• 0 Posts
  • 1 Comment
Joined 3 years ago
cake
Cake day: August 2nd, 2023

help-circle
  • I can explain a major reason why public services and administration are begrudgingly moving to FOSS or OSS at all. They need to apply security standards like ISO 27001 and when they start going through what the documentation requires they realize that most OSS let alone FOSS make it very hard to have any say in the development of the software.

    How do you make sure that the security flaws are patched promptly? Do you open a ticket on GitHub and simply hope it gets picked up by the devs? I can tell you from experience that some OSS devs will tell you to make your own merge request if it’s so important to you. GDPR makes having vulnerable public facing services very unattractive. What about support for the product when you need something fixed or have an issue with running the software?

    You can definitely get a license for an OSS, or get a legal agreement for support from the OSS devs for money. I can guarantee you that when managers in public services look at either patching together and managing a bunch of separate OSS or using Microsofts integrated infrastructure, they see the advantages right away.

    That is the sad truth… It’s resource intensive and a regulatory problem to create and manage a whole infrastructure. It’s much easier to use integrated and centralized solutions.