265 Active Chapters
53 New Chapters added to date - 16 are Student chapters
13 Chapters granted reactivation exception in May deactivated again:
Fix the inactive chapter merry-go-round
Leaders are not grasping that a meeting needs to occur in 90 days of reactivation. Requirements should be clear and simple to understand and automate.
- An inactive OWASP chapter is a chapter that has not met the minimum activity requirements defined in this policy.
- An inactive chapter must either be reactivated or dissolved.
- The OWASP Foundation will revoke the inactive chapter leadership and refer the inactive chapter to the Chapter Committee to help find fresh leadership or to run elections to elect new leadership.
- Use this form to reactivate a chapter. Where an inactive chapter does not hold a meeting within 90 days of being reactivated, or new leadership could not be appointed within 90 days of failing to meet activity targets, the Chapter Committee will discuss the inactive chapter and vote on it. If agreed, the chapter will be dissolved by the OWASP Foundation.
Currently, we have seen several chapters being given multiple chances to become active after the reactivation project concluded. In the following months, these leaders chose not to hold any meetings or activities. However, as soon as they were made inactive, they immediately contacted the Chapter Committee and were granted active status again, with no activity plan or new leadership requirements. Some are now due for their second or third deactivation this year as they again have failed to meet. Our current policy has no methods to stop inactive leaders maintaining inactive chapters indefinitely if they follow the current policy. For example, OWASP Cusco leadership submitted a ticket but did not have the agreement or meet with the Chapter Committee.
We either need to have no policy around inactive chapters as it's completely ineffective now (which would be bad), or alternatively, it needs to be fixed so that inactive chapters are given a realistic chance of new leadership who will actually hold meetings. Being a leader is not a right, but a privilege, and it requires activity to maintain.
We need an re-activation plan amended into the policy to ensure chapters become active for the benefit of OWASP's mission and our members, otherwise we will continue to waste valuable OWASP committee, volunteer, and staff time, and effectively allow OWASP funds to go down the drain month after month. Worst of all, local chapter members are denied meetings and our community.
One way to amend the chapter policy's reactivation clauses is for inactive leaders to meet with the Chapter committee to discuss and document an agreed-upon plan to reactivate. The plan's terms must include dates to complete, and should include that this is a final exception. A representative from the chapter leadership and Committee needs to be dated and signed to submit the ticket to reactivate to keep on file. If the terms of the activation plan are not successful, the chapter is made inactive, and the inactive leaders will not be permitted to hold another leadership position for a period of 12 months. A new leadership team not consisting of any of the ineligible leaders could step up during this time, to permit local members a chance to hold meetings and take over the chapter permanently.
With some luck, a policy change to provide a circuit breaker will stop the merry-go-round of reactivation for the benefit of our members.
Leaders as members
Historically since 2008, you don't need to be an OWASP member to be an OWASP leader, which is practically unique in non-profit membership organizations such as OWASP.
Slowly over time, we have been increasing our membership to support OWASP's mission and activities. It's almost certainly time to re-evaluate the role of membership requirements for leaders. As this can be a controversial topic in OWASP by a very small minority of leaders (only 8% have taken up complimentary membership), it's time to re-evaluate if complimentary membership and indeed optional membership for leaders is desirable from a policy perspective for a membership organization.
In 2020, the Board created a mechanism that allowed for complimentary membership for active leaders in 2020. Recently that changed it to remove the un-automatable aspects of the policy. Take up of complimentary membership has been very low by leaders, and it costs the Foundation funds to maintain and provide benefits to those 1.2% of members who do not pay any fees.
We recommend the Board consult with the 5400+ strong OWASP Member Community to detemine if it's time to require OWASP leaders to be OWASP members, such as in pretty much all other membership organizations, and if so, if complimentary memberships should be abolished as it both demonstrates a lack of committment to the organization as well as devaluing the memberships of the other 5380+ members.
17-Nov 17-Dec Increase
One Yr/Student 3444 3522 78
Two Yr 1084 1095 11
Lifetime 748 761 13
Complimentary 83 85 2
Total 5359 5463 104
Membership Benefit Partnerships in the pipeline:
- AppSec Phoenix - end of January 2022
- Security Journey - Security Dojo Contract negotiations