Past Meetings

OWASP Board Meeting — April 4, 2018

Official minutes of this Board meeting.

Meeting Details

  • Date: Wednesday, April 4, 2018
  • Time: 1:00 PM EDT – 2:30 PM
  • Location: Remote

Meeting recording

Call to Order

Board Members

Directors will be recorded when the meeting is called to order.

Guests

  • Karen Staley
  • Dawn Aitken
  • Kelly Santalucia
  • Claudia Aviles-Casanovas
  • Harold Blankenship
  • Tom Pappas

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Old Business

Old Business

Board Report : https://docs.google.com/document/d/1nfdjjij8GJkWswxNccZFGmQRW5PGdIG2sOyOEPM3gk8/edit

Matt Konda - based on this report Karen, I can not get a feel about how staffing is going. Are you backlog, etc.

Karen - we are definitely treading, a lot of clean up and reorganizing. Right now it would be hard to take on anything new, but we are moving forward.

  • We are consolidating our tools
  • Chapters - a lot of clean up
  • Latam Tour - is going well, we are guiding but not controlling the event
  • AppSec EU and USA are moving forward.
    • We are waiting for the agenda to be posted.
    • Kelly is handling sponsorship and pleased with the progress.
  • Emails - cleaning up all the different OWASP email accounts
  • PayPal - we are in the process of reviewing and consolidating the three different PayPal accounts.
  • Staff is definitely at its capacity.

New Business

New Business

Compliance Committee Changes - posted by Greg Anderson

Greg - wanted to reach out to the Board to see if they are interested in making some changes with the Compliance Committee. Greg feels based on the questions posed to the nominated individuals for the Board, the community feels there needs to be changes regarding compliance.

Andrew - since we are volunteers, I feel that we don’t make a rapid enough decision and at times made no decision at all. We also have failed because when we make a decision we do not update the appropriate documents, handbooks, etc.

Greg - Andrew do you mean the Compliance Committee or the Board takes too long

Andrew - it sometimes takes too long for the Compliance Committee because the committee is so small and they are volunteers. At times there are numerous issues and it is not done in a timely matter. I also believe that we need to be more transparent on how we come to our decisions.

Martin - right now the Compliance Committee consists of Richard Greenberg, Bil Corry and Fiona Collins. The committee gets overloaded at times. Also if it is a staff issue it goes to HR and a Board issue can sometimes go to an external company.

We also should start to analyze who should be on the committee. We can also have a vote for individuals to be on the committee.

Matt - I believe like Andrew, our decisions should be done in a more timely manner. Also, we should identify to everyone what the steps of the process are.

Greg - I am willing to take this on because I do believe this is what the community would like. My suggestions are:

  • More people on the committee
  • The individuals should be elected
  • The decisions should be binding as long as they don’t violate our bylaws, etc.

Martin - suggested Greg to reach out to the current committee.

Matt - the current committee was not elected. I asked for volunteers when I was Board Chair.

Business Plan Development - posted by Greg

Greg - OWASP votes on a operating budget, however it is not a mature business plan for OWASP to operate on. We should define a business plan and operate in a more standardized fashion.

Now that we have an Executive Director and are reshaping the organization, I think we should design a business plan with our target goals, etc.

Are you interested in developing this?

Matt - I think this is a great idea. I do believe that it will need deep input from Karen.

Karen - this is definitely on my radar. I believe the model that we use, should be a road to our future. I have been talking with the staff, leaders and the community to find out what they think OWASP is and what it should be.

I am not sure I have the vision yet. So what I started was to review the chapter model. We are going to present to the Board a story of the chapters.

  • How many do we have
  • How much money do they have
  • How much funding do we issue for chapters
  • Where the funds currently are
  • What are the different in Chapters per region
  • Challenges/Opportunities

As Matt stated I would need deep input from the Board on where we want to be in a year or 2 years. To have commitment from the Board and the next Board so the staff can deliver the plan.

My plan now is to continue to reorganize and clean up our procedures to be able to expand and look at 2019.

I would like to have a draft by June and then work on the budget for 2019 in July and get if approved for 2019.

Greg - I think a 3 year plan would give us a better vision into the future.

Martin - strategic goals in the past did not make the impact we wanted. We also had committee but unfortunately they did not last.

Karen - The strategic plan is where we want to me and the business plan is how we are going to get there. I want to make sure we keep that separate.

We would have our strategy plan, then yearly we would review our business plan and make any necessary changes to keep on track of our strategy plan. The plan will always focused on our mission. I hope we can get together face to face to discuss this.

Greg - I think the best opportunity to get everyone together is AppSec EU.

Martin - I think meeting face to face is a great idea since we have so many new Board Members.

Chapter and Project Committees - posted by Karen

We have several community members that feel a Chapter and Project Committee will be very valuable.

Josh Sokol is interested in running a Chapter committee and Matt Tesauro is interested in the Project committee.

I would like to begin to develop these and outline a plan.

Martin - we have to go back and look at the previous committees, initiatives and the handbooks to see what worked and what didn’t work.

Matt - I am all for having committees. However, I do believe it should be individuals who come together to make this happen, not something we design. The structure is already laid out, so I don’t see this has a Board level thing but more of a community thing.

Approval of the Budget Do not have quorum

Future Board Meetings Do not have quorum

Tom P. - I just wanted to state that by the time we get all the bank statements and reconcile, we are looking at the third week of the month.

failed because when we make a decision we do not update the appropriate documents, handbooks, etc.

Result: failed because when we make a decision we do not update the appropriate documents, handbooks, etc.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.