About The Open Web Application Security Project
- 1 The OWASP Foundation
- 2 OWASP Governance
- 3 Citations
- 4 Core Values
- 5 Core Purpose
- 6 Code of Ethics
- 7 Principles
- 8 Tax Status: 501(c)(3) Not-For-Profit Organization
- 9 Tax Status: OWASP Europe
- 10 OWASP Mascot
- 11 Tax Deductability of Payments to OWASP
- 12 Membership or Donations
- 13 Contacting OWASP
- 14 Global Board Members
- 15 Board Meeting Minutes
- 16 W2 Employees of the OWASP Foundation
- 17 1099 Contractors
- 18 Operational Procedures
- 19 Volunteer Support
- 20 Licensing
- 21 Participation and Membership
- 22 Projects
- 24 Tax Filings
- 25 Budgets
The OWASP Foundation
The OWASP Foundation came online on December 1st 2001 it was established as a not-for-profit charitable organization in the United States on April 21, 2004 to ensure the ongoing availability and support for our work at OWASP. OWASP is an international organization and the OWASP Foundation supports OWASP efforts around the world. OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security. We advocate approaching application security as a people, process, and technology problem because the most effective approaches to application security include improvements in all of these areas. We can be found at www.owasp.org.
OWASP is a new kind of organization. Our freedom from commercial pressures allows us to provide unbiased, practical, cost-effective information about application security. OWASP is not affiliated with any technology company, although we support the informed use of commercial security technology. Similar to many open-source software projects, OWASP produces many types of materials in a collaborative, open way. The OWASP Foundation is a not-for-profit entity that ensures the project's long-term success.
OWASP and its materials are used, recommended and referenced by many government, standards and industry organisations. We maintain a list of some of the more important citations on the Industry:Citations page.
OPEN Everything at OWASP is radically transparent from our finances to our code.
INNOVATION OWASP encourages and supports innovation/experiments for solutions to software security challenges.
GLOBAL Anyone around the world is encouraged to participate in the OWASP community.
INTEGRITY OWASP is an honest and truthful, vendor agnostic, global community.
Be the thriving global community that drives visibility and evolution in the safety and security of the world’s software.
Code of Ethics
Each of us is expected to behave according to the principles contained in the following Code of Ethics. Breaches of the Code of Ethics may result in the foundation taking disciplinary action.
- Perform all professional activities and duties in accordance with all applicable laws and the highest ethical principles;
- Promote the implementation of and promote compliance with standards, procedures, controls for application security;
- Maintain appropriate confidentiality of proprietary or otherwise sensitive information encountered in the course of professional activities;
- Discharge professional responsibilities with diligence and honesty;
- To communicate openly and honestly;
- Refrain from any activities which might constitute a conflict of interest or otherwise damage the reputation of employers, the information security profession, or the Association;
- To maintain and affirm our objectivity and independence;
- To reject inappropriate pressure from industry or others;
- Not intentionally injure or impugn the professional reputation of practice of colleagues, clients, or employers;
- Treat everyone with respect and dignity; and
- To avoid relationships that impair — or may appear to impair — OWASP's objectivity and independence.
- Free & Open
- Governed by rough consensus & running code
- Abide by a code of ethics (see ethics)
- Not driven by commercial interests
- Risk based approach
Tax Status: 501(c)(3) Not-For-Profit Organization
The OWASP Foundation is a U.S. recognized 501(c)(3) not-for-profit charitable organization. The OWASP Foundation received its formal recognition by the U.S. government of its 501(c)(3) status on December 10, 2004. This not-for-profit status allows contributors to deduct any donations made to the OWASP Foundation.
Tax Status: OWASP Europe
OWASP Europe VZW Leinstraat 104A 9660 Opbrakel Belgium
VAT number: BE.0836.743.279
Tax Deductability of Payments to OWASP
OWASP membership fees, OWASP conferences fees, OWASP conference sponsorships, and OWASP banner ads are not considered tax-deductible donations due to the benefits the paying organization/individual receives.
Direct donations to OWASP are fully tax-deductible given OWASP's recognized U.S. not-for-profit status.
OWASP's U.S. Employer Identification Number (EIN) is: 20-0963503.
Membership or Donations
If you are interested in joining OWASP as a member, or donating funds for OWASP's efforts, please check out the OWASP Membership Page.
The easiest way to contact the OWASP Foundation is via e-mail. If you have a question concerning a particular project, we strongly recommend using the mailing list for that project. Many questions can also be answered by searching the OWASP web site, so please check there first!
Our address for general correspondence and faxes can be sent to our physical office address, to the attention of Kate Hartmann, at:
OWASP Foundation 9175 Guilford Road Suite #300 Columbia, MD 21046 301-604-8033 (fax) Submit a Inquiry
Global Board Members
Michael Coates - Elected Board Member 2011 - Current
Sebastien Deleersnyder - Elected Board Member 2007 - Current
Dave Wichers - Elected Board Member 2004 - Current
Matt Tesauro - Elected Board Member 2010 - Current
Eoin Keary - Elected Board Member 2010 - Current
Tom Brennan - Board Member 2008 - Current
Jeff Williams - Board Member and Chair 2004 - 2011
Board Meeting Minutes
Global Committee Structure
OWASP recognized the extraordinary contribution of our most active leaders by engaging them to lead a set of six new committees. Each democratically established committee will focus on a key function or geographic region, such as OWASP projects, conferences, local chapters, membership and industry outreach.
|OWASP GLOBAL COMMITTEES (OWASP GC)|
|Education||Chapters||Conferences||Industry||Projects & Tools||Membership|
W2 Employees of the OWASP Foundation
Kelly Santalucia Kelly's Role w/OWASP
OWASP Membership Committee
Participation and Membership
Everyone is welcome to participate in our forums, projects, chapters, and conferences. OWASP is a fantastic place to learn about application security, to network, and even to build your reputation as an expert.
If you find the OWASP materials valuable, please consider supporting our cause by becoming an OWASP member. All monies received by the OWASP Foundation go directly into supporting OWASP projects.
For more information, please see the Membership page.
OWASP's projects cover many aspects of application security. We build documents, tools, teaching environments, guidelines, checklists, and other materials to help organizations improve their capability to produce secure code.
For details on all the OWASP projects, please see the OWASP Project page.
Given OWASP’s mission to help organizations with application security, you have the right to expect protection of any personal information that we might collect about our members.
In general, we do not require authentication or ask visitors to reveal personal information when visiting our website. We collect Internet addresses, not the e-mail addresses, of visitors solely for use in calculating various website statistics.
We may ask for certain personal information, including name and email address from persons downloading OWASP products. This information is not divulged to any third party and is used only for the purposes of:
- Communicating urgent fixes in the OWASP Materials
- Seeking advice and feedback about OWASP Materials
- Inviting participation in OWASP’s consensus process and AppSec conferences
OWASP publishes a list of member organizations and individual members. Listing is purely voluntary and "opt-in." Listed members can request not to be listed at any time.
For more information, please see the pages listed below:
- Contributions for details about how to make contributions
- Advertising if you're interested in advertising on the OWASP site
- How OWASP Works for more information about projects and governance
- OWASP brand usage rules for information about using the OWASP brand