Public Sector

We've had the pleasure of working with UK and overseas central and local government departments, including Healthcare (NHS and Foundation Trusts), Defence, Education (Universities and colleges), many of the main Civil Service departments, Emergency Services; also public-owned corporations including the BBC, Bank of England, Ordnance Survey, and regulatory bodies such as Ofgem.

We are registered on Crown Commercial Service’s (CCS) Dynamic Purchasing System (RM6219 Training and Learning) and also with numerous tender portals such as Ariba, Coupa and Delta E-Sourcing.

Read more...

Graduate Training Schemes

Framework Training has a strong track record of providing a solid introduction into the working world for technical graduates across myriad industries. We provide the opportunity to learn and gain valuable hands-on experience in a supportive, friendly and sociable training environment.

Attract & retain the brightest new starters

We know it is vital for our clients to invest in the future of their talented grads; not only to provide them with high-quality, professional training essential for their roles, but to embed them within the organisation’s culture and guide them on the right path to a successful career.

After all, your new hires could well be the next leaders and their creative ideas and unique insights are invaluable to your business.

Read more ...

Learning & Development

Our unique portfolio of high-quality technical courses and training programmes are industry-respected. They’re carefully designed so that delegates can seamlessly apply what they’ve learnt back in the workplace. Our team of domain experts, trainers, and support teams know our field — and all things tech — inside out, and we work hard to keep ourselves up to speed with the latest innovations. 

We’re proud to develop and deliver innovative learning solutions that actually work and make a tangible difference to your people and your business, driving through positive lasting change. Our training courses and programmes are human-centred. Everything we do is underpinned by our commitment to continuous improvement and learning and generally making things much better.

Read more...

Corporate & Volume Pricing

Whether you are looking to book multiple places on public scheduled courses (attended remotely or in our training centres in London) or planning private courses for a team within your organisation, we will be happy to discuss preferential pricing which maximise your staff education budget.

Enquire today about:

  • Training programme pricing models  

  • Multi-course voucher schemes

Read more...

Custom Learning Paths

We understand that your team training needs don't always fit into a "one size fits all" mould, and we're very happy to explore ways in which we can tailor a bespoke learning path to fit your learning needs.

Find out about how we can customise everything from short overviews, intensive workshops, and wider training programmes that give you coverage of the most relevant topics based on what your staff need to excel in their roles.

Read more...

Understanding the Open Source project security baseline: a comprehensive guide

We explore the intricacies of the Open Source Project Security Baseline, its significance in the current technological landscape, and how it could revolutionise the open source security approach.

April 2nd, 2025

The open source software ecosystem has become an integral part of modern technology infrastructure. As organisations increasingly rely on open-source components, ensuring the security and integrity of these projects has become paramount. To address this critical need, the Open Source Security Foundation (OpenSSF) has introduced a ground-breaking initiative: the Open Source Project Security Baseline. This comprehensive framework aims to establish minimum security requirements for open-source software, providing a roadmap for developers to enhance the trustworthiness of their projects.

So, if your coding team uses open-source software, this initiative needs some consideration, as it is possible that some degree of training will be needed to ensure that all are aware of this critical change.

In this article, we will explore the intricacies of the Open Source Project Security Baseline, its significance in the current technological landscape, and how it could revolutionise the open source security approach.

The Genesis of the Open Source Project Security Baseline

Recognising the Need for Standardised Security Practices

The open source community has long grappled with the challenge of maintaining robust security practices across diverse projects. With the increasing complexity of software supply chains and the growing sophistication of cyber threats, the need for a standardised approach to security became evident.

The Role of the Open Source Security Foundation

The OpenSSF, a collaborative effort under the Linux Foundation, took the initiative to address this pressing concern. By leveraging the collective expertise of industry leaders and security professionals, the foundation set out to create a framework that would be both comprehensive and practical for open source projects of all sizes.

Collaborative Development Process

The development of this initiative was a collaborative one, involving input from various stakeholders in the open source ecosystem. This inclusive approach ensured that the resulting framework would be relevant and applicable across a wide range of projects and development environments.

Core Principles of the Open Source Project Security Baseline

Establishing a Universal Security Floor

At its core, the Open Source Project Security Baseline aims to establish what the OpenSSF describes as a "universal security floor" for open-source projects. This concept emphasises the importance of implementing basic security measures across all projects, regardless of their size or scope.

Tessellated pattern floor tilesTiered Approach to Security Requirements

Recognising the diverse nature of open source projects, the baseline adopts a tiered approach to security requirements. This structure allows projects to implement security measures that are appropriate for their specific context and resources.

Emphasis on Practical Implementation

The framework is designed with practicality in mind, focusing on security measures that can be realistically implemented and maintained by small teams. This approach ensures that even projects with limited resources can take meaningful steps towards enhancing their security posture.

Alignment with International Standards

While tailored for the open source community, the Open Source Project Security Baseline aligns with recognised international cybersecurity frameworks, standards, and regulations. This alignment facilitates compliance and enhances the credibility of projects that adhere to the baseline.

Structure and Components of the Baseline

Maturity Levels: A Progressive Approach

The Open Source Project Security Baseline is built around three distinct maturity levels, each catering to projects at different stages of development and with varying levels of resources:

  1. Level 1: Applicable to all projects, regardless of size or number of maintainers

  2. Level 2: Targeted at projects with at least two maintainers and a small user base

  3. Level 3: Designed for projects with a large number of users and more complex security needs

Key Security Areas Addressed

The baseline covers a comprehensive range of security areas, ensuring a holistic approach to project security:

  • Access Control

  • Build and Release Processes

  • Documentation

  • Governance

  • Legal Considerations

  • Quality Assurance

  • Security Assessment

  • Vulnerability Management

Specific Requirements for Each Level

Each maturity level outlines specific requirements across these security areas. For instance, at Level 1, projects are expected to implement multi-factor authentication for version control system access, while Level 3 may require more advanced privilege management and comprehensive testing protocols.

Education is key to achieving better security. Depending on the types of OS software you're developing, you may be interested in taking a look at instructor-led training including OWASP Top 10 Web App SecurityOWASP Top 10 API, and DevSecOps courses.  

Implementing the Open Source Project Security Baseline

Getting Started: Assessing Your Project's Current State

The first step in implementing the baseline is to assess your project's current security practices. This evaluation helps identify areas that need improvement and determines the appropriate maturity level to target.

Prioritising Security Measures

Once the assessment is complete, project maintainers can prioritise the implementation of security measures based on their project's specific needs and resources. The tiered structure of the baseline allows for a gradual approach to enhancing security.

Leveraging Existing Tools and Resources

The OpenSSF provides guidance on leveraging existing tools and resources to meet the baseline requirements. This includes recommendations for security scanning tools, documentation templates, and best practices for implementing specific security measures.

Continuous Improvement and Adaptation

Implementing the baseline is not a one-time effort but an ongoing process. Projects are encouraged to regularly review and update their security practices, adapting to new threats and evolving best practices in the field.

Benefits of Adopting the Open Source Project Security Baseline

Enhanced Project Trustworthiness

By adhering to the baseline, open-source projects can demonstrate their commitment to security, enhancing their trustworthiness among users and contributors. This increased trust can lead to wider adoption and more active community participation.

Photo of a trustworthy german shepherd dogImproved Security Posture

The systematic approach provided by the baseline helps projects identify and address potential security vulnerabilities proactively. This proactive stance can significantly reduce the risk of security incidents and their associated impacts.

Facilitated Compliance with Regulations

The alignment of the baseline with international standards and regulations makes it easier for projects to demonstrate compliance with various regulatory requirements. This can be particularly beneficial for projects that are used in regulated industries or government applications.

Streamlined Security Processes

By providing a clear framework for security practices, the baseline helps streamline security-related processes within open-source projects. This can lead to more efficient development practices and reduced overhead in managing security concerns.

Challenges and Considerations in Adoption

Resource Constraints for Smaller Projects

While the baseline is designed to be accessible to projects of all sizes, smaller projects may still face challenges in allocating resources for implementation. Addressing this concern requires creative solutions and community support.

Balancing Security with Development Agility

Implementing comprehensive security measures can potentially impact development speed and agility. Projects must find the right balance between robust security practices and maintaining the flexibility often crucial in open source development.

Ensuring Consistent Application Across Projects

With the vast diversity in the open source ecosystem, ensuring consistent application of the baseline across different projects can be challenging. This highlights the need for ongoing education and community-driven support mechanisms.

Adapting to Evolving Threat Landscapes

The cybersecurity landscape is constantly evolving, necessitating regular updates to security practices. Projects adopting the baseline must be prepared to adapt their approaches as new threats emerge and best practices evolve.

The Role of the Community in Baseline Evolution

Continuous Refinement Through Feedback

The Open Source Project Security Baseline is designed to be a living framework, evolving based on feedback from the community. This collaborative approach ensures that the baseline remains relevant and effective in addressing real-world security challenges.

Sharing Best Practices and Lessons Learned

As more projects adopt the baseline, there's an opportunity for the community to share best practices and lessons learned. This knowledge-sharing can accelerate the adoption of effective security measures across the ecosystem.

Contributing to Framework Development

The OpenSSF encourages stakeholders to contribute to the ongoing development of the baseline. This open approach allows for the incorporation of diverse perspectives and expertise, enhancing the framework's effectiveness and applicability.

Future Directions and Potential Impact

Integration with Automated Tools

Looking ahead, there's potential for the development of automated tools that can assess and verify compliance with the baseline. Such tools could significantly streamline the implementation and auditing processes.

Influencing Industry Standards

As the baseline gains widespread adoption, it has the potential to influence broader industry standards for software security. This could lead to a more unified approach to security across both open-source and proprietary software development.

Enhancing Global Software Supply Chain Security

By raising the security bar for open source projects, the baseline contributes to enhancing the overall security of global software supply chains. This has far-reaching implications for the resilience of digital infrastructure worldwide.

Conclusion: A New Era for Open Source Security

The Open Source Project Security Baseline represents a significant milestone in the evolution of open source security practices. By providing a structured, accessible framework for implementing security measures, it empowers projects of all sizes to enhance their security posture and build trust with their users and contributors.

As the open source ecosystem continues to grow and evolve, initiatives like the Open Source Project Security Baseline will play a crucial role in ensuring that security remains at the forefront of development practices. By embracing this framework and actively participating in its ongoing refinement, the open source community can collectively work towards a more secure and resilient digital future.

The journey towards comprehensive open source security is ongoing, and the Open Source Project Security Baseline serves as a valuable roadmap for this important endeavour. As projects, developers, and organisations continue to adopt and refine these practices, we can look forward to a new era of enhanced security and trust in the open-source world.

Would you like to know more?

If you found this article interesting you might be interested in some of our Security Training Courses.

Share this post on:

We would love to hear from you

Get in touch

or call us on +44 (0) 20 3137 3920