ISO compliance adds confidence in open source for UK healthcare

ISO compliance adds confidence in open source for UK healthcare

PRESS RELEASE: for 14th December 2020

Applications and software are increasingly being developed using open source (https://www.cnbc.com/2019/12/14/how-open-source-software-became-the-new-industry-standard.html; and https://techcrunch.com/2019/01/12/how-open-source-software-took-over-the-world/). This means licence confidence is now critical in open source applications for health and social care.

The Develop in the Open (DITO - https://dito.tech) project team has asserted that an ISO standard awarded to OpenChain will enable best practice sensible defaults to orgs investing in open source.

OpenChain is an auditable system of recording provenance, modification and license of digital assets and has now been approved as ISO standard "ISO/IEC 5230" (https://www.iso.org/standard/81039.html). This ISO certification is based on the ability to audit software to ensure it can be used for its intended purpose. Compliance enables the user to understand their licence obligations, which is vital when using open source for professional and business-critical applications.

Stuart Mackintosh, DITO lead, explains: "Open source is free to use and distribute, but what if there is a different licence or specific restrictions or caveats being used in one component of a solution, such as an open-source modified licence? For example, when an Open Source licence has the caveat of not being used to generate profit or to cause harm.

"Without a licence audit such as OpenChain, an organisation can't confidently determine if they can use, support or distribute software, without inadvertently contravening a licence."

Open-e-REACT, an electronic patient observation solution developed using the DITO process under the custodianship and governance of the Apperta Foundation, is open source and stores clinical data using open standards. It is due to be launched to the market in 2021. Through the Custodian Model, all health and care organisations can both use the product and contribute to its development, either directly or through an implementation partner.

David Jobling, Apperta Foundation, commented: “The OpenChain process is crucial in the development of an application like this so as part of the DITO project we are creating automated tools that will enable organisations to complete the audit of open source code required for the Openchain ISO certification, in a manner which is more effective to implement than if the auditing was attempted with manual or human processes. Any software developed through the Custodian Model will be automatically scanned to ensure ISO standards are met. This is integrated into the Accredited Professional Services Partners software deployment process.”

The DITO team worked with OpenUK, the UK Open Source industry association and Moorcrofts, one of Europe's leading open Source legal practices, to develop and support the Open-e-React OpenChain compliance.

Mackintosh comments: “It is essential that health and social care organisations have confidence that the compliance position is appropriate for their use. As with software security, licensing clarity should be a critical factor for purchasing decisions.”

About DITO

The Develop in the Open (DITO) project (supported by Innovate UK) was set up to advance how the Custodian Model can be used effectively and to develop an outline process and set of best practices. Led by OpusVL, the clinical partners are South London and Maudsley NHS Trust, the Cheshire and Wirral Partnership NHS Trust, research partner Coventry University, the Apperta Foundation, and OpenUK. More is at dito.


Sources and references


要查看或添加评论,请登录

Don Phillips的更多文章

  • Aligning Strategy with the Operating Model - The key steps

    Aligning Strategy with the Operating Model - The key steps

    Connecting a strategic plan with an operating model and planning its transformation involves several key steps. This…

    1 条评论
  • Discovering History over a Pint

    Discovering History over a Pint

    I went to my local pub today, expecting the usual: a cold pint, some friendly banter, and maybe a game on the telly…

    2 条评论
  • An Open Digital Approach

    An Open Digital Approach

    Several NHS Trusts are now taking an Open Digital Approach to delivering tailored technology for both clinical and…

  • The Open Digital Approach to the NHS

    The Open Digital Approach to the NHS

    Working in both clinical and non-clinical domains, OpusVL offer a collaborative, end-to-end process to implement…

  • Developing publically owned solutions for our national treasure, the NHS

    Developing publically owned solutions for our national treasure, the NHS

    This article has appeared in the 'insights' section of the OpusVL website, offering a way of solving a known problem…

    2 条评论
  • 'You're On Mute' - A handy guide to video call etiquette.

    'You're On Mute' - A handy guide to video call etiquette.

    I like this insight from the OpusVL team As the pandemic rumbles on, we seem destined to spend at least a few more…

    1 条评论
  • NHS IT function delivers!

    NHS IT function delivers!

    The NHS has proven itself to be the wonderful creation it is over this last year of fighting COVID19. We’ve seen on the…

  • Is Your Business A Digital Goldberg Machine?

    Is Your Business A Digital Goldberg Machine?

    Anyone running a business has ambition, the goal of growth, expansion and of course, smooth operation. Achieving this…

  • Open Source and the NHS

    Open Source and the NHS

    One of our customers in the NHS came out with a great quote when describing why he had chosen our solution at OpusVL…

    2 条评论
  • Open source business management software. Customised to fit the way you work.

    Open source business management software. Customised to fit the way you work.

    This is how we work Developed and refined over 20 years, our delivery process is designed to put your business needs…

    3 条评论

社区洞察

其他会员也浏览了