Episode 224: Ciarán O’Riordan on the EU's Cyber Resiliency Act

EPISODE · Mar 15, 2024 · 39 MIN

Episode 224: Ciarán O’Riordan on the EU's Cyber Resiliency Act

from Sustain · host SustainOSS

Guest Ciarán O’Riordan Panelist Richard Littauer | Leslie Hawthorne Show Notes In this episode, host Richard Littauer and co-host Leslie Hawthorne engage with Ciarán O’Riordan, Senior Policy Advisor from Open Forum Europe (OFE), diving into the intricacies of the Cyber Resiliency Act (CRA) and its implications for the Free and Open Source Software (FOSS) community. Ciarán shares his journey from software development to policy advocacy, emphasizing the critical role of policy work in shaping the future of open source. He provides an in-depth analysis of the CRA, highlighting concerns about its initial draft, the involvement of the FOSS community in shaping its final form, and the potential challenges and opportunities it presents. The discussion also touches on other significant legislative developments in Europe, such as the Product Liability Directive and the AI Act, and their potential effects on open source software. Press download now to hear more! [00:01:25] Ciarán explains how he became a Senior Policy Advisor, his passion for policy work, tracing his journey from a software developer in Dublin to his 20-year career in Brussels focusing on policy advocacy, including his recent position at OFE. [00:06:08] Leslie asks Ciarán for a summary of the Cyber Resilience Act (CRA) and its specific implications for the free and open source software ecosystem. Ciarán contrasts the initial and final versions of the CR, detailing the changes made, the lightened obligations for free and open source software, and the ongoing compliance challenges for commercial distributions. [00:11:02] Leslie inquires how software foundation’s responsible for producing commercialized software are impacted by the Cyber Resilience Act. Ciarán explains that the final version of the Act introduces a new category called “Open Source Stewards” for entities like software foundations, which have a reduced set of obligations without fines. He also mentions the timeline for the CRA, stating in will come into force around summertime 2027, after being officially signed. [00:16:09] Richard asks about the CRA’s impact on individual non-European developers, like himself, who have repositories on platforms like GitHub or GitLab. Ciarán responds that the specifics of how the CRA will affect such developers will become clear once the standards are developed. [00:17:55] Ciarán clarifies the role of software foundations is to provide services or procedures for compliance, which may vary across different foundations. [00:19:36] Richard wonders who benefits from this Act, and Ciarán discusses the justification for the CRA, which is cost-based, comparing the cybersecurity costs with compliance costs. [00:21:31] Leslie asks about the process of creating standards for CRA compliance and how average FOSS developers can influence these standards and questions the best ways for FOSS developers to get involved in influencing the outcomes beneficial to the FOSS ecosystem. Ciarán notes that working on standards and policy is complex and compares it to contributing to software development on short notice. [00:26:07] Ciarán discusses OFE’s multi-layered structure and the FOSS community list, which serves as a base for information sharing and connection. [00:27:24] Richard questions the impact CRA on individual developers with numerous dependencies in their projects. Ciarán reassures that there is no immediate cause for panic as the CRA will not come into force until summer 2027 and many details will be clarified in the coming years. [00:28:39] Leslie shifts the discussion the Product Liability Directive (PLD) and its relevance to the FOSS ecosystem and Ciarán goes in depth about it. [00:33:36] Find out where you can learn more about Ciarán and OFE on the web. Quotes [00:04:58] “We’d love to have better cyber security, especially if it just falls from the sky.” [00:22:31] “Working on standards and policy in general is about as complex as working on software development.” [00:24:00] “In terms of getting involved, two important things: First is getting in contact with other people, and the second is the need to do some work on your own initiative without having been brought into some of these groups.” Spotlight [00:35:35] Leslie’s spotlight is the Open Source in The European Legislative Landscape devroom. [00:35:59] Richard’s spotlight is the book, “Better Living Through Birding.” [00:36:42] Ciarán’s spotlight is two books: “Thy Neighbour’s Wife” and “The Life Show.” Links SustainOSS SustainOSS Twitter SustainOSS Discourse [email protected] SustainOSS Mastodon Open Collective-SustainOSS (Contribute) Richard Littauer Socials Leslie Hawthorne LinkedIn Ciarán O’Riordan LinkedIn Ciarán O’Riordan- Presentation of the Cyber Resilience Act (YouTube) OpenForum Europe OpenForum Europe Events OpenForum Europe Open Source Open Source Policy Community List Sustain Podcast-Episode 125: Astor Nummelin Carlberg of OFE on the Economic Impact of Open Source Product Liability Directive 1985 Open Source In The European Legislative Landscape devroom Better Living Through Birding: Notes From A Black Man In The Natural World by Christian Cooper Thy Neighbour’s Wife by Liam O’Flaherty The Life Show by Chi Li Credits Produced by Richard Littauer Edited by Paul M. Bahr at Peachtree Sound Show notes by DeAnn Bahr Peachtree Sound Special Guest: Ciarán O'Riordan.

NOW PLAYING

Episode 224: Ciarán O’Riordan on the EU's Cyber Resiliency Act

0:00 39:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Chewing the Fat with WorkForge WorkForge Bite-Sized Conversations for Building a Stronger Workforce Welcome to Chewing the Fat, a podcast delving deep into the world of food manufacturing. Dive into real conversations around critical topics like staffing, retention, onboarding, and career development in this essential industry. Subscribe now to gain insights from your peers, subject matter experts and more on the biggest issues facing food manufacturers today: -Hiring and retaining employees -Addressing the challenges of the Silver Tsunami -Improving time to productivity of new employees -Engaging employees from hire to retire And more... Tune in to Chewing the Fat, a WorkForge podcast, and join the conversation on how to build and sustain a resilient, high-performing workforce in food manufacturing. Leap Like Me Lisa Hoashi Sometimes life asks us to make a bigger change than we expected. Welcome to Leap Like Me, where we offer real stories, inspiration and practical advice on how to make purposeful, brave leaps in life – and sustain them even through challenging times. Life Coach Lisa Hoashi explores the strategies and mindset you need to make brave changes in your life and work. Featuring guest appearances from people who have stretched their sense of what's possible in their own lives, the show will help you to reimagine what's possible for you too. Two Writing Teachers Podcast Two Writing Teachers Since 2007, Two Writing Teachers has been a vibrant community of reflective writers. We're excited to take our passion for teaching writing to new heights in the second season of our podcast. Join us as we explore ways to create, lead, and sustain joyful and productive writing workshops, empowering educators to help their students become competent, brave, and confident writers. Let's make writing instruction engaging and rewarding for everyone involved!Would your company like to sponsor an episode of the Two Writing Teachers Podcast? Click here to learn more about sponsorship opportunities. Emotional Intelligence: Your Greatest Asset and Key to Success Jami Carlacio The podcast centers on the value of Emotional Intelligence, which is both a mindset and an approach to life that regards problems as situations that help you learn and grow; it is a way of being and doing in the world that enables you to develop and sustain a positive relationship with yourself and others, at home, at work, and everywhere in between.  Coupled with mental fitness, emotional intelligence is an essential component of Positive Intelligence (PQ) that enables you to leverage your power to communicate well, make good decisions that align with your values, and create a positive environment wherever you are. In a word, Positive Intelligence is the  key element that creates your path to success. Episodes are theme-oriented and correspond to a letter of the alphabet, like this: A = Awareness, Acceptance, and Action; B= Bold and Brave (with a little vulnerability thrown in), and so on.  POSITIVE INTELLIGENCE® and ©PQ are trademarks of Positive Intelligenc
URL copied to clipboard!