) is designated as a Federal Cyber Center by National Security Presidential Directive 54/Homeland Security Presidential Directive 23, as a Department of Defense (DoD) Center Of Excellence for Digital and Multimedia (D/MM) forensics by DoD Directive 5505.13E, and serves as the operational focal point for the Defense Industrial Base (DIB) Cybersecurity program. DC3 operates as a Field Operating Agency (FOA) under the Inspector General of the Department of the Air Force.

The Center for Homeland Defense and Security at the Naval Postgraduate School (NPS) in Monterey, California is a school focusing on homeland security education.

Digital supply chain security refers to efforts to enhance cyber security within the supply chain. It is a subset of supply chain security and is focused on the management of cyber security requirements for information technology systems, software and networks, which are driven by threats such as cyber-terrorism, malware, data theft and the advanced persistent threat (APT). Typical supply chain cyber security activities for minimizing risks include buying only from trusted vendors, disconnecting critical machines from outside networks, and educating users on the threats and protective measures they can take.

Homeland Open Security Technology (HOST) is a five-year, $10 million program by the Department of Homeland Security's Science and Technology Directorate to promote the creation and use of open security and open-source software in the United States government and military, especially in areas pertaining to computer security.

<span class="mw-page-title-main">DHS Cyber Security Division</span>

The Cyber Security Division (CSD) is a division of the Science and Technology Directorate (S&T Directorate) of the United States Department of Homeland Security (DHS). Within the Homeland Security Advanced Research Projects Agency, CSD develops technologies to enhance the security and resilience of the United States' critical information infrastructure from acts of terrorism. S&T supports DHS component operational and critical infrastructure protections, including the finance, energy, and public utility sectors, as well as the first responder community.

<span class="mw-page-title-main">FedRAMP</span> US government cybersecurity program

The Federal Risk and Authorization Management Program (FedRAMP) is a United States federal government-wide compliance program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

References

  1. "DON Open Source Software Guidance". United States Navy . Retrieved 2011-05-26.
  2. "DISA Earns National GOSCON Honors". Defense Information Systems Agency. 2009-11-03. Retrieved 2011-05-26.
  3. "What Are the Stages of the Software Development Life Cycle?". 2023-11-01. Retrieved 2023-12-28.
  4. "Homeland Open Security Technology (HOST)". Department of Homeland Security. Retrieved 2011-05-26.

Further reading