This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Project Manager Activity Reports/November 12 2012"

From OWASP
Jump to: navigation, search
(Created page with "== OWASP Project Manager Report == ==== Work accomplished since October 08, 2012 ==== *'''Project Numbers''' **Active Projects: 113 **Archived Projects: 41 **Graveyard Proje...")
 
 
(6 intermediate revisions by the same user not shown)
Line 3: Line 3:
  
 
*'''Project Numbers'''
 
*'''Project Numbers'''
**Active Projects: 113
+
**Active Projects: 114
 
**Archived Projects: 41
 
**Archived Projects: 41
**Graveyard Projects: 24
+
**Merged Projects: 43  
**Merged Projects: 43
 
  
*'''Pending Project Donations''': We are still working on creating a Project Donation Contract.
+
*'''New Projects''':
**[[OWASP XSSER|OWASP XSSER]]
+
**[https://www.owasp.org/index.php/Projects/OWASP_Periodic_Table_of_Vulnerabilities OWASP Periodic Table of Vulnerabilities]  
**OWASP XSS Cheat Sheet
 
**[[OWASP Security Shepherd|OWASP Security Shepherd]]
 
  
*'''Pending New Project Leader Appointment'''
+
*'''Pending Incubator Project Applications'''
**[[OWASP Stinger project|OWASP Stinger project]]: This project is currently being transfered. The new project leader has been appointed.
+
**OWASP Application Security Awareness Top 10 E-Learning Project (Set up this week)
 +
**OWASP JSON Sanitizer (Set up this week)
 +
 
 +
==Project Manager Q4 Objectives==
 +
#Identify and initiate 3 grant opportunities.
 +
#Complete metadata for Salesforce import related to projects.
 +
#Finalize and launch the Project database communication tool and webpage.
 +
#Complete the project lifecycle redesign.  
 +
#Complete Version 2 of the Project Handbook.
  
 
==Currently Working On==
 
==Currently Working On==
*'''Project Manager Q4 Objectives'''
+
*'''Grant Opportunities Updates'''
**Identify and initiate 3 grant opportunities.
+
**The ESAPI proposal is done and submitted: Thank you Chris Schmidt and Kevin Wall for helping to finalising the document.
**Complete metadata for Salesforce import related to projects.
+
**Deborah, the DHS representative, has confirmed.
**Finalize and launch the Project database communication tool and webpage.
+
**Submission was held up due to some budget questions raised by Kevin and Chris.
**Complete the project lifecycle redesign.  
+
**We re-evaluated the budget and made some changes.
**Complete Version 2 of the Project Handbook.
+
**This is for $25,000 from the DHS.
 
+
**The Google Grant process is a little trickier than expected
*'''[https://www.owasp.org/index.php/Test2test Projects Communications Restructuring]'''
+
**Nevertheless, I am moving forward with the application with help from a Google for Non-Profits representative.
**I have created a tabs based wiki page for OWASP Projects.
+
**I hope to complete the application by this week, if all goes well.
**The aim is to migrate to this after Q4.
+
**I've already started the process for the OWASP ModSecurity Proposal as well.
**I continue to update this every week with the relevant data.
+
**Ryan has responded to my query regarding funding, and he is interested in pursuing the proposal.
**[https://docs.google.com/a/owasp.org/document/d/1dN-6GrwN-FB3Im0Ggj5dlVmxZNLs0IUigQegP1eSd8Q/edit# Projects Implementation Plan]
+
**I am putting together a reply with information on proposal procedure and budget requirements to send Ryan.
  
 
*'''SalesForce Metadata Migration'''
 
*'''SalesForce Metadata Migration'''
**Currently collecting information for all of our projects to put into SalesForce.  
+
**All project data is now in Salesforce.
**Working on gathering Active Project's data.
+
**I continue to work with Kate to finish the migration.
 +
**We are currently working on creating a template e-mail to send to all active project leaders asking them to update their information.  (Still seeking help for this)
 +
**Developed 8 forms to help with future requests: You can find them in the [https://docs.google.com/a/owasp.org/document/d/15lPNSxokO5ogGxWo-xvLNYh0C3c8-nWjgWnRfTfm0OU/edit Project Processes Document: Section I].
 +
**Currently looking into developing the forms in Salesforce, and updating the active project information directly from Project Leaders.
  
*'''Daily Project based queries and requests'''
+
*'''[https://www.owasp.org/index.php/Test2test Projects Communications Restructuring]'''
**This has not changed much since I began the post: questions are very similar in nature.  
+
**The aim is to make this page live in January 2013.
**AppSec USA 2012 queries
+
**I continue to update this with the relevant data.
**Travel queries
+
**Working on developing the project handbook, finalising project stage benefits, and finalising project graduation process before finalising updates to this page. 
**Budget based questions
 
**Funding questions
 
**Project based administrative help
 
**Project status information
 
** Information request from outside the community regarding projects
 
  
*'''[https://docs.google.com/a/owasp.org/document/d/1MA3TI5ssclxvheV8At_ffu2Fuic55SDpOokS3AOvBUc/edit#bookmark=id.ceef3790c8d6 DHS Host Project Funding Proposal]'''
+
*'''[https://docs.google.com/a/owasp.org/document/d/15lPNSxokO5ogGxWo-xvLNYh0C3c8-nWjgWnRfTfm0OU/edit Project Processes & Lifecycle Development]'''
**Our Proposal was accepted, and we have been awarded $25k for the Guidebook Projects.
+
**Putting the handbook aside until these are fleshed out and agreed to.
**Deborah has sent us the agreement letter, and I have agreed to the terms.
+
**I feel it is a much better idea to tackle individually, and them add them to the handbook.  
**We are currently waiting to hear back from Deborah regarding funds transfer.
+
**Process form development
**They need a more detailed project plan from us so I am currently putting that together for OWASP and DHS.
+
**Project Stage Benefits
 
+
**Project Graduation Process
*'''[https://docs.google.com/a/owasp.org/document/d/1xek9eZqAAt-koEuhOcXE9PoVCsAZ1WZJJoLzVMVj2Ew/edit AppSec USA OSS]'''
+
**Project Graduation Criteria
**All 6 attendees have confirmed.
+
**Project Migration Process
**Greg has agreed to our terms: We pay for his airfare if he agrees to participate as a volunteer at the conference.
 
**Travel requirements for Kostas have changed. He is still going to participate in the OSS, but now his airfare and hotel expenses will be paid by the OWASP Track Fund as he is now a speaker.
 
**[https://docs.google.com/a/owasp.org/document/d/1urkb-k3zHCfcS_8TLFgQaEv95Yr6gNXmLElDFHeEgM4/edit Presentation Schedule]
 
 
 
*'''[https://docs.google.com/a/owasp.org/document/d/1f83ShmjwLpmybSVJIBhEXDxTrKuNcIPO3ok0ubAs4t8/edit Atlassian Open Source License]'''
 
**Andrew and I worked together on this application.
 
**We created a new proposal for the community license.
 
**Our proposal has been accepted, and we are now able to use the software.
 
  
 
*'''[https://docs.google.com/a/owasp.org/document/d/1ilLGVEM4zWiPgMPDRHe8ARdeLSnoBTUtMq0C-Ta45tc/edit?authkey=CLTW_MUO&authkey=CLTW_MUO Projects Handbook]'''
 
*'''[https://docs.google.com/a/owasp.org/document/d/1ilLGVEM4zWiPgMPDRHe8ARdeLSnoBTUtMq0C-Ta45tc/edit?authkey=CLTW_MUO&authkey=CLTW_MUO Projects Handbook]'''
 
**GPC and I have been working on completing the OWASP Projects Handbook.
 
**GPC and I have been working on completing the OWASP Projects Handbook.
 
**Currently in the middle of developing a second version of the Handbook that is more relevant to the current state of OWASP Projects.
 
**Currently in the middle of developing a second version of the Handbook that is more relevant to the current state of OWASP Projects.
**Emphasis on simplification of processes and creating a solid framework that we can later build on if needed.
+
**Emphasis on simplification of processes and creating a solid framework that we can later build on if needed.  
 
+
**Much of the handbook has been edited and discussed.
==More Funding Potential==
+
**Areas that are still under development can be found in the Project Processes & Lifecycle Development section of this report.  
#[https://docs.google.com/a/owasp.org/document/d/16ZFXaML8C7aDAZdyTMDDg4BzLr1vUTOz9eqmYE8ZW8U/edit OWASP ESAPI FUNDING PROPOSAL]
 
#DHS has expressed interest in funding the OWASP ESAPI Project.
 
#We have started by creating a new proposal questionnaire document.
 
#Chris Schmidt, ESAPI Project Leader, and I have a meeting scheduled this week to discuss this proposal.  
 
  
 
==Important GPC Meeting Outcomes and Discussion Points==
 
==Important GPC Meeting Outcomes and Discussion Points==
*High Priority Objectives for Handbook:  
+
#[https://www.owasp.org/index.php/GPC/Meetings/2012-09-11 GPC Report: November 09, 2012]
**Migration to Incubator, Labs, Flagship system.
+
#Samantha: Continue to attempt to contact the SourceForge account people, and attempt to schedule a meeting with them.
**Sorting out reviews/reviewer process
+
#There has been no communication back from SourceForge people. We have decided to close the account so they will not continue to charge us. Samantha will move forward with this plan.
**Focus on simplification of processes
+
#Samantha: Develop a communications piece letting the community know why the account with SourceForge was closed.
*Samantha will duplicate the current handbook document: Aim is to start with a fresh document using the previous version as reference.
+
#Samantha: Send Kate the file for the OWASP Initiatives Technical banner. 
*GPC Members will go through handbook and cross off information that will no longer be relevant: Flagship designation, Sourceforge references, etc.
+
#Samantha: Finish Project Processes document and send to GPC for review.
*Flagship designation will be left out for now. We will start with Incubator and Labs.
+
#GPC: Look through [https://docs.google.com/a/owasp.org/document/d/15lPNSxokO5ogGxWo-xvLNYh0C3c8-nWjgWnRfTfm0OU/edit Project Processes Document] and note down any critiques, objections, suggestions, etc  
*Double check FSF licenses and create a list.
+
#Nishi Announcement: Working on putting together the presentations and video for each speaker at AppSec 2012. Nishi will send us a link once work is completed.
*Ownership of Projects: Agreed that this needs further development in the future, but for now we will leave it as "business as usual". Project Leaders keep ownership of their projects.
+
#Samantha: Move forward with ModSecurity Project Grant Proposal and Google Grants Application Process.  
 +
#Kate: Will be in touch with Nishi regarding OWASP India initiatives.

Latest revision as of 15:39, 12 November 2012

OWASP Project Manager Report

Work accomplished since October 08, 2012

  • Project Numbers
    • Active Projects: 114
    • Archived Projects: 41
    • Merged Projects: 43
  • Pending Incubator Project Applications:
    • OWASP Application Security Awareness Top 10 E-Learning Project (Set up this week)
    • OWASP JSON Sanitizer (Set up this week)

Project Manager Q4 Objectives

  1. Identify and initiate 3 grant opportunities.
  2. Complete metadata for Salesforce import related to projects.
  3. Finalize and launch the Project database communication tool and webpage.
  4. Complete the project lifecycle redesign.
  5. Complete Version 2 of the Project Handbook.

Currently Working On

  • Grant Opportunities Updates
    • The ESAPI proposal is done and submitted: Thank you Chris Schmidt and Kevin Wall for helping to finalising the document.
    • Deborah, the DHS representative, has confirmed.
    • Submission was held up due to some budget questions raised by Kevin and Chris.
    • We re-evaluated the budget and made some changes.
    • This is for $25,000 from the DHS.
    • The Google Grant process is a little trickier than expected
    • Nevertheless, I am moving forward with the application with help from a Google for Non-Profits representative.
    • I hope to complete the application by this week, if all goes well.
    • I've already started the process for the OWASP ModSecurity Proposal as well.
    • Ryan has responded to my query regarding funding, and he is interested in pursuing the proposal.
    • I am putting together a reply with information on proposal procedure and budget requirements to send Ryan.
  • SalesForce Metadata Migration
    • All project data is now in Salesforce.
    • I continue to work with Kate to finish the migration.
    • We are currently working on creating a template e-mail to send to all active project leaders asking them to update their information. (Still seeking help for this)
    • Developed 8 forms to help with future requests: You can find them in the Project Processes Document: Section I.
    • Currently looking into developing the forms in Salesforce, and updating the active project information directly from Project Leaders.
  • Projects Communications Restructuring
    • The aim is to make this page live in January 2013.
    • I continue to update this with the relevant data.
    • Working on developing the project handbook, finalising project stage benefits, and finalising project graduation process before finalising updates to this page.
  • Project Processes & Lifecycle Development
    • Putting the handbook aside until these are fleshed out and agreed to.
    • I feel it is a much better idea to tackle individually, and them add them to the handbook.
    • Process form development
    • Project Stage Benefits
    • Project Graduation Process
    • Project Graduation Criteria
    • Project Migration Process
  • Projects Handbook
    • GPC and I have been working on completing the OWASP Projects Handbook.
    • Currently in the middle of developing a second version of the Handbook that is more relevant to the current state of OWASP Projects.
    • Emphasis on simplification of processes and creating a solid framework that we can later build on if needed.
    • Much of the handbook has been edited and discussed.
    • Areas that are still under development can be found in the Project Processes & Lifecycle Development section of this report.

Important GPC Meeting Outcomes and Discussion Points

  1. GPC Report: November 09, 2012
  2. Samantha: Continue to attempt to contact the SourceForge account people, and attempt to schedule a meeting with them.
  3. There has been no communication back from SourceForge people. We have decided to close the account so they will not continue to charge us. Samantha will move forward with this plan.
  4. Samantha: Develop a communications piece letting the community know why the account with SourceForge was closed.
  5. Samantha: Send Kate the file for the OWASP Initiatives Technical banner.
  6. Samantha: Finish Project Processes document and send to GPC for review.
  7. GPC: Look through Project Processes Document and note down any critiques, objections, suggestions, etc
  8. Nishi Announcement: Working on putting together the presentations and video for each speaker at AppSec 2012. Nishi will send us a link once work is completed.
  9. Samantha: Move forward with ModSecurity Project Grant Proposal and Google Grants Application Process.
  10. Kate: Will be in touch with Nishi regarding OWASP India initiatives.