Past Meetings

OWASP Board Meeting — March 3, 2014

Official minutes of this Board meeting.

Meeting Details

  • Date: Monday, March 3, 2014
  • Time: 7:00 AM PST – 10:00 AM
  • Location: Remote

Call to Order

  • Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)

Board Members

  • board meetings are recorded
  • publicly available as of March
  • 2013
  • Joining the call acknowledges your awareness of recording
  • consent to be recorded
  • public dissemination of the recording.
  • Meeting Recording pt 1
  • Meeting Recording pt 2 - Jeremiah Grossman
  • Time
  • 7:00am - 10:00am PST

Guests

No guests listed.

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Old Business

OLD BUSINESS

  • Follow up - action item to update Google Hacking Inquiry on WIki

  • Follow up - bylaws section 4.02 updated

  • Follow up - on motions on

    • Motion #2: Proposal to remove the current text of "A revoked member IS permitted to attend OWASP meetings as they are open and free by design." and replace it with the following text in order to allow chapter leaders to disallow those who would cause problems at their meeting.

    • Version 1 - A revoked member who has not shown full compliance with the OWASP Code of Ethics during the period of revocation may, at the discretion of the Chapter Leader(s), be asked not to attend their Chapter events.

    • Version 2: A member who has not shown full compliance with the OWASP Code of Ethics may, at the discretion of the Chapter Leader(s), be asked not to attend their Chapter events.

    • Version 3: Participation in OWASP activities (conferences, meetings, mailings lists, projects, etc) is subject to adherence to the OWASP Code of Ethics and OWASP leaders may revoke the privilege of participation to those who choose not to abide by that code.

    • Action: Josh to collect community vote/survey on updating bylaws

    • Intent is that would include motion 2 & 3

    • Motion #3: Proposal to add the following text to the policy in order to allow mailing list owners to moderate or reject communications from those causing problems on the list(s).

    • A revoked member may, at the discretion of the list owner(s), have their mailing list communications moderated or rejected without warning.

    • Proposed text sent to Leader’s List - received one positive responses: Participation in OWASP activities (conferences, meetings, mailings lists, projects, etc) is subject to adherence to the OWASP Code of Ethics and OWASP leaders may revoke the privilege of participation to those who choose not to abide by that code.

    • Need to define what the process is if someone objects to a decision made by a leader at the local level...

    • Action - Josh to define appeal process and send out for a vote via email.

New Business

NEW BUSINESS

  • Whistleblower policy - What at is the initiation process? what is the reporting process? What are the deliverables at the end of the process?
    • Add standing item to Board meeting?
    • Is clarification needed around purpose and role?
    • Is the compliance officer the judge, jury and executioner? Where is the delineation of duties?
    • Action - josh to review policy and draft propose revisions

################## break at 7:30 am Pacific time ################## restart at 9:00 am Pacific time Attendance:

  • Tobias Gondrom

  • Jim Manico

  • Eoin Keary

  • Michael Coates

  • Fabio Cerullo

  • Kate Hartmann

  • Sarah Baso

  • Samantha Groves

  • Jeremiah Grossman

Notes:

  • Scheduled input from Jeremiah Grossman at 9am PST - how will we grow appsec in the coming years? Suggestion for OWASP Certification program.

From Jeremiah: Thank you, I much appreciate the opportunity. The ideal time for me is March 3 at 9am PT.

The subject I’d like to discuss is, "Growing the Application Security Industry,” a topic that’s important to a great many people in the industry and I suspect OWASP as an organization as well. 20min should be enough to carry on a useful discussion.

As requested for context, while the application security industry has grown and grown up a lot over the years, it is still very small by any comparison from where it needs to be. Consider, Gary McGraw (CTO, Cigital) says roughly 2% of all programmers should be software security pros through his BSIMM research. If so, then at a worldwide programmer population of 17 million, we’ll be needing 340,000 software security pros. I don’t have to tell you all, we’re no where that. And don’t even get me started on the completley inadequate level of monetary investment in the space relative to other less important area of InfoSec.

What I’m advocating everyone to consider, including the OWASP board, is to begin looking at every community project, every software and documentation initiative, and every donated dollar spent to help closing this gap. Investing resources to increase OWASP membership, increase the number of people using it’s materials, and by extension the number of organizations that have application security programs in general. And then look with a skeptical eye for anything that doesn’t move the needle in that direction.

I have some ideas sure, but they are just that, ideas. What I think we need most, is a new way of thinking about the AppSec industry.

Question from Tobias: small comment: as mentioned before, if you have specific ideas or actionable items that you like the board to vote on, please send these questions before the meeting so people have time to think about them and involve the community for opinions. As you did not mention specific vote questions, I assume your talk is planned as food for thought and potential medium term ideas, but does not contain requests for immediate actions. (Of course, in the end nothing would prevent the board from voting during the meeting if it decides so.)

From Jeremiah:

Tobias, First, thank you very much. And second, your suspicions are correct. While I’ve plenty of “ideas” to float by everyone, they’ve not been fully vetted and certainly not something I think is anywhere near board vote ready.

The one I’ve been trying to get socialized for years is an OWASP run application security certification (a variety of them actually). While yet another crappy certification scares many people in the community, and for good ISC2 reasons, I find they mostly disagree with the implementation, but not the concept in general. That says to me, if done well, if done right, this could fly, and do great things. It would give people a real reason to become OWASP members.

OWASP sets the minimum standard of experience / skill for a certification. The organization creates and curates the testing question bank.

Any organization may then offer in-person / CBT training for those wishing to be OWASP certified. Of course some will be better than others, but this is a community issue.

An independent third-party professional testing facility, of which there are many, is approved by OWASP… paid for by the test-taker will then manage the testing processes.

Everyone plays a role, all interests are in alignment, and hiring managers may rejoice!

Anyway, that’s one…

Regards,

Jeremiah-

  • Jim and Tobias will take point on putting together pros/cons and proposed item for community vote

For reference: Certification discussion from 2008 Summit: https://www.owasp.org/index.php/OWASP_Working_Session_-_OWASP_Certification

Certification discussion from 2011 Summit: https://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session039

Upcoming board meetings

  • April 30th, 9am pacific
  • AppSec EU - June 27 - AM
  • Appsec USA - September 16th Tuesday 6-9PM
  • Wednesday, November 12 9am Pacific times

Michael motion to close, Tobias second. Meeting close at 9:55 am Pacific

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.