Past Meetings

OWASP Board Meeting — June 7, 2017

Official minutes of this Board meeting.

Meeting Details

  • Date: Wednesday, June 7, 2017
  • Time: 6:00 PM GMT+2 – 9:00 PM
  • Location: Remote

Meeting recording

Call to Order

Recording: Matt Konda advised that the call will be recorded.

Attendees

Board Members - Matt Konda, Andrew van der Stock, Josh Sokol, Tobias Gondrom, , Martin Knobloch, Michael Coates, Tom Brennan

Staff - Claudia Casanovas, Kate Hartmann, Dawn Aitken, Matt Tesauro, Tom Pappas

Community - Bev Corwin, Sean Auriti, Kevin Greene

Prior Meeting Minutes - May 9, 2017

The minutes show that the vote on the OWASP Summit was motioned at the least meeting, but not seconds.

Voting History on the wiki reflects that the voting was completed electronically.

Josh motions to approve, Tom Brennan seconds

Matt Konda - asked if anyone objects - no objections - minutes approved.

Financial Summary Reports

Matt Konda - asked if there are concerns regarding the budget from Tom Pappas and Andrew van der Stock. Tom Pappas stated that the Chapter budgets are still high.

Tobias Gondrom stated that he was surprised how much goes through EU.

Tom Brennan asked if at AppSec EU was there an OWASP EU entity meeting. Tobias stated that no meeting took place. Tom stated that it is a requirement of the entity.

Tobias Gondrom will follow up on status of the required yearly meeting.

Tom Brennan posted officers of OWASP EU entity.

Tom Brennan brought up the discuss of the third OWASP entity, which is listed on the wiki page.

OWASP Norway Chapter Entity Record v/Kåre Presttun c/o Mnemonic as Wergelandsveien 25 0167 OSLO

Tom Pappas stated there is no record of a third entity.

This needs to be researched to make sure no Chapters are creating their own entity. We need to clarify to our Leaders what our procedure is regarding branding and trademark.

Action - Matt Tesauro and Tom Pappas are going to research and update the Board at the July Board Meeting on the status of the third entity.

Board Members

Directors will be recorded when the meeting is called to order.

Guests

  • Claudia Casanovas
  • Kate Hartmann
  • Dawn Aitken
  • Matt Tesauro
  • Tom Pappas

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Old Business

OLD BUSINESS

Hiring Executive Director

  • Josh is taking lead from Johanna Curiel.
  • Josh has submitted timeline (which he stated is behind). He has reworked the job description and received feedback, including Kate’s suggestions.
  • Spreadsheet has been published for anyone interested in helping with the process. If they are applicating for the position, they can not be part of the committee.
  • Once the job description is finalized, it will be published.
  • Josh will be asking the community to help promote.
  • Josh is researching a third party agency (which might be costly).
  • Josh notified all prior candidates that we are not interested in pursuing.
  • Josh contacted the two candidates that had positive feedback and will will migrate their resumes into Recruiterbox.
  • Members of the Committee do not have to be OWASP Members.

The Board discussed procedure for hiring. It was agreed that the committee will review resumes and give feedback and suggestions to the Board.

The Board will make the final decision on the hiring of the Executive Director.

Motion - to update Section 3.02 of the OWASP Bylaws, Josh Sokol motions, Tom Brennan seconds

This revision is an addition to the prior vote of Section 2.02 of the OWASP Bylaws

This has already been approved and should just be cleanup for the ByLaws since I missed that it was mentioned twice.

Revise Section 3.02 of the OWASP Bylaws to read as follows:

The number of directors of the Foundation shall be no less than five and no more than seven. Each director shall hold office for two years unless duly removed. An individual is limited to no more than two (2) terms in any ten year period. Each director must be elected as prescribed in the election policy and procedure.

Vote Andrew van der Stock - Yes Tom Brennan - Yes Josh Sokol - Yes Michael Coates - Yes Tobias Gondrom - Yes Matt Konda - Yes Martin Knobloch - SHADOW VOTE - Yes

New Board Member - Martin Knobloch

Martin has been given all paperwork from Kate Hartman. He will sign the document once he has completed reading the orientation package.

Action - Kate will forward him the document.

  • Andrew van der Stock: YES
  • Tom Brennan: YES
  • Josh Sokol: YES
  • Michael Coates: YES
  • Tobias Gondrom: YES
  • Matt Konda: YES
  • Martin Knobloch - SHADOW VOTE: YES

New Business

NEW BUSINESS

Sean Aurti’s Budget Requests

Andrew responses to the budget requests:

  • Owasp learning gateway $100k full time staff. - Hire full time staff member to build out the learning gateway. [1] - Anything in reference to grant writing or gateway, should be on hold until an Executive Director is hired. The Executive Director can come up with a strategy plan.

  • Owasp grant initiative $100k full time staff - Hire full time grant writer to work on grants for OWASP. [2] - Anything in reference to grant writing or gateway, should be on hold until an Executive Director is hired. The Executive Director can come up with a strategy plan.

  • OWASP BLT development and marketing $5k, (12 monthly prizes of $100, $1200 + development) [3] This needs to be taken on has a generic process for more projects and at this time a little more work then we can do right now.

  • Owasp project kickstart. $10k - $100 to 100 projects to use Coderbounty on 2-5 of their Github tasks to get coding done. [4] My concern is that Code of Bounty is owned by Sean, so we need to be more transparent. It is quite a good idea, however it’s execution needs to be flushed and we could get it across the line.

  • Owasp innovation lab $250k [5] - This is 10% of the OWASP budget, so no.

  • Grant engine / Spurri $50k - development [6] - Again this is something that the Executive Director can set up a strategy plan for.

  • OWASP Hackathon sponsor $5k sponsor a hackathon with prizes and food for 2017 focused on OWASP [7] Like to see a Hackathon that can be a repeatable event. But since we have put so money into Project Summits this year the funding is not available. I believe that we should start planning to do something in 2018 and have a proper proposal submitted.

  • Fundraiser events / membership drive $300 per month $3,600 - Have a monthly membership drive / fundraiser, $300 for food and drinks.[8] This should be done Globally and work with Kelly, not focus on a single Chapter.

  • Volunteer portal project $50k - development of website.[9]

  • $30k for APAC tour $10k stipend for leaders Send 3 people with $10k stipend each. [10] - I am fine with this request idea, but does need more work. I feel it should be done like the Latam approach and would be a lot easier on the staff to support if it is within two weeks. Again the proposal needs more work. Tobias states that you need a strong volunteer team.

  • OWASP Mentor Initiative with HQ NY $6,000 [11] - I believe this is a good idea, but we need to set this up Globally and submit a formal budget.

  • OWASP Organizational Development Initiative with HQ Brooklyn $50,000 [12]

Matt Konda - my goal today, is there any of these that we should take action on today. Obviously, we can not approve all of the above, Andrew would there be one that we should pick that we should discuss in more detail.

Andrew van der Stock - I believe the Hackathon because we are already doing something like this. I think this could be delegated to Claudia to take on board.

Project Kickstart - my concern is Sean owns the Code of Bounty. If we could drive volunteers in our projects particularly Labs and Incubators would be fantastic. If we could figure out a way forward and get passed that issue of how do we actually reward people. How much money do we actually put up.

Matt Tesauro - in reference to the Project Kickstart, I already spoke with Sean Auriti and told him I am happy doing a RFP like we did for the Bug Bounty system, like we are using for Projects.

If it is an open RFP, I don’t see a problem, this way we give a vendor an option to say they I do or don’t want to play in that space.

Tobias Gondrom - I believe we need to discuss the Project Kickstart more if there is a conflict of interest. I do have an issue if someone is proposing something that actually puts money in their pocket.

Matt Konda - Sean if we could hear from you and let us know what you think we should advance with.

Sean Auriti - I believe that the Project Kickstart and the Mentor Program, because I believe that aligns with the goals of OWASP.

In reference to the conflict of interest, I am the incorporated for Code of Bounty but I do not take a salary it is a separate legal entity. Code of Bounty takes a 10% commission for the bounties and that goes to Code of Bounties not me.

Mentor Initiative - we already linked this to the Learning Gateway, we have code in place and mentors that are learning from each other and this is already in motion with Bev and global members. So this would be great to have funding to move this forward.

Tom Brennan - I like to point out that if the OWASP Foundation is unable at this time to approve certain proposals that these proposals can be proposed to Chapters and Projects for funding. I do believe these proposals line up with our strategic goal of training.

Bev Corwin - I am in favor of the Mentor Program. We currently have 75 active participants and still waiting for approval of the committee, for over a year.

The Mentor Program is where the Learning Gateway Project came from, it was membership driven. The Learning Gateway Project has helped build membership and helps get OWASP information out into the community.

We have submitted proposals, but they were not accepted. We did however have them with the WIA. In reference to WIA (Women in AppSec), it shows that women do better if they have a mentor program.

Josh Sokol - how will the money be used?

Sean - funding will be used for development, marketing and trips to events.

Development - is the timeline to see how the individuals are progressing.

Motion - I would propose that we approve the Mentor Initiative. The proposal need more detail in where the money will be spent. Tom Brennan seconds.

Josh Sokol - where is the metric, how do we measure the success of the program.

Bev Corwin - I think a measurement should be set up for all of the OWASP budgets. I would like help with that measurement.

Sean Auriti - there will be a goal tracking system

Bev Corwin - Noreen Whysel is the process of researching the development of the Learning Gateway.

Pathways - track the personal progression of the mentees.

Mentors - can define timelines.

Josh Sokol - without metrics it is hard to know what the specific objectives are. I am not seeing where the money is going.

Bev Corwin - the committee would have to design a budget and approve it and then submit it to the Board for approval before spending any monies.

Tom Brennan - I feel this aligns with our training strategic goal.

Bev Corwin - the Learning Gateway is also set up to generate revenue for the OWASP Foundation within a few years.

We are about a third into the big picture. For instance, Kelly and I were able to work with a few organizations to promote the training. Example: O’Reilly. Any OWASP Chapter is able to participate as well as investors.

The goal is to help successful pathways and sponsorship programs, partnerships with human resources departments of companies.

Matt Konda - I believe the proposal needs to be cleaned up and it moves forward as states in the goal, we would have Matt Tesauro get involved.

Motion - grant $6,000 to the OWASP Mentor Initiative run by Bev Corwin and Sean Auriti.

Josh Sokol - just to do the Mentor Initiative not the Learning Gateway Project.

Bev Corwin - the Learning Gateway is building around the Mentor Initiative.

Tom Brennan - I always state that we should start things locally and then move globally. This now should be an OWASP Project not a chapter allocation.

Josh Sokol - Tiffany, why has the Mentor Committee not been established.

Tiffany Long - I officially need the request to have a committee and the scope of the committee.

Bev Corwin - she will follow up with Tiffany, the original scope changed because we started the Gateway Learning Project. I will revise the scope and submit it to Tiffany asap.

Josh Sokol - request for amendment - that the $6,000 should be allocated to the pending Mentor Committee not the NYC Chapter.

Motion - to approve $6,000 to the Mentor Initiative via the Mentor Committee. Matt Konda motions, Tom Brennan seconds

Vote Andrew van der Stock - yes Tom Brennan - abstain (is a member of the Mentor Committee) Josh Sokol - yes Martin Knobloch - yes (shadow vote) Michael Coates - yes Tobias Gondrom - yes Matt Konda - yes


Strategic Goal Training

Matt Tesauro - in reference to the strategic goal of training, I wanted to give the Board the right of refusal or suggestion regarding the issue of refunds for registrations. If we do a mass refund process the bank will flag as a high risk account.

I listed other alternatives, gift cards, etc.

The Board decided that this is an operational task and is comfortable with the staff handling it.

Crest International Tom Brennan - just an FYI that I am currently on the Board for Crest International.

Kate Hartmann

Matt Konda - I wanted to publicly state that as many of you are aware that Kate Hartmann has resigned. I wanted to publicly thank her and let her know she will be missed.

Matt Tesauro is handling the transition plan.

Matt Konda - I will be sending an email out to the community.

Motion to adjourn meeting, Matt Konda motions, Josh Sokol seconds.

  • Andrew van der Stock: YES
  • Tom Brennan: ABSTAIN
  • Josh Sokol: YES
  • Martin Knobloch: YES
  • Michael Coates: YES
  • Tobias Gondrom: YES
  • Matt Konda: YES

passed that issue of how do we actually reward people. How much money do we actually put up.

Result: passed that issue of how do we actually reward people. How much money do we actually put up.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.