This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Project Manager Activity Reports/September 09 2013"

From OWASP
Jump to: navigation, search
(Created page with "== OWASP Projects Manager Report == ==== Work accomplished since July 08, 2013 ==== *'''[https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdHBGbDhXQko4akJoVnMtMUpvZnJu...")
 
 
(8 intermediate revisions by the same user not shown)
Line 1: Line 1:
== OWASP Projects Manager Report ==
+
== OWASP Project Manager Report ==
==== Work accomplished since July 08, 2013 ====
+
==== Work accomplished since August 06, 2013 ====
  
 
*'''[https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdHBGbDhXQko4akJoVnMtMUpvZnJucVE&usp=sharing Project Numbers]'''
 
*'''[https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdHBGbDhXQko4akJoVnMtMUpvZnJucVE&usp=sharing Project Numbers]'''
**Active Projects: 168
+
**Active Projects: 135
**Inactive Projects: 67
+
**Inactive Projects: 103
 +
 
 +
*'''[https://docs.google.com/spreadsheet/ccc?key=0Amvv_7Gz8Z7TdHZfWGhHZ0Z4UFFwZU42djBXcVVLSlE&usp=sharing New Project Applications]'''
 +
**OWASP JAWS Project
 +
**OWASP Media Project
  
 
*'''New OWASP Projects'''
 
*'''New OWASP Projects'''
**[https://www.owasp.org/index.php/OWASP_WebSandBox_Project OWASP WebSandBox Project]
+
**[https://www.owasp.org/index.php/OWASP_Framework_Security_Project OWASP Framework Security Project]
**[https://www.owasp.org/index.php/OWASP_HA_Vulnerability_Scanner_Project OWASP HA Vulnerability Scanner Project]
+
**[https://www.owasp.org/index.php/OWASP_Ruby_on_Rails_and_friends_Security_Guide OWASP Ruby on Rails and friends Security Guide Project] - Adoption
**[https://www.owasp.org/index.php/OWASP_Dependency_Track_Project OWASP Dependency Track Project]
 
**[https://www.owasp.org/index.php/OWASP_Security_Principles_Project OWASP Security Principles Project]
 
 
 
*'''[https://docs.google.com/spreadsheet/ccc?key=0Amvv_7Gz8Z7TdHZfWGhHZ0Z4UFFwZU42djBXcVVLSlE&usp=sharing Project Applications]'''
 
**SecLists Project
 
  
 
*'''Projects Under Review'''
 
*'''Projects Under Review'''
 
**[https://www.owasp.org/index.php/Cheat_Sheets OWASP Cheat Sheets Project]
 
**[https://www.owasp.org/index.php/Cheat_Sheets OWASP Cheat Sheets Project]
**[https://www.owasp.org/index.php/OWASP_Java_HTML_Sanitizer_Project OWASP Java HTML Sanitizer Project]
+
**[https://www.owasp.org/index.php/OWASP_Java_HTML_Sanitizer_Project OWASP Java HTML Sanitizer Project] (Testing)
**[https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework Xenotix XSS Exploit Framework]
+
**[https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework Xenotix XSS Exploit Framework]  
**[https://www.owasp.org/index.php/OWASP_Cornucopia OWASP Cornucopia Project]
+
**[https://www.owasp.org/index.php/OWASP_Cornucopia OWASP Cornucopia Project] (Testing)
**[https://www.owasp.org/index.php/OWASP_Java_Encoder_Project OWASP Java Encoder Project]
+
**[https://www.owasp.org/index.php/OWASP_Java_Encoder_Project OWASP Java Encoder Project] (Testing)
**Project reviews are on hold until new assessment criteria is developed.  
+
**Project reviews are on hold until the Technical Advisory group complete and test the [https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdHJUSl9rbGtscGJfSGRWVFNUM2JPMlE&usp=sharing updated assessment criteria].
  
 
==Project Manager Q3 2013 Objectives==
 
==Project Manager Q3 2013 Objectives==
Line 35: Line 34:
 
==Currently Working On==   
 
==Currently Working On==   
 
   
 
   
*'''[https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdEdCYVJpdmZHaWJYZ055WHROa19qN3c&usp=sharing Determining Active Project Status]'''
+
*'''[https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdEdCYVJpdmZHaWJYZ055WHROa19qN3c&usp=sharing Active Project Audit]'''
**This is a status update on this initiative.
+
**The Project Audit is now complete.  
**I have completed the first round of requests for all Flagship, Labs, and Incubator projects.
+
**I reached out to every project leader listed in our inventory, and asked them to confirm the status of their project.
**I am now going through the list, and e-mailing the non-responsive Leaders once again.
+
**The majority of our Leaders responded, and their project activity status was marked accordingly.
**I have gone ahead and re-sent my request for a 3rd time to un-responsive Labs Project Leaders.
+
**Those that did not respond were sent 3 messages before their project was marked inactive.
**The deadline to reply back to my request was, Friday, 26th of July.  
+
**Due to the audit, the number of active OWASP Projects in our inventory went down from 169 to 132.  
**Those Leaders who did not respond to my e-mails  will now have their projects archived.  
+
**I have also created an [https://lists.owasp.org/mailman/listinfo/owasp_project_leader_list OWASP Project Leader Mailing List], and I added all of our confirmed active Leaders to it.
**The same process will be used for the un-responsive Leaders of Incubator projects.  
+
**The next audit will take place on February 2014.
 
 
*'''Grants & Fundraising Intern'''
 
**I have put together role and qualification criteria for the Fundraising Internship Opportunity.
 
**The internship opportunity was made live two weeks ago.
 
**There have been three applicants for the role, so far.
 
**I hope to get more applications in the coming weeks.
 
**[https://www.owasp.org/index.php/Projects/Internships/Grants_and_Fundraising_Intern Grants & Fundraising Internship]
 
**I am looking for a student or recent graduate to help with grant research, writing, and volunteer coordination.  
 
  
*'''Project Summit: AppSec USA 2013'''
+
*'''[http://owasp.blogspot.com/2013/09/meet-our-new-technical-project-advisors.html Technical Project Advisors: Work Update]'''
**I continue to plan the logistics for the project summit taking place at AppSec USA this year.
+
**The Advisors and I met last week to discuss their review of the current Assessment criteria.
**I continue to gather estimates, flight, and roadmap details from Leaders.
+
**We also reviewed Chuck's comments, and discussed each in more detail.
**I am now closer to finalizing the travel arrangements for each project leader.  
+
**We made some changes to the original document, and I've put together a revised draft based on our conversation.
**Moreover, we are in the process of organizing the schedule of project talks for the conference days.
+
**Here is [https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdHliVUlMYVdPRWpqajF1bGtnSGtWckE&usp=sharing Ly's original document] with Chuck's comments and my notes.
 +
**Here is [https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdHJUSl9rbGtscGJfSGRWVFNUM2JPMlE&usp=sharing new revised draft].  
 +
**We plan to use the revised draft to test 3 projects against the criteria.  
 +
***Project being reviewed are the following:
 +
***[https://www.owasp.org/index.php/OWASP_Java_HTML_Sanitizer_Project OWASP Java HTML Sanitizer Project] (Testing)
 +
***[https://www.owasp.org/index.php/OWASP_Cornucopia OWASP Cornucopia Project] (Testing)
 +
***[https://www.owasp.org/index.php/OWASP_Java_Encoder_Project OWASP Java Encoder Project] (Testing)
  
 
*'''Women in AppSec: AppSec USA 2013'''
 
*'''Women in AppSec: AppSec USA 2013'''
**The team has now completed their fundraising activities.  
+
**The team has now selected three new members for the Women in AppSec Selection Committee.
**We are happy to report that we have now raised $6,500.00 for the program.
+
**These individuals will help review the applications and select the two winners.  
**The OWASP MSP Chapter kindly donated the remaining funds needed to reach our goal for the program this year.  
+
**The following people make up the selection committee: Helen Gao, Bev Corwin, Jim Manico, Tom Ryan, Lucas Ferreira, and Samantha Groves.
**The University of Washington has donated $500.00 today, as well.  
+
**Once the selection committee was established, we began discussing the selection criteria in more detail.
**The call for entries is now live, as well.  
+
**We are now in the fourth version of the criteria.  
 +
**[https://docs.google.com/document/d/1W0RJ85uP78m47R58xnGdi0_09QpalnPT2Woz4zb5_94/edit?usp=sharing Women in AppSec Program Selection Criteria: 4th Draft].  
 +
**We plan on beginning our selection process after the 9th of September once the application deadline has passed.  
 
**[https://docs.google.com/forms/d/1WEtInvzlxLDXpTgfXh-E1E7e8H5FRfEOPIaTOizlBpk/viewform Women in AppSec Application Form.]
 
**[https://docs.google.com/forms/d/1WEtInvzlxLDXpTgfXh-E1E7e8H5FRfEOPIaTOizlBpk/viewform Women in AppSec Application Form.]
 
**The application deadline is Monday, September 09, 2013 at 5pm GMT.
 
**The application deadline is Monday, September 09, 2013 at 5pm GMT.
 +
**The deadline for sponsors is Monday, September 09, 2013, as well. 
  
*'''OWASP Marketing'''
+
*'''[https://www.owasp.org/index.php/Projects/Internships/Grants_and_Fundraising_Intern Grants & Fundraising Intern]'''
**I continue to work with Design Foundry and the OWASP Ops Team to finalize Phase 3 of our Marketing Project.  
+
**My search for a Grants & Fundraising intern is coming to an end
**We are in the final stages of development and design.
+
**I received four applications for the role, and I had interviews with each applicant last week.
**Patrick, Design Foundry's graphic designer, is working hard to get our work completed.
+
**I have already made my decision, and I will announce the successful applicant on the 9th of September.  
**We hope to have all of our designs finalized by mid-August.  
+
**Application Deadline: Monday August 26 2013 5PM GMT. (Now Closed)
**We are also seeking community feedback on several key design pieces.  
+
**Interviews Scheduled: First Week of September. (Interviews Scheduled for Next Week)
**[https://www.owasp.org/index.php/Marketing/Community_Input Marketing Community Feedback Wiki Page]
+
**Selection Announcement: Monday, September 09th 2013.
 +
**Start Date: Monday, September 16th 2013.
 +
**Internship End Date: Monday, January 13th 2014.
  
*'''OWASP at Black Hat'''
+
*'''Projects at Conferences'''
**I have just come back from Las Vegas where I attended Black Hat and DEF CON.
+
**The two conferences left to plan for this year are AppSec LATAM, and AppSec USA.
**I helped with the OWASP Booth at Black Hat, and met with quite a few people that had questions about our programs.
+
**I have reached out to two project leaders in the Latin America region, and asked them if they would speak at the conference.
**Overall, it was a very productive time.  
+
**Both leaders agreed to give a talk at the conference. 
**We made many great connections that I am following up with, this week.  
+
**I have been helping them with their travel, accommodation, and conference logistics planning.
 +
**Thank you to Michael Hidalgo and Rafael Gil Larios for representing OWASP Projects at AppSec LATAM.
 +
**AppSec USA planning for projects is going very well.  
 +
**Now, all of the Project Leaders have booked their travel, and only one project leader hasn't confirmed his talk time slot.
  
==Grants Updates==
+
==Project Funding Updates==
*'''OWASP OpenSAMM Grant Proposal'''
+
*'''OWASP OWTF Project: Brucon 5x5 Award'''
# Amount: TBD
+
# Amount: €5,000.00 (Approx. $6,670.00)
# Status: This proposal is still in the planning and writing phase.
+
# Status: Awarded. Congratulations, Abraham Aranguren and all involved in the project, for your award.
 +
 
 +
*'''[https://docs.google.com/file/d/0B1lOCxlYdf1AQm52T2xjX215M28/edit?usp=sharing OWASP OWTF Grant Proposal]'''
 +
# Amount: $55,800 USD
 +
# Status: This proposal is complete, and has been submitted.
 +
 
 +
*'''[https://docs.google.com/document/d/1cFbmOLqEQQG8eXPrMTlU6JUivgRIacUeL7D599bZm_E/edit?usp=sharing OWASP AppSensor Grant Proposal]'''
 +
# Amount: $15,000 USD
 +
# Status: This proposal is complete, and has been submitted.
 +
 
 +
*'''[https://docs.google.com/document/d/1Vz7BLFdt1h5AhmW-Zc2B_KlqhzsSkSAaEASML5U4VQs/edit?usp=sharing OWASP OpenSAMM Grant Proposal]'''
 +
# Amount: $112,000 USD
 +
# Status: This proposal is complete, and has been submitted.  
  
 
*'''[https://docs.google.com/document/d/1MA3TI5ssclxvheV8At_ffu2Fuic55SDpOokS3AOvBUc/edit?usp=sharing OWASP Guidebooks Proposal]'''
 
*'''[https://docs.google.com/document/d/1MA3TI5ssclxvheV8At_ffu2Fuic55SDpOokS3AOvBUc/edit?usp=sharing OWASP Guidebooks Proposal]'''
Line 108: Line 125:
 
*'''European Commission Grant Proposal'''
 
*'''European Commission Grant Proposal'''
 
#Amount: €250,000
 
#Amount: €250,000
#Status: This proposal has been completed and submitted.  
+
#Status: Denied.
  
 
*'''Google Summer of Code'''
 
*'''Google Summer of Code'''
#Amount: $5,500.00
+
#Amount: $5,500
 
#Status: Awarded
 
#Status: Awarded
  
 
*'''Projects breakdown:'''
 
*'''Projects breakdown:'''
**4 ZAP Projects: $2,000.00
+
**4 ZAP Projects: $2,000
**4 OWTF Projects: $2,000.00
+
**4 OWTF Projects: $2,000
 
**1 PHP Security Project: $500
 
**1 PHP Security Project: $500
 
**1 Hackademics Project: $500
 
**1 Hackademics Project: $500
Line 122: Line 139:
 
**Note: Big thank you to Fabio Cerullo for coordinating and managing this award.  
 
**Note: Big thank you to Fabio Cerullo for coordinating and managing this award.  
  
*'''Total Grant Funds Awarded: $150,500 USD for 2013.'''
+
 
 +
*'''Total Funds Awarded: $157,170 USD for 2013.'''
  
  
==OWASP Projects Manager Weekly Reports==
+
==OWASP Project Manager Weekly Reports==
#[https://www.owasp.org/index.php/Projects/Reports/2013-05-07 Project Manager Report: July 05 2013]
+
#[https://www.owasp.org/index.php/Projects/Reports/2013-09-08 Project Manager Report: August 09 2013]
#[https://www.owasp.org/index.php/Projects/Reports/2013-12-07 Project Manager Report: July 12 2013]
+
#[https://www.owasp.org/index.php/Projects/Reports/2013-16-08 Project Manager Report: August 16 2013]
#[https://www.owasp.org/index.php/Projects/Reports/2013-19-07 Project Manager Report: July 19 2013]
+
#[https://www.owasp.org/index.php/Projects/Reports/2013-23-08 Project Manager Report: August 23 2013]
#[https://www.owasp.org/index.php/Projects/Reports/2013-26-07 Project Manager Report: July 26 2013]
+
#[https://www.owasp.org/index.php/Projects/Reports/2013-30-08 Project Manager Report: August 30 2013]
#Project Manager Report: August 02 2013 - No Report this week. PM was away at Black Hat & DEFCON 2013.
+
#Project Manager Report: September 06 2013 - No Report this week. PM was out of the office.

Latest revision as of 14:49, 9 September 2013

OWASP Project Manager Report

Work accomplished since August 06, 2013

Project Manager Q3 2013 Objectives

  1. Marketing: Work with Sarah to solicit feedback from community on Marketing deliverables and finalize relationship with Patrick and Denita.
  2. Project Review Process - Work with new Technical Project advisors to finalize project review criteria and process.
  3. Grants: Develop a grant strategy for rest of 2013 and 2014, utilizing fundraising intern(s) as part of this strategy.
  • Ongoing Objectives for 2013
    • Work with Project leaders to reach grant required milestones - ONGOING
    • Develop a project charter outlining appropriate grant revenue spending and grant required milestones. - DUE IN SEPTEMBER - ONGOING
    • Oversight of Marketing and Graphic Design deliverables (Phase 2/Phase 3) provided by 3rd party contractor

Currently Working On

  • Active Project Audit
    • The Project Audit is now complete.
    • I reached out to every project leader listed in our inventory, and asked them to confirm the status of their project.
    • The majority of our Leaders responded, and their project activity status was marked accordingly.
    • Those that did not respond were sent 3 messages before their project was marked inactive.
    • Due to the audit, the number of active OWASP Projects in our inventory went down from 169 to 132.
    • I have also created an OWASP Project Leader Mailing List, and I added all of our confirmed active Leaders to it.
    • The next audit will take place on February 2014.
  • Women in AppSec: AppSec USA 2013
    • The team has now selected three new members for the Women in AppSec Selection Committee.
    • These individuals will help review the applications and select the two winners.
    • The following people make up the selection committee: Helen Gao, Bev Corwin, Jim Manico, Tom Ryan, Lucas Ferreira, and Samantha Groves.
    • Once the selection committee was established, we began discussing the selection criteria in more detail.
    • We are now in the fourth version of the criteria.
    • Women in AppSec Program Selection Criteria: 4th Draft.
    • We plan on beginning our selection process after the 9th of September once the application deadline has passed.
    • Women in AppSec Application Form.
    • The application deadline is Monday, September 09, 2013 at 5pm GMT.
    • The deadline for sponsors is Monday, September 09, 2013, as well.
  • Grants & Fundraising Intern
    • My search for a Grants & Fundraising intern is coming to an end
    • I received four applications for the role, and I had interviews with each applicant last week.
    • I have already made my decision, and I will announce the successful applicant on the 9th of September.
    • Application Deadline: Monday August 26 2013 5PM GMT. (Now Closed)
    • Interviews Scheduled: First Week of September. (Interviews Scheduled for Next Week)
    • Selection Announcement: Monday, September 09th 2013.
    • Start Date: Monday, September 16th 2013.
    • Internship End Date: Monday, January 13th 2014.
  • Projects at Conferences
    • The two conferences left to plan for this year are AppSec LATAM, and AppSec USA.
    • I have reached out to two project leaders in the Latin America region, and asked them if they would speak at the conference.
    • Both leaders agreed to give a talk at the conference.
    • I have been helping them with their travel, accommodation, and conference logistics planning.
    • Thank you to Michael Hidalgo and Rafael Gil Larios for representing OWASP Projects at AppSec LATAM.
    • AppSec USA planning for projects is going very well.
    • Now, all of the Project Leaders have booked their travel, and only one project leader hasn't confirmed his talk time slot.

Project Funding Updates

  • OWASP OWTF Project: Brucon 5x5 Award
  1. Amount: €5,000.00 (Approx. $6,670.00)
  2. Status: Awarded. Congratulations, Abraham Aranguren and all involved in the project, for your award.
  1. Amount: $55,800 USD
  2. Status: This proposal is complete, and has been submitted.
  1. Amount: $15,000 USD
  2. Status: This proposal is complete, and has been submitted.
  1. Amount: $112,000 USD
  2. Status: This proposal is complete, and has been submitted.
  1. Amount: $25,000 USD
  2. Status: Awarded. The first payment has been allocated to our project budgets. The second invoice has now been sent to Georgia Tech for payment.
  3. OWASP Development Guide Plan
  4. OWASP Testing Guide Plan
  5. OWASP Code Review Guide Plan
  1. Amount: $25,000 USD
  2. Status: The ESAPI proposal is still being reviewed.
  1. Amount: $30,000 USD
  2. Status: The ModSecurity proposal is still being reviewed.
  • Google Grants Proposal
  1. Amount: $120,000 USD in Adwords Funds
  2. Status: Awarded.
  3. Note: There is no link to show the proposal for this grant. There was a form that was submitted to Google, and we did not receive a record of this form.
  • European Commission Grant Proposal
  1. Amount: €250,000
  2. Status: Denied.
  • Google Summer of Code
  1. Amount: $5,500
  2. Status: Awarded
  • Projects breakdown:
    • 4 ZAP Projects: $2,000
    • 4 OWTF Projects: $2,000
    • 1 PHP Security Project: $500
    • 1 Hackademics Project: $500
    • 1 Modsecurity Project: $500
    • Note: Big thank you to Fabio Cerullo for coordinating and managing this award.


  • Total Funds Awarded: $157,170 USD for 2013.


OWASP Project Manager Weekly Reports

  1. Project Manager Report: August 09 2013
  2. Project Manager Report: August 16 2013
  3. Project Manager Report: August 23 2013
  4. Project Manager Report: August 30 2013
  5. Project Manager Report: September 06 2013 - No Report this week. PM was out of the office.