This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Project Manager Activity Reports/March 11 2013"

From OWASP
Jump to: navigation, search
(Created page with "== OWASP Project Manager Report == ==== Work accomplished since February 11, 2013 ==== *'''Project Numbers''' **Active Projects: 129 **Inactive Projects: 67 *'''New Incubat...")
 
 
(7 intermediate revisions by the same user not shown)
Line 3: Line 3:
  
 
*'''Project Numbers'''
 
*'''Project Numbers'''
**Active Projects: 129
+
**Active Projects: 136
 
**Inactive Projects: 67
 
**Inactive Projects: 67
  
 
*'''New Incubator Projects'''
 
*'''New Incubator Projects'''
**[https://www.owasp.org/index.php/O-Saft O-Saft]
+
**[https://www.owasp.org/index.php/OWASP_Dependency_Check OWASP Dependency Check]
**[https://www.owasp.org/index.php/OWASP_Crowdtesting OWASP Crowdtesting]
+
**[https://www.owasp.org/index.php/OWASP_Scada_Security_Project OWASP Scada Security Project]
**[https://www.owasp.org/index.php/OWASP_Focus OWASP Focus]
+
**[https://www.owasp.org/index.php/OWASP_Cornucopia OWASP Cornucopia]
**[https://www.owasp.org/index.php/OWASP_1-Liner OWASP 1-Liner]
+
**[https://www.owasp.org/index.php/OWASP_PHPRBAC_Project OWASP PHPRBAC Project]
**[https://www.owasp.org/index.php/OWASP_Embedded_Application_Security OWASP Embedded Application Security]
+
**[https://www.owasp.org/index.php/OWASP_Secure_Application_Design_Project OWASP Secure Application Design Project]
**[https://www.owasp.org/index.php/OWASP_OpenStack_Security_Project OWASP OpenStack Security Project]
+
**[https://www.owasp.org/index.php/OWASP_Hive_Project OWASP Hive Project]
**[https://www.owasp.org/index.php/OWASP_Desktop_Goat_and_Top_5_Project OWASP Desktop Goat and Top 5 Project]
 
**[https://www.owasp.org/index.php/OWASP_Bricks OWASP Bricks]
 
  
 
*'''Project Announcements'''
 
*'''Project Announcements'''
**[http://code.google.com/p/zaproxy/downloads/list OWASP ZAP 2.0.0 is now available for download].
+
**[https://www.owasp.org/index.php/OWASP_Periodic_Table_of_Vulnerabilities OWASP Periodic Table of Vulnerabilities Project:  Working Group Forming].
**Simon is hosting a Google hangout demonstrating many of these features at 17:00 UTC on Friday 8th Feb.  
+
**A working group is now forming under the leadership of James Landis to produce the 1.0 draft of the OWASP Periodic Table of Vulnerabilities.  
**Details to be announced via https://twitter.com/zaproxy
+
**The goal of this project is to identify the ideal solution target for known web application vulnerability classes as a first step toward eliminating many classes of vulnerabilities altogether.
**[https://www.owasp.org/index.php/Category:OWASP_AntiSamy_Project OWASP AntiSamy Version 1.5 is finally released].
+
**[https://code.google.com/p/owasp-igoat/ OWASP iGoat Project V.2.0 Released!].
  
 
*'''Projects Under Review'''
 
*'''Projects Under Review'''
**[https://www.owasp.org/index.php/Cheat_Sheets OWASP Cheat Sheets Project]
+
**[https://www.owasp.org/index.php/Cheat_Sheets OWASP Cheat Sheets Project]: Test Reviewed.
**[https://www.owasp.org/index.php/OWASP_Java_HTML_Sanitizer_Project OWASP Java HTML Sanitizer Project]
+
**[https://www.owasp.org/index.php/OWASP_Java_HTML_Sanitizer_Project OWASP Java HTML Sanitizer Project]: Test Reviewed.
 +
**[https://www.owasp.org/index.php/OWASP_Codes_of_Conduct OWASP Codes of Conduct]: Reviewing Under Legacy Process. 
 +
**[https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework Xenotix XSS Exploit Framework]: New Review Submission.
  
 
==Project Manager Q1 2013 Objectives==
 
==Project Manager Q1 2013 Objectives==
#Continue grant funding research: Target $150 K in 2013.
+
#Continue grant funding research: Target $150,000 in 2013. ($5000 left to raise to reach target for 2013)
#Finalize and Implement New Project Infrastructure processes.
+
#Finalize and Implement New Project Infrastructure processes. (Ongoing)
 
#Coordinate OSS and OWASP Track documentation, guidelines, and processes as they apply to Global AppSec Conferences.  (Ongoing for 2013)
 
#Coordinate OSS and OWASP Track documentation, guidelines, and processes as they apply to Global AppSec Conferences.  (Ongoing for 2013)
#Increase Sales Force use for project management.
+
#Increase Sales Force use for project management. (Ongoing)
#Complete and Launch Projects page.
+
#Complete and Launch Projects page. (Completed)
#Finalize the Project Leader Handbook.  
+
#Finalize the Project Leader Handbook. (Completed)
  
 
==Currently Working On==
 
==Currently Working On==
 
*'''Grant Opportunities Recap & Updates'''
 
*'''Grant Opportunities Recap & Updates'''
**Guidebooks Proposal: We are still waiting for the first payment.
+
**Guidebooks Proposal: We are still waiting for the first payment. DHS is currently reviewing their budgets for the year so their funds are frozen until then.
 
**Amount: $25,000
 
**Amount: $25,000
 
**ESAPI Proposal: This proposal is still under review.   
 
**ESAPI Proposal: This proposal is still under review.   
Line 42: Line 42:
 
**Google Grants: We have been awarded this grant. Working on developing strategies to implement/use these funds.   
 
**Google Grants: We have been awarded this grant. Working on developing strategies to implement/use these funds.   
 
**Amount: $120,000 a year in Google Adwords Money
 
**Amount: $120,000 a year in Google Adwords Money
**ModSecurity Proposal: This proposal is now complete, and it has been submitted and accepted by DHS 
+
**ModSecurity Proposal: This proposal is still under review. 
 
**Amount: $30,000  
 
**Amount: $30,000  
 
**'''OWASP Static Analysis Tools Funding Opportunity: DHS'''
 
**'''OWASP Static Analysis Tools Funding Opportunity: DHS'''
 
**There is a possibility of funding some of our Static Analysis tools.
 
**There is a possibility of funding some of our Static Analysis tools.
**The interested party is a different department within the DHS.
+
**Kevin Greene is responsible for a different program than the DHS program that has already funded us.
**I am currently in talks with the DHS representative responsible for these initiatives.
+
**Kevin and I plan to discuss the possibility of moving forward with a project once their budgets are released for the year.  
  
*'''Total Grant Funds Awarded: $145,000 for 2013 so far.'''    
+
*'''Total Grant Funds Awarded: $145,000 for 2013 so far.'''    
 +
 +
*'''Project Reviews Process: Workflow Adjustment'''
 +
**Testing of original Reviews Process developed in early 2013 produced quality concerns.
 +
**I developed a new management work flow with Jim Manico's assistance. 
 +
**It will involve a working group of technical project advisors headed by a member of the board.
 +
**I feel this person should be, Jim Manico, as he has shown great dedication and support to our projects overall. (Lead Technical Project Advisor).
 +
**The working group should be made up of the following areas: Secure Development, Secure Lifecycle Activity, Static Analysis, Dynamic Analysis, Governance, and Knowledge.
 +
**Each of these areas should be a project division role filled by one individual.
 +
**Each role will have a six month limit, or the individual can resign the post if he/she can no longer fulfill the role's duties.
 +
**These roles will be responsible for reviewing projects, and increasing the quality of the project review process and criteria.
 +
**This working group will be managed by the Lead Technical Project Advisor with updates and outcomes reported to the OWASP PM.
 +
**[https://www.owasp.org/index.php/Projects/Reviews_Management_Proposal_2013 Projects Review Process Proposal]
  
*'''New Project Web Page'''
+
*'''AppSec USA: OPT &OSS'''
**The web page has been launched.  
+
**We are developing two different event modules for AppSec USA.
**It has replaced the [https://www.owasp.org/index.php/Category:OWASP_Project OWASP Projects Page]
+
**OPT: This event module will be omitted for AppSec USA.
**I am focusing on updating and maintaing our projects page at least twice a week.  
+
**OSS: This event module will be altered to include a full day of 30 minute, presentation like demos.
 +
**Mini Project Working Groups: This event module will be developed for this conference. The idea is to coordinate working groups for a hand full of projects at the conference.  
 +
**Project Leader Workshop: I will put together and run the Project Leader Workshop at AppSec USA.
  
*'''Projects Handbook 2013'''
+
*'''AppSec EU Research: OPT &OSS'''
**The Projects Handbook is now live.
+
**I started creating documents for the AppSec EU Research Open Source Showcase and OWASP Projects Track.  
**Users can download it on the [https://www.owasp.org/index.php/Category:OWASP_Project Projects Web Page].  
+
**[https://docs.google.com/a/owasp.org/spreadsheet/viewform?formkey=dDMwck9VZC1ieWluekdsbUVFZGhGMnc6MA#gid=0 AppSec EU Research OPT Form.]
 +
**[https://docs.google.com/a/owasp.org/spreadsheet/viewform?formkey=dGhkUUhkeDBWOVZPcVdzcWloYWhla3c6MA#gid=0 AppSec EU Research OSS Form.]
 +
**[https://docs.google.com/a/owasp.org/document/d/1dOrUYtwlBXwfhPyZa9JYqV1MeUUjSxvjm5mwgMqJXhE/edit AppSec EU Research Projects Document.]
 +
**I am waiting to hear from the local conference organizers on how they wish to proceed with this event module.  
  
*'''FOSDEM'''
+
*'''Black Hat EU'''
**FOSDEM went very well for the Event team in Brussels.
+
**I am scheduled to attend Black Hat EU this week.
**The flyers went down very well.
+
**I am helping manage our OWASP Booth for two days.
**Simon's presentation on ZAP went very well according to attendees.
+
**Goal: Familiarize myself with Black Hat event management, branding, activities.  
**The OWASP representatives at the event mentioned that many developers were not aware of OWASP.
+
**Martin Knobloch and Ferdinand Vroom are scheduled to volunteer as well.
**It is suggested we attend more events like these for outreach.  
+
**I will be attending the Netherlands Chapter Meeting during the conference as well.  
  
*'''Preparation for London BSides'''
+
*'''OWASP Marketing'''
**Fabio Cerullo and I had a conversation about flyers and Schwag for this event.
+
**I am taking a more active role in OWASP's Global Marketing Initiatives.
**We are still in the process of creating, and sourcing items for this.  
+
**The next initiatives meeting will involve the Marketing Company we are currently working with.
**[http://www.securitybsides.org.uk/ Security BSides London]
+
**They will present their Phase 1 research findings to the entire community.  
 
+
**Goal: To develop a marketing and brand strategy for the organization.  
*'''Guidebooks Project Management'''
+
**I will coordinate Phase 3 & 4 of our Marketing Initiatives.  
**The Guidebooks Projects have now begun their work.
 
**We are using a collaborative Gantt chart tool to manage our work flow.
 
**Start Date: February 4th 2013
 
**End Date: June 4th 2013
 
  
 
==Important Projects Division Outcomes and Discussion Points==
 
==Important Projects Division Outcomes and Discussion Points==
#[https://www.owasp.org/index.php/GPC/Meetings/2013-18-01 GPC Meeting: January 18 2013 Project Manager Report]
+
#[https://www.owasp.org/index.php/GPC/Meetings/2013-15-02 GPC Meeting: February 15 2013 Project Manager Report]
#[https://www.owasp.org/index.php/GPC/Meetings/2013-25-01 GPC Meeting: January 25 2013 Project Manager Report]
+
#[https://www.owasp.org/index.php/GPC/Meetings/2013-22-02 GPC Meeting: February 22 2013 Project Manager Report]
#[https://www.owasp.org/index.php/GPC/Meetings/2013-01-02 GPC Meeting: February 01 2013 Project Manager Report]
+
#[https://www.owasp.org/index.php/GPC/Meetings/2013-01-03  Project Manager Report: March 01 2013]
#[https://www.owasp.org/index.php/GPC/Meetings/2013-08-02 GPC Meeting: February 08 2013 Project Manager Report]
+
#[https://www.owasp.org/index.php/GPC/Meetings/2013-08-03  Project Manager Report: March 08 2013]
#GPC members have decided to meet once every month to discuss project related issues/initiatives.
+
#I will have a projects meeting each month that will be open to all the OWASP community starting in April.  
#I have scheduled the call, and all of the community is welcomed and encouraged to join in.
+
#I continue to developing a template, visual branding, and review criteria to meet our project identification needs as I feel this is a very important distinction to make between our projects.
#I will add the meeting time and details to the Global OWASP Calendar. 
 
#Meeting Date: March 08, 2013.
 
#I continue to developing a template, visual branding, and review criteria to meet this need as I feel it is a very important distinction to make between our projects.
 

Latest revision as of 15:21, 11 March 2013

OWASP Project Manager Report

Work accomplished since February 11, 2013

  • Project Numbers
    • Active Projects: 136
    • Inactive Projects: 67

Project Manager Q1 2013 Objectives

  1. Continue grant funding research: Target $150,000 in 2013. ($5000 left to raise to reach target for 2013)
  2. Finalize and Implement New Project Infrastructure processes. (Ongoing)
  3. Coordinate OSS and OWASP Track documentation, guidelines, and processes as they apply to Global AppSec Conferences. (Ongoing for 2013)
  4. Increase Sales Force use for project management. (Ongoing)
  5. Complete and Launch Projects page. (Completed)
  6. Finalize the Project Leader Handbook. (Completed)

Currently Working On

  • Grant Opportunities Recap & Updates
    • Guidebooks Proposal: We are still waiting for the first payment. DHS is currently reviewing their budgets for the year so their funds are frozen until then.
    • Amount: $25,000
    • ESAPI Proposal: This proposal is still under review.
    • Amount: $25,000
    • Google Grants: We have been awarded this grant. Working on developing strategies to implement/use these funds.
    • Amount: $120,000 a year in Google Adwords Money
    • ModSecurity Proposal: This proposal is still under review.
    • Amount: $30,000
    • OWASP Static Analysis Tools Funding Opportunity: DHS
    • There is a possibility of funding some of our Static Analysis tools.
    • Kevin Greene is responsible for a different program than the DHS program that has already funded us.
    • Kevin and I plan to discuss the possibility of moving forward with a project once their budgets are released for the year.
  • Total Grant Funds Awarded: $145,000 for 2013 so far.
  • Project Reviews Process: Workflow Adjustment
    • Testing of original Reviews Process developed in early 2013 produced quality concerns.
    • I developed a new management work flow with Jim Manico's assistance.
    • It will involve a working group of technical project advisors headed by a member of the board.
    • I feel this person should be, Jim Manico, as he has shown great dedication and support to our projects overall. (Lead Technical Project Advisor).
    • The working group should be made up of the following areas: Secure Development, Secure Lifecycle Activity, Static Analysis, Dynamic Analysis, Governance, and Knowledge.
    • Each of these areas should be a project division role filled by one individual.
    • Each role will have a six month limit, or the individual can resign the post if he/she can no longer fulfill the role's duties.
    • These roles will be responsible for reviewing projects, and increasing the quality of the project review process and criteria.
    • This working group will be managed by the Lead Technical Project Advisor with updates and outcomes reported to the OWASP PM.
    • Projects Review Process Proposal
  • AppSec USA: OPT &OSS
    • We are developing two different event modules for AppSec USA.
    • OPT: This event module will be omitted for AppSec USA.
    • OSS: This event module will be altered to include a full day of 30 minute, presentation like demos.
    • Mini Project Working Groups: This event module will be developed for this conference. The idea is to coordinate working groups for a hand full of projects at the conference.
    • Project Leader Workshop: I will put together and run the Project Leader Workshop at AppSec USA.
  • Black Hat EU
    • I am scheduled to attend Black Hat EU this week.
    • I am helping manage our OWASP Booth for two days.
    • Goal: Familiarize myself with Black Hat event management, branding, activities.
    • Martin Knobloch and Ferdinand Vroom are scheduled to volunteer as well.
    • I will be attending the Netherlands Chapter Meeting during the conference as well.
  • OWASP Marketing
    • I am taking a more active role in OWASP's Global Marketing Initiatives.
    • The next initiatives meeting will involve the Marketing Company we are currently working with.
    • They will present their Phase 1 research findings to the entire community.
    • Goal: To develop a marketing and brand strategy for the organization.
    • I will coordinate Phase 3 & 4 of our Marketing Initiatives.

Important Projects Division Outcomes and Discussion Points

  1. GPC Meeting: February 15 2013 Project Manager Report
  2. GPC Meeting: February 22 2013 Project Manager Report
  3. Project Manager Report: March 01 2013
  4. Project Manager Report: March 08 2013
  5. I will have a projects meeting each month that will be open to all the OWASP community starting in April.
  6. I continue to developing a template, visual branding, and review criteria to meet our project identification needs as I feel this is a very important distinction to make between our projects.