This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Projects/Reports/2014-02-05"

From OWASP
Jump to: navigation, search
 
Line 27: Line 27:
 
=CURRENTLY WORKING ON=       
 
=CURRENTLY WORKING ON=       
  
*'''OSS in Cambridge'''
+
*'''Project Activity Modules in Cambridge UK'''
**I am happy to report that we now have 8 applicants for the Open Source Showcase.  
+
**I am happy to report that we now have enough submissions to run the OSS.
**I asked the community to help spread the word, and we were successful in getting the applications we needed to move the activity forward.  
+
**We also have 5 submitted and confirmed working sessions for the summit.  
**We put together this blog post to announce the opportunity: [http://owasp.blogspot.com/2014/04/open-source-showcase-demo-your-project.html OSS at AppSec EU]
+
**Here is the current schedule:  
**We hope to get more submissions in the coming weeks.  
+
**Please contact Kait.Disney.Leugers@owasp.org if you would like to submit a summit session.  
**I have also worked with Kelly this week to put together a sponsorship proposal so she cal sell to potential sponsors for the OSS.
+
**I have also worked with Kelly a sponsorship proposal so she cal sell to potential sponsors for the OSS and the summit.
 
**We are asking for $5K per sponsor.  
 
**We are asking for $5K per sponsor.  
 +
**Please contact [email protected] if you are interested in sponsoring these event modules.
  
*'''Project Summit 2014'''
+
*'''All OWASP Flagship Projects Demoted'''
**I have been working with the AppSec EU team to organize the 2014 Project Summit.
+
**OWASP no longer has any projects under the flagship designation in its inventory.
**I have been trying to promote the event like crazy these past few weeks, but I am not getting too many submissions.
+
**The board made a decision to promote all of the projects this past Wednesday.
**I am having to reach out to Leaders directly to invite them to join in.  
+
**We will not move projects up to this designation until a new model is decided on.  
**We currently have 3 summit sessions, but I need more.
 
**We are also seeking 10K USD sponsorship for the summit.
 
**I worked with Kelly this week to put together a sponsorship proposal so she cal sell to potential sponsors for the Summit.
 
**We are asking for $5K per sponsor, as well.
 
 
 
*'''Project Reviews'''
 
**Sarah and I spoke about the reviews and the process that was created by the Technical Advisory Board.
 
**We decided to move forward with the reviews using the forms and process we created at the [https://www.owasp.org/images/c/c3/OWASP_2013_PROJECT_SUMMIT_REPORT.pdf 2013 Summit].
 
**The only catch is that we are dropping the Open Samm questionnaire, and we are only using the Project Quality and Health assessments.
 
**Here are the two forms we are using:
 
**[https://docs.google.com/a/owasp.org/forms/d/1mZ9QJDOS0jYaWDPCooxaa_BZPD7zm5U0REnMjt0RRoM/viewform Project Health]
 
**[https://docs.google.com/a/owasp.org/forms/d/1UUSrQySyvwQPq_KzhF6Q-9wvOptvLiDzNSjdXwiPOPg/viewform Project Quality: Code and Tool]
 
**[https://docs.google.com/a/owasp.org/forms/d/1TSj-V-rkngi1crB6BjOqabsCcjOVDjHKSelSitBqRU4/viewform Project Quality: Documentation]
 
**Simon Bennetts and Johanna Curiel completed a full review of the OWTF Project this week using this process.
 
**This is the first time the full process has been used to review and graduate a project.
 
**The OWASP OWTF Project is now a Lab Project.  
 
**See the full review report here: [https://www.owasp.org/images/4/49/OWASP_Project_Review-OWTF_Project.pdf OWASP OWTF Project Review Results]
 
  
 
*'''Project Task Force'''
 
*'''Project Task Force'''
**The Project Task Force is getting on with operational project tasks.
+
**The Project Task Force is still going strong.
**I am so glad this is working so well.
+
**If you want to get involved, please see the links below.
**We are underway with our project active/inactive audit.
+
**There is lots of work to do.  
**We have already eliminated over 10 projects from the active project inventory.
 
**This group will focus on getting stuff done for our OWASP Projects.  
 
**There are quite a few tasks that we need to get sorted so please join in if you are interested in helping out.  
 
 
**[https://www.owasp.org/index.php/Category:OWASP_Project#tab=Project_Task_Force Project Task Force Page]  
 
**[https://www.owasp.org/index.php/Category:OWASP_Project#tab=Project_Task_Force Project Task Force Page]  
 
**[https://groups.google.com/forum/#!forum/owasp-projects-task-force Google Group Page]
 
**[https://groups.google.com/forum/#!forum/owasp-projects-task-force Google Group Page]
  
 
*'''Graphic Design: Hugo'''
 
*'''Graphic Design: Hugo'''
**Hugo has completed some amazing design projects this week.
+
**Hugo has had his work cut out for him, but he is excellent.
**Below are some of the examples of his work:
+
**He is working on a few books at the moment, and has a Top Ten re-design in his queue.
**[https://www.owasp.org/images/3/3a/CodeReviewCover_2014.pdf Code Review Guide Book Covers]
+
**I am excited to see what he comes up with.  
**[https://www.owasp.org/images/8/86/Testing_Guide_V4_final.pdf Testing Guide Book Cover]
 
**[https://www.owasp.org/images/8/8a/Cambridge_2014_flyer_curves.pdf AppSec EU Triptic Brochure]
 
  
 
*'''Projects Intern: Kait'''
 
*'''Projects Intern: Kait'''
**Kate has been helping me with different administrative project duties this week.
+
**Kait has quite the work load this next week, as well.
**She is working on getting some additional metrics we need for our project inventory.
+
**She will be helping to monitor the task force while I am away.
**She is also working on reaching out to leaders and finding out if their projects are inactive or not.
+
**She is currently undertaking the project activity tasks.
**We will do this first pass, and then I want to give the list to Johanna so she can do a more thorough pass.  
+
**May 9th is the last time she will be contacting leaders about their project activity so please respond to her queries.  
**Kait is also helping with promotion of the OSS, Summit, and Women in AppSec.  
 
  
 
*'''Daily Project based queries and requests'''
 
*'''Daily Project based queries and requests'''

Latest revision as of 01:15, 3 May 2014

OWASP Project Header.jpg

Metrics

  • Active Projects: 171
  • Inactive Projects: 112
  • Incubator Projects: 138
  • Lab Projects: 33
  • Flagship Projects: 0

OWASP Project of the Month

Passfault01.jpg

AppSecEU 2014.jpg

  • Project Activity Modules in Cambridge UK
    • I am happy to report that we now have enough submissions to run the OSS.
    • We also have 5 submitted and confirmed working sessions for the summit.
    • Here is the current schedule:
    • Please contact [email protected] if you would like to submit a summit session.
    • I have also worked with Kelly a sponsorship proposal so she cal sell to potential sponsors for the OSS and the summit.
    • We are asking for $5K per sponsor.
    • Please contact [email protected] if you are interested in sponsoring these event modules.
  • All OWASP Flagship Projects Demoted
    • OWASP no longer has any projects under the flagship designation in its inventory.
    • The board made a decision to promote all of the projects this past Wednesday.
    • We will not move projects up to this designation until a new model is decided on.
  • Graphic Design: Hugo
    • Hugo has had his work cut out for him, but he is excellent.
    • He is working on a few books at the moment, and has a Top Ten re-design in his queue.
    • I am excited to see what he comes up with.
  • Projects Intern: Kait
    • Kait has quite the work load this next week, as well.
    • She will be helping to monitor the task force while I am away.
    • She is currently undertaking the project activity tasks.
    • May 9th is the last time she will be contacting leaders about their project activity so please respond to her queries.
  • Daily Project based queries and requests
    • This has not changed much since I began the post: questions are very similar in nature.
    • Global AppSec questions.
    • Funding queries.
    • Travel availability.
    • Project based administrative help.
    • Project status information.
    • Several project donation questions.
    • Marketing questions.
    • Grant funding questions.
    • OWASP social media updates.
    • What's happening with projects, questions.
    • Managing Salesforce cases.

General Awards

  • OWASP OWTF Project: Brucon 5x5 Award
  1. Amount: €5,000.00 (Approx. $6,670.00)
  2. Status: Awarded. Congratulations, Abraham Aranguren and all involved in the project, for your award.

Proposals Awarded

  1. Amount: $25,000 USD
  2. Status: Awarded. The first payment has been allocated to our project budgets. The second invoice has now been sent to Georgia Tech and payment has been received.
  3. OWASP Development Guide Plan
  4. OWASP Testing Guide Plan
  5. OWASP Code Review Guide Plan
  • Google Grants Proposal
  1. Amount: $120,000 USD in Adwords Funds
  2. Status: Awarded.
  3. Note: There is no link to show the proposal for this grant. There was a form that was submitted to Google, and we did not receive a record of this form.
  4. Google Grants Usage Report
  • Google Summer of Code
  1. Amount: $5,500
  2. Status: Awarded
  • Projects breakdown:
    • 4 ZAP Projects: $2,000
    • 4 OWTF Projects: $2,000
    • 1 PHP Security Project: $500
    • 1 Hackademics Project: $500
    • 1 Modsecurity Project: $500
    • Travel Expenses: $1,896.38 (Reimbursement)
    • Note: Big thank you to Fabio Cerullo for coordinating and managing this award.
  1. Amount: $15,000 USD
  2. Status: Awarded.
  • Total Funds Awarded: $172,170 USD for 2013.

Proposals Denied

  • European Commission Grant Proposal
  1. Amount: €250,000
  2. Status: Denied.
  1. Amount: $112,000 USD
  2. Status: Denied
  1. Amount: $25,000 USD
  2. Status: Denied
  1. Amount: $30,000 USD
  2. Status: Denied
  1. Amount: $55,800 USD
  2. Status: Denied

Current Project Funds

2014 OWASP Project Summit: Need Working Session Ideas!

The 2014 OWASP Project Summit will be taking place during AppSec EU 2014 in Cambridge, UK, and we need your help to make it our best Project Summit yet. We are calling on all OWASP Project Leaders to submit your project to participate in this year’s Summit. The Project Summit is a great opportunity to reach project milestones, as well as receive feedback from the OWASP community by enlisting new volunteers to your project.

Help shape the 2014 Project Summit by submitting to lead a working session. We would also, like your feedback on what tracks and session you would like to see at the Summit. The planning team would like your input on ideas to creating a productive event this year. The Summit team will take your ideas, and develop a comprehensive schedule that suits the needs of our Project Leaders and community.

Help make the 2014 Project Summit in Cambridge a great success for OWASP Projects. Submit your ideas for tracks and sessions to Samantha Groves ([email protected]) and Kait Disney-Leugers ([email protected]).

Open Source Showcase: Demo your Project at AppSec EU 2014!

As part of AppSec EU, the conference organizers are looking for projects to participate in the Open Source Showcase. The Open Source Showcase is a unique event module that allows project leaders and/or project contributors to showcase their work in a demo setting and gain exposure for their projects without the need to conduct a full talk session. The showcase allows a more personal view of the project between attendees.

The guidelines for submitting to the Open Source Showcase are simple: the Open Source Showcase is open to ANY project - not just OWASP projects. The only requirement for submission is that the project must be licensed under an approved Open Source License.

All open source projects are encouraged to apply to take part in the Open Source Showcase at AppSec EU 2014 in Cambridge, UK. The application form can be found here: Submission Form.

If you have additional questions, please contact the AppSec EU 2014 Planning Team ([email protected]).

Webinar Opportunity for OWASP Project Leaders

We are still in need for Project Leaders to showcase their projects via our Webinar series. The webinars will be held every third (3) Wednesday of every month at 10am EST. Below are the dates when each webinar will be held, and you can indicate the month if you are interested:

  • May 21: Jonathan Carter
  • June 18
  • July 16
  • August 20
  • September 17
  • October 15
  • November 19
  • December 17

Please reach out to Samantha Groves ([email protected]) if you are interested in giving a 45 minute webinar on your OWASP Project.

"OWASP 24/7" with Mark Miller is a series of recorded broadcasts, highlighting OWASP projects and people from around the world. With over 43,000 members in 100 countries, the OWASP 24/7 channel is available on demand, at anytime, anywhere on the planet. You are welcome to embed the broadcasts on your page, download them for your personal listening or keep up to date by subscribing to the iTunes channel. Please view the Podcast Project page for a list of current interviews.


View All Available Broadcasts or choose a single episode below


Upcoming interviews

  • Kevin Wall (ESAPI)
  • Andrew van der Stock (Pro-Active Controls)
  • Andrew van der Stock
  • Chetan Karande - Node.jsGoat
  • Mark Arnold - OWASP Boston Chapter Lead
  • Mike McCabe, Ken Johnson
  • Rafael Gil
  • Seba Deleersnyder