This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Project Manager Activity Reports/February 18 2013"

From OWASP
Jump to: navigation, search
Line 129: Line 129:
 
#Status: Awarded.  
 
#Status: Awarded.  
 
#Note: There is no link to show the proposal for this grant. There was a form that was submitted to Google, and we did not receive a record of this form.  
 
#Note: There is no link to show the proposal for this grant. There was a form that was submitted to Google, and we did not receive a record of this form.  
 +
#[https://www.owasp.org/images/e/ed/2013_Campaign_Report.pdf Google Grants Usage Report]
  
 
*'''Google Summer of Code'''
 
*'''Google Summer of Code'''
Line 140: Line 141:
 
**1 Hackademics Project: $500
 
**1 Hackademics Project: $500
 
**1 Modsecurity Project: $500
 
**1 Modsecurity Project: $500
 +
**Travel Expenses: $1,896.38 (Reimbursement)
 
**Note: Big thank you to Fabio Cerullo for coordinating and managing this award.  
 
**Note: Big thank you to Fabio Cerullo for coordinating and managing this award.  
  
Line 170: Line 172:
 
# Status: Denied
 
# Status: Denied
  
 +
==Current Project Funds==
  
=PROJECT ANNOUNCEMENTS=
+
* [https://docs.google.com/a/owasp.org/spreadsheet/pub?hl=en_US&hl=en_US&key=0Atu4kyR3ljftdEdQWTczbUxoMUFnWmlTODZ2ZFZvaXc&output=html Chapter and Individual Project Funds]
 +
* [https://www.owasp.org/index.php/Projects_Reboot_2012 Project Reboot 2012 Information]
 +
* [https://www.owasp.org/images/a/ae/Project_Funds-Q1_2013.pdf Q1 2013: Funds Allocated to Projects]
 +
* [https://www.owasp.org/images/a/a0/PROJECT_FUNDS_Q2_2013.pdf Q2 2013: Funds Allocated to Projects]
 +
* [https://www.owasp.org/images/c/ce/Due_To_Projects_Q3.pdf Q3 2013: Funds Allocated to Projects]
 +
* [https://www.owasp.org/images/b/b3/Due_To_Projects_Q4_2013.pdf Q4 2013: Funds Allocated to Projects]
  
==Message from Project Leader, Larry Conklin: OWASP Code Review Guide==
 
  
Eoin and I had the great pleasure to present the Code Review Guide 2.0 project at APPSECUSA2013.  I want to thank everyone involved in the project and to give you my personal thank you. It was very much an honor to talk about our success and hard work. We are not done but I feel we surprised a lot of people with how much work a few dedicated volunteers have done.
+
=PROJECT ANNOUNCEMENTS=
 
 
Please don't loose sight of the end but we are getting closer. Below is our wiki pages loaded into a word doc. Yes, it is rough, but we made sure everyone knew it was an early release document. Also my ppt is included attached.
 
 
 
Larry Conklin, CISSP
 
  
*[https://www.owasp.org/images/f/fa/Code_Review_Guide_Pre-AlphaV2_%281%29.pdf Code Review Guide: ALPHA]
+
==CISO Guide Survey Report 2013 V1.0 Released==
  
*[https://www.owasp.org/images/f/f7/APPSEC2013-CRV2.pdf Code Review Guide AppSec USA 2013 Presentation]
+
'''[https://www.owasp.org/index.php/OWASP_CISO_Survey OWASP CISO Survey Report 2013 Version 1.0]'''
 +
 +
Among application security stakeholders, Chief Information Security Officers (CISOs), are responsible for application security from governance, compliance and risk perspectives. The OWASP CISO Survey provides tactical intelligence about security risks and best practices to help CISOs manage application security programs according to their own roles, responsibilities, perspectives and needs. It also complements nicely with its sister project, the Application Security Guide For CISOs.
  
==Message from Project Leader, Jonathan Marcil: OWASP Media Project==
+
* Report: https://www.owasp.org/index.php/OWASP_CISO_Survey
 +
* PDF Download: https://www.owasp.org/index.php/File:Owasp-ciso-report-2013-1.0.pdf
  
Hi leaders,
+
'''Please share and spread the word!'''
  
I'm glad to announce that we have 43 online talks for 32 hours of
+
==[https://www.owasp.org/index.php/OWASP_Research_Book_Project OWASP Research Book Project]==
content from AppSecUSA 2013. Some have been available since the day
 
after the first day of the conference and we've been added them
 
gradually in the past week.
 
  
And now the links:
+
The [https://www.owasp.org/index.php/OWASP_Research_Book_Project OWASP Research Book Project] is a new Incubator project that aims to collect and consolidate a collection of research papers that have been donated to OWASP. Ahmed Neil is currently looking for contributors and authors to help him work on his idea. He hopes to be able to move this project forward as soon as he is able to gather some interest in the project. If you are interested, please contact Ahmed Neil ([email protected]).
  
Playlist, all the recorded talks are available on this page:
+
==Webinar Opportunity for OWASP Project Leaders==
https://www.youtube.com/playlist?list=PLpr-xdpM8wG8ODR2zWs06JkMmlRiLyBXU
 
Short URL: http://sl.owasp.org/usa13_videos
 
  
YouTube, people will be able to see AppSecUSA featured contents on:
+
We are still in need for Project Leaders to showcase their projects via our Webinar series. The webinars will be held every third (3) Wednesday of every month at 10am EST. Below are the dates when each webinar will be held, and you can indicate the month if you are interested:
https://www.youtube.com/owaspglobal
 
  
Link directly to the whole playlist beginning with the first talk:
+
*February 19
https://www.youtube.com/watch?v=pYFtLA2yTR8&list=PLpr-xdpM8wG8ODR2zWs06JkMmlRiLyBXU&index=1
+
*March 19
 +
*April 16: Cam Morris
 +
*May 21
 +
*June 18
 +
*July 16
 +
*August 20
 +
*September 17
 +
*October 15
 +
*November 19
 +
*December 17
  
 +
Please reach out to Samantha Groves ([email protected]) if you are interested in giving a 45 minute webinar on your OWASP Project.
  
If you want to help, go watch and "Like" the ones you prefer, share them
+
==Project Review Assistance Required==
and subscribe to the channel.
 
  
Thanks,
+
Hello Leaders,
  
Jonathan Marcil
+
We are still in need of more survey results. We would like to ask that you take a bit of time to fill in a short survey that we will use to assess the Usability and Value of each project to its users and the community. 
  
==Message from Project Leader, Jim Manico: OWASP Podcast Series==
+
You can find the assessment survey here: [https://docs.google.com/a/owasp.org/forms/d/1K2fXppFhAuuus34J5zpafFUw7dWyAXT0_v5sH6OsnHY/viewform Project Usability and Value Assessment]
  
Leaders,
+
Below are the projects we are currently focusing on assessing:
  
I am very excited to pass the OWASP Podcast baton over to Mark Miller. Mark is a very experienced podcaster who will be taking over as Executive producer and host of the OWASP Podcast.
+
*[https://www.owasp.org/index.php/Cheat_Sheets OWASP Cheat Sheets Project]
 +
*[https://www.owasp.org/index.php/OWASP_Java_HTML_Sanitizer_Project OWASP Java HTML Sanitizer Project]
 +
*[https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework Xenotix XSS Exploit Framework]
 +
*[https://www.owasp.org/index.php/OWASP_Cornucopia OWASP Cornucopia Project]
 +
*[https://www.owasp.org/index.php/OWASP_Java_Encoder_Project OWASP Java Encoder Project]
 +
*[https://www.owasp.org/index.php/OWASP_Project_Inventory#Flagship_Projects All OWASP Flagship Projects]
 +
 +
Please note that this is only one part of the full assessment for each project. The more responses we can get for each project, the better. Please only complete the assessment if you are familiar with the project, or if you have time to familiarize yourself with the project. Thank you to those of you who have submitted your responses. Your assistance is very much appreciated.  
  
There will be a little overlap. I will be posting to https://www.owasp.org/download/jmanico/podcast.xml for just three more shows and will end my feed with OWASP Podcast #100 by the end of the year.
+
Please reach out to me if you have any questions.  
  
Please enjoy the new OWASP Podcast feed from Mark Miller. http://feeds.soundcloud.com/users/soundcloud:users:63303345/sounds.rss will will be the new RSS address for the podcast moving forward.
+
Thank you for your assistance, Leaders.  
  
Jim
+
Samantha Groves, OWASP Projects Manager
  
  
 
__NOTOC__ <headertabs />
 
__NOTOC__ <headertabs />

Revision as of 01:16, 19 February 2014

OWASP Project Header.jpg

Metrics

DATE August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 (thus far)
TOTAL 168 Active Projects 134 Active Projects 142 Active Projects 144 Active Projects 149 Active Projects 160 Active Projects 170 Active Projects


  • Project Numbers
  • Active Projects: 170
  • Inactive Projects: 102
  • Incubator Projects: 116
  • Lab Projects:18
  • Flagship Projects: 15

New OWASP Projects

Projects Under Review

Project Manager Q4 2013 Objectives

  1. Finish planning Project Summit & Execute Summit at AppSec USA.
  2. Develop & Finish Global Projects Strategy for 2014: Includes Budget.
  3. Finish Fundraising Strategy for 2014: Includes Budget.
  • Ongoing Objectives for 2013
    • Quarterly Report to DHS.
    • Continue helping leaders reach their grant required milestones.
    • Finalize graphic design delivery from Patrick: 2 pieces to go. Done.

OWASP Project Manager Weekly Reports


  • Project Leader Workshop Overview
    • The project leader workshop went very well during AppSec USA.
    • There was lots of discussion brought on by the project leaders.
    • There were a few potential project leaders as well.
    • The forum went well with a presentation of information followed by discussion.
    • It was also important to allow Leaders to interrupt the talk to ask questions.
    • I felt the way it was organized should be used as a framework for future project leader workshops.
    • 45 minutes was not enough as well.
    • I suggest leaving 1 hour and 30 minutes for the session.
  • 2013 Project Summit Overview
    • I believe the project summit was a great success.
    • I was a bit nervous about it as I had never even done one before.
    • However, a good amount of Leaders helped me put this together, and it is thanks to them that this summit was such a great success.
    • There were many lessons learned, and I am working towards putting together a post summit document for the community.
  • Women in AppSec: AppSec USA 2013 Overview
    • I think the Women in AppSec program went very well at AppSec USA.
    • Both winners let me know that they really enjoyed themselves, and they were glad to participate in the panel.
    • Kait, our Grants and Fundraising intern, kindly helped me manage the Women in AppSec schedules and timetables at the conference.
    • We are not working on post event administration for the program.
  • OWASP Marketing
    • I am glad to say that the marketing materials have now all been delivered.
    • Patrick is in the process of delivering the final invoice for work completed.
  • Project Guidelines
    • There was a good amount of discussion regarding the project guidelines during the conference and at the board meeting.
    • There are a few changes to make, and I am working on getting these done by the end of this week.
  • Daily Project based queries and requests
    • This has not changed much since I began the post: questions are very similar in nature.
    • Global AppSec questions.
    • Funding queries.
    • Travel availability.
    • Project based administrative help.
    • Project status information.
    • Several project donation questions.
    • Marketing questions.
    • Grant funding questions.
    • OWASP social media updates.
    • What's happening with projects, questions.

General Awards

  • OWASP OWTF Project: Brucon 5x5 Award
  1. Amount: €5,000.00 (Approx. $6,670.00)
  2. Status: Awarded. Congratulations, Abraham Aranguren and all involved in the project, for your award.

Proposals Awarded

  1. Amount: $25,000 USD
  2. Status: Awarded. The first payment has been allocated to our project budgets. The second invoice has now been sent to Georgia Tech and payment has been received.
  3. OWASP Development Guide Plan
  4. OWASP Testing Guide Plan
  5. OWASP Code Review Guide Plan
  • Google Grants Proposal
  1. Amount: $120,000 USD in Adwords Funds
  2. Status: Awarded.
  3. Note: There is no link to show the proposal for this grant. There was a form that was submitted to Google, and we did not receive a record of this form.
  4. Google Grants Usage Report
  • Google Summer of Code
  1. Amount: $5,500
  2. Status: Awarded
  • Projects breakdown:
    • 4 ZAP Projects: $2,000
    • 4 OWTF Projects: $2,000
    • 1 PHP Security Project: $500
    • 1 Hackademics Project: $500
    • 1 Modsecurity Project: $500
    • Travel Expenses: $1,896.38 (Reimbursement)
    • Note: Big thank you to Fabio Cerullo for coordinating and managing this award.
  1. Amount: $15,000 USD
  2. Status: Awarded.
  • Total Funds Awarded: $172,170 USD for 2013.

Proposals Denied

  • European Commission Grant Proposal
  1. Amount: €250,000
  2. Status: Denied.
  1. Amount: $112,000 USD
  2. Status: Denied
  1. Amount: $25,000 USD
  2. Status: Denied
  1. Amount: $30,000 USD
  2. Status: Denied
  1. Amount: $55,800 USD
  2. Status: Denied

Current Project Funds


CISO Guide Survey Report 2013 V1.0 Released

OWASP CISO Survey Report 2013 Version 1.0

Among application security stakeholders, Chief Information Security Officers (CISOs), are responsible for application security from governance, compliance and risk perspectives. The OWASP CISO Survey provides tactical intelligence about security risks and best practices to help CISOs manage application security programs according to their own roles, responsibilities, perspectives and needs. It also complements nicely with its sister project, the Application Security Guide For CISOs.

Please share and spread the word!

OWASP Research Book Project

The OWASP Research Book Project is a new Incubator project that aims to collect and consolidate a collection of research papers that have been donated to OWASP. Ahmed Neil is currently looking for contributors and authors to help him work on his idea. He hopes to be able to move this project forward as soon as he is able to gather some interest in the project. If you are interested, please contact Ahmed Neil ([email protected]).

Webinar Opportunity for OWASP Project Leaders

We are still in need for Project Leaders to showcase their projects via our Webinar series. The webinars will be held every third (3) Wednesday of every month at 10am EST. Below are the dates when each webinar will be held, and you can indicate the month if you are interested:

  • February 19
  • March 19
  • April 16: Cam Morris
  • May 21
  • June 18
  • July 16
  • August 20
  • September 17
  • October 15
  • November 19
  • December 17

Please reach out to Samantha Groves ([email protected]) if you are interested in giving a 45 minute webinar on your OWASP Project.

Project Review Assistance Required

Hello Leaders,

We are still in need of more survey results. We would like to ask that you take a bit of time to fill in a short survey that we will use to assess the Usability and Value of each project to its users and the community.

You can find the assessment survey here: Project Usability and Value Assessment

Below are the projects we are currently focusing on assessing:

Please note that this is only one part of the full assessment for each project. The more responses we can get for each project, the better. Please only complete the assessment if you are familiar with the project, or if you have time to familiarize yourself with the project. Thank you to those of you who have submitted your responses. Your assistance is very much appreciated.

Please reach out to me if you have any questions.

Thank you for your assistance, Leaders.

Samantha Groves, OWASP Projects Manager