Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New Associate Member Application: Qazaq Open Source Initiative #42

Open
25 tasks
hythloda opened this issue Jan 25, 2025 · 0 comments
Open
25 tasks

New Associate Member Application: Qazaq Open Source Initiative #42

hythloda opened this issue Jan 25, 2025 · 0 comments

Comments

@hythloda
Copy link
Member

What is your name? Qasym Majen

What is your email? [email protected]

What is your member company? Qazaq Open Source Initiative

Identify which category their organization falls under: Non-profit

Link to your website: https://qosi.kz

What is your organizational mission statement: To position Kazakhstan at the forefront of digital transformation by advocating for and implementing open-source solutions in government, finance, artificial intelligence, and education. We envision a future where open-source technology is the cornerstone of innovation and growth in our nation.

What drives your interest in joining the OpenSSF? Joining OpenSSF aligns with QOSI’s mission to enhance open-source security in Kazakhstan by integrating best practices into cloud-native, AI, and government projects while fostering security education and global collaboration.

What are your organization’s aspirations for contributing to the OpenSSF, and how do you anticipate that your membership will bolster the OpenSSF's growth and support? QOSI aspires to contribute to OpenSSF by advancing open-source security adoption in Central Asia, focusing on cloud-native security, AI safety, and secure digital infrastructure for governments while localizing security best practices for Kazakh-speaking developers; in turn, our membership will help OpenSSF expand its global reach, foster new security initiatives in emerging markets, and strengthen collaboration in multilingual open-source security frameworks.

Could you summarize your organization’s contributions to OpenSSF? QOSI contributes to OpenSSF by advancing open-source security adoption in Central Asia, integrating cloud-native security practices into government and enterprise IT modernization, enhancing AI safety for Kazakh-language models, and localizing OpenSSF best practices for Kazakh-speaking developers to expand global security awareness and collaboration.

Please include any contributions made to OpenSSF or other OpenSSF projects and open-source projects developed using any OpenSSF dependencies. QOSI is a young non-profit focused on adapting and promoting open-source security best practices, advocating for secure cloud-native infrastructure, AI safety, and DevSecOps education, with plans to integrate OpenSSF frameworks into regional cybersecurity initiatives and contribute to supply chain security and AI security efforts.

How many developers do you expect to have contribute to OpenSSF projects in the next 6-12 months? Are there other roles such as researchers, analysts or any other positions that you plan on contributing? QOSI is committed to fostering a culture of open-source contribution in Kazakhstan by connecting local companies and specialists with global initiatives like OpenSSF; while we do not have an exact number of planned contributors in the next 6-12 months, our focus is on expanding awareness, building developer engagement, and encouraging participation from developers, researchers, and security analysts as our open-source movement grows this year.

How do you currently leverage any OpenSSF resources in your organization? In our efforts to assist quasi-government companies with cloud-native transformation, we leverage a minimal open-source security stack comprising Wazuh SIEM, Suricata, ClamAV, NeuVector, pfSense, Netbird, and Teleport, which align with OpenSSF resources and principles to enhance security, particularly in areas like SIEM, intrusion detection, endpoint protection, and Zero Trust Network Access (ZTNA).

Do you have signing authority for your entire institution? If no, who does? Yes

Do you agree to follow the OpenSSF Code of Conduct Yes

1. Organizational Information/Alignment:

Organizational Mission Alignment:

  • Does the organization's mission statement align with the goals of OpenSSF, such as promoting open source security, enhancing software supply chain integrity, or contributing to cybersecurity education?
    • Yes
    • No

Non-Profit, Government, or Academic Status:

  • Is the organization a recognized non-profit, government agency, or academic institution?
    • Yes
    • No

Brand Alignment and Reputation:

  • Is the organization in good standing within its community and the broader open source ecosystem, with a reputation that aligns with OpenSSF's values and brand?
    • Yes
    • No

2. Commitment to Open Source Security and Contribution:

Commitment to Contribution:

  • Has the organization demonstrated a clear interest in actively contributing to the OpenSSF community through development, research, or other relevant activities?
    • Yes
    • No
  • Can the organization commit to contributing a specified minimum number of developers, researchers, analysts, or other professionals to OpenSSF projects within the next 6-12 months?
    • Yes
    • No

Commitment to Open Source Security:

  • Has the organization previously contributed to OpenSSF or other open-source projects?
    • Yes
    • No
  • If not, do they plan on contributing to the OpenSSF?
  • Does the organization maintain or contribute to open-source projects that use OpenSSF dependencies or tools?
    • Yes
    • No

Commitment to Open Source Security:

  • Does the organization have a history or a nascent plan to promote, improve, or contribute to open source security beyond its participation in OpenSSF?
    • Yes
    • No

Utilization of OpenSSF Resources:

  • Does the organization currently leverage OpenSSF resources, tools, or frameworks within its operations or projects?
    • Yes
    • No

Educational and Community Engagement:

  • Does the organization engage in educational activities, community outreach, or other efforts to spread awareness about open source security?
    • Yes
    • No

3. Compliance and Ethics:

Open Source Licensing and Compliance:

  • Does the organization adhere to open source licensing standards and demonstrate compliance with open source security best practices?
    • Yes
    • No

No Conflict of Interest:

  • Can the organization certify that its membership and contributions to OpenSSF will not pose a conflict of interest with the foundation's objectives and policies?
    • Yes
    • No
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant