<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Using i* to Represent OSS Ecosystems for Risk Assessment</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Claudia Ayala</string-name>
          <email>cayala@essi.upc.edu</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Xavier Franch</string-name>
          <email>franch@essi.upc.edu</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Lidia López</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Mirko Morandini</string-name>
          <email>morandini@fbk.eu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Angelo Susi</string-name>
          <email>susi@fbk.eu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Fondazione Bruno Kessler, Center for Information Technology</institution>
          ,
          <addr-line>via Sommarive 18, 38123 Povo, Trento</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Software Engineering for Information Systems Research Group (GESSI) Universitat Politècnica de Catalunya (UPC) Barcelona</institution>
          ,
          <country country="ES">Spain</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2013</year>
      </pub-date>
      <volume>978</volume>
      <fpage>73</fpage>
      <lpage>78</lpage>
      <abstract>
        <p>Open Source Software (OSS) is a strategic asset for organisations thanks to its short time-to-market, the opportunity for a reduced development effort and total cost of ownership, and its customization capabilities. OSS-based solutions include projects that are developed and co-evolve within the same organisation, OSS communities, companies, and regulatory bodies, forming an articulated strategic business ecosystem. The adoption of OSS in commercial projects leads to numerous challenges in the wide spectrum of available OSS solutions and risks emerging from the intrinsic structure of an OSS project. In this position paper we devise the use of i* models for understanding the strategic perspective of OSS ecosystems, representing actors, intentional dependencies and responsibilities. We argue that these models can play a crucial role in the analysis of organisational risks inherent to OSS component adoption and in the definition of risk mitigation activities.</p>
      </abstract>
      <kwd-group>
        <kwd />
        <kwd>OSS</kwd>
        <kwd>iStar</kwd>
        <kwd>Software adoption</kwd>
        <kwd>risk</kwd>
        <kwd>goal-oriented requirements engineering</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>The strategic importance of Open Source Software (OSS) technologies in the
development of commercial software is growing steadily. Gartner recently highlighted1: by
2016 OSS will be included in 95% of all commercial software packages. In spite of
this trend, IT companies and organizations are still facing difficulties and challenges
when they decide to adopt OSS solutions. It stands that OSS is about freedom and
choice, but freedom and choice introduce risks2.</p>
      <p>OSS components integration in the development of complex software systems has
became a popular way of OSS adoption. However, despite the potential benefits of
1 Understand the Challenge of Open-Source Software. Gartner Reports, September 2012.
2 Critical Strategies to Manage Risk and Maximize Business Value of Open Source in the
Enterprise. Gartner Reports, June 2011.
reusing OSS components, such integration involves several risks and challenges. As a
result, traditional project and risk management strategies should be put forward;
specially for assessing the wide, often complex, interactions of the diverse actors
related with the internal and external development, maintenance and evolution of the
OSS component and the context where the OSS component will be integrated. Thus,
two important viewpoints should be considered and reconciled: the OSS project
ecosystem and the adopting organization ecosystem. On the one hand, the OSS
project ecosystem. comprises not only the developers, but the whole community,
including users, regulatory bodies, and companies involved with the project (if any).
It also covers technical support, marketing and possible financial aspects (including
the business model(s) behind the project). On the other hand, the adopting
organization ecosystem comprises the technical and business issues of the project
where the OSS component will be integrated. Both ecosystems together could be
considered as the OSS-based ecosystem. In this complex setting several questions
emerge, e.g.:
– Which viewpoints should be considered for assessing the OSS-based ecosystem in
order to ensure a smooth integration and evolution of the OSS component?
– How to secure that specific properties of an OSS do not harm business models and
their underlying business strategies?
– How to implement a systematic approach towards understanding and representing
dependencies that involve OSS components, for assessing possible risks?
We believe that the answer to these questions requires a clear understanding of the
OSS-based ecosystems from a strategic perspective, with the identification of
strategic dependencies (not just related to software component dependencies) as a
means to identify risks coming from the adoption of OSS components and to design
risk mitigation strategies along the lifetime of a software product.</p>
      <p>Along this line the paper introduces an approach, currently explored in the context
of the European project RISCOSS (RISks and Costs in Open Source Software
adoption), that promotes the use of i* to understand the strategic perspective of OSS-based
ecosystems.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Objectives of the research</title>
      <p>In the RISCOSS project we envision methods and tools for supporting the analysis of
risks and costs that organizations need to evaluate for deciding the integration of OSS
components in the development of software products.</p>
      <p>
        The processes for the adoption of commercial off-the-shelf (COTS) components
are well established in many companies. Many medium and large companies follow
strict guidelines for risk analysis, cost estimation, and contract agreement. Such
agreements are typically based on the principles of liability and confidence, in
exchange of a single or recurrent fee. However, when it comes to OSS components, the
situation is different. On the one side, there is access to the source code, making
possible (depending on license implications) to use and customize the component without
any contract agreements and payment authorization [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. This opens the possibility for
a less bureaucratic but uncontrolled use of OSS components without a thorough
analysis of risks and undesirable implications, as evidenced in industrial surveys [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. On
the other side, the own characteristics of the OSS project ecosystem are highly
different from that of traditional software. The community behind the OSS component is
not generally driven by a single business goal, the motivations and objectives of the
contributors are manifold, the software is provided without quality of service
agreements and the community cannot formally commit on the future roadmap.
      </p>
      <p>Consequently, to evaluate risks and opportunities of OSS components adoption, it
would be crucial to further understand the strategic perspective of the OSS project
ecosystem in order to evaluate its adequacy to the strategic perspective of the
adopting organization (i.e., the adopting organization ecosystem).</p>
      <p>
        Important risks related to the OSS project ecosystem [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], could be for instance: the
lack of a roadmap and/or ownership of the project, unclear liability/responsibility, and
bug fixing time. From the point of view of the adopting organization, liability and
support can sometimes be commissioned, to a certain degree, to specialised
companies, thus de facto forcing the component to go through the COTS adoption process.
However, this is not always possible and often not a favourable solution, both from
the point of view of costs and additional risks. Moreover, the uncoupling of
companies, developers and software gives rise to issues with which traditional risk analysis
processes are not able to cope, as evidenced in various empirical studies [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>In this context, our first objective is to support the risk assessment processes of
OSS adoption by using i* models as a basis for the analysis of the strategic
perspective of the OSS-based ecosystem that involves the assessment of the OSS project
ecosystem and the adopting organization ecosystem.
In this work we envisage several scientific contributions that are mainly related to the
use of i* for supporting the assessment of risks in OSS-based ecosystems.
Patterns of ecosystems and organisations. A first research challenge is the possibility
to extract and represent OSS-based ecosystem patterns (at different levels of
abstraction). These patterns would allow abstracting the roles, goals and dependencies in the
OSS project ecosystem and in the adopting organization ecosystem; and identifying
schemas that have the property to be more prone to risks or to be particularly useful to
implement organisational risk mitigation strategies. They should identify and
highlight properties of an ecosystem, such as ownership and leadership in the structure of
the community, its stability (distributiveness, centralism, presence of heroes), the role
and involvement of companies in the project (e.g., technical support, financial
promotion, developer contribution, community support and influence), as well as their
business model.</p>
      <p>To do so, we have identified several dimensions to classify the entities involved in
such ecosystems:
– Role: producer, consumer, community.
– Setting: industrial (large, medium, small), academia, public administration.
– Business strategy: from full OSS collaboration to OSS exploitation.
– Business process: adoption, migration, consolidation, and improvement.</p>
      <p>
        Each data point determined by these dimensions provides a scenario that may be
analyzed and characterised by different patterns. In RISCOSS we are currently
approaching several of these scenarios by analysing 5 use cases that cover situations
from very limited OSS implication in the business strategy to a full collaborative
approach. Such real cases will help to establish a solid evidence for the design of our
patterns. For instance, we have a large industrial company that produces highly
reliable software products and aims to integrate an OSS component in its software product
line. Its business strategy regarding OSS is to just exploit the component functionality
(without involvement in the OSS project) and does not have interest to change
processes. On the other hand, we have also the case of a medium-sized company, whose
business strategy relies entirely on OSS adoption and development and therefore
adapted its processes and the whole organization to such an approach.
Level of abstraction in the models. Another important issue is related to the need of
representing the ecosystems at several levels of detail, at both class and instance level,
to facilitate the reasoning about the model, focusing on the high level structure of the
ecosystem or going into further details, with a particular focus on OSS-specific actors
such as individuals, community groups, etc. In line with previous experiences in other
settings [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], in order to use i* models as a communication means, we need to keep the
models as simple as possible, so they could be understood by all the industrial
partners of the RISCOSS project. So far, we are using general actors without classifying
them except for those that clearly are agents. Also we limit the use of soft goals to the
most fundamental ones. The number and relationships of actors has driven us to adopt
a third kind of model, the Strategic Actor Diagram as proposed by Leite et al. [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ],
which gives a useful perspective on the system.
      </p>
      <p>
        Guidelines for the specification of the models and repositories. To support the
specification of the OSS-based ecosystems, a clear process is needed to specify a set of i*
diagrams. We have taken as a starting point the RiSD methodology for SD diagrams
[
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], and we plan to refine it and to create similar versions for the other types of i*
diagrams. A shared or company-internal repository of such models could be
implemented to allow the evaluation of the structure of the OSS-based ecosystem, based on
organisational patterns. Thanks to this repository, analysts could get an overview of
the OSS project ecosystem and adopt analysis guidelines to identify risks and to
manage them for getting pursuable criteria for OSS adoption decisions.
      </p>
      <p>
        New modelling concepts. We are also considering the need of enriching the set of i*
modelling concepts on the basis of specific characteristics of the ecosystems and of
domain risks [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Concerning the ecosystems, there could be a need for concepts able
to express aggregation between actors for a direct representation of teams or
communities. Also, some specification relationships between actors may be expected to
emerge. Moreover, in a community-driven environment, central i* concepts such as
delegation and responsibility need to be re-discussed. In OSS, the strict concept of
delegation changes to a more relaxed concept of expectation and observance of
norms. Responsibility is scattered and can often not be clearly identified, and must
thus often be taken over by the companies adopting the software for their products.
Moreover, in this context many roles are defined by access rights and by own interest
and can dynamically change. Concerning risks, we plan to follow a strategy similar to
the one used in Nomos [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], namely incorporating new concepts for the representation
of risk, of the impact that the risk has on the structure of the organisation and of
possible mitigation activities. Available i* risk modelling approaches such as [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ],
defining risks, events, affected assets and treatments, will be taken into account for this as
well.
4
      </p>
    </sec>
    <sec id="sec-3">
      <title>Conclusions, ongoing and future work</title>
      <p>In this paper we described one of the main objectives of the European project
RISCOSS that is to support decision making related to the assessment of risks in the
integration of OSS components. We envision the use of i* models to capture the
intentional aspects that drive the OSS project ecosystem as well as the adopting
organization ecosystem, in order to analyse both points of view and their potential risks.</p>
      <p>
        Based on the analysis of five adopting organizations represented by the industrial
partners of the RISCOSS project, we are currently: applying existing guidelines for
the specification of i* models, identifying elements and relationships that may
represent potential patterns or new modelling concepts. Furthermore, we are performing
systematic literature reviews on OSS ontologies, OSS ecosystems and OSS risk
management with the purpose of developing an ontology to be linked to the i* core. We
plan to use some foundational ontology (e.g., UFO, DOLCE) to connect these two
worlds, aligning with ongoing research on the semantic meaning of i* constructs [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
    </sec>
    <sec id="sec-4">
      <title>Acknowledgements References</title>
      <p>This work is a result of the RISCOSS project, funded by the EC 7th Framework
Programme FP7/2007-2013 under the agreement number 318249.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Morgan</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          &amp;
          <string-name>
            <surname>Finnegan</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <article-title>Open innovation in secondary software firms: an exploration of managers' perceptions of open source software SIGMIS Database</article-title>
          , ACM,
          <year>2010</year>
          ,
          <fpage>76</fpage>
          -
          <lpage>95</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Hauge</surname>
          </string-name>
          , Ø.;
          <string-name>
            <surname>Cruzes</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ; Conradi,
          <string-name>
            <surname>R.</surname>
          </string-name>
          ; Velle,
          <string-name>
            <given-names>K. S.</given-names>
            &amp;
            <surname>Skarpenes</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T. A.</given-names>
            <surname>Risks</surname>
          </string-name>
          and
          <article-title>Risk Mitigation in Open Source Software Adoption: Bridging the Gap between Literature</article-title>
          and
          <string-name>
            <surname>Practice</surname>
            <given-names>OSS</given-names>
          </string-name>
          ,
          <year>2010</year>
          ,
          <fpage>105</fpage>
          -
          <lpage>118</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Carvallo</surname>
            <given-names>J.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Franch</surname>
            <given-names>X.</given-names>
          </string-name>
          :
          <article-title>On the Use of i* for Architecting Hybrid Systems: A Method and an Evaluation Report</article-title>
          .
          <source>PoEM</source>
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Leite</surname>
            <given-names>J.</given-names>
          </string-name>
          et al.:
          <article-title>Understanding the Strategic Actor Diagram: an Exercise of Meta Modelling</article-title>
          .
          <source>WER</source>
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Franch</surname>
            <given-names>X.</given-names>
          </string-name>
          et al.:
          <article-title>Systematic Construction of i* Strategic Dependency Models for SocioTechnical Systems</article-title>
          . IJSEKE
          <volume>17</volume>
          (
          <issue>1</issue>
          ),
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Franch</surname>
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maté</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Trujillo</surname>
            <given-names>J.C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cares</surname>
            <given-names>C.</given-names>
          </string-name>
          :
          <article-title>On the joint use of i* with other Modelling Frameworks: a Vision Paper</article-title>
          . RE,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Alberto</given-names>
            <surname>Siena</surname>
          </string-name>
          , Ivan Jureta, Silvia Ingolfo, Angelo Susi, Anna Perini, John Mylopoulos:
          <article-title>Capturing Variability of Law with Nómos 2</article-title>
          .
          <source>ER</source>
          <year>2012</year>
          :
          <fpage>383</fpage>
          -
          <lpage>396</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Asnar</surname>
            ,
            <given-names>Y</given-names>
          </string-name>
          ; Giorgini,
          <string-name>
            <given-names>P.</given-names>
            ,
            <surname>Mylopoulos</surname>
          </string-name>
          , J. :
          <article-title>“Goal-driven risk assessment in requirements engineering” Requirements Engineering</article-title>
          .
          <volume>16</volume>
          (
          <issue>2</issue>
          ),
          <fpage>101</fpage>
          -
          <lpage>116</lpage>
          .
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Guizzardi</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Franch</surname>
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Guizzardi</surname>
            <given-names>G.</given-names>
          </string-name>
          :
          <article-title>Applying a Foundational Ontology to Analyze Means-End Links in the i* Framework</article-title>
          .
          <string-name>
            <surname>RCIS</surname>
          </string-name>
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>