Skip to content

Commit c7a3374

Browse files
committed
Three proposed social contract policies that many suppliers are now requiring
1 parent 02056d7 commit c7a3374

3 files changed

Lines changed: 297 additions & 3 deletions

File tree

Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
---
2+
3+
title: Anti–Modern Slavery and Human Trafficking Policy (DRAFT WIP)
4+
layout: col-document
5+
document: Rules of Procedure
6+
tags: Rules of Procedure
7+
notice: 2026-05-21
8+
9+
---
10+
11+
{% include draft-notice.html %}
12+
13+
## 1. Purpose
14+
15+
This policy affirms OWASP's commitment to preventing modern slavery, forced labor, and human trafficking in all areas of our work, supply chains, partnerships, and community activities. We uphold the dignity, safety, and human rights of every individual.
16+
17+
## 2. Scope
18+
19+
This policy applies to all staff, volunteers, contractors, suppliers, and partner organizations engaged in activities on behalf of the organization.
20+
21+
## 3. Our Commitment
22+
23+
We commit to:
24+
25+
- Zero tolerance for modern slavery, human trafficking, child labour, or any form of exploitation.
26+
- Conducting due diligence on suppliers, contractors, and partners to identify and mitigate risks.
27+
- Ensuring fair and safe working conditions across our operations and supply chains.
28+
- Providing training and awareness to staff and volunteers on identifying and reporting concerns.
29+
- Taking immediate, appropriate action if any instance of modern slavery is suspected or identified.
30+
31+
## 4. Reporting Concerns
32+
33+
Anyone connected to the organization may report concerns confidentially to the Executive Director or through the [whistleblower process](https://policy.owasp.org/operational/whistleblower). All reports will be taken seriously, investigated promptly, and handled with discretion to protect the rights and safety of all parties involved.
34+
35+
## 5. Responsibilities
36+
37+
- The Executive Director is responsible for implementing this policy and ensuring compliance, with oversight from the Board of Directors.
38+
- Staff and volunteers must remain vigilant, report concerns, and uphold ethical conduct.
39+
- Suppliers and partners must agree to comply with this policy as a condition of engagement.
40+
41+
## 6. Review
42+
43+
This policy will be reviewed annually or sooner if legislation, risk factors, or organizational activities change.

operational/antitrust.md

Lines changed: 107 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,118 @@
11
---
22

3-
title: Antitrust Policy for Board of Directors
3+
title: Antitrust, Anti Corruption, and Competition Policy (DRAFT WIP)
44
layout: col-document
55
document: Rules of Procedure
66
tags: Rules of Procedure
7-
notice: 2025-10-10
7+
notice: 2026-05-21
88

99
---
1010

11-
Approved by the Board of Directors: 2025-12-16
11+
{% include draft-notice.html %}
12+
13+
## 1. Purpose
14+
15+
The purpose of this policy is to ensure that the OWASP Foundation, Inc. and its Board of Directors conduct all activities in full compliance with applicable anti‑trust, competition, corruption, and anti‑bribery laws. As a global nonprofit stewarding open-source projects and community collaboration, OWASP must uphold the highest standards of fairness, independence, and ethical conduct.
16+
17+
This policy establishes expectations for Board members, volunteers, project leaders, and contributors to prevent anti‑competitive behavior, bribery, corruption, and improper influence.
18+
19+
## 2. Scope
20+
21+
This policy applies to:
22+
23+
- Members of the Board of Directors
24+
- Officers, employees, contractors, and volunteers
25+
- OWASP leaders, contributors, and maintainers
26+
- Any individual acting on behalf of OWASP
27+
- All OWASP programs, projects, events, partnerships, and community activities
28+
29+
## 3. Our Commitment
30+
31+
The OWASP Foundation, Inc. and its Board commit to:
32+
33+
### 3.1 Compliance With Anti‑Trust Laws
34+
35+
Board members must not engage in discussions or agreements—formal or informal—that could influence or distort the competitive marketplace in favor of one or more entities.
36+
37+
This includes avoiding:
38+
39+
- Collusion or coordination between competing organizations
40+
- Discussions of pricing, commercial strategy, or exclusionary practices
41+
- Sharing proprietary or confidential information that could affect competition
42+
- Using OWASP influence to benefit any particular company
43+
44+
### 3.2 Independent Decision‑Making
45+
46+
All decisions must be made solely in the best interest of OWASP’s mission and community.
47+
48+
### 3.3 Anti‑Bribery and Anti‑Corruption Standards
49+
50+
OWASP prohibits:
51+
52+
- Offering, giving, soliciting, or accepting bribes
53+
- Providing anything of value to improperly influence decisions
54+
- Kickbacks, facilitation payments, or undisclosed gifts
55+
- Preferential treatment in exchange for favors, donations, or sponsorships
56+
57+
Permitted items include:
58+
59+
- Nominal‑value promotional items
60+
- Disclosed and approved sponsorships
61+
- Transparent, documented contributions that do not influence governance decisions
62+
63+
### 4. Meeting Conduct
64+
65+
Board meetings must follow the published agenda and avoid anti‑competitive topics. At the start of each meeting the following statement shall be read aloud:
66+
67+
“As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and [must recuse themselves from discussion and voting](https://policy.owasp.org/legal/bylaws#section-101-transactions-with-interested-parties)
68+
69+
Conflicts of interest must be disclosed, and affected members must recuse themselves.
70+
71+
### 5. Responsibilities
72+
73+
#### 5.1 Board Members
74+
75+
- Uphold anti‑trust and anti‑bribery laws in all discussions and decisions
76+
- Avoid conflicts of interest and recuse when appropriate
77+
- Ensure OWASP activities remain vendor‑neutral and mission‑aligned
78+
- Maintain confidentiality of sensitive information
79+
80+
#### 5.2 OWASP Leaders and Contributors
81+
82+
- Avoid accepting gifts, payments, or influence from vendors
83+
- Ensure project decisions are transparent and free from improper influence
84+
85+
#### 5.3 Employees, Contractors, and Volunteers
86+
87+
- Report any suspected violations
88+
- Decline gifts or benefits that could influence judgment
89+
- Maintain independence in procurement, partnerships, and program decisions
90+
91+
Where a contract exceeds the Executive Director’s signing authority, a competitive bidding process must be followed, and the contract must be reviewed and approved by the Board of Directors to ensure compliance with this policy.
92+
93+
#### 5.4 Reporting Concerns
94+
95+
Any suspected anti‑trust, anti‑bribery, or ethical violation must be reported promptly to:
96+
97+
- The Whistleblower Program: https://policy.owasp.org/operational/whistleblower
98+
- The Executive Director
99+
- The Board Chair
100+
101+
OWASP prohibits retaliation against anyone who reports concerns in good faith.
102+
103+
### 6. Annual Review
104+
105+
This policy will be reviewed annually by the Board Governance Committee to ensure:
106+
107+
- Continued compliance with global anti‑trust and anti‑bribery laws
108+
- Alignment with nonprofit best practices
109+
- Updates to reflect regulatory changes, OWASP operational needs, and community expectations
110+
111+
Board members reaffirm their commitment each year through signing the Director’s Commitment Agreement and updating their conflict of interest disclosures as their circumstances change, or annually, whichever comes first.
112+
113+
---
114+
115+
Existing policy approved by the Board of Directors on 2025-12-16 that remain in effect until amended or replaced:
12116

13117
As members of the Board of Directors of the OWASP Foundation, Inc., we are committed to upholding all applicable antitrust laws and ensuring that our activities promote fair competition and ethical collaboration.
14118

operational/csr.md

Lines changed: 147 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,147 @@
1+
---
2+
3+
title: Corporate and Social Responsibility (DRAFT WIP)
4+
layout: col-document
5+
document: Rules of Procedure
6+
tags: Rules of Procedure
7+
notice: 2026-05-21
8+
9+
---
10+
11+
{% include draft-notice.html %}
12+
13+
## 1. Purpose
14+
15+
This Corporate and Social Responsibility (CSR) Policy outlines The OWASP Foundation’s commitment to ethical conduct, responsible stewardship, and positive social and environmental impact. It provides a framework for integrating CSR principles into governance, operations, programs, partnerships, and decision‑making.
16+
17+
## 2. Scope
18+
19+
This policy applies to:
20+
21+
- Board members
22+
- OWASP Foundation leadership and staff
23+
- OWASP leaders, volunteers, contributors, and participants
24+
- Contractors and consultants
25+
- Partners, collaborators, and suppliers engaged in organizational activities
26+
27+
All individuals and entities acting on behalf of The OWASP Foundation are expected to uphold the standards set out in this policy.
28+
29+
## 3. Alignment With Mission and Values
30+
31+
The OWASP Foundation’s CSR commitments are grounded in its mission to serve the community with openness and transparency, innovation, global inclusiveness, and integrity. All OWASP activities must:
32+
33+
- Advance The OWASP Foundation’s charitable purpose ("No more insecure software")
34+
- Reflect its core values of stewardship, inclusivity, accountability, and community benefit
35+
- Avoid activities that conflict with The OWASP Foundation’s apolitical, nonprofit status
36+
37+
## 4. Ethical Governance and Accountability
38+
39+
The OWASP Foundation is committed to:
40+
41+
- Complying with all applicable laws, regulations, and governance standards
42+
- Maintaining transparent and ethical decision‑making processes
43+
- Ensuring Board oversight of CSR commitments and performance
44+
- Upholding high standards of conduct through the [Code of Conduct](https://policy.owasp.org/operational/code-of-conduct), [Conflict of Interest Policy](https://policy.owasp.org/operational/conflict-of-interest), and related [governance documents](https://policy.owasp.org/).
45+
46+
## 5. Environmental Responsibility
47+
48+
The OWASP Foundation seeks to minimize its environmental footprint by:
49+
50+
- Minimizing travel emissions through sourcing local speakers, trainers, and volunteers, holding virtual meetings where possible, and offsetting unavoidable travel emissions
51+
- Reducing waste, energy use, and emissions in operations and events
52+
- Prioritizing sustainable procurement and resource use
53+
- Encouraging environmentally responsible behavior among staff, volunteers, and partners, including locally sourcing materials and services, reducing single-use plastics, and promoting digital collaboration to reduce travel needs
54+
- Considering environmental impacts when designing programs, travel, and activities
55+
56+
## 6. Social Responsibility
57+
58+
The OWASP Foundation is committed to:
59+
60+
- Fostering a safe, inclusive, and respectful environment for all
61+
- Promoting belonging, inclusion, and fairness within the application security community, particularly for underrepresented groups
62+
- Ensuring fair labor practices and safe working conditions for its staff, volunteers, and contractors
63+
- Upholding safeguarding standards for children and vulnerable people where applicable
64+
- Engaging communities in ways that are culturally respectful and responsive
65+
- Having a zero‑tolerance stance towards discrimination, harassment, exploitation, and abuse in all forms
66+
67+
The [Code of Conduct](https://policy.owasp.org/operational/code-of-conduct) and related policies provide guidance on expected behavior and standards of conduct. All personnel must report suspected misconduct immediately through established [whistleblower reporting](https://policy.owasp.org/operational/whistleblower) channels.
68+
69+
## 7. Responsible Financial Stewardship
70+
71+
The OWASP Foundation will:
72+
73+
- Use donor funds and resources responsibly, transparently, and in alignment with mission
74+
- Maintain strong internal controls to prevent misuse of funds
75+
- Ensure ethical fundraising practices consistent with regulatory and sector standards
76+
- Avoid conflicts of interest in financial and procurement decisions
77+
78+
## 8. Human Rights and Community Impact
79+
80+
The OWASP Foundation respects and promotes human rights by:
81+
82+
- Ensuring programs and partnerships do not cause harm or perpetuate inequity
83+
- Supporting the dignity, rights, and wellbeing of all individuals and communities served
84+
- Incorporating community feedback into program design and evaluation
85+
- Avoiding partnerships with entities that violate human rights or engage in harmful practices
86+
87+
## 9. Partnership and Supplier Standards
88+
89+
The OWASP Foundation expects partners and suppliers to:
90+
91+
- Operate ethically and in alignment with The OWASP Foundation’s values
92+
- Comply with labor, environmental, and human rights standards
93+
- Demonstrate transparency in their operations
94+
- Avoid practices that could harm The OWASP Foundation’s reputation or beneficiaries
95+
96+
Where appropriate, The OWASP Foundation may conduct due diligence or require declarations of compliance.
97+
98+
## 10. Anti‑Corruption and Anti‑Bribery Commitments
99+
100+
OWASP maintains a zero‑tolerance stance towards corruption and bribery. The Board, OWASP Staff, Leaders and Participants, and suppliers must adhere to the highest ethical standards, avoiding any form of:
101+
102+
- Bribery
103+
- Corruption
104+
- Fraud
105+
- Embezzlement
106+
- Improper influence or inducements
107+
108+
OWASP's [Antitrust, Anti Corruption, and Competition Policy](https://policy.owasp.org/operational/antitrust) and related policies provide guidance on expected behavior and ethical standards. All personnel must report suspected misconduct immediately through established [whistleblower reporting](https://policy.owasp.org/operational/whistleblower) channels.
109+
110+
## 11. Data Privacy and Digital Responsibility
111+
112+
The OWASP Foundation is committed to:
113+
114+
- Protecting personal information in accordance with applicable privacy laws
115+
- Ensuring secure handling, storage, and disposal of data
116+
- Using digital tools and technologies ethically and responsibly
117+
- Maintaining cybersecurity practices that safeguard organizational and stakeholder information
118+
119+
The [Privacy Policy](https://policy.owasp.org/operational/privacy) and related data protection measures are integral to OWASP's CSR commitments in this area.
120+
121+
## 12. Transparency and Public Reporting
122+
123+
The OWASP Foundation will:
124+
125+
- Publish accurate and timely information about its activities, finances, and impact on a monthly basis through its Board meeting minutes, annual reports, and public disclosures
126+
- Provide annual reporting to members, donors, and the public through the publication of an annual impact report containing financial statements
127+
- Disclose CSR‑related commitments, progress, and challenges where appropriate
128+
129+
## 13. Mechanism for Reporting Non‑Compliance (Whistleblower Policy)
130+
131+
Concerns about breaches of this policy—including unethical behavior, misconduct, or non‑compliance—may be reported through OWASP's [Whistleblower Policy](https://owasp.org/whistleblower-policy/). This mechanism allows for confidential reporting of concerns without fear of retaliation.
132+
133+
## 14. Implementation and Responsibilities
134+
135+
- Board of Directors: Provides oversight, ensures alignment with mission and governance standards, and reviews CSR performance.
136+
- Executive Leadership: Integrates CSR principles into strategy, operations, and risk management; ensures compliance across the organization.
137+
- Directors and OWASP : Implement CSR practices within their areas, monitor compliance, and support staff and volunteers.
138+
- Staff and Volunteers: Uphold the policy in daily activities and report concerns or breaches.
139+
- Partners and Suppliers: Comply with relevant sections of this policy as a condition of engagement.
140+
141+
## 15. Review Periods
142+
143+
This policy will be:
144+
145+
- Reviewed every two years, or sooner if required by regulatory changes or organisational needs
146+
- Updated to reflect evolving best practices in governance, sustainability, and social responsibility
147+
- Approved by the Board of Directors following each review cycle

0 commit comments

Comments
 (0)