The Chapter Re-activation program has come to an end. From here on, Chapter management is now business as usual. We will continue to automate to policy now that Chapter data is now in a known-clean state. See below for more details. I worked with Lisa and Dawn and wrote a tool to automate the discovery of anomalies and status. This dramatically improved productivity and will end up being the basis for future notifications to chapter leaders who want to know how to get to the next level.
The NIST Executive Order workshop was okay. We were not selected to speak, but I made a lot of points on the chat, and we have been invited to participate in the SSDF secure development lifecycle framework working group. This is a good start, but not as good as I had hoped. I will continue to engage with NIST on this because I still believe OWASP has a key role to play in delivering the Executive Order.
Corporate Membership program has been progressed, and is discussed above. This is hand in hand with the trademark marks being readied around the world for licensing. We need to ensure all marks are ready for licensing before we go to market, and we need to ensure that there's a legally enforcable contract or license.
Event training splits have been improved, and will be socialized with prominent trainers and the Events Committee. This will encourage more trainers to train with us, whilst respecting that OWASP is not a commercial entity. We wish to maintain our low cost training offerings to ensure more people can attend and learn from OWASP trainers.
I engaged Virtual's VP of Marketing to develop a strategic marketing plan for us. I hope to have that to hand by the August Board meeting, but implement many of its recommendations before then. Marketing is a missing piece of the puzzle for us. We've never really done it before, and what marketing we've had is usually single event focused and simply promotional in nature. Marketing is more than simply advertising, it's reaching and engaging with new audiences. We do not have this skill set, and if we want to reach out mission target (developers), we need a plan, and we need to be execute it on very little money indeed.
The Events Committee remains in limbo. We need one or two more "officers" for the Committee to be formed. The charter exists, and there is a lot of support for for the committee, but it's important that we have sufficient OWASP members motivated to be on the Events Committee to help all local and regional events get back on their feet over the coming years as we return from COVID lockdowns.
I met with some of the AppSec Cali organizers. I am hopeful that we can hold a scaled back AppSec Cali early next year. This will require a board vote to redirect some funds, but we are also looking into if event sponsors would be interested in booking on early to cover deposits and other costs before I raise a vote.
The updated Project policy is in review, and the comment period is drawing to an end. This should be ready for being voted on by July's board meeting.
The updated Events policy is now in draft. I hope to have that ready for your vote in July. Please review.
The updated Expenses policy is nearly ready. The other operational fires kept this one from being published, but it's very close. I hope to get this into review such that it also can be reviewed prior to the July Board meeting. This is the last of the macro reforms I have in mind, and once in place, we can concentrate on operational delivery and improvements.
As this is a light month this month, I encourage the Board to consider the platform that they were elected to do, and consider raising motions or working with me on the 2022 Operating Plan to get it done next year. I need to get the 2022 Operating Plan ready by November at the latest, so we can work on the budget for next year to be voted on in the January 2022 Board meeting. I am keen to work with you on your platform and agenda.