Past Meetings

OWASP Board Meeting — June 27, 2014

Official minutes of this Board meeting.

Meeting Details

  • Date: Friday, June 27, 2014
  • Time: 8:00 AM GMT+1 – 4:00 PM
  • Location: June 27, 2014 , 8am - 4 pm BST, In person at AppSec Europe

Call to Order

  • Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)

Board Members

  • Jim
  • Fabio
  • Tobias

Quorum Last 2 hours): http://youtu.

Guests

  • we can in the future expand their tasks?

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

New Business

Minutes

Board Meeting June 27, 2014

Google Hangout (Participant): https://plus.google.com/hangouts/_/hoaevent/AP36tYeFfXaimWHLh9tmARCs4OrLUxTU2v-DePFvPHG-Z2TOWJqkHw

YouTube (Broadcast Only): http://youtu.be/OirhuWolamE Anglia Ruskin University, Lord Ashcroft Building, Room 309

Agenda Items - Early in the Day 10am-1pm BST Attendees: Jim, Fabio, Tobias (no quorum)

  • Review budget vs actual expenditures
    • Membership: drop in membership income and membership numbers. What can be benefits of memberships?
    • Corporate Memberships: have declined a little?
    • Can we improve coordination for approach to corporate sponsors
    • action item (Michael): ask Kelly whether we can support her role with acquiring corporate sponsors?
    • OWASP tour LATAM was very successful, we should copy that for Asia
    • Merchandise:
      • rethink what our merchandising is and how we can make it more cost effective
      • action item (Michael): ask GK what Merchandise we should do and how?
      • Jim’s idea to maybe look at tech gadgets (USB firewall, lockpick kits, webcam slide, ...)
    • Seeking collaboration and support for grant writing?
      • How can we get more proactive in applying for various pertinant grants for the foundation?
    • Expenses: Contractors: why are we below that?
    • (Tobias) Expense: Prof Training for staff: what kind of trainings have been taken by the individual staff - maybe they learned something new and we can in the future expand their tasks?
    • Expenses: Projects are underspending?
    • Expense: Projects Spending Budget is 46kUSD - while combined budgets in projects is 31kUSD
  • Committees 2.0
    • review of Committees 2.0 proposal
    • Main ideas:
      • main issue with previous was accountability (people not doing things) - not necessarily lack of empowerment.
      • no way to make people leave the committees
      • do committees need a budget?
      • What Committee should we have?
        • Projects
        • Chapters - why? Do we have enough with a chapter-leader-mailing-list or do we need a committee for that? (write chapter leader handbook, guide chapters)?
        • Education (contact with Universities) - formed by volunteers from Academia
        • Industry (vendor neutral, ISO, hold relations with corporate and industry orgs)
        • governance committee (by-laws, banning)
        • conferences (not do)
    • who get’s in a committee?
      • is an OWASP member.
      • get endorsements,
      • committee needs to vote on new members (majority)
      • committee needs to vote every six months on renewal of members (except for themselves)
      • committee chair is elected by committee.
    • How get we accountability?
      • board is sponsor of
      • point of contact is committee chair, is voice to board, has “board member champion”.
      • submit promises quarterly lists of what you are planning to do. If list is empty, board is committed to kick people out.
      • sign-up every 6 months,
      • Do we have a way to track their activities?
      • question: does the OWASP Community Portal have a recognition systems / badges?
      • Action item (Tobias): get briefing from Kate/GK about reward / badge system so we can identify and inspire active members and potentially recruit them committees
      • how do we kick people out: 1. not self-signing up, 2. committee self-policing, 3. board will enforce inactive members to not sign-up again.

Agenda Items - Late in the Day: 1pm-4pm BST

attendees: Josh, Tom, Jim, Fabio, Tobias (we have quorum)

  • Committees 2.0
    • Josh is giving brief on current committee 2.0 proposal
    • Discussion about membership in committees,
    • Staff involvement: staff shall be involved, but not do policing, scheduling of meetings, taking notes,
    • Review of Staff proposal for Committees 2.0:
      • platforms to be offered to committee, not mandated
      • comm is scoped, does not have be limited to tasks
    • committee membership:
      • is an OWASP member.
      • get endorsements,
      • committee needs to vote on new members (majority)
      • committee needs to vote every six months on renewal of members (except for themselves)
      • difference between voting members and non-voting members
    • board members within committees are taking part within committees as simple community volunteers
    • board members as sponsors for the committee?
    • board members are not speakers / lead for committee.
    • Tom question: give examples for a few abuse cases? (e.g. conflicts of interest, use of money for non-mission related topics)
    • Tom: what motivates people to do the committees? Gamification, Fabio: MemberNation can help with that recognition system?
    • Action Item (Michael/Tobias): ask all staff for review for their input
  • Current ethical challenges
    • Ethical Committee
      • Bev Corwin? Bil Cory?
    • Action Item (Tom+Eoin): Scope for an ethics committee
  • Project "manager/support/administration" function for the future
    • Action Item (Sarah+Fabio+Tobias): Define the scope for that position, involve task force?
    • Not wait for Virtual (aimed for end of August), maybe not enough time to wait until end of August?
  • Project summits: discuss format (conference separate), funding
    • Project Summit: should be part of the summit.
  • Project Review & QA: Johannas project proposal https://www.owasp.org/index.php/Proposal_Project_Review_QA_Approach
  • Google summer of code ethical issues
    • Hiring a professional publishing company to help with main documentation
  • Discussion and open for community discussion
  • Strategic goals - status?
  • (minor item) OWASP Asia tour: We did a good work with the LATAM tour and we would like to organise something similar for Asia. But I think we might not have a budget for that? @Sarah: or did I misunderstand and we do have a small budget for the Asia tour 2014 in our budget already?

Board Attendance:

Staff Attendance:

Others: Michael Coates - reviewed meeting minutes July 2, 2015

Minutes: Please add timestamps at 30 minute intervals so those watching archive can jump to sections of interest.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.