Past Meetings

OWASP Board Meeting — November 22, 2013

Official minutes of this Board meeting.

Meeting Details

  • Date: Friday, November 22, 2013
  • Time: 8:00 AM EST – 3:30 PM
  • Location: In Person

Call to Order

Notice of Recording

  • Notice to all attendees - board meetings are recorded and publicly available as of March, 2013
  • Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.


Time

8:00am - 3:30pm EST

Location

In Person

Brecht room on the 4th floor of the hotel (not the suite previously planned).

Teleconference Information:

1. Please join my meeting. https://www3.gotomeeting.com/join/349738774

2. Use your microphone and speakers (VoIP) - a headset is recommended. Or, call in using your telephone.

United States: +1 (619) 550-0006 Australia: +61 2 6108 4655 Austria: +43 (0) 7 2088 1403 Belgium: +32 (0) 28 08 4294 Canada: +1 (416) 800-9295 Denmark: +45 (0) 69 91 88 65 Finland: +358 (0) 942 41 5781 France: +33 (0) 182 880 459 Germany: +49 (0) 811 8899 6901 Ireland: +353 (0) 14 845 979 Italy: +39 0 699 36 98 81 Netherlands: +31 (0) 208 080 382 New Zealand: +64 (0) 4 974 7214 Norway: +47 21 03 58 99 Spain: +34 931 81 6669 Sweden: +46 (0) 852 503 499 Switzerland: +41 (0) 435 0167 09 United Kingdom: +44 20 7151 1857

Access Code: 349-738-774 Audio PIN: Shown after joining the meeting

Meeting ID: 349-738-774

GoToMeeting® Online Meetings Made Easy®

Not at your computer? Click the link to join this meeting from your iPhone®, iPad® or Android® device via the GoToMeeting app.


Board Meeting Attendance Tracker


Meeting Minutes

Board Members

Directors will be recorded when the meeting is called to order.

Guests

  • * Martin Knobloch

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Reports

Executive Director Review of 2012 Finances and 2013 budget -https://docs.google.com/presentation/d/1nSBcPyQUpDBzaVl3X5TNgNV2xaDs8cXsIWZdWM3HPzs/edit?usp=sharing

New Business

Introductions

  • Welcome to New Staff Member - Laura Grau
  • Welcome to New Board members - Tobias Gondrom, Fabio Cerullo, Josh Sokol

OWASP & Commitment to user privacy - inquiries from governments and our response to protect user privacy

  • Action: Sarah request letter of closure for previous govt request
  • Action: Post user privacy policy that we can point to in the instance of future inquiries

Energizing wiki contributors

  • Possible edit-a-thon?
  • Direct people where? how to edit: https://owasp.org/index.php/Tutorial
  • Guidance on owasp-specific formatting and templates
  • Jim to coordinate next steps on how we can energize the community & set up an initiative

4.Project Sponsorship https://docs.google.com/a/owasp.org/document/d/1ADEy8NhgIqi5vyV0JSvOfeIqfIRQSzlOCLCmhEuPAWA/edit

  • Are project leaders mandated to accept project funds?
    • No, project leader can decide to accept sponsorships or not - but this is across the board (yes to all sponsors or no to all sponsorship support)
    • However if a project leader wants to reject a specific sponsor (not across the board) then exception requested from Board
  • Where are we posting acknowledgements in printed book?
    • Template acknowledgements - “OWASP does not endorse vendors, but we would like to acknowledge the following contributions....”
    • Will this be on first /last page, do we care? This can be at the beginning or end of the book, just not on the covers.
  • Acknowledgements on non-documentation projects
  • How do we give appropriate credit to original creator/founder? Create a section in the acknowledgements to give credit to previous versions’ contributors as well as the founder(s), founder’s name and logo can be displayed and this decision (to include a founder) is separate than the decision to accept sponsors.
  • How long to leave sponsors logos on wiki/product: Logos posted AT LEAST 1 year or until the next major release
  • How will we handle current/existing projects & “sunsetting” of projects:
    • Starting Jan 1, 2013 -- 12 mo. to comply (6 months check in) comply or withdrawal
  • Need to change title of document from “Project Spending Guidelines” to “Project Spending Policy”

Project Spending Guidelines

https://docs.google.com/a/owasp.org/document/d/15XuKIezpBpNH4BQYwSJ8i9125ga8IBE0IpvkO14RukI/edit

  • If we have a project that gets released and there are still funds left, how do we handle the excess funds?

    • ACTION: as of Jan 1, 2014, will add a T & C to donation page regarding OWASP reserves the right to reallocate funds to the general Foundation income account.
    • For all money received by projects prior to Jan 1 - OWASP will make best efforts to contact donors to respect their donor intent before reallocating funds in the instance of inactive projects.
    • Project audit every 6 months to determine whether active/inactive. Expectations for project requirements for active status to be posted to project page for easy reference.
  • #7 - hiring project leaders as contractors -

    • Try to find a 3rd party (not the project leader) if possible.
    • Who decides who get’s paid? Call for candidates with selection criteria

Recap on AppSec USA

European OWASP Entity - Review past 2 years and discuss benefits, costs, challenges

  • Pros
    • Facilitate payment in Euros
    • Currency exchange for Euros (lose on exchange rate 2x)
    • Local presence for local sponsors, easier to sponsor
    • Applying for European Grants, requires European entity
    • VAT recommendations
    • Credibility as a European organization
  • Cons
    • Additional tax considerations, work, human effort, and costs
    • More complex payment systems
    • Large operational time requirement
  • Considerations
    • Official board representation on european entity - 3 people (from any place)
    • Bank changes require individuals to be in person\
    • Action item for December 9.

Review of 2013 Board Strategic Goals, setting 2014 Strategic Goals

https://docs.google.com/a/owasp.org/document/d/19BJMDMTVWlwqMcvUfDy1Mcjtd_bKGbhu-D-VBE-7kFU/edit

  • New ideas:

    • New and innovative projects - incentivize
    • OWASP training program
    • Membership double
    • Rabid transparency
    • Chapter reach and self sufficient, toolkits
    • Developer outreach measured
    • Solve a tough security problem
    • Security Metrics?
    • Mobilize OWASP Community to encourage
    • OWASP “bug” program - to fit security problems in major frameworks/apps (that are reused)
    • Same as above for builders, breakers, & defenders
  • For each goal:

    • Title - what is goal
    • Metric of success
    • Why we’re doing this
    • Board Member Sponsor

Previous Board Votes: Votes Passed recently:

Social media policy: Vote passes -

Conflict of Interest Policy: Vote passes -

Update to Bylaws: Vote passes -

Whistleblower and Antiretaliation Policy Vote passes -

Project Guidelines and Spending Policies To Vote for.

Passed recently:

Result: Passed recently:

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.