Past Meetings

OWASP Board Meeting — August 15, 2018

Official minutes of this Board meeting.

Meeting Details

  • Date: Wednesday, August 15, 2018
  • Time: 1:00 PM EDT – 2:30 PM
  • Location: Remote

Meeting recording

Call to Order

Board Members

Directors will be recorded when the meeting is called to order.

Guests

  • Karen Staley
  • Kelly Santalucia
  • Harold Blankenship
  • Tom Pappas
  • Matt Tesauro

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

Reports

Reports

Board of Director Report:

  • Staff has spent the last weeks focusing on Appsec EU
  • The team pulled together to bring the event to fruition.
  • New staff addition; Welcome back Matt Tesauro, Director Community and Operations
  • Dawn Aitken continues to clean up the chapter details and open new chapters
  • Corporate membership – is continuing to come in but we are bit behind last year. Staff (Karen and Kelly) will focus on membership after AppSec EU.
  • Working on tooling – Matt T is leading the initiative to consolidate and maximize tool use
  • The Staff is working on updating the wiki with a new landing page and other necessary updates. Martin suggested a friend who can help with this and Matt T stated he would work on this with support from Martin.

Financials

Tom Pappas

  • About 70k ahead in revenue
  • More expenses incurred from regional events
  • OWASP May cash position better is getting better
  • Owed to chapter and payable in VAT 928k- we need to find a solution regarding the chapter split
  • 200k liquid cash, this will be reduced when AppSec Cali receives their 90% split
  • Hasn’t been closed due to continued activity
  • 100+ operating cash end of May
  • OWASP is Tracking to budget, our operating cash is position better
  • For this event, down to 1-2 sponsors that haven’t paid

Karen Discussion Topics

  • Receivables are down. The staff worked hard to collect on sponsors with only 1-2 not paid at the time of AppSec EU
  • We hope to work with regional events to assist in management to keep expenses in check and not to out-pace expenses over revenue. Staff get more involved with organizing events and what costs are. Help negotiate and set up new sponsors. Reduce some of the costs.
  • Karen replied to Matt K. that the OWASP team and Virtual are working more closely together with some processes in place to help with communication and reporting. working challenges in the past month things have been a little bit more busy due to AppSec EU workload.

Registration Report AppSecEU

  • Very pleased with numbers
  • The revenue exceeded the budget by 106%
  • Hoping for substantial gain and surplus
  • Registration and training numbers up for paid attendees
  • We expect strong attendance
  • The goal is to keep money in the EU to fund new endeavors

New Business

New Business

Strategy to discuss Global Events - Vote

  • High level approach to the global events going forward
  • Provide peers and Board more time to think about it
  • Strive to hold 4 global events a year
  • Transparent and fair for cities etc make it more fair and easier to host an event
  • During community calls there was hesitation as to the amount of work that needed to be done to hold a conference- Staff plans to reduce work and allow community the ability to focus on content
  • Make OWASP community more diverse – events should be more dynamic and agile

Vote -Strive to have 4 – hold at least 3 – Motioned: Sherif, second Martin. In Favor: Andrew, Chenxi, Greg, Martin, Owen, Sherif: Motion Passed

Global event in Tel Aviv- Vote

Tel aviv have stipulated that they will not hold their free event in 2019 The event was approved for 2018, due to its high quality submission

Motioned: Sherif Mansour, host a global AppSec event in Tel Aviv in 2019 seconded by Andrew van der Stock In Favor: Chenxi, Greg, Martin, Matt, Owen, Sherif, and Andrew: Motion Passed.

Compliance Committee- Vote

Discussion on Compliance Committee: If you are going to have a formal committee we need to define the roles. Does the committee need to be formed through an election? It is one way to handle community complaints The compliance committee issue was one of the top 3 items for all new board members It is up to the board to enforce the advisement from the compliance committee Should the board enable the compliance committee and give them more power Should OWASP Restructure the compliance committee charter Create a revised means of handling community complaints

  • Warn a person of infringement
  • Suspend a person or ban a person from events or org
  • Resolutions are binding Structure of the committee should be similar to the board, rotate people more often due to the need to have enthusiastic people, terms should be shorter Have elections at the same time as the board

Concerns with the current structure:

  • It takes a long time to work through the issues
  • Include an SLA to ensure things move quick
  • Putting time limit to it can aid for a quick resolution
  • A large sized committee(5 persons) may be hard to build
  • Issue can be transferred to legal advice if it falls outside the scope of the compliance committee
  • Discussion about it makes it so we may need to comply all the time

Get the communities input and then have an evote.

Motion vote on electing compliance members – Greg, Andrew second

In Favor: Andrew, Greg, Martin, Owen, Sherif. Motion passed Not in Favor: Matt Konda

Coursera

Martin was reached out to for training possibilities. We would like to collaborate with Coursera as they want to use OWASP material to create a course but want to give something back to the community Host wiki content created by OWASP on their website Content accessible by everyone. Courses will not be public A discount for OWASP members would be a great benefit.

Motion – Martin, second Greg

In Favor: Andrew, Greg, Martin, Matt, Owen, Sherif, Motion Passed

Amend Bylaws in relation to board meeting attendance Proposed revisions to be based upon tabulation of member involvement over any 6-month period and not a full year. Also insure meetings are set up a minimum one month in advance to facilitate participation.

Matt Tesauro current staff member and past board member, suggested that the board members come together at face to face a minimum of twice a year.

Motioned: Martin, Andrew second

In Favor: Andrew, Greg, Martin, Matt, Owen, Sherif- Motioned Passed

Passed

Result: Passed

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.