Rules of Procedure | Code of Conduct (original) (raw)

Rules of Procedure

Adopted by the Board of Directors on September 25, 2024

Participation in activities of The OWASP Foundation (“OWASP”) is conditional upon each such participant adhering to the requirements of this Code of Conduct. Accordingly, by participating in OWASP activities, each individual doing so agrees that when so participating and in connection with OWASP activities, such individual will comply with the following:

Conduct Generally

Reporting violations of this code of conduct

If a participant, member, Director or staff member has violated this code of conduct, please refer to the Whistleblower and Anti-Retaliation Policy to report the issue to a Compliance Officer or the Executive Director.

Sanctions

The Executive Director can suspend participation in OWASP for up to 30 days for perceived or actual breaches of this Code of Conduct or applicable law. Depending on the severity of the breach, the member or participant may be subject to longer suspension or other sanctions, including termination of participation or membership, by decision of the OWASP Board of Directors (“Board”).

For first time Code of Conduct breaches, where no violation of applicable law has occurred:

The member or participant may be subject to temporary suspension imposed by the Executive Director for all OWASP participation for up to 30 days. Membership will not be extended to cover the suspension.

For repeat or serious breaches of the Code of Conduct, or where a participant has been charged with a crime:

The Executive Director must suspend the member and refer the matter to the Compliance Team. The Compliance Team will then independently evaluate the matter and recommend to the Board either no action or proposed sanctions, which may include (but are not limited to) revocation of leadership position(s), participation, membership privileges and/or membership. The initial suspension will remain in place until after the Board votes on the matter.

If the Board decides to take no action: (a) full participation will be reinstated and (b) if the suspended participant was a member, their membership will be extended for a period equal to the duration of the suspension.

Transparency and Oversight

To provide transparency and oversight, the Executive Director will inform the Board of the actions being taken in connection with sanctions, including by informing the Compliance Team as required, providing applicable Compliance Team recommendations to the Board, and in concert with the Board, scheduling a Board vote as necessary. Referrals, reports, recommendations, and decisions made by the Executive Director, Compliance Team, or Board will be stored and kept confidential for a period of seven years.