The newest version of SAMM provides new introductory content including an executive summary and a clear explanation of the model's focus on providing security activities centered around business functions.
Version 1.0 also includes a guide for assessing organizations against the SAMM. Companies can use the provided worksheet consisting of yes or no questions to acertain the maturity of a software security development process. This could be applied to help:
- Decide whether to purchase software from a vendor
- Determine which software-as-a-service or cloud computing providers to select
- Choose whether to develop software in-house or to contract out the work
- Determine where the weaknesses in your organization's software security process are
- Demonstrate progress in improving your organization's software security process
- Independent Software Vendor
- Online Service Provider
- Financial Services Organization (New)
- Government Organization (New)
No comments:
Post a Comment