Showing posts with label SAMM. Show all posts
Showing posts with label SAMM. Show all posts

Sunday, June 7, 2009

SAMM Inteview Template Version 1.0

Several individuals (including me) plan on proposing an effort to evaluate the OWASP organization using the Software Assurance Maturity Model (SAMM). One of the action items I took on was to create an interview template to help determine the organization's current maturity level.

The first release of the SAMM Interview Template is available below.

View the SAMM Interview Template here: http://spreadsheets.google.com/pub?key=rYpVqQR3026Zu4DNg8LBIwg&output=html

Download the SAMM Interview Template XLS here (Some formatting is lost): http://spreadsheets.google.com/pub?key=rYpVqQR3026Zu4DNg8LBIwg&output=xls

If you have questions or comments about this template or you wish to help assess OWASP using SAMM, please send a message out on the OWASP SAMM Mailing List.

Thursday, March 26, 2009

Software Assurance Maturity Model 1.0 Released

Pravir Chandra recently released the 1.0 version of the Software Assurance Maturity Model (SAMM). I recommend everyone visits the www.OpenSAMM.org website to review model. Jim Manico also interviewed Pravir on OWASP Podcast #14, where they discussed SAMM becoming an OWASP project and briefly discussed why two distinct models, the Building Security In Maturity Model (BSIMM) and SAMM have emerged.

The newest version of SAMM provides new introductory content including an executive summary and a clear explanation of the model's focus on providing security activities centered around business functions.

Version 1.0 also includes a guide for assessing organizations against the SAMM. Companies can use the provided worksheet consisting of yes or no questions to acertain the maturity of a software security development process. This could be applied to help:
  • Decide whether to purchase software from a vendor
  • Determine which software-as-a-service or cloud computing providers to select
  • Choose whether to develop software in-house or to contract out the work
  • Determine where the weaknesses in your organization's software security process are
  • Demonstrate progress in improving your organization's software security process
SAMM also includes roadmaps for various industry types. These roadmaps demonstrate Pravir's assertion that all organizations do not necesarilly need to have a maturity of "3" in ALL security practices. Sample roadmaps are defined for the following industry types:
  • Independent Software Vendor
  • Online Service Provider
  • Financial Services Organization (New)
  • Government Organization (New)
Again, I encourage everyone to review the Software Assurance Maturity Model at www.OpenSAMM.org.