Past Meetings

OWASP Board Meeting — February 11, 2015

Official minutes of this Board meeting.

Meeting Details

  • Date: Wednesday, February 11, 2015
  • Time: 4:00 PM PST – 5:00 PM
  • Location: at AppSec-EU

Call to Order

  • Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)

Board Members

Directors will be recorded when the meeting is called to order.

Absent

  • Non-Board AttendanceAbsent

Guests

  • Paul Ritchie
  • Kate Hartmann
  • Kelly Santalucia
  • Noreen Whysel

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Reports

Reports

Chairman’s report –

  • Welcomes us all for 2015.
  • Thank you to Eoin and Tom.
  • Budget for Asia Tour information to follow later.

Vice Chair report –

  • Working on transition from Josh to Fabio.

Treasurer report - N/A.

  • Absent at initial review.

Secretary report -

BoD Members at Large report -

Andrew:

  • Hangout to do background and clean up comments.
  • Asked to have Kelly, Paul and Andrew get together to talk about election process and by-laws.

Jim:

  • Attended codemash - true developer conference.

Michael:

  • Good outreach to PHP community. Call to action from people in the PHP security community.
  • TODO: Matt and Michael - Find existing document tracking developer conference presence and share it with the community.

Executive Director Report.

https://docs.google.com/a/owasp.org/document/d/1aFAOfj6QkgM3nwB_ViAE21wfQ6oE2mYTwNkM7HZ8TDU/edit

  • ED Updates Filled temporary events manager role for both AppSec EU&USA and LATAM Tour. Staff performance reviews completed for 2014.

Budget - following previously proposed budget for 2015. Still in draft mode pending finalization of 2015 Strategic Goals which may reallocate some funds. EU Entity - Background, Seba & Eoin have given notice they will be stepping down from their Board of Director roles for the OWASP VZW legal entity in Belgium. Tobias is currently the 3rd named Director on legal records. Next steps to find volunteers to take over the Board seats for Europe are not yet clear. Discussion around whether Fabio and Tobias are volunteering to be on the board. Fabio has offered to assist with the work effort, but cannot signup as the legal Board representative for OWASP VZW. Therefore, he cannot go to Belgium to sign paperwork.

TODO: Paul to investigate who can sign.
TODO: Paul to investigate moving the organization from Belgium to another place that may be more manageable.

  • Finance

    • Overall in good shape.
    • Follow Up:
      • Working to clarify how to provide better reporting on track what we owe to chapters (liabilities).
      • New discussion:
        • Significant budget (500K) allocated to Chapters that has been unused.
        • Michael asked about data related to income and expenditures by chapter.
        • Josh pointed out that it is partly an operational responsibility to help the chapters to understand what is going on and what they could do with it.
        • Jim asks to make information about budget available and visible by emailing community list. Tobias suggests to leave it to Noreen.
        • Matt asks perhaps to use chapters that are spending (and doing other things) as case study example in communications.
        • Andrew - potentially
    • End of Year Summary
      • Unaudited budget, but same trend from last couple of months.
  • Membership update:

    • In ED report.
    • Tobias wonders if time is a limiting factor for securing corporate sponsorships? Kelly indicates “yes”. Tobias clarifies that the question is “are we leaving money on the table.” Paul comments that it may be worth taking a look at adding a resource and what the potential
  • A comprehensive Events management report:

    • In ED report.
  • Additional Highlights:

    • Kate working on reviewing how handling customer service inquiries. Also looking at what kinds of questions are being asked.
    • Noreen is out there meeting with the community and writing. Also making sure there is correct information about leaders. Capture questions into a FAQ.
      • Jim points out that google points to owasp wiki for chapters and so we need to keep up the information on the wiki pages.
    • Tracking AppSecUSA:
      • Good location, good sponsorship thus far.

New Agenda Items

  • Follow up on 2015 Strategic Goals
  • Review of China Chapter
    • Conversation with chapter leaders from China that they explained that they do not collect membership fees and China “membership” is that you register to a mailing list. It is clear to people in China that they are not purchasing a clear membership. Asked them to make it even more clear that they are not full members and do not have voting rights.
    • Fabio reports that there is evidence that there is a board, infrastructure, and that they are charging.
    • TODO: Ask operations to bring China chapter in line with organization. Paul indicates that we can start Phase 2 and reach out and get real clarity.
  • Motion to change Interim Executive Director to Executive Director
    • Follow up after meeting with Virtual next week.
  • Tobias follow up on Asia tour.
    • Tobias reports he only used 2 of 12K of funding. Local used their own money first. Hereby release 10K back to global organization.
    • TODO: Update on the numbers for the Asia tour.
  • Josh urges to follow up on sensitivity training.
    • TODO: Paul to plan training (group or online - Virtual to provide that)
  • Tobias follow up on AppSecEU being a face to face board meeting. Andrew indicates that there would be quorum and suggests that it be planned that way.

Next Board Meeting – Wednesday, February 11, 2015. Start-time 09:00 Pacific / 12:00 Eastern / 18:00 CET

Jan 14 Board Meeting was adjourned at 10:00 Pacific by unanimous consent.

The following were listed as old business but did not get discussed:

Open Action Items from Prior meetings

  • Oct. 8 - Review ‘Interim’ status of Executive Director & discuss conversion to full time ED. Michael leading this discussion. Still Open per Dec. 10 meeting.
  • Oct. 8 - Board to review how website in China is being used and the financial arrangement to ensure it is in line with OWASP Foundation policy. Still Open. To be discussed following AsiaPac Tour.
  • Sept. 16 - 2015 Strategic Planning. Board to address with new Board members.
  • Sept. 16 - 2014 Goals & accomplishments to be presented by owners of goals. Still Open. Would be good content for 2014 Annual Report.

Follow Up and Other Action Items

  • OWASP Bugcrowd Bug Week Follow Up
  • Whistleblower Policy
    • Next steps: replace one on the wiki.
      • TODO: Josh - Martin and community.
      • TODO: Paul - note to staff that whistleblower policy has changed.
  • Code of Ethics Discussion
    • TODO: Michael to follow up with Martin (already partly done)
  • 2015 Budget (Paul)

New Business

No items.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.