8000 Working Groups with necessary bylaw changes by vanderaj · Pull Request #153 · OWASP/www-policy · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Working Groups with necessary bylaw changes #153

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

vanderaj
Copy link
Member

This PR creates the necessary framework for working groups, and minimally updates the bylaws to allow the rapid creation and dissolution of working groups.

Please comment by no later than May 28, 2025, so this can be brought to a vote in the May Board meeting.

@vanderaj vanderaj self-assigned this Apr 28, 2025
@vanderaj vanderaj requested a review from Copilot April 28, 2025 03:34
Copy link
@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces a new Working Groups Policy and updates existing policies to support the rapid creation and dissolution of working groups, as well as making necessary adjustments to the bylaws.

  • Introduces a new Working Groups policy document outlining structure, governance, and operational procedures.
  • Updates the Committees policy document to clarify that Working Groups guidance takes precedence for WG matters.
  • Modifies the bylaws to include Working Groups and delegates authority to create or disband Committees or Working Groups.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
operational/working-groups.md New draft policy for Working Groups, including detailed guidelines for establishment and operation.
operational/committees.md Added notice indicating that the Working Groups policy takes precedence during the review period.
legal/bylaws.md Revised clause (b) and added clause (d) to incorporate Working Groups and assign related authority.

@@ -339,10 +339,12 @@ Each member of a Board Committee shall serve for such term as shall be establish

(a) A Project Committee of the Foundation is hereby established, which may have such Sub-Groups as from time to time may be approved by the Board of Directors. The Project Committee and its Sub-Groups shall be the principal Member-level forum for the discussion and preliminary adoption of technical strategy and standards, subject to the review, and within the strategic direction established by, the Board of Directors and such Member Committee shall otherwise have such rights and privileges as shall from time to time be established by the Board of Directors, or as set forth in such Project Committee charter, rules, and policies as shall have been previously adopted by the Board of Directors. The Project Committee may make technical recommendations to the Board of Directors concerning technical strategy and other technical work products of the Foundation and may undertake such other tasks as may from time to time be established by the Board of Directors, provided that all strategies and standards may only be finally adopted by the Board of Directors

(b) From time to time, the Board of Directors may establish additional Member Committees. Each Member, so long as it remains a Member in good standing, shall be entitled to appoint such representatives to each such Member Committee, with such voting rights (if any), as set forth in Article II. Unless otherwise specified in these By-laws or by the Board of Directors, each Member Committee may have such sub-groups, working groups, and other groups as from time to time may be approved by such Member Committee, within the strategic direction established by the Board of Directors (each a "Sub-Group")
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I know this text wasn't modified but I'm left wondering:

Each Member, so long as it remains a Member in good standing

Is this supposed to be about people? If so then a better word than "it" should be used IMHO.


## Operations and Decision-Making

Working Groups must maintain transparent, consensus-driven decision-making processes. Regular meetings shall be scheduled with clear agendas distributed in advance, concise documentation of decisions, and prompt follow-up of assigned actions. Meetings should be operationally efficient, action-oriented, and inclusive.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

action-oriented, inclusive, and public.

?

Comment on lines +53 to +55
WG Chairs are required to submit quarterly Chairs Reports to the Executive Director and OWASP Board, providing concise updates on achievements, challenges, and upcoming objectives.

The Chairs report will directly inform decisions to be made by the Executive Director regarding WG continuation, modification, or sunset.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Capital on "Reports" or not? To be consistent between the two sentences.

@@ -339,10 +339,12 @@ Each member of a Board Committee shall serve for such term as shall be establish

(a) A Project Committee of the Foundation is hereby established, which may have such Sub-Groups as from time to time may be approved by the Board of Directors. The Project Committee and its Sub-Groups shall be the principal Member-level forum for the discussion and preliminary adoption of technical strategy and standards, subject to the review, and within the strategic direction established by, the Board of Directors and such Member Committee shall otherwise have such rights and privileges as shall from time to time be established by the Board of Directors, or as set forth in such Project Committee charter, rules, and policies as shall have been previously adopted by the Board of Directors. The Project Committee may make technical recommendations to the Board of Directors concerning technical strategy and other technical work products of the Foundation and may undertake such other tasks as may from time to time be established by the Board of Directors, provided that all strategies and standards may only be finally adopted by the Board of Directors

(b) From time to time, the Board of Directors may establish additional Member Committees. Each Member, so long as it remains a Member in good standing, shall be entitled to appoint such representatives to each such Member Committee, with such voting rights (if any), as set forth in Article II. Unless otherwise specified in these By-laws or by the Board of Directors, each Member Committee may have such sub-groups, working groups, and other groups as from time to time may be approved by such Member Committee, within the strategic direction established by the Board of Directors (each a "Sub-Group")
(b) From time to time, the Board of Directors may establish additional Member Committees, or Working Groups, and additionally, delegate the authority to create or disband Committees or Working Groups to the Executive Director. Each Member, so long as it remains a Member in good standing, shall be entitled to appoint such representatives to each such Member Committee, with such voting rights (if any), as set forth in Article II. Unless otherwise specified in these By-laws or by the Board of Directors, each Member Committee may have such sub-groups, working groups, and other groups as from time to time may be approved by such Member Committee, within the strategic direction established by the Board of Directors (each a "Sub-Group").

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Doesn't seem like the Board can disband committees, might want to change it to read "may establish or disband"

@@ -339,10 +339,12 @@ Each member of a Board Committee shall serve for such term as shall be establish

(a) A Project Committee of the Foundation is hereby established, which may have such Sub-Groups as from time to time may be approved by the Board of Directors. The Project Committee and its Sub-Groups shall be the principal Member-level forum for the discussion and preliminary adoption of technical strategy and standards, subject to the review, and within the strategic direction established by, the Board of Directors and such Member Committee shall otherwise have such rights and privileges as shall from time to time be established by the Board of Directors, or as set forth in such Project Committee charter, rules, and policies as shall have been previously adopted by the Board of Directors. The Project Committee may make technical recommendations to the Board of Directors concerning technical strategy and other technical work products of the Foundation and may undertake such other tasks as may from time to time be established by the Board of Directors, provided that all strategies and standards may only be finally adopted by the Board of Directors

(b) From time to time, the Board of Directors may establish additional Member Committees. Each Member, so long as it remains a Member in good standing, shall be entitled to appoint such representatives to each such Member Committee, with such voting rights (if any), as set forth in Article II. Unless otherwise specified in these By-laws or by the Board of Directors, each Member Committee may have such sub-groups, working groups, and other groups as from time to time may be approved by such Member Committee, within the strategic direction established by the Board of Directors (each a "Sub-Group")
(b) From time to time, the Board of Directors may establish additional Member Committees, or Working Groups, and additionally, delegate the authority to create or disband Committees or Working Groups to the Executive Director. Each Member, so long as it remains a Member in good standing, shall be entitled to appoint such representatives to each such Member Committee, with such voting rights (if any), as set forth in Article II. Unless otherwise specified in these By-laws or by the Board of Directors, each Member Committee may have such sub-groups, working groups, and other groups as from time to time may be approved by such Member Committee, within the strategic direction established by the Board of Directors (each a "Sub-Group").

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Each Member, so long as it remains a Member in good standing, shall be entitled to appoint such representatives to each such Member Committee, with such voting rights (if any), as set forth in Article II.

As written, any OWASP member can appoint representatives. Is it supposed to be Board Members? Or members of the committee/group/etc? And whoever it is that appoints, should they also be able to rescind?


Working Groups are proposed by OWASP Members. Proposals to create a WG must be clearly aligned with OWASP’s strategic priorities and demonstrate tangible benefit to the OWASP community.

Proposals must be submitted in the form of a Scope and Programme of Work and submitted to the OWASP Executive Director. The Scope and Programme of Work shall clearly describe:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"Programme" is a UK spelling. Not sure if we care here?


Operational responsibility for vetting potential WG Chairs lies with the OWASP Executive Director or an appointed staff representative. Candidates must demonstrate sufficient expertise, relevant professional experience, and alignment with OWASP’s core values.

The Executive Director is responsible for confirming appointments of WG Chairs following successful vetting, formally documenting decisions, and communicating appointments clearly to all parties involved.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Who can remove Chairs? Should Chairs be re-confirmed annually? Should there be term limits to enable fresh perspectives? Or annual votes within the committee for Chair?


## Working Group Participation

Participation in Working Groups is open to anyone with relevant interest and willingness to actively contribute, including non-members of OWASP. WG Chairs are responsible for clearly communicating participant expectations, maintaining a welcoming environment, and ensuring adherence to OWASP’s Code of Conduct.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds like anyone can participate. Is there a mechanism to remove / bar participants that are disruptive?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants
0