Past Meetings

OWASP Board Meeting — February 24, 2014

Official minutes of this Board meeting.

Meeting Details

  • Date: Monday, February 24, 2014
  • Time: 8:00 AM PST – 10:00 AM
  • Location: Remote

Call to Order

  • Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)

Board Members

  • board meetings are recorded
  • publicly available as of March
  • 2013
  • Joining the call acknowledges your awareness of recording
  • consent to be recorded
  • public dissemination of the recording.
  • Meeting Recording
  • Time
  • 8:00am - 10:00am PST

Guests

No guests listed.

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Old Business

OLD BUSINESS

2014 Strategic Goals

  • [Board Goal] Attract and retain volunteers and security professionals to contribute to OWASP Projects or the OWASP community.

    • Sarah thoughts on Metric: The staff has discussed this as well as the possible/suggested metrics and while we have operational plans to increase volunteerism, we do not think there is a meaningful metric available at this point to measure this. It seems prudent to develop a way to quantify and recognize volunteerism in the next year and then in the future years maybe we will have a better metric to measure this.
    • Sarah - If an expectation or measurement of success needs to be set on this, I would recommend something like this: Define an engagement program that facilitates volunteer involvement, expectation setting and recognition of individual efforts.
    • Revision on goal: Define an engagement program that facilitates volunteer involvement by enabling volunteers to self-identify and create a plan to incentivize and measure their volunteerism.
  • [Board Goal] Mobilize OWASP volunteers to help address security issues in large software systems/applications/frameworks.

    • Sarah - Metric: Build an OWASP program that incentivizes the security community to find and fix security problems in software.
    • Sarah - Metric: By the end of the year we have at least two successful completed initiatives reviewing security issues in one or two of the major frameworks
  • [Board Goal] Strengthen OWASP chapters and increase Chapter’s abilities to spread message of OWASP through locally organized and run events.

    • Metric: Chapter participation in at least 60 local events (events hosted by chapter or chapter participation in a non-OWASP outreach/appsec event) by the end of the year.
    • Metric: Hold at least 4 (quarterly) virtual chapter leader meetings in addition to in person chapter meetings (at global appsec conferences) to incentivize more collaboration and support between chapter leaders
    • Metric: All chapters with funds in excess of $5000 and 10% of chapters with less than $5000 in funds engaged in annual budgeting.
    • Metric: Annual survey of all chapter leaders asking for their alignment to our mission and strategic goals.
    • Suggested - metric related to conversion of chapter mailing list/meeting attendees to members
    • Suggested - create a success template that can be used by other chapters to copy
    • Not necessarily budgeting - strategic planning for chapters
  • [Board Goal] Build a scalable OWASP training program that spreads security training around the world

    • Recommended: remove “developers” from this goal since the trainings will most likely target (or be open to) more than just developers
    • Metric: At least six total training events with at least three being free to attend by the end of the year (in addition to global appsec conferences) - live or online.
    • Metric: OWASP delivered training to 800 additional people (i.e. in addition to the number attending our AppSec training programs last year).
  • [Board Goal] Maintain a capable, agile and financially sustainable organisation

    • While I have suggested metrics below that are goals specified in the annual budget, I think this goal should be removed primarily because this isn’t an annual strategic goal but something that a healthy organization should be doing EVERY YEAR.
    • Metric: Increase corporate membership income by 75% and individual membership by 25%
    • Metric: Achieve profit goals for all 4 Global AppSec Conferences
    • Metric: Build scalable models for at least 2 new revenue sources
    • Metric: Put at least 5% of Foundation annual revenue into “foundation reserves” at the end of the year.
    • In favor of removing as this a strategic goal is a recurring annual goal - Michael, Eoin, Jim, Tom (no - Tobas, Fabio, Josh)
    • Fabio - include this as goals are different than budgeting
  • Vote

    • Motion to vote - michael, eoin second
    • Vote approve - Michael, Eoin, Tom, Josh, Tobias, Fabio, Jim
Break########

New Business

New Business

  • Motion to modify the Google Hacking Inquiry (https://docs.google.com/document/d/1nlV_scZICPFKGprpKfh5RJMo5aRih6whDNXX_xU01AM/edit?usp=sharing)
    • We need a proxy for the Google Hacking page on the wiki if we are removing.
    • Alternative wording proposal: The terms of this issue have been completed. This issue is no longer relevant in detail.
    • Alternative wording proposal: The terms of this issue have been completed. We feel that it is in the best interests of the OWASP Foundation and all concerned parties to wipe the slate clean by removing the details of the inquiry from our public records at this time.
    • Motion to vote on revision:
    • Motion Josh & Jim - to remove all public-facing OWASP references to the Google Hacking Inquiry and move them to the OWASP Board archives.

All locations previously hosting these references will be replaced with the following text:

Recently, information has been brought to our attention which allows the current OWASP Board to revisit OWASP’s position on the Google Hacking Inquiry that was undertaken in July of 2010. The OWASP Code of Ethics states that we should not intentionally injure or impugn the professional reputation of colleagues and, upon consideration, we feel that perpetuating the inquiry results would do just that. As such, we feel that it is in the best interests of the OWASP Foundation and all concerned parties to wipe the slate clean by removing the details of the inquiry from our public records at this time. We feel sincerely sorry for any damages that this inquiry may have caused to any of the parties involved.

  • Yes - Jim, Tom, Tobias, Josh, Michael, Eoin

  • NO

  • No vote received -

  • Action: remove from wiki by March 1

  • Motions to modify the membership revocation policy (https://docs.google.com/document/d/1OBUWEPSEE0g9SORgn7x6tCWHpc7MIcbKivBA1YR-Aq0/edit?usp=sharing)

    • Motion #1: Proposal to add the following text to the policy in order to allow the Board to permanently ban an individual from participating in OWASP.

    • A revoked member who has not shown full compliance with the OWASP Code of Ethics during the period of revocation may, at the discretion of the OWASP Board of Directors, have the revocation period extended indefinitely.

      • Notes - included in the bylaws - 4.03 SECTION 4.03 Termination of Membership. The Board of Directors, by affirmative vote of two ­thirds of all members of the Board, may suspend or expel a member, and may, by a majority vote of those present at any regularly constituted meeting, terminate, suspend or expel the membership of any member who becomes ineligible for membership.
      • What is “eligibility for membership”? Should this change the qualification for membership?
      • 4.02 - modification - add “in good-standing subject to our code of ethics”
      • SECTION 4.02 Qualifications. Membership may be granted to any individual or organization that supports the mission and purposes of the Foundation, is in good-standing subject to our code of ethics, and who pays the annual dues as set by the Board of Directors or is approved by the Board of Directors as having provided a benefit to the organization deserving of membership.
      • Motion - Jim motion to approve, eoin second - yes: Jim, Eoin, Tom, Michael, Josh
    • Motion #2: Proposal to remove the current text of "A revoked member IS permitted to attend OWASP meetings as they are open and free by design." and replace it with the following text in order to allow chapter leaders to disallow those who would cause problems at their meeting.

    • Version 1 - A revoked member who has not shown full compliance with the OWASP Code of Ethics during the period of revocation may, at the discretion of the Chapter Leader(s), be asked not to attend their Chapter events.

    • Version 2: A member who has not shown full compliance with the OWASP Code of Ethics may, at the discretion of the Chapter Leader(s), be asked not to attend their Chapter events.

    • Version 3: Participation in OWASP activities (conferences, meetings, mailings lists, projects, etc) is subject to adherence to the OWASP Code of Ethics and OWASP leaders may revoke the privilege of participation to those who choose not to abide by that code.

    • Action: Josh to collect community vote/survey on updating bylaws

    • Intent is that would include motion 2 & 3

    • Motion #3: Proposal to add the following text to the policy in order to allow mailing list owners to moderate or reject communications from those causing problems on the list(s).

    • A revoked member may, at the discretion of the list owner(s), have their mailing list communications moderated or rejected without warning.

  • Tom - survey sent to “owasp-all” to collect heart of the community.

  • Christian has revoked his request for reinstatement of his membership

  • Wiki curation (remove/edit) from Jeff Williams: https://www.owasp.org/index.php/Issues_Concerning_The_OWASP_Top_Ten_2013 - page is not objective

    • What is a statement from OWASP vs. one person’s opinion
    • What are our policies/expectations on wiki content?
    • Opinion/debate - could be moved to the “Talk” page
    • Option to template talk page: to include something like: “NOTE : THIS ARTICLE IS THE OPINION OF ONE INDIVIDUAL AND IS NOT AN OFFICIAL POSITION BY THE OWASP FOUNDATION”

Upcoming board meetings

  • 9am pacific - April 30th
  • AppSec EU - June 27 - AM
  • Appsec USA - September 16th Tuesday 6-9PM
  • Wednesday, November 12 9am Pacific times

OWASP AppSec EU 2014 (Wiki) June 23, 2014 - June 26, 2014 Cambridge, UK TBD AppSec USA 2014 Sept. 16, 2014 - Sept. 19, 2014 Denver, CO

Motion to close - 12:20 pm - Michael, Josh

  • Motion - Jim motion to approve, eoin second: YES

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.