Working groups

OWASP working groups collaborate on focused initiatives. Select a group to view its page and materials.

Featured groups

More working groups

Chapter Leader Orientation Course Working Group

This working group is developing an Orientation Training Course for candidate Chapter Leaders. Once ready, it will be mandatory to complete this course before a person can be confirmed as a Chapter Leader.

Funding Working Group

The OWASP Funding Advisory Council identifies, cultivates, and pursues funding opportunities that strengthen the long‑term financial sustainability of the OWASP Foundation. The primary aim of the committee is to expand and diversify revenue streams by researching, evaluating, and recommending opportunities, including grants, sponsorships, philanthropic partnerships, and strategic collaborations.

GovOps Working Group

The GovOps Working Group will develop a new scalable operational architecture for governing authorization risk across modern software systems, infrastructure, and endpoints. GovOps elevates “capability” as the primary unit of governance for measuring, managing, and reducing authorization risk. The group’s initial work will define a standard catalog of capabilities, new metrics to measure the direction of travel, and an architecture overview with implementation and governance guidance. By exposing capabilities, governors can deploy new tools to help prioritize mitigating the authorization risks with the biggest impacts, hold the right parties accountable, and foster organizational risk transparency. This work supports OWASP’s mission by advancing software security in an area that is becoming increasingly urgent: authorization governance. As AI agents and autonomous workloads expand, organizations need open, vendor-neutral methods to make access decisions visible, measurable, and accountable. GovOps will help OWASP provide leadership in securing the next generation of application, API, and agentic systems.

ISO Liaison Working Group

The purpose of the OWASP ISO Liaison Working Group is to formally bridge the gap between OWASP’s practitioner-led security guidance and the International Organization for Standardization’s (ISO) global policy frameworks. While OWASP dominates the operational reality of application security, ISO standards (such as the 27000 series) drive governance and compliance.

Marketing Working Group

A dedicated Marketing Working Group will create the structure, focus, and agility needed to promote OWASP’s mission more effectively in today’s dynamic digital and cybersecurity landscape. With clearly defined responsibilities, a skilled team, and measurable objectives, this WG can play a critical role in building OWASP’s brand equity and community strength for years to come.

Mentorship Program Working Group

The OWASP Mentorship Program will foster meaningful connections between experienced professionals and emerging leaders, reinforce OWASP’s mission, and expand its global influence through structured knowledge sharing and community advocacy. 

OWASP Certified Secure Developer

OWASP Certified Secure Developer (OCSD) is a proposed foundation-level certification focused on web application security for developers.

PURL Expansion Working Group

The CPE machine-readable software identifier used by the CVE program for two decades has been included in fewer than 50% of published CVEs, making it extremely difficult to identify vulnerable components. Last October, the CVE program accepted PURL as an alternative identifier; PURL is superior to CPE in many ways. But a much wider effort is needed for PURL to become the predominant software identifier in CVE records. The PURL Expansion Working Group will make that effort.

Sponsorship Working Group

To support OWASP flagship and community-led projects by providing a consistent, transparent, and scalable approach to attracting and managing sponsorships. This WG will act as an enabler—offering frameworks, templates, expert guidance, and executional help for projects lacking dedicated sponsorship experience or resources.

Student Chapters Working Group

Group to improve student chapters

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.