This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Project Manager Activity Reports/September 10 2012"

From OWASP
Jump to: navigation, search
 
(10 intermediate revisions by the same user not shown)
Line 1: Line 1:
 
== OWASP Project Manager Report ==
 
== OWASP Project Manager Report ==
==== Work accomplished since July 30, 2012 ====
+
==== Work accomplished since August 13, 2012 ====
===== DHS Funding Proposal =====
+
*'''Projects Set Up'''
*We had two [https://docs.google.com/a/owasp.org/document/d/1MA3TI5ssclxvheV8At_ffu2Fuic55SDpOokS3AOvBUc/edit#bookmark=id.ceef3790c8d6 DHS Host Project Funding proposal] meetings this month. The first meeting was with the OWASP Guide project leads. Andrew van der Stock, Eoin Keary and I addressed queries and concerns that were brought to our attention by Deborah from the Home Office. The second meeting was held between Kate Harmann, Debroah Bryant and myself. We discussed her concerns in more detail, and Deborah agreed to get back to us with a more detailed explanation of additional information she requires from us. We are still waiting to hear back from her at this time. Thank you to [[User:Kate Hartmann|Kate Hartmann]], Andrew van der Stock, Matteo Meucci, and Eoin Keary for all of their hard work on this project. We hope to hear from Deb sometime this week. The proposal is for $25,000 USD.
+
**[[OWASP XSSER|OWASP XSSER]]  
===== Projects Set Up =====
+
**[[OWASP ONYX|OWASP ONYX]]  
*[[OWASP Top 10 Defences|OWASP Top 10 Defences]]
+
**[[OWASP Crossword of the Month|OWASP Crossword of the Month]]
*[[OWASP OpenESSS Project|OWASP OpenESSS Project]]
+
 
*[[OWASP Java J2EE Secure Development Curriculum|OWASP Java J2EE Secure Development Curriculum]]
+
*'''Projects Confirmed'''
*[[OWASP AW00T|OWASP AW00T]]
+
**[[OWASP Review BSI IT-Grundschutz Baustein Webanwendungen|OWASP Review BSI IT-Grundschutz Baustein Webanwendungen]]  
*[[OWASP Passfault|OWASP Passfault]]
+
**[[OWASP XSSER|OWASP XSSER]]  
*[[OWASP OctoMS|OWASP OctoMS]]
+
 
*[[OWASP OWTF|OWASP OWTF]]
+
*'''Pending Project Confirmations'''
*[[OWASP Java Uncertain Form Submit Prevention|OWASP Java Uncertain Form Submit Prevention]]
+
**Forensic Guide: Waiting to hear back from the Project Leader.
*[[OWASP Ecuador|OWASP Ecuador]]
+
**Xelenium: Waiting to hear back from the Project Leader.
*[[OWASP Path Traverser|OWASP Path Traverser]]
+
**Intelligent Security: Waiting to hear back from the Project Leader.
*[[OWASP Watiqay|OWASP Watiqay]]
+
**Testing the Web Project
*[[OWASP Mantra OS|OWASP Mantra OS]]
+
 
*[[OWASP Security Shepherd|OWASP Security Shepherd]]
+
*'''Pending Project Donations'''
*[[OWASP Xenotix XSS Exploit Framework|OWASP Xenotix XSS Exploit Framework]]
+
**[[OWASP XSSER|OWASP XSSER]]
===== Project Set Up Confirmations =====
+
**OWASP XSS Cheat Sheet
*[[OWASP File Hash Repository|OWASP File Hash Repository]]
+
 
*[[:Category:OWASP WebGoat.NET|OWASP WebGoat.NET]]
+
*'''Pending New Project Leader Appointment'''
*[[OWASP AJAX Crawling Tool|OWASP AJAX Crawling Tool]]
+
**[[OWASP Stinger project|OWASP Stinger project]]
*[[OWASP Odz MultiCMSScanner Project|OWASP Odz MultiCMSScanner Project]]
+
 
===== Pending Project Applications =====
+
 
*XSSER: Waiting to hear back from Project Leader. Will not confirm his identity.
+
==Currently Working On==
*OWASP BSI IT-Grundschutz Baustein Webanwendungen Review: Waiting to hear back from the Project Leader.
+
*'''Projects Communications Restructuring'''
*Forensic Guide: Waiting to hear back from the Project Leader.
+
**I have begun to create the wiki template for the new OWASP Projects page.  
*Xelenium: Waiting to hear back from the Project Leader.
+
**I am having a bit of trouble with the tabs, but I am getting help from volunteers on how to do this.
*Intelligent Security: Waiting to hear back from the Project Leader.
+
 
===== Other Issues =====
+
*'''Daily Project based queries and requests'''
*Updated Creating Project wiki page, studied Project handbook and Project Assessment Criteria
+
**Answering daily project related queries from OWASP Project Leaders and Members
*Had a very successful on-boarding process. I was very quickly set up with all the necessary accounts, and went through training with [[User:Kate Hartmann|Kate Hartmann]] on the project management work flow for OWASP project set-ups.
+
**Corresponding with project applicants on the status of their applications
*Naming issue: If a project applicant refuses to give me his/her real name, should I set up the project any way? Would this violate the OWASP Core Value of Transparency?
+
**I've kept the following OWASP Project databases up-to-date:
=====Day-to-Day Tasks =====
+
*** [https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0Amvv_7Gz8Z7TdHZfWGhHZ0Z4UFFwZU42djBXcVVLSlE#gid=0 Incubator Project Applications].
*Answering daily project related queries from OWASP Project Leaders and Members
+
*** [https://spreadsheets0.google.com/a/owasp.org/spreadsheet/ccc?pli=1&key=tF9r45eprbpdY6xuSbwEuMw#gid=0 OWASP Project Inventory].
*Corresponding with project applicants on the status of their applications
+
 
*Setting up projects that meet the 'Sanity Test' on the Incubator Project Applications document (IPA)
+
*'''[https://docs.google.com/a/owasp.org/document/d/1xek9eZqAAt-koEuhOcXE9PoVCsAZ1WZJJoLzVMVj2Ew/edit AppSec USA OSS]'''
*Confirming set up and status of projects on IPA document that seem to already be set up
+
**We rolled out the marketing for this recently, and we have received 6 entries.
*Creating mailing lists and roadmap pages for projects that are missing this on their wiki pages
+
**As of today, all 6 entries have been accepted.
*I've kept the following OWASP Project databases up-to-date for the past two weeks:
+
**I am drafting acceptance letters with information on what comes next for the attendees.These will be sent out next week. We are now sorting logistics for the accepted project leaders.
** [https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0Amvv_7Gz8Z7TdHZfWGhHZ0Z4UFFwZU42djBXcVVLSlE#gid=0 Incubator Project Applications].
+
**There is the question of travel aid for some of the project leaders. I suggest we set aside $3,000 for those PLs that ask for financial assistance to get to AppSec USA.
** [https://spreadsheets0.google.com/a/owasp.org/spreadsheet/ccc?pli=1&key=tF9r45eprbpdY6xuSbwEuMw#gid=0 OWASP Project Inventory].
+
 
==== Proposal of future activity ====
+
*'''[https://docs.google.com/a/owasp.org/document/d/13jWO7jFfe9NUVlGIddZRrnLA8G5IOTNPjogb61lbbB0/edit OWASP ZAP Project Marketing Recommendations]'''
*Continue answering all project related questions
+
**The marketing recommendations have been agreed on by Simon and I.
*Continue setting up new projects as they come in
+
**I am currently putting together the projects plan to implement them.
*Continue to implement all GPC requests:
+
 
**Meet with the Committee to discuss project lifecycle, project processes and Project Reboot
+
*'''[https://docs.google.com/a/owasp.org/document/d/1MA3TI5ssclxvheV8At_ffu2Fuic55SDpOokS3AOvBUc/edit#bookmark=id.ceef3790c8d6 DHS Host Project Funding Proposal]'''
**Build and implement marketing standards and offerings for OWASP Projects
+
**Andrew, Matteo, Eoin and I met to speak about this in more depth. Deborah, the home office representative, had some concerns about PM software and travel expenses in the budget.
**Continue managing Project databases and keeping them up-to-date
+
**She would like to know if we are able to re-allocate the PM software and travel expenses to the OWASP portion of the budget. This meeting clarified many of the questions I had about Deborah's concerns.
*Manage the current 200+ OWASP projects  
+
**The PM software is available as open source to open source projects, and we have applied for a license already. The travel expenses can now come from the OWASP section of the budget.
*Research more project funding possibilities
+
**Kate, Deborah and I participated in an interview where we discussed DHS concerns. See above. The interview went very well, and we are currently waiting to hear back from her.
 +
**Meeting Outcome: She was going to send us specific instructions on what she needed from us regarding the budget, and she is going to send us an updated proposal form so we can start applying for 2 other OWASP projects she expressed an interest in.
 +
**Deborah has gotten back to us with instructions and I am in the process of amending our budget proposal for her to meet DHS standards.
 +
 
 +
*'''[https://docs.google.com/a/owasp.org/document/d/1f83ShmjwLpmybSVJIBhEXDxTrKuNcIPO3ok0ubAs4t8/edit Atlassian Open Source License]'''
 +
**Andrew and I worked together on this application.
 +
**The Atlassian representative has gotten back to us and the company has decided that a community license would be better for this project. We are in the process of writing an application for the new license recommendation.
 +
 
 +
 
 +
==Projects Communication Structure Development Update==
 +
# We agreed to organize our projects communication through the use of Tabs in the OWASP Projects section of the wiki. I am currently developing the tabs structure on my local machine.
 +
# We agreed that all of the projects documentation must either be updated or created and organized in the correct locations on the wiki. I am currently organizing the documentation.
 +
 
 +
 
 +
==AppSec Ireland==
 +
# Have been in Dublin, Ireland for AppSec Ireland: From Monday, September 03 - Thursday, September 06.
 +
# Went to help out with the conference and familiarize myself with the way AppSec events are run.
 +
# Sat in on a full day training with Jim Manico: Thank you Jim.
 +
# Helped coordinate the printing and delivery of OWASP branded items.
 +
# Helped manage the registration and information desk.
 +
 
 +
 
 +
==Important GPC Meeting Outcomes and Discussion Points==
 +
# We will have weekly meetings to discuss updates on projects issues. The next meeting will be held on Friday, September 14th 2012 at 2pm BST.
 +
# Jason Li has expressed concern over his minimal availability to represent the GPC as Chair of the Committee.
 +
# Discussion on the availability of all members.
 +
# Larry Casey has resigned his post on the GPC.
 +
# Welcome Nishi Kumar, our newest member!

Latest revision as of 15:58, 10 September 2012

OWASP Project Manager Report

Work accomplished since August 13, 2012

  • Pending Project Confirmations
    • Forensic Guide: Waiting to hear back from the Project Leader.
    • Xelenium: Waiting to hear back from the Project Leader.
    • Intelligent Security: Waiting to hear back from the Project Leader.
    • Testing the Web Project
  • Pending Project Donations


Currently Working On

  • Projects Communications Restructuring
    • I have begun to create the wiki template for the new OWASP Projects page.
    • I am having a bit of trouble with the tabs, but I am getting help from volunteers on how to do this.
  • Daily Project based queries and requests
    • Answering daily project related queries from OWASP Project Leaders and Members
    • Corresponding with project applicants on the status of their applications
    • I've kept the following OWASP Project databases up-to-date:
  • AppSec USA OSS
    • We rolled out the marketing for this recently, and we have received 6 entries.
    • As of today, all 6 entries have been accepted.
    • I am drafting acceptance letters with information on what comes next for the attendees.These will be sent out next week. We are now sorting logistics for the accepted project leaders.
    • There is the question of travel aid for some of the project leaders. I suggest we set aside $3,000 for those PLs that ask for financial assistance to get to AppSec USA.
  • DHS Host Project Funding Proposal
    • Andrew, Matteo, Eoin and I met to speak about this in more depth. Deborah, the home office representative, had some concerns about PM software and travel expenses in the budget.
    • She would like to know if we are able to re-allocate the PM software and travel expenses to the OWASP portion of the budget. This meeting clarified many of the questions I had about Deborah's concerns.
    • The PM software is available as open source to open source projects, and we have applied for a license already. The travel expenses can now come from the OWASP section of the budget.
    • Kate, Deborah and I participated in an interview where we discussed DHS concerns. See above. The interview went very well, and we are currently waiting to hear back from her.
    • Meeting Outcome: She was going to send us specific instructions on what she needed from us regarding the budget, and she is going to send us an updated proposal form so we can start applying for 2 other OWASP projects she expressed an interest in.
    • Deborah has gotten back to us with instructions and I am in the process of amending our budget proposal for her to meet DHS standards.
  • Atlassian Open Source License
    • Andrew and I worked together on this application.
    • The Atlassian representative has gotten back to us and the company has decided that a community license would be better for this project. We are in the process of writing an application for the new license recommendation.


Projects Communication Structure Development Update

  1. We agreed to organize our projects communication through the use of Tabs in the OWASP Projects section of the wiki. I am currently developing the tabs structure on my local machine.
  2. We agreed that all of the projects documentation must either be updated or created and organized in the correct locations on the wiki. I am currently organizing the documentation.


AppSec Ireland

  1. Have been in Dublin, Ireland for AppSec Ireland: From Monday, September 03 - Thursday, September 06.
  2. Went to help out with the conference and familiarize myself with the way AppSec events are run.
  3. Sat in on a full day training with Jim Manico: Thank you Jim.
  4. Helped coordinate the printing and delivery of OWASP branded items.
  5. Helped manage the registration and information desk.


Important GPC Meeting Outcomes and Discussion Points

  1. We will have weekly meetings to discuss updates on projects issues. The next meeting will be held on Friday, September 14th 2012 at 2pm BST.
  2. Jason Li has expressed concern over his minimal availability to represent the GPC as Chair of the Committee.
  3. Discussion on the availability of all members.
  4. Larry Casey has resigned his post on the GPC.
  5. Welcome Nishi Kumar, our newest member!