A Security Practices Evaluation Framework
Source Code Availability
Description
Ross Anderson has claimed that, for sufficiently large software systems, source code availability aids attackers and defenders equally, but the balance shifts based on a variety of project-specific factors. We track the source code availability for each project measured.
Data Collection
Discuss source code availability with the project staff, or infer from the existence of a public repository or other, legal, public distribution of the source code.
Values: Open Source, Closed Source