Past Meetings

OWASP Board Meeting — May 22, 2015

Official minutes of this Board meeting.

Meeting Details

  • Date: Friday, May 22, 2015
  • Time: 6:00 PM GMT+2 – 8:00 PM
  • Location: May 22, 2015 , 18:00-20:00 CEST in Amsterdam @ AppSec-EU , 9:00am-11:00am PST;

Call to Order

  • Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)

Board Members

Directors will be recorded when the meeting is called to order.

Absent

  • Michael CoatesAbsent

Guests

  • Paul Ritchie
  • Kate Hartmann
  • Kelly Santalucia
  • Noreen Whysel

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Reports

Reports

Chairman’s report – No update Vice Chair report – No update Treasurer report - No update Secretary report - No update BoD Members at Large report - Andrew: Would like to discuss:

  • Bylaws
  • Ring fencing Jim: Would like to discuss:
  • Strategic goals Michael:

All passed to focus on the business from the meeting.

Executive Director Report.

  • ED Updates
    • https://drive.google.com/a/owasp.org/file/d/0BxjNZI6rYJRKQzZRSUNBTmdnVzQ/view?usp=sharing
    • Project Coordinator - Almost complete. Down to two candidates.
      • Offer expected next week.
    • Conversion to Insperity from Virtual completed during May so May payroll processed directly between OWASP and Insperity as payroll admin.
    • Laura back and working hard on LATAM tour. Andrea’s last day of this week.
    • Laura is working directly with Matteo and Seba for AppSecEU 2016 (Rome).
    • Anti-harassment training is in our inboxes and take care of it by June. Paul provided link to online training program. This is recommended action item for all Board & Executive Director from last year’s audit report. Target is for all to complete online training by end of June.
    • Jim suggests bringing anti-harassment to leaders. Tobias suggests doing that only after we participate to make sure we think it is worthwhile.
    • Virtual agreement includes:
      • Financial support piece
      • Will revisit audit fixits in June.
    • Mark Miller podcast interview (May 12) with new ED, Paul Ritchie to be released soon.
    • OWASP Quickbooks accounting system was moved from a single laptop to a server at Virtual. Another audit recommendation completed to enhance backup, safety, and two step access and authentication as needed.
    • Check with chapter in China - Helen communicated with Ivy and there is no intermediary between China and the Foundation. Taken down a site that was a marketing front.
      • OWASP China website. owasp.org.cn.
    • Financials:
  • Director update
  • Membership update
      • Community Manager Update
    • Chapters - younger chapters giving updated materials
    • Country chapters splitting into regions (Spain, Argentina)
    • Thailand wanted to start a chapter in south, discussing to make it accessible.
    • New chapter in Columbia in South Carolina.
    • Possible chapter in South Africa.
    • Spending funds at the chapter level? Not really something that is coming up.
      • Tobias, Josh and Jim all suggest sending email to chapter leaders, with balance and suggestions
      • Recommends renaming donation scoreboard to chapter.
      • Action: --> Community manager to outreach. Support from a board member would be welcome.
      • Josh: OWASP Austin - donated 10K, could have been in Connector or shown how it was spent. Technically I wasn't saying we should figure out how to thank OWASP Austin. What I was saying is that I was a bit disheartened by the acknowledgement (or lack thereof) by the foundation and if we want to encourage others to follow suit, we need to do a better job with that.
  • Chairman’s report: NO
  • Vice Chair report: NO
  • Treasurer report: NO
  • Secretary report: NO

passed to focus on the business from the meeting.

Result: passed to focus on the business from the meeting.

Old Business

Old Business

  • Summer of Code: Timeframe and call out for proposals and ideas.
    • Hoping to have project co-ordinator to take lead.
    • 2 month summer of code with OWASP.
    • Open on June 1, Applications due 6/21, Evaluations 6/22-6/29.
      • Successful proposals start in July.
      • Coding starts
      • End of August / beginning of September wrap it up.

New Agenda Items

  • Strategic Goals

    • Training
      • Jim notes conflict of interest but proposes paying someone to build OWASP syllabus.
      • Andrew will identify resources at University level but thinks that we should get syllabus defined.
      • Tobias - academics not always ready to share their syllabus.
      • Matt asks who the audience is…?
      • This was in reference to me running a training program for a large international corporation. This makes it sound like I (like just me) am the audience.
      • Matt Tesauro says that the book gives you the syllabus.
      • Tobias should hire someone to do this? Is it going to distract people from volunteering?
      • Andrew suggests we should look at University.
      • Jim suggests it is strategic to look at academic and professional.
      • Fred - if you want it to work on something like this and make it work in the US, we need to get an academic that can help it could very helpful.
      • Josh - fine paying someone to do it, make it transparent about paying someone to do that.
    • OWASP Paid Training Model
      • Josh - Should not be supporting particular vendors for training because it raises a conflict of interest. Different at conferences because the training at conferences are chosen based on material and not branded.
      • Tobias - what about if we just provide a list.
      • Josh - disclaimer about not an endorsement.
      • Fabio - Describes selection process. Call for training.
        • Provide email to community.
        • Score proposals.
        • Organization picking based on top 3.
      • Andrew - Why would we provide anything more than a directory?
      • Josh - Multiple red flags.
        • First red flag: private company.
        • Second: OWASP Mailing list
        • Third: team select 3.
        • Four: training delivered to private entity.
      • Josh - I don’t think we should put a directory up.
      • Andrew - PCI - you can choose any QSA.
      • Fabio - Same revenue model as we use for training. Will generate revenue for Foundation.
        • Delivery of paid training.
        • Webcast to make it available to everyone.
        • Checks several boxes.
      • Jim
        • If company paid for PCI / OWASP training.
      • Paul
        • We want to try this.
        • Agrees with some red flags.
      • Josh -
        • OK moving forward with commitments we made.
        • But want to think about it in the future.
      • Paul
        • Process is moving forward.
        • Cultural message of how we operate.
        • Action: Take feedback and refresh where we are.
      • Matt
        • (Has conflict of interest)
        • Uncomfortable having list of service providers on the wiki
        • Sees PCI training as a huge opportunity but will need to walk before we run so looking at producing free content for PCI as a solution to this problem is not actively.
        • Gently uncomfortable with moving forward.
      • Tobias
        • Try and say ok not the best.
        • Let them walk with what they did.
      • Andrew moves to continuing in good faith with this vendor. Fabio seconds.
        • Andrew Yes.
        • Jim - Abstain.
        • Matt - No.
        • Josh - No.
        • Fabio - Yes.
        • Tobias - Yes.
        • Motion passes.
  • How to improve chapter engagement.

    • Jerry Hoff - How to cross pollinate and help chapters meet together.
    • OWASP Calendar of all events.
  • Mature the OWASP Projects Platforms -

    • Jim - Pay developers to help improve projects.
    • Matt - dev site, etc.
    • Josh - Make sure when we’re creating policies to chapters / projects.
    • Fabio - See value of project summit.
      • Talk about funding project summit at the next project.

Next Board Meeting – June 14, 2015. Wednesday 9:00am-10:00am PST.

May 22 Board Meeting was adjourned at 20:15 CET by unanimous consent.

  • Jim: ABSTAIN
  • Matt: NO
  • Josh: NO
  • Fabio: YES
  • Tobias: YES

New Business

No items.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.