{
  "schemaVersion": "gships-review-packet-1",
  "packetId": "events:series-nist-software-supply-chain-assurance-forum",
  "stableId": "series-nist-software-supply-chain-assurance-forum",
  "family": "events",
  "slug": "nist-software-supply-chain-assurance-forum",
  "title": "NIST Software and Supply Chain Assurance Forum",
  "status": "prepared-human-review-not-started",
  "release": {
    "releaseId": "public-alpha-2026-07-26-research-visuals-r14",
    "sourceCommit": "3eb036fce3d711336c8c605625895e8a2e799ab0",
    "corpusGeneratedAt": "2026-07-25",
    "frozenAt": "2026-07-26T22:50:50.000Z",
    "canonicalOrigin": "https://gships.dammonburden.com"
  },
  "paths": {
    "human": "/review/events/nist-software-supply-chain-assurance-forum",
    "family": "/review/events",
    "packet": "/review-packets/events/nist-software-supply-chain-assurance-forum.a5476749969302bd.json",
    "decisionTemplate": "/review-packets/events/nist-software-supply-chain-assurance-forum.a5476749969302bd.decision-template.json",
    "worksheet": "/review-packets/events/nist-software-supply-chain-assurance-forum.a5476749969302bd.worksheet.md",
    "byFingerprint": "/review-packets/by-fingerprint/a5476749969302bdd54fbcc463f15e5d37507851da3396a68d31754462ac4d1b.json"
  },
  "boundary": "Prepared review packet; human review has not started. This packet is not a completed review, endorsement, reviewer appointment, partnership, or authorization to act.",
  "governingPolicies": [
    {
      "id": "policy-editorial-governance-001",
      "version": "0.1.0",
      "path": "/editorial-policy",
      "recordType": "governing-policy",
      "fingerprint": "1f6a1f823e8bfe891b6a707c5dce2ee2337c0bb7d915b48d6060ca82b8da1b47",
      "snapshot": {
        "id": "policy-editorial-governance-001",
        "version": "0.1.0",
        "status": "foundation-policy-controls-not-yet-staffed",
        "adoptedForFoundation": "2026-07-25",
        "title": "Editorial governance and independent review",
        "publisher": "GShips Project",
        "maintainer": "Dammon Burden",
        "publisherInterest": "The maintainer intends to explore a commercial venture based on some GShips work. No entity, outside funding, customer, sponsor, or indexed-organization relationship currently exists.",
        "currentBoundary": "No independent domain reviewer or review council is currently appointed. Foundation records and outlines may not be represented as independently reviewed.",
        "reviewerSelection": [
          "Publish the reviewer’s name, relevant credentials or lived expertise, review scope, compensation status, and declared conflicts with consent.",
          "Select for the actual claim domain rather than general prestige; include affected-community and disability-led expertise where rights or access are involved.",
          "Do not treat an employee, investor, customer, sponsor, source author, or directly supervised collaborator as independent for the affected claim."
        ],
        "reviewProcess": [
          "Provide the exact claim, sources, locators, assumptions, counterevidence, transfer limits, and proposed evidence dimensions.",
          "Record approve, revise, contest, or reject at claim level; silence and event attendance never count as review.",
          "Publish material minority findings and the editor’s reasoned response.",
          "High-consequence medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use claims require two qualified independent reviewers with complementary scopes.",
          "A reviewer may recuse at any time; unresolved conflicts or missing expertise block the reviewed label."
        ],
        "appealAndCorrection": [
          "A correction receives a reference identifier and triage record; safety-critical allegations receive priority.",
          "A material editorial decision may be appealed to a reviewer not involved in the original decision once such a panel exists.",
          "Substantive reversals, unresolved disputes, and removed conclusions receive a dated public record that protects reporter privacy.",
          "No sponsor, customer, founder, or reviewer may purchase, suppress, or unilaterally assign an evidence grade."
        ],
        "publicationGate": "Public 1.0 requires named review coverage across every Academy track, documented high-consequence two-person review, a material-corrections log, reviewer conflict records, and an operating appeal path.",
        "correctionPath": "/corrections"
      }
    },
    {
      "id": "policy-dual-use-001",
      "version": "0.1.0",
      "path": "/dual-use",
      "recordType": "governing-policy",
      "fingerprint": "81637e2849f9c0866d23f7174eb9a2ce522b86313167ebf5022fca122d6e506c",
      "snapshot": {
        "id": "policy-dual-use-001",
        "version": "0.1.0",
        "status": "planned-controls-not-yet-operational",
        "adoptedForFoundation": "2026-07-25",
        "title": "Civil, defensive, and rights-preserving use boundary",
        "summary": "GShips may research safety, resilience, logistics, communications, recovery, and cyber defense only within explicit end-use, rights, and independent-review controls. Calling an activity defensive is never sufficient by itself.",
        "scopeTrigger": "Apply dual-use review before accepting or materially advancing customer, funder, collaborator, operational, procurement, or publication-sensitive work whose capability, data, end use, or transfer could reasonably enable a prohibited use. Public non-actionable education still follows prohibited-content and sensitive-publication controls.",
        "allowedInPrinciple": [
          "Safety engineering and independently assessed protection",
          "Resilience, graceful degradation, recovery, and disaster response",
          "Civil logistics, maintenance, communications, and knowledge continuity",
          "Cyber defense, secure software, incident response, and recovery",
          "Rights-preserving health, accessibility, ecology, education, and governance research"
        ],
        "prohibited": [
          "Identification, tracking, prioritization, or engagement of people or assets for force, weapons, repression, or offensive operations; safety navigation, astronomy, collision avoidance, search and rescue, and independently governed planetary defense are not prohibited by this clause",
          "Weapons command-and-control or targeting support",
          "Offensive access, persistence, exploitation, or destructive cyber payloads",
          "Mass surveillance, biometric repression, or political-control systems",
          "Autonomous force application",
          "Coercive reproductive, medical, genetic, disability, or civic control",
          "Nonconsensual experimentation or treating residents as research instruments"
        ],
        "reviewRequiredBeforeAnyRelevantWork": [
          "Customer, funder, collaborator, jurisdiction, beneficial-owner, and end-use screening",
          "Export-control and sanctions review by qualified counsel when applicable",
          "Written scope, allowed-use, prohibited-use, audit, termination, and incident clauses",
          "Independent stop-work authority with a named alternate and founder recusal",
          "Sensitive-publication and information-hazard review",
          "Whistleblowing, escalation, incident response, appeal, and anti-retaliation paths",
          "Aggregate transparency reporting that protects legitimate privacy and security"
        ],
        "currentBoundary": "No screening body, independent stop-work authority, contractual controls, or appeal body currently exists. Therefore no relevant customer, defense, dual-use, or operational engagement is authorized by this policy.",
        "changeControl": "Material changes require a dated public rationale, independent review, and may not be approved by the founder alone.",
        "correctionPath": "/corrections"
      }
    }
  ],
  "reviewContract": {
    "questions": [
      {
        "id": "question-1",
        "text": "Do the official sources support the series identity and every current occurrence, date, deadline, access rule, and eligibility statement?",
        "required": true
      },
      {
        "id": "question-2",
        "text": "Are location, remote access, accommodations, cost, travel, visa, and participation uncertainty represented without invention?",
        "required": true
      },
      {
        "id": "question-3",
        "text": "Does the founder action remain proposed and separately authorized rather than implied as registration or attendance?",
        "required": true
      }
    ],
    "exclusions": [
      "A listed event is not endorsed, sponsored, attended, booked, or affiliated with GShips.",
      "A current occurrence can expire; historical packet approval cannot establish a future event date."
    ],
    "requestedScopeCodes": [
      "accessibility-disability-justice",
      "event-access-freshness"
    ],
    "dispositions": [
      "approve",
      "revise",
      "contest",
      "reject",
      "recuse"
    ],
    "prohibitedInputs": [
      "private legal names or contact details",
      "identity documents or raw credential files",
      "accessibility or medical records",
      "confidential conflict evidence",
      "classified, export-controlled, proprietary, or exploit material"
    ],
    "freshness": {
      "maximumDecisionAgeFromFreezeDays": 14,
      "eventOccurrenceRule": "A current-occurrence approval must be decided no later than the frozen occurrence end date; a later review requires a refreshed record and packet."
    },
    "completionRule": "Every primary record must receive the required number of valid, current-fingerprint approvals; every complementary scope group and required domain must be covered; any unresolved revise, contest, or reject disposition blocks publication.",
    "highConsequenceRule": "Named medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use conclusions require two distinct qualified independent humans covering complementary domain-method and rights/public-interest scopes."
  },
  "primaryRecords": [
    {
      "recordType": "event-series",
      "recordId": "series-nist-software-supply-chain-assurance-forum",
      "title": "NIST Software and Supply Chain Assurance Forum",
      "publicPath": "/events/series/nist-software-supply-chain-assurance-forum",
      "recordFingerprint": "765db3d9a075b9e5f8d2ae641084bd47308a4e160dec787e816c85639eaa1fcd",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "event-access-freshness"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "series-nist-software-supply-chain-assurance-forum",
        "slug": "nist-software-supply-chain-assurance-forum",
        "name": "NIST Software and Supply Chain Assurance Forum",
        "occurrenceIds": [
          "event-nist-software-and-supply-chain-assurance-forum"
        ],
        "organizerOrganizationIds": [],
        "relationship": "indexed only; no formal relationship"
      }
    },
    {
      "recordType": "event-occurrence",
      "recordId": "event-nist-software-and-supply-chain-assurance-forum",
      "title": "NIST Software and Supply Chain Assurance Forum",
      "publicPath": "/events/nist-software-and-supply-chain-assurance-forum",
      "recordFingerprint": "abeee8bf7a0996bd2f242a4c15ccfc9faa810c25c3e0fc5140179d8a5ffaac96",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "accessibility-disability-justice",
              "event-access-freshness"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "event-nist-software-and-supply-chain-assurance-forum",
        "slug": "nist-software-and-supply-chain-assurance-forum",
        "name": "NIST Software and Supply Chain Assurance Forum",
        "url": "https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management/SSCA",
        "startDate": "2026-09-22",
        "endDate": "2026-09-23",
        "location": "McLean, United States",
        "focus": "Software supply chain, SBOMs, provenance, and assurance",
        "founderAction": "Evaluate attendance as a public software-assurance learning option; register only after schedule, travel, accessibility, and a specific Update Airlock learning agenda are approved.",
        "accessNotes": "NIST lists the September 22–23 forum as in person at MITRE in McLean, free and open to the public, with registration required and now open. NIST says tentative topics will be available in late July and a draft agenda in August. Capacity, accessibility, recording, host-site access, and final agenda fit require confirmation.",
        "eligibility": "The forum is described as open to the public, subject to required registration and the host site's access procedures. No registration, attendance, or NIST/MITRE relationship has been undertaken.",
        "actionStatus": "proposed; not undertaken",
        "status": "monitor",
        "verifiedAt": "2026-07-26",
        "conflicts": "Publisher intends to explore a commercial venture based on some GShips work; no event registration, submission, sponsorship, attendance commitment, or organizer relationship exists.",
        "evidenceBoundary": "NIST's SSCA series page supports the next occurrence's dates, location, free/public status, and registration requirement; it does not establish agenda quality, GShips fit, accessibility, capacity, admission, or participant availability.",
        "whatWouldChange": "A NIST update to the occurrence date, venue, agenda, registration availability, public-access rule, or host-site requirements would change this profile."
      }
    }
  ],
  "linkedRecords": [
    {
      "recordType": "event-task-match",
      "recordId": "event-match-cyber-nist-2026",
      "title": "disconnected-cyber-recovery · event-nist-software-and-supply-chain-assurance-forum",
      "publicPath": "/partners",
      "recordFingerprint": "730ad9966b8963be4148073808ed18e4a3a90da29762b308a1c65d1f6e46d35e"
    }
  ],
  "referenceSnapshots": [
    {
      "sourceId": "official-event-occurrence-event-nist-software-and-supply-chain-assurance-forum",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "c0d4ed94fa570b9ad7bebf62b2a5139e9c4112dc44529f08fa6f73a077975001",
      "snapshot": {
        "title": "NIST Software and Supply Chain Assurance Forum",
        "url": "https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management/SSCA",
        "checkedAt": "2026-07-26",
        "scopeNote": "NIST's SSCA series page supports the next occurrence's dates, location, free/public status, and registration requirement; it does not establish agenda quality, GShips fit, accessibility, capacity, admission, or participant availability.",
        "subjectRecordType": "event-occurrence",
        "subjectRecordId": "event-nist-software-and-supply-chain-assurance-forum"
      }
    }
  ],
  "packetFingerprint": "a5476749969302bdd54fbcc463f15e5d37507851da3396a68d31754462ac4d1b"
}
