This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Projects/Reports/2013-07-06"

From OWASP
Jump to: navigation, search
(Created page with "__TOC__ = OWASP Global Projects Report = *'''[https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdHBGbDhXQko4akJoVnMtMUpvZnJucVE&usp=sharing Project Numbers]''' **Activ...")
 
 
(4 intermediate revisions by the same user not shown)
Line 7: Line 7:
  
 
*'''[https://docs.google.com/spreadsheet/ccc?key=0Amvv_7Gz8Z7TdHZfWGhHZ0Z4UFFwZU42djBXcVVLSlE&usp=sharing Project Applications]'''
 
*'''[https://docs.google.com/spreadsheet/ccc?key=0Amvv_7Gz8Z7TdHZfWGhHZ0Z4UFFwZU42djBXcVVLSlE&usp=sharing Project Applications]'''
**VCR Project
 
**Windows Binary Executable Files Security Checks
 
**Wordpress Security Checklist
 
**Simple Host Base Incidence Detection System
 
**Chat Application
 
 
**Supporting Legacy Web Applications in the Current Environment
 
**Supporting Legacy Web Applications in the Current Environment
 +
 +
*'''New Projects'''
 +
**[https://www.owasp.org/index.php/OWASP_Windows_Binary_Executable_Files_Security_Checks_Project OWASP Windows Binary Executable Files Security Checks Project]
 +
**[https://www.owasp.org/index.php/OWASP_Wordpress_Security_Checklist_Project OWASP Wordpress Security Checklist Project]
 +
**[https://www.owasp.org/index.php/OWASP_Simple_Host_Base_Incidence_Detection_System_Project OWASP Simple Host Base Incidence Detection System Project]
 +
**[https://www.owasp.org/index.php/OWASP_SeraphimDroid_Project OWASP SeraphimDroid Project]
  
 
*'''Projects Under Review'''
 
*'''Projects Under Review'''
Line 24: Line 25:
 
*'''OWASP Projects at AppSec Conferences 2013'''
 
*'''OWASP Projects at AppSec Conferences 2013'''
 
**Planning continues for the project event modules for AppSec USA 2013.  
 
**Planning continues for the project event modules for AppSec USA 2013.  
**I continue to work with our project summit participating leaders to work out costs and logistics for their attendance.  
+
**I continue to work with our project summit participants to help plan the logistics for their participation.  
**I am in the process of putting together our project leader workshop materials.  
+
**We are meeting next week to discuss roadmaps and goals for each project.  
**The workshop will be a 45 - 50 minute interactive presentation for current and potential OWASP Project Leaders.
+
**I am still working on the Project Leader Workshop materials.  
**It will take place at the AppSec USA 2013 conference in New York.
 
 
**I will continue to provide support to the local event planning team for AppSec EU, as needed.  
 
**I will continue to provide support to the local event planning team for AppSec EU, as needed.  
  
 
*'''Women in Security: AppSec USA 2013'''
 
*'''Women in Security: AppSec USA 2013'''
**The team has finished a first draft of the Sponsorship Document.  
+
**The team has now finalized the copy for our sponsorship document.
 +
**The copy has now been sent to the AppSec USA graphic designer.  
 
**The plan is to reach out to different organizations for sponsorship.  
 
**The plan is to reach out to different organizations for sponsorship.  
 
**You can find more information on the [http://appsecusa.org/2013/activities/owasp-women-in-application-security-appsec-program/ AppSec USA website].  
 
**You can find more information on the [http://appsecusa.org/2013/activities/owasp-women-in-application-security-appsec-program/ AppSec USA website].  
Line 38: Line 39:
 
**The total amount we are requesting is $6,000.00 to cover conference fee, training fee, travel and accommodation for both winners.  
 
**The total amount we are requesting is $6,000.00 to cover conference fee, training fee, travel and accommodation for both winners.  
 
**We are working hard to make this a possibility for our 2 potential winners.  
 
**We are working hard to make this a possibility for our 2 potential winners.  
 
*'''[https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdEdCYVJpdmZHaWJYZ055WHROa19qN3c&usp=sharing Determining Active Project Status]'''
 
**This is a status update on this initiative.
 
**I am reaching out to each leader individually to confirm these pieces of data for all 154 projects.
 
**Flagship projects are completed.
 
**Labs are completed.
 
**Incubator projects are now in the 3rd phase of 4 phases.
 
  
 
*'''Technical Project Advisory Roles'''
 
*'''Technical Project Advisory Roles'''
**I am currently on the 1st stage of the interview process for each candidate.
+
**I am at the transition stage between the first and second stages of the interview process for each candidate.
 
**I have created job descriptions for each role, and I have had those roles posted for over a month.
 
**I have created job descriptions for each role, and I have had those roles posted for over a month.
 
**We have had a good amount of candidates apply for each role.  
 
**We have had a good amount of candidates apply for each role.  
 
**I have sent out e-mails asking each candidate to answer 3 questions regarding their interest in these roles.
 
**I have sent out e-mails asking each candidate to answer 3 questions regarding their interest in these roles.
**I will reach out to those individuals that responded to my request by next week.  
+
**I have now had 10 responses from candidates.
 +
**I will schedule interviews with them to discuss the roles further.
  
 
*'''Marketing Phase 3 Update'''
 
*'''Marketing Phase 3 Update'''
**The marketing deliverables are going smoothly.
+
**We are at the final stages of of our copywriting work with Sisterworks Publishing.
**There is quite a bit of work to be done during this phase as this is where the back and forth approval process takes place.
+
**Design Foundry is now starting their first drafts of several pieces of marketing collateral.  
**The Ops Team is diligently working on this phase with Sisterworks Publishing and Design Foundry.
+
**We will work with the designer to finalize these designs for community review.  
**At the moment, we are working on finalizing the copy for several pieces of collateral that are scheduled to be designed.  
 
 
**[https://www.owasp.org/images/7/7c/OWASP_Background-Research_Phase1_Final_%281%29.pdf Phase 1 Deliverable]
 
**[https://www.owasp.org/images/7/7c/OWASP_Background-Research_Phase1_Final_%281%29.pdf Phase 1 Deliverable]
 
**[https://www.owasp.org/images/c/c5/OWASP_Recommendations-Presentation2-April24.pdf Phase 2 Deliverable]
 
**[https://www.owasp.org/images/c/c5/OWASP_Recommendations-Presentation2-April24.pdf Phase 2 Deliverable]
Line 63: Line 57:
 
***We are not necessarily moving forward with these recommendations towards implementation.
 
***We are not necessarily moving forward with these recommendations towards implementation.
 
***Sisterworks and Design Foundry are helping with our brand consistency and collateral design.  
 
***Sisterworks and Design Foundry are helping with our brand consistency and collateral design.  
 
*'''Strategic Goals Presentation'''
 
**Ludovic petit has requested that we put together a presentation that the community can use to communicate our 2013 Strategic Goals.
 
**Sarah and I have put together a first draft of the deck. 
 
**We plan to add to it over the coming weeks to make certain we encompass the thinking behind each goals for this year.
 
**[https://www.owasp.org/images/1/13/OWASP_2013_Strategic_Goals.pdf 2013 Strategic Goals draft]
 
  
 
*'''Personal Development'''
 
*'''Personal Development'''
**I am currently reading ''Board Member Orientation: The Concise and Complete Guide to Non-Profit Board Service'' by Michael E. Batts.  
+
**I am half way through reading ''Board Member Orientation: The Concise and Complete Guide to Non-Profit Board Service'' by Michael E. Batts.  
 
**I am still taking my online course from Coursera.
 
**I am still taking my online course from Coursera.
 
**The course topic is Information Security and Risk Management in Context.
 
**The course topic is Information Security and Risk Management in Context.
**I am currently in week 6 of the course.
 
 
**Additionally, I am going to take a week long course in late June in the UK.
 
**Additionally, I am going to take a week long course in late June in the UK.
 
**The course topic is Intellectual Property Strategy.
 
**The course topic is Intellectual Property Strategy.
**I will write a report on my learnings for the community after the course ends.  
+
**I will write a report on my learnings for the community after the course ends.
 +
**I have completed my logistics planning for this trip.
 +
**I will be away from Monday, June 17 - Saturday, June 22 2013.  
  
 
*'''Daily Project based queries and requests'''
 
*'''Daily Project based queries and requests'''

Latest revision as of 01:15, 8 June 2013

OWASP Global Projects Report

Currently Working On

  • OWASP Projects at AppSec Conferences 2013
    • Planning continues for the project event modules for AppSec USA 2013.
    • I continue to work with our project summit participants to help plan the logistics for their participation.
    • We are meeting next week to discuss roadmaps and goals for each project.
    • I am still working on the Project Leader Workshop materials.
    • I will continue to provide support to the local event planning team for AppSec EU, as needed.
  • Women in Security: AppSec USA 2013
    • The team has now finalized the copy for our sponsorship document.
    • The copy has now been sent to the AppSec USA graphic designer.
    • The plan is to reach out to different organizations for sponsorship.
    • You can find more information on the AppSec USA website.
    • We are currently attempting to raise $3,000.00 for each winner.
    • We plan on having 2 winners for 2013.
    • The total amount we are requesting is $6,000.00 to cover conference fee, training fee, travel and accommodation for both winners.
    • We are working hard to make this a possibility for our 2 potential winners.
  • Technical Project Advisory Roles
    • I am at the transition stage between the first and second stages of the interview process for each candidate.
    • I have created job descriptions for each role, and I have had those roles posted for over a month.
    • We have had a good amount of candidates apply for each role.
    • I have sent out e-mails asking each candidate to answer 3 questions regarding their interest in these roles.
    • I have now had 10 responses from candidates.
    • I will schedule interviews with them to discuss the roles further.
  • Marketing Phase 3 Update
    • We are at the final stages of of our copywriting work with Sisterworks Publishing.
    • Design Foundry is now starting their first drafts of several pieces of marketing collateral.
    • We will work with the designer to finalize these designs for community review.
    • Phase 1 Deliverable
    • Phase 2 Deliverable
      • Note: Phase 2 Deliverable has recommendations made by Sisterworks and Design Foundry based on their research.
      • We are not necessarily moving forward with these recommendations towards implementation.
      • Sisterworks and Design Foundry are helping with our brand consistency and collateral design.
  • Personal Development
    • I am half way through reading Board Member Orientation: The Concise and Complete Guide to Non-Profit Board Service by Michael E. Batts.
    • I am still taking my online course from Coursera.
    • The course topic is Information Security and Risk Management in Context.
    • Additionally, I am going to take a week long course in late June in the UK.
    • The course topic is Intellectual Property Strategy.
    • I will write a report on my learnings for the community after the course ends.
    • I have completed my logistics planning for this trip.
    • I will be away from Monday, June 17 - Saturday, June 22 2013.
  • Daily Project based queries and requests
    • This has not changed much since I began the post: questions are very similar in nature.
    • Global AppSec questions.
    • Funding queries.
    • Travel availability.
    • Project based administrative help.
    • Project status information.
    • Several project donations questions.
    • Marketing questions.
    • Grant funding questions.
    • OWASP Social Media Updates.
    • What's happening with projects, questions.

Grants Updates

  1. Amount: $25,000 USD
  2. Status: The first payment has been allocated to our project budgets.
  3. OWASP Development Guide Plan
  4. OWASP Testing Guide Plan
  5. OWASP Code Review Guide Plan
  1. Amount: $25,000 USD
  2. Status: The ESAPI proposal is still being reviewed.
  1. Amount: $30,000 USD
  2. Status: The ModSecurity proposal is still being reviewed.
  • Google Grants Proposal
  1. Amount: $120,000 USD in Adwords Funds
  2. Status: We now have a better idea of the initiatives and tasks we must undertake to better leverage this award. We will discuss possible solutions during our Mid-Term (6-12 month) marketing planning.
  3. Note: There is no link to show the proposal for this grant. There was a form that was submitted to Google, and we did not receive a record of this form.
  • European Commission Grant Proposal
  1. Amount: €250,000
  2. Status: This proposal has been completed and submitted.


  • Total Grant Funds Awarded: $145,000 USD for 2013.