Past Meetings

OWASP Board Meeting — April 29, 2015

Official minutes of this Board meeting.

Meeting Details

  • Date: Wednesday, April 29, 2015
  • Time: 1:00 PM PDT – 2:00 PM
  • Location: in person or virtually by board members is required at no less than 75% of the total meet

Call to Order

  • Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)

Board Members

Directors will be recorded when the meeting is called to order.

Absent

  • Andrew van der StockAbsent

Guests

  • Paul Ritchie
  • Laura Grau
  • Kate Hartmann
  • Kelly Santalucia

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Reports

Reports

Chairman’s report –

  • We have asked Paul Ritchie to become our full time ED and will effectively start on May 1. A formal job offer was made and Paul accepted via written confirmation. Vice Chair report – No update Treasurer report - No update other than Financial statement for March 2015 and summary in Executive Director report Secretary report - No update BoD Members at Large report - No update Andrew:
    Jim: Michael:

All passed to focus on the business from the meeting.

Executive Director Report.

  • ED Updates
    • Project Coordinator - Scheduling interviews with 5 candidates screened by 6 person review team including 4 from Community & 2 from Operations Staff.
    • Changing employees to be insperity / owasp instead of virtual goes into effect 5/1.
      • Key benefit here is some cost savings, removal of Virtual mgmt between OWASP & Insperity, and the ‘repatriation’ of OWASP employees from their status as ‘Virtual Mgmt Inc. employees’ under the previous HR hosting and payroll services agreement.
    • Per Audit & Best Practice procedure, Board level Anti-harassment training will be available to Board members in May: Insperity will provide training which we need to complete in May and June.
    • AppSecEU 2016 - AppSecEU in Rome, with Matteo on point to organize. Laura to work with Matteo on detail logistics to confirm University venue & major Vatican event in 2016.
    • https://drive.google.com/a/owasp.org/file/d/0BxjNZI6rYJRKZWd3dXh5WGtxNGs/view?usp=sharing)
    • Financially health. Good cash balances available at Chapter, Project & Foundation level.
    • Project available growing
    • No very large expenses. Expect them at the end of the appsec event.
  • Director update
  • Membership update
  • Community Manager Update
  • IT Update - https://docs.google.com/a/owasp.org/document/d/1VTXiz7F8a7iDgxghzpyfCm1dF8y8-X6EIIGrB99qesU/edit?usp=sharing
  • Update from LATAM
    • Maybe 900 people. Chapter leaders traveling, and good collaboration.

New Agenda Items

  • Compliance Officer - Board Duty to Appoint an Officer
    • What is the plan for 2015?
    • Josh nominated Martin.
    • Jim put out that a committee approach might be best.
    • Perhaps let Martin be the main point of contact and then have a committee to help execute.
    • Josh consider having governance committee with the compliance officer at the front.
    • Motion: Josh moves to select Martin as compliance officer for 2015. Second by Jim. Jim, Josh, Matt, Michael, Tobias, Fabio all say yes.
    • Note to select compliance officer in Q4.
  • Summer of Code
    • Fabio presents the idea as a good thing.
    • Josh asks about timing. Doesn’t want to support the proposal as is but wants to move forward in the longer term.
    • Fabio indicates that the summer of code is for students who are free during the summer.
    • Jim indicates the proposal isn’t ready.
    • Matt indicates that he would support given funds available and little staff impact.
    • Tobias suggests compromise where 50% from projects with funds that have them.
    • Josh has strong reservations regarding the precedent this sets regarding how the Foundation treats "ring fenced" funds.
    • Motion: Fabio moves to vote. Matt seconds. Motion is ‘should Board approve the updated proposal on process and funding for a Summer of Cord program?’ Discussion voiced.
      • Jim - no.
      • Josh - no.
      • Fabio - yes.
      • Matt - yes.
      • Michael - (no longer present)
      • Tobias - yes.

3 yes, 2 no proposal passes.

  • Community Update on Google Hangout Tomorrow

Next Board Meeting – May 22, 2015. Friday evening in Amsterdam after the conclusion of the AppSecEU conference.

  • Replaces the Saturday morning meeting in order to allow teleconference attendance by the 3 BoD not attending in Amsterdam. Old Start-time 8:00 AM Pacific / 17:00 CEST (@AppSecEU), Saturday, May 23.

April 29 Board Meeting was adjourned at 13:00 Pacific by unanimous consent.

  • Vice Chair report: NO
  • Treasurer report: NO
  • Secretary report: NO
  • BoD Members at Large report: NO
  • Jim: NO
  • Josh: NO
  • Fabio: YES
  • Matt: YES
  • Tobias: YES

passed to focus on the business from the meeting.

Result: passed to focus on the business from the meeting.

New Business

No items.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.