OWASP OOVS OSINT Verification Standard

Version 0.1.0 · Foundational baseline

The ten
requirements.

Each one states an obligation, the evidence that demonstrates it, how an assessor tests it, and what counts as failure. Nothing here depends on a particular tool, vendor, or platform.

How assessment works

Two things can be assessed. Four results are possible.

An assessment covers either a defined workflow or a defined intelligence product — never a whole organisation, and never a tool in the abstract. Scope, time period, and sampling method are recorded with the result, so a narrow assessment cannot later be presented as a general one.

Each requirement is recorded as met, partially met, not met, or not applicable. Not applicable is disciplined: it requires an objectively missing precondition. Cost, inconvenience, and absence of evidence are explicitly invalid grounds.

The outcome is calculated, not claimed

An overall result of meets all applicable requirements holds only when every applicable requirement is fully met. Any other combination produces does not meet. The summary is derived from the detail mechanically, which removes the room for a favourable headline over unfavourable findings.

Self-assessment and independent assessment are always distinguished on the record.

The baseline

What every requirement asks.

  1. 01 Authorised purpose and proportionality

    Before material collection begins, record the decision it serves, the accountable owner, the authority relied on, the necessity and expected benefit, the foreseeable harm, the less intrusive alternatives considered, and the point at which the work stops or escalates.

    Fails when: work begins with no recorded purpose or owner, or continues after authority becomes unclear.

  2. 02 Collection boundary and data minimisation

    Define and enforce limits on sources, techniques, fields, access, and time. Minimise incidental and sensitive data. Never bypass access controls, use credentials without authority, or induce disclosure by deception. Public availability alone is not authority to process.

    Fails when: collection exceeds approved boundaries, or unnecessary sensitive data is retained.

  3. 03 Source provenance and integrity

    Every material item records where it came from, when it was observed, who or what collected it, how it was acquired, whether it is original or derived, and what was changed. Integrity mechanisms are used where appropriate — and never described as proof that content is true.

    Fails when: a claim cannot be traced back to an observation, or a copy is presented as an original.

  4. 04 Source and claim assessment

    Judge the reliability of a source separately from the credibility of the specific claim. Where apparent corroboration affects a decision, trace shared origins far enough to avoid counting reposts, quotations, syndicated reporting, or machine restatements as independent support.

    Fails when: repetition of one origin is counted as corroboration, or a source's reputation substitutes for assessing the claim.

  5. 05 Corroboration and confidence

    State confidence and the basis for it. Scale verification depth to the consequence of being wrong. Where sufficient corroboration is unavailable, label the claim accordingly — and do not let it be the sole basis for consequential action outside a documented emergency process.

    Deliberately sets no universal source count: two weak reports can be less probative than one strong primary record.

  6. 06 Analytic transparency and reproducibility

    Distinguish what was observed from what was inferred, assumed, considered as an alternative, or remains unknown. Record methods, selection criteria, and exclusions well enough that a competent authorised reviewer can reconstruct the reasoning without exposing sensitive material publicly.

    Fails when: fact and inference are blurred, or a reviewer cannot reconstruct a material judgment.

  7. 07 Rights, privacy, and safeguarding

    Identify the legal, policy, contractual, human-rights, records, and safeguarding obligations that actually apply in your context, then implement proportionate minimisation, access control, retention and deletion, accuracy review, and a route to correction or redress. High-consequence use receives documented specialist review.

    Fails when: controls exist on paper only, or a known error cannot be corrected downstream.

  8. 08 AI and automation assurance

    Treat automated output as an unverified aid until it is validated against traceable evidence. Record the system, its configuration, the provenance of its inputs, the evaluation performed, its known limitations, and the accountable human reviewer. Machine output never corroborates its own inputs, and never makes an unreviewed high-consequence determination.

    May be marked not applicable only where no automated system materially participates.

  9. 09 Dissemination and action controls

    Every product identifies its intended decision, audience, confidence, caveats, handling constraints, validity period, and release authority. Distinguish an allegation, a lead, an assessment, and a verified finding. Maintain a route to withdraw or correct material already distributed.

    Fails when: caveats disappear downstream, a lead is presented as a finding, or a correction cannot reach known recipients.

  10. 10 Governance, audit, and improvement

    Assign accountable roles, set competence expectations, maintain a challenge route proportionate to risk, review controls periodically, and record incidents, errors, corrections, and the improvements that followed. High-consequence release approval cannot rest solely with whoever produced the judgment.

    Small teams may use an external or cross-team challenger; independence is judged functionally, not structurally.

Design choices

What was deliberately rejected.

Several conventional approaches were considered and turned down. Each appears somewhere in current practice.

RejectedBecause
Tiers by audience — journalist, enterprise, stateTies safeguards to identity rather than risk. A two-person team can take a high-consequence decision.
A fixed number of sourcesTwo weak reports may be less probative than one strong primary record, and many reports can share a single origin.
A mandatory handling label on every productHandling schemes are community instruments. A universal mandate misstates their function and displaces neither law nor contract.
Treating a hash or credential as proof of authenticityIt establishes integrity or an assertion, never the truth of what is depicted.
Encoding one jurisdiction's rules as globalProduces obligations that are simply wrong outside that jurisdiction.
Certification in the first releaseRequires assessor competence rules, impartiality, sampling methodology, appeals, surveillance, and accreditation. None of that exists yet, and a mark without it degrades the meaning of assurance.