

OWASP San Fernando Valley: First Chapter Meeting
Tuesday, September 22, 2026 | 5:30 PM to 9:00 PM | In person, venue being finalized
OWASP San Fernando Valley is back, and this is our first meeting.
Featured talk: Shifting from the Monster GRC to the Introspective GRC
Our speaker is Karina Klever, founder of Klever Compliance.
Our GRC pendulum has swung to a maddening and excess extreme. Too many tools, both in IT Operations and GRC, promising "automagic" results. The many published company documents that should contain measurable controls correlating to regulatory and framework requirements are scattered under the rugs and hidden in corners, completely dismissed. We are hoarding too much data, it's unstructured, unmanaged, and not governed by basic classification principles. Why are we encrypting publicly available data instead of purging it?!
Unfortunately, we've tossed data discipline, data mapping, data purposefulness and data grooming away. The vendors who handle our data use liability invisible cloaks for convenient lack of accountability, especially when they pass our data downstream. Despite us creating all of this overwhelming noise, we are losing data at a ridiculously drastic rate.
Let's stop continuing to do the same excessive things that got us in this mess and expecting different results. This session will bring us all back to some of the best practice governance basics and provide the attendee with hints on how to tame the monster. We'll identify some recommendations on how to optimize your GRC program to actually work for your company, not bog it down.
About the speaker
Karina Klever has spent more than 35 years in technology, starting in 1989 as a computer operator. After programming and decades of project/program managing, compliance took a larger focus starting in the early 2000s. Karina would go on to establish GRC Centers of Excellence for Fortune 500 companies. Successes span industries, maturities, regulations, and frameworks. After years of witnessing compliance being implemented as nothing more than a checkbox exercise, Karina opened her own boutique company to guide midsized companies into establishing governance programs that are appropriate for their particular industry, level of maturity, size, risk posture, and goals. Checkbox compliance leaves gaping security holes!
Beyond the talk, come and meet the chapter leaders and the other people building and securing software in the Valley. We want to hear what you work on, what you want from a local OWASP chapter, and what future meetings should cover. Bring an idea, or just come and listen.
Schedule
5:30 PM to 6:15 PM - Arrival, food, and networking
6:15 PM to 6:30 PM - Welcome, and meet your chapter leaders
6:30 PM to 7:15 PM - Featured talk and Q&A
7:15 PM to 7:45 PM - Open discussion: what you want from us
7:45 PM to 9:00 PM - Networking and close
Everyone is welcome: engineers, developers, students, researchers, and anyone curious about how software holds up against an attacker. You do not need to be an OWASP member and you do not need a security background. The meeting is free, and food and drinks are provided.
Location: we are finalizing the venue, most likely at California State University, Northridge. We will update the location on this event as soon as it is set. Space will be limited, so please RSVP.
We plan to take photos and use them on the chapter page and on LinkedIn. If you would rather not be in them, tell one of the leaders when you arrive and we will keep you out of shot.
OWASP is the Open Worldwide Application Security Project, a nonprofit that publishes free, open resources for building and running safer software.
Chapter page: https://sfv.owasp.org/
CODE OF CONDUCT
OWASP is a welcoming community and we expect everyone at our meetings to keep it that way. The OWASP Code of Conduct applies: