Governance · OSMS 1.0

The Review Board

The board consolidates the findings of the public review and recommends what enters OSMS 1.0. It is curated and invite-only — assembled by the editor to cover board, CISO, SOC and audit perspectives — and every one of its decisions is logged publicly.

What the board does

  • Reviews and prioritises consolidated findings from the public review.
  • Recommends whether OSMS 1.0 is ready to freeze — measured against the published review KPIs, not gut feeling.
  • Guards the card contract: no change to ID, formula, scope, direction or minimum data fields without a documented version break.

How it decides

The board recommends and prioritises — it does not redesign cards by committee. Every finding receives exactly one documented outcome:

data-en="acceptedrejecteddeferred → v1.1accepted riskbreaking → blocks freeze" data-de="akzeptiertabgelehntzurückgestellt → v1.1akzeptiertes Risikobreaking → blockiert Freeze" data-h="1">acceptedrejecteddeferred → v1.1accepted riskbreaking → blocks freeze

Outcomes are applied as public labels on the findings themselves and summarised in the Review Board Summary published at freeze.

Members

TO BE ANNOUNCED

Membership is by invitation of the editor. Members are credited by name in the OSMS 1.0 specification and the forthcoming official guide.