<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=SAMM_-_Roadmap_-_Government_Organization</id>
		<title>SAMM - Roadmap - Government Organization - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=SAMM_-_Roadmap_-_Government_Organization"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SAMM_-_Roadmap_-_Government_Organization&amp;action=history"/>
		<updated>2026-05-16T15:38:59Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SAMM_-_Roadmap_-_Government_Organization&amp;diff=60111&amp;oldid=prev</id>
		<title>Pravir Chandra at 00:53, 5 May 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SAMM_-_Roadmap_-_Government_Organization&amp;diff=60111&amp;oldid=prev"/>
				<updated>2009-05-05T00:53:13Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 00:53, 5 May 2009&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{OpenSAMM}}&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{OpenSAMM}}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:OWASP Software Assurance Maturity Model Project]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Government Organization=&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Government Organization=&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Pravir Chandra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SAMM_-_Roadmap_-_Government_Organization&amp;diff=59978&amp;oldid=prev</id>
		<title>Pravir Chandra: New page: {{OpenSAMM}} Category:OWASP Software Assurance Maturity Model Project  =Government Organization= &lt;div style=&quot;width:48%; float:right;&quot;&gt; 370px &lt;/div&gt; &lt;div s...</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SAMM_-_Roadmap_-_Government_Organization&amp;diff=59978&amp;oldid=prev"/>
				<updated>2009-05-03T21:11:37Z</updated>
		
		<summary type="html">&lt;p&gt;New page: {{OpenSAMM}} &lt;a href=&quot;/index.php/Category:OWASP_Software_Assurance_Maturity_Model_Project&quot; class=&quot;mw-redirect&quot; title=&quot;Category:OWASP Software Assurance Maturity Model Project&quot;&gt;Category:OWASP Software Assurance Maturity Model Project&lt;/a&gt;  =Government Organization= &amp;lt;div style=&amp;quot;width:48%; float:right;&amp;quot;&amp;gt; &lt;a href=&quot;/index.php/File:SAMM-Roadmap-GO.png&quot; title=&quot;File:SAMM-Roadmap-GO.png&quot;&gt;370px&lt;/a&gt; &amp;lt;/div&amp;gt; &amp;lt;div s...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{OpenSAMM}}&lt;br /&gt;
[[Category:OWASP Software Assurance Maturity Model Project]]&lt;br /&gt;
&lt;br /&gt;
=Government Organization=&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:48%; float:right;&amp;quot;&amp;gt;&lt;br /&gt;
[[Image:SAMM-Roadmap-GO.png|370px]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:48%; float:left; padding-right:10px;&amp;quot;&amp;gt;&lt;br /&gt;
==Rationale==&lt;br /&gt;
A Government Organization involves the core business function of being a state-affiliated organization that builds software to support public sector projects.&lt;br /&gt;
&lt;br /&gt;
Initially, Governance Practices are established, generally to get an idea of the overall compliance burden for the organization in context of the concrete roadmap for improvement.&lt;br /&gt;
&lt;br /&gt;
Because of risks of public exposure and the quantity of legacy code generally in place, early emphasis is given to Security Testing within the Verification Practices and later the more involved Code Review or Design Review Practices are developed.&lt;br /&gt;
&lt;br /&gt;
Similar emphasis is placed on the Construction and Deployment Practices. This helps establish the organization’s management of vulnerabilities and moves toward bolstering the security posture of the operating environment. At the same time, proactive security activities under Construction are built up to help prevent new issues in software under development.&lt;br /&gt;
&lt;br /&gt;
==Additional Considerations==&lt;br /&gt;
===Outsourced Development===&lt;br /&gt;
For organizations using external development resources, restrictions on code access typically leads to prioritization of Security Requirements activities instead of Code Review activities. Additionally, advancing Threat Assessment in earlier phases would allow the organization to better clarify security needs to the outsourced developers. Since expertise on software configuration will generally be strongest within the outsourced group, contracts should be constructed to account for the activities related to Operational Enablement.&lt;br /&gt;
&lt;br /&gt;
===Web Services Platforms===&lt;br /&gt;
For organizations building web services platforms, design errors can carry additional risks and be more costly to mitigate. Therefore, activities from Threat Assessment, Security Requirements, and Secure Architecture should be placed in earlier phases of the roadmap.&lt;br /&gt;
&lt;br /&gt;
===Regulatory Compliance===&lt;br /&gt;
For organizations under heavy regulations that affect business processes, the build-out of the Policy &amp;amp; Compliance Practice should be adjusted to accommodate external drivers. Likewise, organizations under a lighter compliance load should take the opportunity to push back build-out of that Practice in favor of others.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;float:left; width:100%;&amp;quot;&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
----&lt;br /&gt;
===Additional Resources===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ __NOEDITSECTION__&lt;/div&gt;</summary>
		<author><name>Pravir Chandra</name></author>	</entry>

	</feed>