Minutes
Board Meeting April 30, 2014 9am to 12pm PST
THIS MEETING IS RECORDED
Board Attendance:
- Michael Coates
- Josh Sokol
- Jim Manico
- Tom Brennan
- Tobias Gondrom
- Eoin Keary
Staff Attendance:
- Sarah Baso
- Kelly
- Kate
- Samantha
Others:
Minutes: Please add timestamps at 30 minute intervals so those watching archive can jump to sections of interest.
9:10 am - Meeting started
Michael Updates
- OWASP Community Updates
- Next update - May 6, 2014
- Last Update - April 22
- Executive Director & Board Sync - monthly to to talk about internal legal and HR issues, first one happened yesterday
No updates from Tom, Josh, Tobias
Jim Updates
- Wiki project cleanup moving forward
- Should owasp do certifications?
- Jim has gathered initial details from action item of last meeting
- Tom suggests initiative to get more feedback on idea
- Tom will be following up with Kelly
Sarah
Credit card for volunteers - agreement this isn’t a responsible option. Foundation will help prepay and reserve to assist as necessary
- Consider pre-paid cards, pre-paying for hotels and plane tickets for longer tours, etc
Bolivia -
- One of its leaders, Luis Antonio Rosales Marcó, was delivering the training and he also works for the company collecting the funds so without a doubt something dodgy is going on here. his profile: bo.linkedin.com/pub/luis-antonio-rosales-marcó/51/a03/2aa/en
- Official letter in violation - this is wrong and what needs to change within 30 days
- Cease and desist letter
- Sarah - to draft letter with evidence and expectations on solutions for compliant 9:30 am (30 minutes in)
Community -
- Josh motion to turn off the community (social media) functionality, initiate a plan of requirements and research
- Tobias - second motion
- Michael
- Should be free to experiment, staff needs to take ownership to ensure success on a research and plan
- Jim
- Worried about “yet another thing to log into”
- Worried about expending more volunteer capital
- Concern about staff resources used
- Tobias - suspend until we have the resources to manage the community and social media functionality
- BOARD VOTE on Josh’s motion to close salesforce social media:
- Yes: Josh, Tom, Jim, Eoin, Tobias
- No: Michael
Old business
- Josh working on details regarding whistleblower policy
- Michael working on privacy policy
New Business
- Engagement with KPMG -
- Seba concerned about significant increase in cost (2k-10k)
- Sarah explaining we are not getting enough service from current relationship with current accounting firm in terms of international compliance
- Tom - motion to move to KPMG, Jim second
- BOARD VOTE to use KPMG for international accounting:
- Yes - Michael, Tobias, Tom, Jim, Eoin, Josh
- Sarah - cost and scope of engagement for US, Sarah will send KPMG detailed info to the Board
- Business plan and Recommendations for project related consulting work - no further discussion needed at this point. We are not moving forward with this business or the proposal with DHS Swamp at this time. There is nothing currently to prevent individuals or other companies from engaging in project development on a contract basis.
- Engagement with KPMG -
Michael - discussion on Board Focus areas:
- Areas for consideration: Community, Chapters, Projects-Code, Projects-Documentation, Project-Tools, Conferences, Wiki, Membership
- discussion combined with community leadership model
Michael: Community Leadership Model
Goal - (1) Empower OWASP leaders (2) learn positives/negatives from committee
Proposal
- Name: Committees, Josh likes "Council", "Chapter Guidance Council", "Project Guidance Council"
Sarah - Project review framework
- working on merging review forms into one form for review
- Moving forward with current review structure (2 people need to complete form)
- Samantha will be socializing plan for project models for community input and vote
Sarah - strategic direction for projects requested from the board
- Josh - his proposed project model covers the direction he would prefer to take http://lists.owasp.org/pipermail/owasp-board/2014-April/013539.html
- projects should move up or down in status
- Tobias
- half time spent on flagship and half on new projects/innovation
- Staff should down grade projects that are no longer in compliance with the current category
- Jim and Josh - reset projects to level set until we have a new project system in place.
- Jim - owasp takes all flagship projects and demotes them to labs as an interim step in reevaluating project status and infrastructure. Second by Tom.
- Jim - We currently are claiming that ”The OWASP Flagship designation is given to projects that have demonstrated superior maturity, established quality, and strategic value to OWASP and application security as a whole.” and currently aren’t representing this in our actions [11:20am 2h20 min]
- OWASP Board Vote : Demote all flagship projects to labs
- Yes - Michael, Josh, Tom, Jim, Tobias
Tom - OAS Cyber Security Program - Need fabio for additional discussion
Tobias - request of staff to update description of roles on wiki - sarah on it already
Tobias - Heartbleed - Should owasp have a cheat sheet? Taking it to the community.
[11:34am 2h34 min]
- Michael motion to close, Tobias second