- Insights This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
Opinion: Create an open source strategy before you end up like Equifax

Photo credit: Pixabay.
US consumer credit-monitoring firm Equifax has revealed one of the most serious data breaches in the US to date, affecting 143 million or one in two Americans. Personal data, including social security numbers, birthdates, addresses, and driver’s license numbers, were stolen.
Equifax confirmed that the cause of the breach was the vulnerability of an open source framework, Apache Struts, used in its website application. The Apache Struts flaw first became public on March 6; a patch to fix the bug was issued the same day. The data breach took place in mid-May, but Equifax only became aware of it in late July.
With pending results from ongoing investigations, it is still early to conclude on the extent of the firm’s negligence. The Apache Struts vulnerability may be more pervasive and may have affected more companies. The issue may also be complicated, as fixing the flaw is labor-intensive and tedious, and would take more than a download and reboot.
The crux of the matter
Apache Struts is not an application software but a framework to create web applications in Java. All applications created using the flawed version of the framework would need to be rebuilt and recompiled using the patched version. It also does not help that Apache Struts has been particularly buggy. This year alone, at least five patches have been released, including the latest in early September.
The transparent and open nature of open source is a double-edged sword. Advocates argue that open source products are more secure than closed software because developers are constantly fixing any flaws they find. Detractors argue that the open nature of the software leaves it vulnerable to hackers because the programming flaws are exposed to the public.
Fifty-seven percent of companies do not have software governance policies, while 65 percent have no control over what goes into their companies’ applications.
Whether or not open source is more secure is not the question at hand. The crux of the matter is the enterprises’ responsibility and standard of care when using open source components. Commercial software vendors would most likely notify users of flaws and provide solutions. But there may be no such thing with open source products. The onus is on users to be vigilant and diligent in checking for updates.
Indeed, the public nature of open source condenses the time frame for remedial action, giving companies an even tighter window to react. Enterprises therefore need to exercise greater care and vigilance when using open source products. They owe it to their customers to maintain a sufficient level of IT governance competence to wisely and responsibly manage open source components.
On top of cybersecurity risks, enterprises need to adequately address the additional legal and compliance risks associated with open source licenses. In recent years, several open source-related IT legal issues have surfaced. In 2015, a string of lawsuits brought by Versata against its customer, Ameriprise, highlights the compliance risks associated with “copyleft” licenses, which may compel users to share the source codes for their derivative products.
Alarmingly, many organizations are behind the curve on IT governance. In a commentary on the Equifax breach, the Wall Street Journal highlights the potential risks and the extent of a lack of IT governance among firms, citing that 57 percent of companies do not have software governance policies, while 65 percent have no control over what goes into their companies’ applications.
Creating a comprehensive strategy
Enterprises seeking to take advantage of open source’s benefits need to take steps toward a comprehensive open source management strategy. Here are a few recommendations:
1. Establish an IT governance and compliance program
Investing in IT governance and compliance is no longer just nice to have but imperative. Open source management should be a key part of the governance and compliance program. Involve the different stakeholders in your organization, including your legal, risk, and compliance teams in formulating your strategy and policies.
Key takeaway
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.







