Hi Mark

Great news,

See my comments below

On 5 Jun 2010, at 17:30, Mark Bristow <mark.bristow at owasp.org> wrote:


The Department of Homeland Security's Software Assurance Forum has
generously provided us with a full day with which to present OWASP projects
and initiatives and we thought this training would be perfect for the
audience at the SwA forum.

This is a great opportunity and we should really make it happen

We did have some questions about the event logistics.  It's my understanding
that the costs are covered out of local chapter funds,

Yes that is the starting point

however what was not clear was the speaker lineup.  Are we supposed to use
your speaker lineup (many of which are intl and would likely exceed our
chapter funds) or can we cover the topics with local resources?

I would say that you should try to find as many local OWASP leaders as

Start with the actual project leaders (Jeff on Top 10, Bruce on WebGoat,
Dave on Top 10, etc..) and then go for the most experienced and reputable
OWASP leaders (i.e. ones have done successful presentations at our

I don't think you need to bring anybody from Europe (you should have enough
talent over there :) ). You should also adjust the schedule to give local
OWASP leaders (at least) a 20m slot to present his project (this is what we
did in London for tools like DirBuster)

On the funding question, here are a couple pointers:

 * Yes you should start with the funds available to the local chapter they
are the easiest to use (and make decisions on). The local chapter has full
decision making power on where to spend these funds  (as long as they are
not paying any OWASP leaders)

 * Note that in London, after taking into account the revenue received from
the 19 new OWASP members that we got, the final cost of theses events for
the London chapter was not that high (and this is not taking into account
that (due to the training) we have a couple strong Corporate memberships on
the way)

 * The SwA events seem to me to be quite a critical and important event for
OWASP, so I would propose that we should try to present the strongest
possible line-up of OWASP leaders, and if there is a need for an extra top
up, as a board member I can give you cover for 2,500 USD, and if more is
needed I'll take it to the Board for decision/approval.

Additionally, we would have to make our event free for all SwA attendees (US
Govt or their guests) in order to make this sucessful, therefore dropping
the Membership requirement (at least this time around).

That is exactly what we did in London, The first event was hosted by British
Airways and the 2nd by Lloyds. Both are NOT current OWASP corporate members,
and the deal was that they would provide the venue (and some coffees) and
bring in up to 15 attendees.

So, yes you can make a model where US Govt + guest don't have to be members
(with the other attendees having to be an OWASP member or part of a company
that is an OWASP Educational Supporter or Corporate member)

Since this has quite a high profile, I think you should email the
owasp-leaders list with the RFP (Request for Presenters (Paulo has an email
template you can use)) and see which OWASP Leaders are available to attend.

But the first step is a date, when do you want to do it?




