Difference between revisions of "About The Open Web Application Security Project"

From OWASP
Jump to: navigation, search
m (OWASP Foundation ByLaws)
(29 intermediate revisions by 10 users not shown)
Line 7: Line 7:
 
[http://www.linkedin.com/companies/owasp https://www.owasp.org/images/9/98/Btn_cofollow_badge.png]
 
[http://www.linkedin.com/companies/owasp https://www.owasp.org/images/9/98/Btn_cofollow_badge.png]
  
==Citations==
+
===OWASP Foundation ByLaws===
OWASP and its materials are used, recommended and referenced by many government, standards and industry organizations. We maintain a list of some of the more important citations on the [[Industry:Citations]] page.
+
 
 +
The business of the OWASP Foundation Inc., outlined in the organizational [http://en.wikipedia.org/wiki/By-law by-laws]. These by-laws govern the organization worldwide and allow the participants to understand the established process for doing so.
 +
 
 +
[[OWASP Foundation ByLaws]]
 +
 
 +
[https://www.owasp.org/images/9/90/126741_OWASP_vzw_modelstatuten_v0.9_EN_REV.pdf OWASP EU Foundation ByLaws (English Translation)]
 +
 
 +
[[Local Chapter ByLaws]]
  
 
== Core Values ==
 
== Core Values ==
Line 52: Line 59:
 
* Risk based approach
 
* Risk based approach
  
==2013 Global Board Members==
+
==2014 Global Board Members==
  
===OWASP Foundation ByLaws===
+
[[User:MichaelCoates|Michael Coates]] - OWASP Chair - San Fransisco, CA USA
 +
<br/>michael.coates(at)owasp.org
  
[https://www.owasp.org/images/d/d6/2011-06-OWASP-BYLAWS.pdf Foundation ByLaws last updated 06-2011]
+
[[User:Brennan|Tom Brennan]] - Vice Chair - New Jersey, USA
 +
<br/>tom.brennan(at)owasp.org
  
[https://www.owasp.org/images/9/90/126741_OWASP_vzw_modelstatuten_v0.9_EN_REV.pdf OWASP EU Foundation ByLaws (English Translation)]
+
[[User:jsokol|Josh Sokol]] - Treasurer - Texas, USA
 +
<br/>josh.sokol(at)owasp.org
  
[[Local Chapter ByLaws]]
+
[[User:tgondrom|Tobias Gondrom]] - Secretary - Hong Kong
 +
<br/>tobias.gondrom(at)owasp.org
  
==
+
[[User:fcerullo|Fabio Cerullo]] - Special Projects: Ireland
 +
<br/>fcerullo(at)owasp.org
  
[[User:MichaelCoates|Michael Coates]] - OWASP Chair - San Fransisco, CA USA
+
[[User:EoinKeary|Eoin Keary]] - Special Projects: Dublin, Ireland
<br/>michael.coates(at)owasp.org
+
 
+
[[User:Sdeleersnyder|Sebastien Deleersnyder]] - Vice Chair - Belgium
+
<br/>seba(at)owasp.org
+
 
+
[[User:Wichers|Dave Wichers]] - Treasurer - Maryland, USA
+
<br/>dave.wichers(at)owasp.org
+
 
+
[[User:EoinKeary|Eoin Keary]] - Secretary/Historian - Dublin, Ireland
+
 
<br/>eoin(at)owasp.org
 
<br/>eoin(at)owasp.org
  
[[User:Brennan|Tom Brennan]] - New Jersey, USA
+
[[User:Jmanico|Jim Manico]] - Special Projects: Hawaii, USA
<br/>tom.brennan(at)owasp.org
+
 
+
[[User:Jmanico|Jim Manico]] - Hawaii, USA
+
 
<br/>jim.manico(at)owasp.org
 
<br/>jim.manico(at)owasp.org
  
 
* OWASP Board Public Mailing List ** http://lists.owasp.org/pipermail/owasp-board/
 
* OWASP Board Public Mailing List ** http://lists.owasp.org/pipermail/owasp-board/
 +
 +
* Additional [https://www.owasp.org/index.php/Board board info]
  
 
==Employees of the OWASP Foundation==
 
==Employees of the OWASP Foundation==
 +
Sarah Baso [[User:Sarah_Baso|Sarah's Role w/OWASP]]
 +
<br/>OWASP Executive Director
 +
<br/> [http://sl.owasp.org/contactus  Contact Me]
  
 
Kate Hartmann - [[User:Kate_Hartmann|Kate's Role w/OWASP]]
 
Kate Hartmann - [[User:Kate_Hartmann|Kate's Role w/OWASP]]
 
<br/>OWASP Operations Director
 
<br/>OWASP Operations Director
 
<br/>[http://sl.owasp.org/contactus  Contact Me]
 
<br/>[http://sl.owasp.org/contactus  Contact Me]
 
Sarah Baso [[User:Sarah_Baso|Sarah's Role w/OWASP]]
 
<br/>OWASP Director
 
<br/> [http://sl.owasp.org/contactus  Contact Me]
 
  
 
Kelly Santalucia [[Kelly's Role w/OWASP]]
 
Kelly Santalucia [[Kelly's Role w/OWASP]]
<br/> OWASP Membership Committee
+
<br/> OWASP Membership & Business Liaison
 
<br/> [http://sl.owasp.org/contactus  Contact Me]   
 
<br/> [http://sl.owasp.org/contactus  Contact Me]   
  
Line 106: Line 107:
 
<br/>[http://sl.owasp.org/contactus  Contact Me]   
 
<br/>[http://sl.owasp.org/contactus  Contact Me]   
  
OPEN - [https://www.owasp.org/index.php/ITSupport IT Administrator Role]
+
Matt Tesauro [https://www.owasp.org/index.php/ITSupport IT Administrator Role]
IT Administrator
+
<br/>IT Administrator
 +
<br/>[http://sl.owasp.org/contactus  Contact Me]
  
[http://sl.owasp.org/contactus  Apply]  
+
Laura Grau
 +
<br/>OWASP Event Manager
 +
<br/> [http://sl.owasp.org/contactus  Contact Me]
  
OPEN - [[Operational Administrative Assistant]]
 
  
[http://sl.owasp.org/contactus  Apply]
+
==Meeting Minutes==
 +
The OWASP Foundation Board meets monthly.
  
==Board Meeting Minutes==
 
The OWASP Foundation Board and Committee Chairs meet monthly.
 
 
[[OWASP_Board_Meetings | Board meeting minutes for the record.]]
 
[[OWASP_Board_Meetings | Board meeting minutes for the record.]]
  
[[Staff Meetings]]
+
[https://docs.google.com/folder/d/0B5Z9zE0hx0LNOWFIRG9reTUwOXM/edit Staff Meetings]
 +
 
 +
[https://docs.google.com/folder/d/0B5Z9zE0hx0LNZ0pqZC1QWWRTM28/edit Global Initiatives Meetings]
 +
 
  
 
== Budgets ==
 
== Budgets ==
 
[https://www.owasp.org/index.php/Global_Committee_Pages Global Committee] Budgets - [https://www.owasp.org/index.php/Global_Committee_Budgets/2011 2011 Link]
 
[https://www.owasp.org/index.php/Global_Committee_Pages Global Committee] Budgets - [https://www.owasp.org/index.php/Global_Committee_Budgets/2011 2011 Link]
 +
 +
[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0AhI4iTO_QojvdFRTX1ZvUHU5U1N3WVRGNm56cDlOM1E#gid=0 2012 OWASP Foundation Budget]
 +
 +
[https://www.owasp.org/images/6/6d/2013_Budget_-_Final.pdf 2013 OWASP Foundation Budget]
 +
  
 
== Operational Procedures ==
 
== Operational Procedures ==
Line 181: Line 191:
  
 
[https://www.owasp.org/images/9/9b/2011_Tax_Return.pdf Click here to get a copy of our 2011 Tax Return].
 
[https://www.owasp.org/images/9/9b/2011_Tax_Return.pdf Click here to get a copy of our 2011 Tax Return].
 +
 +
[https://www.owasp.org/images/0/0d/OWASP_Foundation_990-2012.pdf Click here to get a copy of our 2012 Form 990 Tax Return] and [https://www.owasp.org/images/5/5f/OWASP_990T_2012.pdf 2012 990T]
  
  
Line 191: Line 203:
  
 
   OWASP Foundation
 
   OWASP Foundation
   9175 Guilford Road Suite #300
+
   1200-C Agora Drive, #232
   Columbia, MD 21046
+
   Bel Air, MD 21014
 
   US
 
   US
 +
  Operations - Kate Hartmann +1 301-275-9403
 
   443-283-4021(fax)
 
   443-283-4021(fax)
 
   [http://sl.owasp.org/contactus Contact Us]
 
   [http://sl.owasp.org/contactus Contact Us]
Line 204: Line 217:
 
   B-9660 Opbrakel
 
   B-9660 Opbrakel
 
   Belgium
 
   Belgium
 +
  Operations - Kate Hartmann +1 301-275-9403
 
   [http://sl.owasp.org/contactus Contact Us]
 
   [http://sl.owasp.org/contactus Contact Us]
  
 +
  OWASP Norway Chapter
 +
  [http://w2.brreg.no/enhet/sok/detalj.jsp?orgnr=994253085 Entity Record]
 +
  v/Kåre Presttun
 +
  c/o Mnemonic as
 +
  Wergelandsveien 25
 +
  0167 OSLO
 +
 +
 +
Want to chat on IRC?
 +
The official #owasp channel is now live on http://irc.freenode.net ! Come on in and chat with us!
  
  

Revision as of 12:28, 9 January 2014


Contents

The OWASP Foundation

The OWASP Foundation came online on December 1st 2001 it was established as a not-for-profit charitable organization in the United States on April 21, 2004 to ensure the ongoing availability and support for our work at OWASP. OWASP is an international organization and the OWASP Foundation supports OWASP efforts around the world. OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security. We advocate approaching application security as a people, process, and technology problem because the most effective approaches to application security include improvements in all of these areas. We can be found at www.owasp.org.

OWASP is a new kind of organization. Our freedom from commercial pressures allows us to provide unbiased, practical, cost-effective information about application security. OWASP is not affiliated with any technology company, although we support the informed use of commercial security technology. Similar to many open-source software projects, OWASP produces many types of materials in a collaborative, open way. The OWASP Foundation is a not-for-profit entity that ensures the project's long-term success.

Btn_cofollow_badge.png

OWASP Foundation ByLaws

The business of the OWASP Foundation Inc., outlined in the organizational by-laws. These by-laws govern the organization worldwide and allow the participants to understand the established process for doing so.

OWASP Foundation ByLaws

OWASP EU Foundation ByLaws (English Translation)

Local Chapter ByLaws

Core Values

OPEN Everything at OWASP is radically transparent from our finances to our code.

INNOVATION OWASP encourages and supports innovation/experiments for solutions to software security challenges.

GLOBAL Anyone around the world is encouraged to participate in the OWASP community.

INTEGRITY OWASP is an honest and truthful, vendor neutral, global community.

Core Purpose

Be the thriving global community that drives visibility and evolution in the safety and security of the world’s software.

Code of Ethics

Each of us is expected to behave according to the principles contained in the following Code of Ethics. Breaches of the Code of Ethics may result in the foundation taking disciplinary action. Membership Revocation

  • Perform all professional activities and duties in accordance with all applicable laws and the highest ethical principles;
  • Promote the implementation of and promote compliance with standards, procedures, controls for application security;
  • Maintain appropriate confidentiality of proprietary or otherwise sensitive information encountered in the course of professional activities;
  • Discharge professional responsibilities with diligence and honesty;
  • To communicate openly and honestly;
  • Refrain from any activities which might constitute a conflict of interest or otherwise damage the reputation of employers, the information security profession, or the Association;
  • To maintain and affirm our objectivity and independence;
  • To reject inappropriate pressure from industry or others;
  • Not intentionally injure or impugn the professional reputation of practice of colleagues, clients, or employers;
  • Treat everyone with respect and dignity; and
  • To avoid relationships that impair — or may appear to impair — OWASP's objectivity and independence.

Principles

  • Free & Open
  • Governed by rough consensus & running code
  • Abide by a code of ethics (see ethics)
  • Not-for-profit
  • Not driven by commercial interests
  • Risk based approach

2014 Global Board Members

Michael Coates - OWASP Chair - San Fransisco, CA USA
michael.coates(at)owasp.org

Tom Brennan - Vice Chair - New Jersey, USA
tom.brennan(at)owasp.org

Josh Sokol - Treasurer - Texas, USA
josh.sokol(at)owasp.org

Tobias Gondrom - Secretary - Hong Kong
tobias.gondrom(at)owasp.org

Fabio Cerullo - Special Projects: Ireland
fcerullo(at)owasp.org

Eoin Keary - Special Projects: Dublin, Ireland
eoin(at)owasp.org

Jim Manico - Special Projects: Hawaii, USA
jim.manico(at)owasp.org

Employees of the OWASP Foundation

Sarah Baso Sarah's Role w/OWASP
OWASP Executive Director
Contact Me

Kate Hartmann - Kate's Role w/OWASP
OWASP Operations Director
Contact Me

Kelly Santalucia Kelly's Role w/OWASP
OWASP Membership & Business Liaison
Contact Me

Samantha Groves Samantha's Role w/OWASP
OWASP Project Manager
Contact Me

Alison Shrader - Alison's Role w/OWASP
OWASP Accounting
Contact Me

Matt Tesauro IT Administrator Role
IT Administrator
Contact Me

Laura Grau
OWASP Event Manager
Contact Me


Meeting Minutes

The OWASP Foundation Board meets monthly.

Board meeting minutes for the record.

Staff Meetings

Global Initiatives Meetings


Budgets

Global Committee Budgets - 2011 Link

2012 OWASP Foundation Budget

2013 OWASP Foundation Budget


Operational Procedures

Standard Operations Procedures (SOP)


Licensing

All OWASP materials are available under an approved FLOSS license. For more information, please see the OWASP Licenses page.

Participation and Membership

Everyone is welcome to participate in our forums, projects, chapters, and conferences. OWASP is a fantastic place to learn about application security, to network, and even to build your reputation as an expert.

If you find the OWASP materials valuable, please consider supporting our cause by becoming an OWASP member. All monies received by the OWASP Foundation go directly into supporting OWASP projects.

For more information, please see the Membership page.

Projects

OWASP's projects cover many aspects of application security. We build documents, tools, teaching environments, guidelines, checklists, and other materials to help organizations improve their capability to produce secure code.

For details on all the OWASP projects, please see the OWASP Project page.

Privacy Policy

Given OWASP’s mission to help organizations with application security, you have the right to expect protection of any personal information that we might collect about our members.

In general, we do not require authentication or ask visitors to reveal personal information when visiting our website. We collect Internet addresses, not the e-mail addresses, of visitors solely for use in calculating various website statistics.

We may ask for certain personal information, including name and email address from persons downloading OWASP products. This information is not divulged to any third party and is used only for the purposes of:

  • Communicating urgent fixes in the OWASP Materials
  • Seeking advice and feedback about OWASP Materials
  • Inviting participation in OWASP’s consensus process and AppSec conferences

OWASP publishes a list of member organizations and individual members. Listing is purely voluntary and "opt-in." Listed members can request not to be listed at any time.

All information about you or your organization that you send us by fax or mail is physically protected. If you have any questions or concerns about our privacy policy, please contact us at Submit a Inquiry

Tax Deductability of Payments to OWASP

OWASP membership fees, OWASP conferences fees, OWASP conference sponsorships, and OWASP banner ads are not considered tax-deductible donations due to the benefits the paying organization/individual receives.

Direct donations to OWASP are fully tax-deductible given OWASP's recognized U.S. not-for-profit status.

OWASP's U.S. Employer Identification Number (EIN) is: 20-0963503.

Membership or Donations

If you are interested in joining OWASP as a member, or donating funds for OWASP's efforts, please check out the OWASP Membership Page.

Tax Filings

Click here to get a copy of our 2005 Tax Return.

Click here to get a copy of our 2006 Tax Return.

Click here to get a copy of our 2007 Tax Return and Audit Report.

Click here to get a copy of our 2008 Tax Return.

Click here to get a copy of our 2009 Tax Return.

Click here to get a copy of our 2010 Tax Return and Audit Report.

Click here to get a copy of our 2011 Tax Return.

Click here to get a copy of our 2012 Form 990 Tax Return and 2012 990T



Contacting OWASP

The easiest way to contact the OWASP Foundation is via e-mail. If you have a question concerning a particular project, we strongly recommend using the mailing list for that project. Many questions can also be answered by searching the OWASP web site, so please check there first!

Our global address for general correspondence and faxes can be sent to our physical office address, to the attention of Kate Hartmann, at:

 OWASP Foundation
 1200-C Agora Drive, #232
 Bel Air, MD 21014
 US
  Operations - Kate Hartmann +1 301-275-9403
 443-283-4021(fax)
 Contact Us

The European correspondence address is below. More information is available on the OWASP Europe page.

 OWASP Europe VZW
 Leinstraat 104A
 B-9660 Opbrakel
 Belgium
 Operations - Kate Hartmann +1 301-275-9403
 Contact Us
 OWASP Norway Chapter
 Entity Record
 v/Kåre Presttun
 c/o Mnemonic as
 Wergelandsveien 25
 0167 OSLO


Want to chat on IRC? The official #owasp channel is now live on http://irc.freenode.net ! Come on in and chat with us!

For more information, please see the pages listed below: