This month has been a busy month, as always, but not necessarily on the next thing in our priority list. I appreciate the Community's forebearance on the continuing Chapter Re-activation program, but this highlights in the most visible way the need to automate this process to BAU with inbuilt empathy.
The top of mind has been the Chapter Re-activation program, which has given life back to many, many chapters that were all but defunct. However, deeper inspection of many chapters highlighted there is a policy gap. We will continue to address our processes, in particular by:
a) automating detection of inactive chapters, with these results sent to the leaders of the relevant chapters
b) automation detection of broken chapters (done)
c) A way to ask for an extension if life happens
d) Build a BAU inactive chapter tool to ensure that chapters are made inactivate based around the policy, but with plenty of advanced notice for leaders (up to 90 days) with the goal to replace inactive leaders, rather than shuttering the chapter
e) Ensure that de-activated chapter pages are still visible on owasp.org, but their Meetup will be suspended. Our quarterly bill now approaches $11k, and suspending Meetup helps immeasurably.
f) A retrospective to be held in June to discuss how to improve this process, which is due to be automated later this year
Progress has been made on the trademarks initiative, with applications for OWASP, our logo, AppSec Days, and Global AppSec being applied for under the Madrid protocol in 13 countries, and separately in Chile and Argentina. There is a 7 month period before they are likely to be fully registered, but we will have priority as of our filing date. I will continue to develop the trademark program in concert with an updated Corporate Membership program, which will incorporate a trademark license at most levels.
The Corporate Membership review has identified that we have lost sponsors due to the $25k limit, and it costs us a lot of goodwill when we are arguing about the company's income, which for many organizations is difficult, especially those who are a part of large multi-nationals. I am strongly in favor of abandoning this in favor of a three tier system with different benefits. I will be presenting this at the June Board meeting. As this is operational, I will not require approval, but I would genuinely love to have Board feedback during the development of the Corporate Membership program.
The surprise announcement from the US Government Center for Disease Control on incentives for fully vaccinated individuals has been widely misinterpreted as "no masks for everyone." It is not. Their actual message is "It is safe for vaccinated people who feel comfortable in not wearing a mask to do so, and they can return to normal life.". This guidance specifically excludes unvaccinated and partially unvaccinated individuals. They specifically state that "You will still need to follow guidance at your workplace and local businesses.", which means we can set our own masking policy, which as a global organization is good, because the situation in the USA is very different to most parts of the world. I am asking for community input into a revised in person meeting task, and will likely fall into "If permitted in your local area, and if you are vaccinated, and you feel comfortable returning to in person meetings, you can do so following local masking and PPE guidelines.". However, the question of how do we know (or even if we should) validate vaccination status is an open and very thorny question, as we know some identify as vaccinated and are pugilistic about it. I don't want OWASP to collect or process any health data. I am meeting with MeetUp this coming Wednesday to discuss a privacy respecting option that advises participants that they should only attend if fully vaccinated and they accept the risk of attending in person. For the time being, we must continue hybrid and online only meetings.