바로가기 메뉴 본문 바로가기 주메뉴 바로가기
  • 07-2Are you managing the risk factors of the open-source library?
    Determine applicability: Consider this question if you are using more than one open-source library in developing an AI model in the public sector, and determine if the requirement has been satisfied.

    • Version changes in an open-source library can lead to legal and technical issues. If you have used an open-source library in model development, you must continuously track changes by new versions of the open source library or newly found issues in the current version.

    • You must also manage intellectual property rights as a legal risk factor. An open-source library or software is software in which the copyright holder grants the use of source code and is still under protection by intellectual property rights. Thus, the conditions of the license (copyright) defined by the copyright holder are in effect, and there are several conditions depending on the open-source library. You must review and manage risk factors for the license as there is a risk of legal liability due to license violation and copyright infringement.

    • Managing library compatibility and vulnerabilities as technical risk factors is also necessary. In the development process, select first the type and version in consideration of the library’s compatibility with different open-source libraries or version changes. You must also continuously track and manage security issues and patches of the already installed open-source library.