OWASP Open Source Intelligence Standard

An open, vendor-neutral standard for verifying open-source intelligence. OOVS v0.1.0 defines ten testable requirements published simultaneously as normative text and machine-readable data, with one acceptance test per requirement, a portable assessment schema, and continuous validation.

About OWASP Open Source Intelligence Standard

Why this exists

Open-source intelligence now supports consequential decisions: prioritising cyber defence, investigating fraud, supporting safeguarding referrals, documenting alleged human-rights violations, and publishing investigative journalism. The guidance governing that work is expressed almost entirely as prose.

Prose guidance describes what good practice looks like. It rarely states what evidence would demonstrate it, what sampling would test it, or what observation would falsify it. An organisation can claim it follows a protocol with no artefact a second party could check, and a reviewer cannot distinguish a disciplined workflow from a confident one.

What OOVS provides

Ten testable requirements, each with required evidence, an assessment procedure, pass criteria, and failure conditions. Two assessment targets: a defined workflow or a defined intelligence product. Four result states with a disciplined not-applicable rule, where cost, inconvenience, and absence of evidence are explicitly invalid grounds.

An overall outcome is derived mechanically from individual results, so a favourable summary cannot be asserted over unfavourable detail. Results are recorded in a portable JSON format, so they move between reviewers, tools, and procurement processes. Mappings to established public guidance are stated conservatively as related to, rather than equivalent or compliant.

Specification-as-code

The standard is published as normative prose and as validated machine-readable data, and their agreement is a build-time property rather than an editorial aspiration. Eight check families run in continuous integration: schema validity, instance conformance, cross-artefact identifier and reference consistency, prose-to-data parity, assessment result semantics, expected-failure fixtures that must be rejected for their declared reason, internal link integrity, and release digest verification.

During development the parity check caught a real divergence introduced by ordinary editing. That is the argument for keeping it.

What the requirements cover

Authorised purpose and proportionality, collection boundary and minimisation, source provenance and integrity, source and claim assessment, corroboration and confidence, analytic transparency and reproducibility, rights and safeguarding, AI and automation assurance, dissemination and action controls, and governance and improvement.

Three controls are worth naming. Independence is assessed by counting distinct origins rather than mentions, so reposts, syndication, and model restatements are not mistaken for corroboration. Metadata, hashes, provenance credentials, and detector outputs are treated as signals with documented limitations, never standalone proof. Automated output may not be counted as independent corroboration of its own inputs.

Verify this release yourself

Clone the repository, install the single pinned dependency, and run the validator. Expected output: 6 schemas, 5 canonical artefacts, 5 expected-failure fixtures, 10 prose-to-data requirement pairs, 92 internal links, and 23 manifest digests validated.

Scope

OOVS is a voluntary standard. It is not a certification or accreditation scheme, does not determine legal compliance or evidentiary admissibility, and does not imply endorsement by any government, agency, court, or vendor. It complements the Berkeley Protocol, ICD 203 and 206, W3C PROV, STIX and TAXII, and CASE and UCO rather than replacing them, and it is a standard rather than an intelligence platform.

Assessment results are scoped to a stated target and period. Self-assessment and independent assessment are distinguished.

Project Leaders

Manish Tripathy

Project Leader

Project leader for the OWASP Open Source Intelligence Standard. Designed the OOVS assurance baseline and the specification-as-code pipeline that keeps its normative text, machine-readable requirements, acceptance tests, and hash-pinned release manifests provably consistent in continuous integration. Interests: OSINT verification, provenance and source-origin independence, attribution, and accountable use of AI in analytic workflows.

Email

Project Information

Language
Markdown, JSON Schema, Python
License
CC BY-SA 4.0
Latest Version
0.1.0

Requirements

  • Reading and applying the standard: no tooling required
  • Optional local validation: Python 3.10 or newer
  • Optional local validation: jsonschema 4.25.1 (pinned)
  • Validation runs offline; no network access required

Industry Usage

Cyber Threat IntelligenceInvestigationsJournalismHuman RightsResearch and Academia
Corporate Supporters
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.