Certification of Open Source Software Compliance: Insights From a Conjoint Experiment

IF 6.3 2区 管理学 Q1 INFORMATION SCIENCE & LIBRARY SCIENCE
Information Systems Journal Pub Date : 2026-04-15 Epub Date: 2025-08-27 DOI:10.1111/isj.70014
Michael A. Zaggl, Jörn Block, Juliane Wissel
{"title":"Certification of Open Source Software Compliance: Insights From a Conjoint Experiment","authors":"Michael A. Zaggl,&nbsp;Jörn Block,&nbsp;Juliane Wissel","doi":"10.1111/isj.70014","DOIUrl":null,"url":null,"abstract":"<p>Open source software (OSS) is becoming increasingly crucial for companies as they use OSS components in a wide range of products, including cars, smart-home equipment, and many more, as well as in their internal processes. However, OSS comes with regulations and licensing conditions with which companies need to comply. This complicates the company's software acquisition and hinders the broader diffusion of OSS. In this paper, we study a novel approach that could reduce or overcome barriers to software acquisition in business-to-business transactions: the certification of software suppliers for OSS compliance based on the ISO 5230 regulatory standard. This standard specifies OSS compliance and, in addition to third-party certification involving an auditor, allows suppliers to self-certify. Building on institution-based trust and signalling theory, we hypothesise that a supplier's OSS compliance certification is a critical selection criterion for companies acquiring software. Specifically, we expect that self-certification constitutes a valuable signal influencing the selection decision, although we expect it to be weaker than third-party certification. We further hypothesise that the acquirer's awareness of the standard strengthens the effect of self-certification and that their perceived OSS procurement risk strengthens the impact of third-party certification. Using a discrete choice-based conjoint experiment, we find evidence supporting our hypotheses and demonstrate that self-certification can be a viable substitute for third-party certification. Our study contributes to the understanding of the diffusion and adoption of OSS, extends signalling theory by comparing self-certification with third-party certification, and extends the information systems literature on institution-based trust.</p>","PeriodicalId":48049,"journal":{"name":"Information Systems Journal","volume":"36 3","pages":"386-409"},"PeriodicalIF":6.3000,"publicationDate":"2026-04-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1111/isj.70014","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Information Systems Journal","FirstCategoryId":"91","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1111/isj.70014","RegionNum":2,"RegionCategory":"管理学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"2025/8/27 0:00:00","PubModel":"Epub","JCR":"Q1","JCRName":"INFORMATION SCIENCE & LIBRARY SCIENCE","Score":null,"Total":0}
引用次数: 0

Abstract

Open source software (OSS) is becoming increasingly crucial for companies as they use OSS components in a wide range of products, including cars, smart-home equipment, and many more, as well as in their internal processes. However, OSS comes with regulations and licensing conditions with which companies need to comply. This complicates the company's software acquisition and hinders the broader diffusion of OSS. In this paper, we study a novel approach that could reduce or overcome barriers to software acquisition in business-to-business transactions: the certification of software suppliers for OSS compliance based on the ISO 5230 regulatory standard. This standard specifies OSS compliance and, in addition to third-party certification involving an auditor, allows suppliers to self-certify. Building on institution-based trust and signalling theory, we hypothesise that a supplier's OSS compliance certification is a critical selection criterion for companies acquiring software. Specifically, we expect that self-certification constitutes a valuable signal influencing the selection decision, although we expect it to be weaker than third-party certification. We further hypothesise that the acquirer's awareness of the standard strengthens the effect of self-certification and that their perceived OSS procurement risk strengthens the impact of third-party certification. Using a discrete choice-based conjoint experiment, we find evidence supporting our hypotheses and demonstrate that self-certification can be a viable substitute for third-party certification. Our study contributes to the understanding of the diffusion and adoption of OSS, extends signalling theory by comparing self-certification with third-party certification, and extends the information systems literature on institution-based trust.

Abstract Image

开源软件合规认证:来自联合实验的见解
开源软件(OSS)对公司来说正变得越来越重要,因为他们在广泛的产品中使用OSS组件,包括汽车、智能家居设备等等,以及在他们的内部流程中。然而,OSS伴随着公司需要遵守的规则和许可条件。这使公司的软件收购变得复杂,并阻碍了OSS的广泛传播。在本文中,我们研究了一种可以减少或克服企业对企业交易中软件获取障碍的新方法:基于ISO 5230监管标准的软件供应商的OSS合规认证。该标准规定了OSS合规性,除了涉及审核员的第三方认证外,还允许供应商自行认证。基于基于制度的信任和信号理论,我们假设供应商的OSS合规认证是公司获取软件的关键选择标准。具体地说,我们期望自我认证构成影响选择决策的有价值的信号,尽管我们期望它比第三方认证弱。我们进一步假设,采购方对标准的认知增强了自我认证的效果,他们感知到的OSS采购风险增强了第三方认证的影响。使用基于离散选择的联合实验,我们找到了支持我们假设的证据,并证明自我认证可以替代第三方认证。我们的研究有助于理解OSS的传播和采用,通过比较自我认证和第三方认证来扩展信号理论,并扩展了基于制度的信任的信息系统文献。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
Information Systems Journal
Information Systems Journal INFORMATION SCIENCE & LIBRARY SCIENCE-
CiteScore
14.60
自引率
7.80%
发文量
44
期刊介绍: The Information Systems Journal (ISJ) is an international journal promoting the study of, and interest in, information systems. Articles are welcome on research, practice, experience, current issues and debates. The ISJ encourages submissions that reflect the wide and interdisciplinary nature of the subject and articles that integrate technological disciplines with social, contextual and management issues, based on research using appropriate research methods.The ISJ has particularly built its reputation by publishing qualitative research and it continues to welcome such papers. Quantitative research papers are also welcome but they need to emphasise the context of the research and the theoretical and practical implications of their findings.The ISJ does not publish purely technical papers.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信
小红书