Past Meetings

May 2025 Minutes

Official minutes of this Board meeting.

Meeting Details

  • Date: Wednesday, May 28, 2025
  • Time: 5:30 PM GMT+2 – 7:00 PM
  • Location: In-person / remote

Call to Order

The Chair called the meeting to order at 17:30 CEST.

Board Members

  • Ricardo Griffith
  • Steve Springett
  • Harold Blankenship
  • Ashwini Siddhi
  • Sam Stepanyan
  • Diego Silva Martins
  • Avi Douglen

The Board has quorum.

Guests

  • Andrew van der Stock
  • Dawn Aitken
  • Lauren Thomas
  • Hayden Corry
  • Starr Brown
  • Christian Capellan
  • Heather Kennedy
  • Chris Barbeau
  • Leea Hudson-Wilson

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda - unless otherwise prohibited by anti-trust or competition laws - including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

Pre-reading Material

e-Votes and Special Meeting Motions to read into minutes

Motion to approve Vienna as the location for AppSec EU 2026-2028

Background This is the second motion to decide if we are to host our AppSec EU conferences from 2026-2028 in a single location, Vienna.

After a successful site visit by Sam (thank you for that!), we have received very favorable pricing for holding AppSec EU in Vienna for a period of three years at 157k per year.

Additional information

  • The costs of Food and Beverage (F&B) bill, which are not included in this contract, would be charged separately, are comparable to other venues that we obtained quotes from.
  • The costs of hotel rooms are in line with other European cities at this time of the year
  • The timing of the event would be the same dates for all three years, which is something that the Board has wanted, and allows us to plan and advertise well in advance, similar to the way it happens with other major events like RSA, BlackHat and Defcon.
  • We would only need to register for VAT once in three years, which simplifies the management of ticket sales and invoicing for sponsorships.

Motion: "Resolved, the Board approves the Executive Director signing a contract with Austria Center Vienna as the host convention center for AppSec EU 2026-2028."

Sponsor: Harold Blankenship Second: Ricardo Griffith

  • Result: 6 YES 0 NO 0 ABSTAIN. Motion passes.
Relevant reading

Motion: to decide if we are to host our AppSec EU conferences from 2026-2028 in a single location, Vienna. After a successful site visit by Sam (thank you for that!), we have received very favorable pricing for holding AppSec EU in Vienna for a period of three years at 157k per year. **Additional information** - The costs of Food and Beverage (F&B) bill, which are not included in this contract, would be charged separately, are comparable to other venues that we obtained quotes from. - The costs of hotel rooms are in line with other European cities at this time of the year - The timing of the event would be the same dates for all three years, which is something that the Board has wanted, and allows us to plan and advertise well in advance, similar to the way it happens with other major events like RSA, BlackHat and Defcon. - We would only need to register for VAT once in three years, which simplifies the management of ticket sales and invoicing for sponsorships. **Motion:** "Resolved, the Board approves the Executive Director signing a contract with Austria Center Vienna as the host convention center for AppSec EU 2026-2028." - [e-Vote](https://docs.google.com/forms/d/e/1FAIpQLSdqOiF-bXo5oSyXefO_8FT3smkYfnRnzbn7qPTsKQyH83gqEQ/viewform?usp=sharing&ouid=102207325192678137930)

Sponsor: Harold Blankenship · Second: Ricardo Griffith

6 YES 0 NO 0 ABSTAIN. Motion passes.**

Result: 6 YES 0 NO 0 ABSTAIN. Motion passes.**

New Business

Motion to approve the working group policy

Background This policy establishes the process for creating and managing OWASP working groups. It is intended to provide a clear framework for the establishment, operation, and dissolution of working groups within the OWASP Foundation. The pull request contains changes to the bylaws to allow the creation of working groups, and the committee policy to ensure that the working group policy is the primary source of information for working groups., and lastly, the working group policy itself.

Motion: "Resolved, the bylaws are amended to allow the creation of working groups. This requires a super majority of the Board."

Sponsor: Steve Springett Second: Ricardo Griffith

  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES

Results

Passes 7-0

Motion: "Resolved, the committee policy is amended to ensure that the working group policy is the primary source of information for working groups. This requires a super majority of the Board."

Sponsor: Steve Springett Second: Ricardo Griffith

  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES

Results

Passes 7-0

Motion: "Resolved, that working groups policy is approved."

Sponsor: Steve Springett Second: Ricardo Griffith

  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES

Results

Passes 7-0

Motion: Resolved, the bylaws are amended to allow the creation of working groups. This requires a super majority of the Board.

Sponsor: Steve Springett · Second: Ricardo Griffith

  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES
  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES
  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES

Motion to approve the privacy policy

Background The privacy policy outlines how OWASP collects, uses, and protects personal information. It is designed to ensure compliance with applicable privacy laws and regulations, and to provide transparency to individuals about their data.

Motion: "Resolved, that the privacy policy is approved."

Sponsor: Avi Douglen Second: Diego Silva Martins

  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES

Results

Passes 7-0

Relevant reading

Motion: Resolved, that the privacy policy is approved.

Sponsor: Avi Douglen · Second: Diego Silva Martins

  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES

Motion to approve the travel policy

Background The travel policy outlines the guidelines and procedures for OWASP Board members, participants and volunteers when traveling for OWASP-related business. It is designed to ensure consistency, accountability, and cost-effectiveness in travel arrangements.

Motion: "Resolved, that the travel policy is approved."

Sponsor: Diego Silva Martins Second: Ricardo Griffith

  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES

Results

Passes 7-0

Relevant reading

Motion: Resolved, that the travel policy is approved.

Sponsor: Diego Silva Martins · Second: Ricardo Griffith

  • Steve Springett: YES
  • Harold Blankenship: YES
  • Sam Stepanyan: YES
  • Ashwini Siddhi: YES
  • Avi Douglen: YES
  • Diego Silva Martins: YES
  • Ricardo Griffith: YES

OWASP EU Discussion

Background The OWASP EU discussion is an ongoing conversation about the future of OWASP in Europe, including potential changes to the organizational structure, funding, and outreach efforts.

Certification Program Update

Background The certification program update provides an overview of the current status of OWASP's certification effort, including any changes or improvements that have been made since the last update.

Shruti Kulkarni provided an update on the Certification curriculum development progress. Shruti Kulkani also ran a session on the certification program at AppSec EU 2025 for more information after the Board meeting.

Education & Training Committee Update

Presented by Shruti Kulkarni:

  • Progress on training programs and proof of concept training event in London being planned.

Comments, Announcements, and Other Business

An open Q&A session was held to address questions and comments from OWASP members attending the meeting in person.

Adjournment

Adjournment motion

The next general Board meeting is on June 24 2025, at 12 pm US Eastern Time.

"It is moved, and seconded to adjourn. Those in favor, say "aye""

Sponsor: Ricardo Griffith Second: Avi Douglen

Sponsor: Ricardo Griffith · Second: Avi Douglen

The next general Board meeting is next general Board meeting is on June 24 2025, at 12 pm US Eastern Time..

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.