Thanks as always for the insightful input, Jeff! A lot of this I definitely agree with, and other excellent discussion points as well. Of course projects are a huge part of OWASP - but also not the only part, e.g. chapters, education, guidance, etc. Lots to talk about!
1
2
Chapters are great. Education and guidance are projects….unless you mean paid training (which I’m suggesting doesn’t match well with OWASP values or mission). I want an OWASP that is squarely focused on ideas that have a chance to change the trajectory of app/API security.
1
Thanks Jeff. Your two suggestions, boost fundraising and recruit new projects, fall into two committees, Funding (new) and Projects. Maybe you can bring your ideas and join one or both of those committees?
1
My suggestions can’t be implemented by committees. These are board level strategic decisions about the way OWASP works.
1
3
Are these strategic decisions a motion we pass? Or something else?
1
1
If I was on the board, I’d want a 3 year strategic plan detailing how OWASP achieves the mission and thrives. It’s not about the formalities. The board should be thinking, writing, asking, arguing, synthesizing, analyzing, creating….and ultimately agreeing and committing.
1
1
We just finished our strategic meetings where we did just that. Not a 3-year plan, but rather a reorganization around our core services. Write-ups are coming in the near future about the outcome.
1
2
Does the new structure include an experienced fundraising team?
1
1
To be determined by the new funding committee. We discussed getting an experienced grant writer.
1
1
Honestly it sounds like business as usual. I hope the board is hearing the pleas for real change from folks that care. Again, thanks for all you and the board do.
2
2
We’ve received zero proposals for change, other than Mark Curphey’s to adopt the Linux Foundation model. If you have a specific change in mind, please forward it to the board. Identifying problems isn’t nearly as helpful as concrete proposals and active volunteering.

Sep 18, 2023 · 1:56 AM UTC

1
2
I understand what you’re saying… but I don’t think you should expect people to send you proposals for how to run OWASP. Please correct me if you think differently, but I created the OWASP Board and was Chair for the first 10 years… andI think it’s your job to figure out.
1
1
Got it, thank you for your suggestions.
1