OEMF: Open Exposure Management Framework


Already a member?
Access the OEMF community workspace here

Developing an unbiased, community framework to unite and direct the efforts in preventing, assessing, and resolving exposures in organizational technology.

The Open Exposure Management Framework (OEMF) was created in response to cybersecurity professionals’ desire for a thoughtful, purpose-driven set of parameters to manage exposure. The TC addresses critical gaps in current cybersecurity frameworks by providing detailed guidance for exposure management domains.

Read More

The primary business benefit of the OEMF is providing organizations with a structured methodology to better avoid and correct the exploitability of their technology footprints. By following the OEMF methodology, organizations can more effectively prevent exploitable technology configurations at scale, become more efficient in discovering, prioritizing, and resolving technology exposures, and maximize their limited resources on activities that most significantly reduce organizational susceptibility.

Organizations will make better use of existing exposure data and be enabled to make more educated decisions regarding technology investments and personnel allocation for their Exposure Management programs.

Key factors fueling the need for the OEMF TC include:

  • An aspiration to accommodate security domains such as Vulnerability Management and Cloud Security in a more detailed way than existing cybersecurity frameworks currently do.

  • An opportunity to standardize and structure how technology exposures are defined, discovered, prioritized, and acted upon.

  • A drive to include and focus on critically important upstream activities that prevent technology exposures. 

  • A desire to outline tactical guidance around the processes and technologies that intersect Exposure Management.

  • A present need for an independent, industry accepted scale for measuring Exposure Management maturity.

  • A present need to define best practices and terminology related to Exposure Management in a manner that is agnostic of specific vendor technologies.


TC Convener:
Chris Peltz, GuidePoint Security


Kelly Cullinane, OASIS

Blog Post –
Coming Soon!

Press Release – Coming Soon!

Frequently Asked Questions

What is the main objective of the OEMF TC?

The primary scope of the OEMF TC is to enable the cybersecurity community with a series of best practices around Exposure Management. Following that, the project intends to provide a methodology for cybersecurity professionals or partners to perform self assessments in Exposure Management maturity, much like OWASP has done with the Software Assurance Maturity Model.

Additionally, the project seeks to develop reference material that cybersecurity professionals can leverage to tactically drive Exposure Management maturity within their respective organizations.

The main scope of the OEMF is to provide framework documentation and supplemental educational materials such as videos, presentations, images, and templates regarding Exposure Management.

Why is OEMF needed?

Organizations need a structured, vendor-neutral approach to standardize how exposures are defined, discovered, prioritized, and resolved. Without this framework, cybersecurity professionals lack consistent methodologies for measuring exposure management maturity and making informed decisions about resource allocation and technology investments. The OEMF TC fills this gap by providing tactical guidance and an industry-accepted maturity scale that integrates with existing frameworks while offering the granular detail needed for effective exposure management programs.

What are the benefits of joining the OEMF TC?

Joining the OEMF TC offers cybersecurity professionals the opportunity to directly shape the development of the first comprehensive, vendor-neutral framework for exposure management while gaining early access to cutting-edge methodologies, maturity assessment tools, and implementation guidance.

Participants will collaborate with industry leaders, including CISOs and security directors, to influence capability requirements and framework mappings to existing standards like NIST CSF and CIS, positioning their organizations to achieve higher exposure management maturity faster than competitors. TC members will contribute to educational materials that will benefit the entire cybersecurity community, all within an open collaboration environment

Who should participate?

The OEMF TC welcomes participation from a broad range of stakeholders, including Chief Information Security Officers (CISOs), directors of security, and managers and leads responsible for vulnerability management, application security, cloud security, and identity security. Participants also include executive leadership, risk & compliance personnel, and representatives from customer and partner organizations who benefit from improved exposure reporting and risk reduction. Exposure Management has consistent relevance across all industries, the TC will particularly appeal to enterprises, public entities, and organizations that design their own infrastructure and applications, as these organizations face deeper, more complex Exposure Management considerations and have greater need for the secure design elements that the framework will provide.

OASIS welcomes interested organizations to join and contribute to the development of the framework. Organizations can participate by becoming OASIS members.

How much time is required to participate in the OEMF TC?

Participation in the OEMF TC does not require a significant time commitment. Members will spend about 4–6 hours per month during the first year, including meetings plus collaboration via email and shared documents, scaling down to about 2–3 hours per month after that.

If your availability is limited and you prefer not to affect quorum, you have the option to join as an Observer. Observers can stay informed and contribute without the obligation of full participation, though OASIS membership is still required. View more info on committee participation [here].

How do I view the mailing list archive?

The OEMF TC’s mailing list archive, used by members to conduct Committee work, is available hereTC membership is required to post to this list. TC members are automatically subscribed.

New Members Welcome


Whether you want to actively contribute in decision-making or just observe progress from the inside, you will need to be an OASIS member.

If your employer is already on our current member list, submit this request form to be added to the TC Roster. If not, find out how to join OASIS.

Non-members may monitor the mailing list archives online, view approved documents, and provide feedback to our comments list. Contact Us for more information.