OWASP working groups collaborate on focused initiatives. Select a group to view its page and materials.

Mission Statement: To provide the support and guidance required by all OWASP chapters to thrive and contribute to the overall mission and goals of OWASP
Support OWASP's mission to provide support for education activities to foster collaborations and support relationships with the Application Security, Developer, and Training communities, both academic and industry-based, and to advise the Foundation & Board of an educational strategy for OWASP.
The OWASP Events Committee mainly supports OWASP Staff in managing Global AppSec Events. We are here if you need help managing your event as well - please reach out to us.
To provide the support and guidance required by Projects to thrive and contribute to the overall mission and goals of OWASP.
This working group is developing an Orientation Training Course for candidate Chapter Leaders. Once ready, it will be mandatory to complete this course before a person can be confirmed as a Chapter Leader.
The OWASP Funding Advisory Council identifies, cultivates, and pursues funding opportunities that strengthen the long‑term financial sustainability of the OWASP Foundation. The primary aim of the committee is to expand and diversify revenue streams by researching, evaluating, and recommending opportunities, including grants, sponsorships, philanthropic partnerships, and strategic collaborations.
The GovOps Working Group will develop a new scalable operational architecture for governing authorization risk across modern software systems, infrastructure, and endpoints. GovOps elevates “capability” as the primary unit of governance for measuring, managing, and reducing authorization risk. The group’s initial work will define a standard catalog of capabilities, new metrics to measure the direction of travel, and an architecture overview with implementation and governance guidance. By exposing capabilities, governors can deploy new tools to help prioritize mitigating the authorization risks with the biggest impacts, hold the right parties accountable, and foster organizational risk transparency. This work supports OWASP’s mission by advancing software security in an area that is becoming increasingly urgent: authorization governance. As AI agents and autonomous workloads expand, organizations need open, vendor-neutral methods to make access decisions visible, measurable, and accountable. GovOps will help OWASP provide leadership in securing the next generation of application, API, and agentic systems.
The purpose of the OWASP ISO Liaison Working Group is to formally bridge the gap between OWASP’s practitioner-led security guidance and the International Organization for Standardization’s (ISO) global policy frameworks. While OWASP dominates the operational reality of application security, ISO standards (such as the 27000 series) drive governance and compliance.
A dedicated Marketing Working Group will create the structure, focus, and agility needed to promote OWASP’s mission more effectively in today’s dynamic digital and cybersecurity landscape. With clearly defined responsibilities, a skilled team, and measurable objectives, this WG can play a critical role in building OWASP’s brand equity and community strength for years to come.
The OWASP Mentorship Program will foster meaningful connections between experienced professionals and emerging leaders, reinforce OWASP’s mission, and expand its global influence through structured knowledge sharing and community advocacy.

OWASP Certified Secure Developer (OCSD) is a proposed foundation-level certification focused on web application security for developers.
The CPE machine-readable software identifier used by the CVE program for two decades has been included in fewer than 50% of published CVEs, making it extremely difficult to identify vulnerable components. Last October, the CVE program accepted PURL as an alternative identifier; PURL is superior to CPE in many ways. But a much wider effort is needed for PURL to become the predominant software identifier in CVE records. The PURL Expansion Working Group will make that effort.
To support OWASP flagship and community-led projects by providing a consistent, transparent, and scalable approach to attracting and managing sponsorships. This WG will act as an enabler—offering frameworks, templates, expert guidance, and executional help for projects lacking dedicated sponsorship experience or resources.
Group to improve student chapters