Sophie Barry GDPR for OWASP (see article)
Tom Brennan - a couple of weeks ago there was an email from a former Board Member, Owen Kearny about what OWASP’s GDPR plan and strategic goal.
During the last executive session, Martin agreed to take on this project.
While I was at the Chicago CyberSecurity Conference, I ran into Sophie Barry. Sophie is GPRD focus and we spoke about OWASP. I let her know that we are working on a similar project and asked how she can help in a membership perspective.
I asked her to provide us with a summary of what she can do with our context of 55k people on our mailing list. I would like to share it with the Board and we can ask questions. There is a powerpoint presentation that was sent to all Board Members.
Sophie Barry - I am here with my colleague, David Kane and we work for Qualifa, it is a global data business.
Tom and I discussed GDPR - General data protection regulation that comes into play on May 26, 2018.
So what it means that all data that anyone uses, stores, makes use of or collects any near base compact, it will be under new regulations for next year.
Us at Qualifa are working with organizations to make sure they can still communicate with their audiences as a result of the law that is changing. We are going to have to change the standards of contacting contacts.
I believe the first stages of the projects is cleansing the data.
As per Tom, you have 2 databases
3000 - memberships
55,000 - community members
Global audience
So I wanted to introduce myself and our company services and see if we can help and if you have any questions regarding our presentation.
Tom Brennan - I will forward your information to Martin, who will be handling this project.
Martin Knobloch - the law is already active. It is not a European law it is a regulation. I will look into the different interpretations of the law. The German and Dutch have the most strict regulations.
We are data owners not processors, so we have to ask them
I reached out to Owen but we are in different time frames, so I will call him next week.
Tom Brennan - this sounds like an operational item and you can help lead it.
Martin Knobloch - the law is already active but it will be in enforce in May of next year.
Matt Konda - Sophie, can you describe the options so people can get a feel for your services and we will follow-up with Martin to get the powerpoint presentation reviewed and discuss our options.
Sophie Barry - the way we are working with organizations is to generate their options and consent. Without it you will not be able to continue communicating with your audiences in Europe.
So we basically have a data verification and telemarketing service. The charge is 6.33 lbs per contact. It is not just consulting, it is improving the quality of your data.
Matt Konda - any questions
Tobias Gondrom - I think that we will have to do this on our own. Our community has people who can help the staff with this. I believe this service is unfeasible.
Andrew van der Stock - we have to understand where our data is first. I understand we use several programs, Salesforce, Gmail, Job box, etc. and we have to understand where our data is actually held.
I think there is a discovery phase before we get into a communication phase. I would also like to know what controls we have in place now to protect our data.
Martin Knobloch - we have to review our data and what systems are in use. I will lean on Kelly for this and reach out to Owen and other community members. So we know what the impact will be.
Tom Brennan - I believe we should get a consult letter from our lawyers about GPDR.
Fix Project Balance for the OWASP SAMM project (added by Seba)
Motion - to return the $3677.22 to the SAMM Project funds, Andrew van der Stock motions, Matt Konda seconds.
Vote
Tom Brennan - Yes
Michael Coates - Yes
Josh Sokol - Yes
Martin Knobloch - Yes
Andrew van der Stock - Yes
Tobias Gondrom - Yes
Matt Konda - Yes
Summits attached to Global AppSec conferences
- AppSec EU (Tel Aviv) - venue is already booked - likely not to have availability for add a summit to this event with the runway we have left.
- Assumption is that any Summit attached to a Global AppSec conference will be at AppSec USA 2018 at the earliest and new ED can determine logistical specifics
Matt Tesauro - wanted to clarify the process for the Summit for AppSec EU. Are we planning to have a separate days for a summit or add it to the conference.
Tom Brennan - I believe since we just voted on this, we should just really promote the Project Summit at the conference and anyone who wants to add a project meeting is more than welcome.
Martin Knobloch - I thought it was supposed to be a separate event.
Matt Konda - I believe there are two separate topics here. AppSec EU 2018 and future Project Summits.
I believe we answered for AppSec EU 2018, we will not change anything, just promote what we are doing.
As for proactively for the future, defining when or where it will happen is something I would love to see the staff get heavily involved in.
Everyone agrees.
Budget for 2018
Chris from Virtual - she will defer to Andrew and bring back any questions to Tom.
Andrew van der Stock - he wants to have the budget done by end of year.
- He would to set aside $150k for website design
- Asked the staff and board for any funding initiatives to be submitted asap.
- He will be meeting with Tom Pappas in the first week of December
- Merchandise - we will need to have an inventory count, there will be taxes that will have to pay on merchandise
- We have to be realistic that the operation budget is not enough to fund our needs. Most of our monies are in Chapters/Projects and we have to make a decision about that now. Example: officially using monies from Chapter/Projects for operational expenses, changing the current splits, etc.
- He will set up a meeting for November 27th to have a draft budget to meet with current and newly elected Board Members
Matt Tesauro
- Set up Jira to receive funding requests for 2018 from the community
- Chapters and Projects - Claudia and Tiffany are setting up information in Jira with anyones account that is above 5k, so they can submit budgets
Tom Brennan - is in the process of setting up the procedures for the newly elected Board Members. Sign on documents, etc.
Goals for 2018
Matt Konda - due to the transition period going on with the staff, I think it is not a good idea to push strategic goals at this time. I feel we should table this until the new Executive Director starts to January
Tom Brennan - in the meantime, please review the Chapter Leader meeting record from AppSec USA and you can see what the community is looking for.
Tobias Gondrom - I don’t think we should wait, can we start engaging with the community now.
Martin Knobloch - I agree with Tom Brennan, we are the elected by the community and we are more than capable and selecting the strategic goals.
Josh Sokol - Board is proxy for the members and staff are here to executive our requests. The new Executive Director start date is November 20th.
On a different note, regarding the web redesign what happen with the company we hired who executed all the questionnaires in the past. This was approved in past budgets.
Tobias Gondrom - can we have the staff design and send to the community a survey.
Matt Tesauro - he will have Tiffany do it.
Matt Konda - so the action is that for strategic goals, we come with information to vote on in the December meeting.