Reports - Financial Updates
Operations Report - added
Recording: Matt Konda advised that the call will be recorded.
Attendees
Board Members - Matt Konda, Michael Coates, Tobias Gondrom, Tom Brennan and Martin Knobloch
Staff/Community - Matt Tesauro, Laura Grau, Tom Pappas, James Weiler, Brian Glas
Prior Meeting Minutes - September 19, 2017
Motion - to approve prior meeting minutes. Tom Brennan motions, Martin Knobloch seconds
Minutes approved - no objections
Directors will be recorded when the meeting is called to order.
No guests listed.
As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.
Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.
None listed.
Operations Report - added
Chapter Leader Meeting - Tom Brennan stated that the recording of the Chapter Leader’s Meeting is posted and everyone should take some time and review the recording.
AppSecUSA Leaders Meeting - Recording
Project Summit
Matt Konda - After the Board Meeting in Orlando, Dinis Cruz and Seba Deleersnyder were informed that we will not be supporting the Project Summit as an independent event. The decision was based on the financials of last year’s event and wanting to focus on AppSec events and pulling them together.
Our focus is to have the Projects Summits with the AppSec events.
After the discussion, Seba and Dinis decided to run the event independently. They created a new OCMS event.
They will not be asking for money and any support. The staff however does not think it will go without support.
Is there any reason for us to intervene, support or not support it as a Board?
Michael Coates - it will cost money, there will be contracts to sign, etc.
Matt Konda - it would be us stating that someone else would have to sign the contracts and take the risk. This would fall into a new category, it is not a local or regional event.
Martin Knobloch - how is it not a local event?
Tom Brennan - a local event does not get the support from the foundation. Last month we had a talk on this and had a motion and a vote.
Tobias Gondrom - why does Seba and Dinis not want to do this with an AppSec?
Martin Knobloch - the Project Summit brings its own energy and adding it to an AppSec takes away from the Project Summit.
Matt Konda - we really don’t know how Seba and Dinis feel. They probably already put the leg work into the Project Summit. However our decision was based on that it is too expensive and needs too much staff for us to support an event that loses money.
Matt Konda - We are not trying to reopen this discussion, do we want the event to be a global event, that was voted on. I guess the question, do we ask them not to have the event or do we say go ahead with the event, but you are on the hook for accounting, sponsors, etc. That is good in theory, but is it reality.
Tom Brennan - we are rehashing what did last month. However, if you want to vote on a new procedure for events that is okay.
Michael Coates - does this request fit under our current procedures.
Tobias Gondrom - we should welcome initiatives from the community, our default should be how can we do it.
Michael Coates - can they just do the event on their own.
Tom Brennan - as long as they don’t use OWASP branding.
I think Summits are great, but we have to look at things financially.
Matt Konda - what action should we take?
Tom Brennan - why don’t we ask on Events Manager, Laura for some input.
Laura Grau - it all comes down to how we name it.
If it is a local event, we review and approve contracts and registration. But we do not have to put up money.
Seba an Dinis want the sole focus to be on their summit.
Matt Tesauro - keep in mind, that even local events are supported by the staff.
Tobias Gondrom - so local events receive very little support.
Tom Brennan - we discussed before, if 3 - 5 Projects want to get together and do their own thing that is fine, but we are talking about an global event.
Laura Grau - keep in mind, that if OWASP’s signs contracts we are still liable. This event also pays for people to attend, so we don’t know if they will have the funds to cover the contracts.
Tobias Gondrom - they have to design this that the revenue comes in at the same time that the payments are due.
Martin Knobloch - how much are we going to risk financially for a local event.
Tobias Gondrom - locals events have never had this amount of liability.
Tom Brennan - the liability for local events was based on what the Chapter and/or Project has in their account.
Tobias Gondrom - the Chapter has to have monies in their budget to cover cost.
Matt Konda - the size of this event is much more excessive than the average.
With our global events there is a risk, but we also put a lot of work into this with the staff and have some control of the outcome.
We been discussing this for a long time, I like to hear what others think.
Michael Coates - looking at the different models, if they want to do a local event within the spend of their local budget, that makes sense.
Question - are we willing to take the risk of the amount they don’t have in budget to cover it. I am not aware that we ever do that and I am against that because that is not in line in what we voted for. We voted that the Project Summit should be during an AppSec event.
Also, we can stop it because they legally can not sign a contract for OWASP for example $100k.
Tom Brennan - they can certainly guarantee the credit on their own personal credit. However OWASP will not be liable.
Martin Knobloch - I am in favor of a Summit but the way this is organized it is out of control. They must have funds to cover the contract.
Tom Brennan - why are we not following our vote that Project Summits be added to AppSec events.
Martin Knobloch - it should be its own focus because I seen the value in that in other Summits.
Tobias Gondrom - they have to stay within the budget they have.
Tom Brennan - it was discussed and voted on last month.
Matt Konda - I agree they should do it during an AppSec event.
Tom Brennan - reads the prior vote - All Summits must be attached to a Global AppSec event.
Matt Konda - so the final is that we stand by the vote of the last meeting and that is that Summits should be attached to a Global AppSec event.
Audit
Matt Konda - Andrew van der Stock has sent me the summary of the audit. I will have Tom Pappas discuss further.
Tom Pappas
Tom Brennan - is there a recommend documentation for the audit?
Tom Pappas - there will be a Board Management letter sent out.
So basically we have improved in our recommendation requests, they have decreased by eight.
Tobias Gondrom - this audit was for the US entity only?
Tom Pappas - the books of the EU entity and they also looked at the Chapter balances.
Tom Pappas - we will be working on the 990, which is due on November 15th. Once that is done, I will have the numbers to put into Hugo’s format to get the annual report done.
Tom Brennan - can you discuss the recommendation regarding timesheets because I am sure that salary employees will have questions.
Tom Pappas - this is a recommendation only, because it is a best practice for the functional section of the P&L and in the future if we were to file grants. This will track what staff is working on.
Martin Knobloch - feels this should be an ED decision not the Board.
Matt Konda - so we are just acknowledging not putting anything in place at this time.
Fix Project Balance or the OWASP SAMM Projet (AJV)
Matt Konda - Andrew van der Stock asked that we table this for now.
Clarification of Reimbursements Approval Process
Matt Konda - I don’t we need to discuss this, I believe it is done.
Matt Tesauro - I didn’t feel like I should approve my own expenses.
Motion - that the Chairman or Treasurer approves reimbursements when there is no senior staff to do so.
Martin Knobloch - Yes Michael Coates - Yes Tobias Gondrom - Yes Tom Brennan - Yes Matt Konda - Yes
Discuss of motion:
Tom Brennan - does this include PTO and approval to present trainings?
Tobias Gondrom - I believe this is already listed that the Board Chair approves or the Board Chair can delegate.
Tom Brennan - I think we need to clarify since staff seems to be confused who reports to who.
Tom Brennan - motions that Matt Tesauro be interim ED.
Matt Konda - we should discuss this during the executive session.
Above Motion fails.
AppSec USA Follow Up
Matt Konda - We left off at last meeting that San Jose was interested in hosting. Our next step is to have Laura contact anyone who submitted in 2017 and ask if they are interested in 2018.
Strategic Goals - Recap of 2017
Goal was to have four global training events.
Matt Tesauro - when Kate and Allison left it was decided to reduce the 4 to 3 events. Boston, Tokyo and Tel Aviv
Tokyo - was a great success. There were over 1000+ people over 13 locations.
Boston - about 100 people.
Jim Weiler - he thought the event was a success. He was able to reach out to students - two high schools and two colleges were interested in starting OWASP Chapters.
Tel Aviv - has not taken place yet.
Strategic Goals - 2018
Matt Konda - I have listed some prior years strategic goals.
I have set up a spreadsheet that we can use to submit goals, rank them and start brainstorming.
Martin Knobloch - should we put this on hold, since there will be some many new Board Members next year.
Matt Konda - the goals are based on the budget so I don’t think we should wait. It will be ED’s responsibility to drive the strategy not the Board Members.
I feel the elected Board Members have a duty to provide strategic goals for 2018, since they are members to the end of the year.
Tom Brennan - in reference to your spreadsheet, we did this in prior years with Trello.
Keep in mind, Board Members ran on a platform that community members voted them for, so they should be listed.
Martin Knobloch - we should assign ownership to each strategic goal, can be staff or Board Member.
Jim Weiler - I just wanted to state that I am okay with AppSec events becoming static. I do not have an issue with it being in the same location each year.
Brian Glas - I missed some of the call, I was on to discuss the SAMM budget.
Matt Konda - that was tabled because Andrew van der Stock was not on the call.
Brian Glas - we were hoping to find out because we were going to use the funds for our mini summit.
Matt Tesauro - you do have funds in your EU account.
Tom Pappas - you have 6600 Euros
Matt Konda - will send an email within a week with an explanation of the SAMM budget.
Upcoming Events
List of all the upcoming OWASP events.
Meeting Adjourned
Tobias Gondrom motions
Tom Brennan seconds