This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP SAMM Project"

From OWASP
Jump to: navigation, search
 
(13 intermediate revisions by 2 users not shown)
Line 7: Line 7:
 
<div style="font-size:120%;border:none;margin: 0;color:#000">
 
<div style="font-size:120%;border:none;margin: 0;color:#000">
  
'''OWASP SAMM v1.5 available in the downloads section!'''
+
'''Join us at the Open Security Summit next June'''<br>
 +
We have a dedicated [https://opensecuritysummit.org/tracks/owasp-samm/ SAMM track] at the upcoming Open Security Summit (supported by OWASP)!<br>
 +
You can register for on-site or remote participation [https://opensecuritysummit.org/tickets/ here].<br>
 +
 
 +
'''OWASP SAMMv2 beta released for community review'''<br>
 +
We are very proud to announce a new version of SAMM!<br>
 +
Check it out on our new website: https://owaspsamm.org/.<br>
 +
Please, read our notes on how to provide [https://owaspsamm.org/v2.0b/feedback/ feedback].
 +
 
 +
'''OWASP SAMM v1.5 available in the downloads section!'''<br>
 +
We are now working on the Beta release of OWASP SAMMv2, our work in progress is available [https://owaspsamm.org online on our new web site]. <br>
  
 
'''Join our monthly calls'''
 
'''Join our monthly calls'''
Line 14: Line 24:
 
* The call is open for everybody interested in SAMM or who wants to work on SAMM. <br>
 
* The call is open for everybody interested in SAMM or who wants to work on SAMM. <br>
  
'''2018 OWASP SAMM Summit (4-8 JUNE 2018, London)'''
+
'''Join us on the OWASP SAMM project Slack channel'''
* Join our 2018 OWASP SAMM Summit near London as part of the [https://open-security-summit.org/ Open Security Summit].<br>
+
* Join our project slack channel on https://owasp.slack.com/messages/C0VF1EJGH
 +
* If you do not have an OWASP Slack workspace account yet, contact one of our project leaders to get an invite link.
 +
 
 +
'''2019 OWASP SAMM Summit (3-7 JUNE 2019, Bedford, UK)'''
 +
* Join our 2019 OWASP SAMM Summit at Woburn Forest, Bedfordshire as part of the [https://open-security-summit.org/ Open Security Summit].
 
* We will organize working sessions in a 5-day sprint to draft SAMM v2.0.  
 
* We will organize working sessions in a 5-day sprint to draft SAMM v2.0.  
 
* Register online [https://open-security-summit.org/tickets/ here]
 
* Register online [https://open-security-summit.org/tickets/ here]
 
* Sponsor the SAMM2, more details [https://www.owasp.org/index.php/OWASP_SAMM_Project#tab=Project_Sponsors here]
 
* Sponsor the SAMM2, more details [https://www.owasp.org/index.php/OWASP_SAMM_Project#tab=Project_Sponsors here]
 
  
 
The Software Assurance Maturity Model (SAMM) is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. SAMM helps you:
 
The Software Assurance Maturity Model (SAMM) is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. SAMM helps you:
Line 38: Line 51:
  
 
== Quick Download v1.5 ==
 
== Quick Download v1.5 ==
[https://github.com/OWASP/samm/blob/master/v1.5/Final/OWASP_SAMM_v1.5.zip All SAMM v1.5 files (.zip)] <br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.5/Final/OWASP_SAMM_v1.5.zip All SAMM v1.5 files (.zip)] <br>
[https://github.com/OWASP/samm/blob/master/v1.5/Final/SAMM_Core_V1-5_FINAL.pdf SAMM Core Model] <br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.5/Final/SAMM_Core_V1-5_FINAL.pdf SAMM Core Model] <br>
[https://github.com/OWASP/samm/blob/master/v1.5/Final/SAMM_How_To_V1-5_FINAL.pdf How-To Guide] <br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.5/Final/SAMM_How_To_V1-5_FINAL.pdf How-To Guide] <br>
[https://github.com/OWASP/samm/blob/master/v1.5/Final/SAMM_Quick_Start_V1-5_FINAL.pdf Quick Start Guide] <br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.5/Final/SAMM_Quick_Start_V1-5_FINAL.pdf Quick Start Guide] <br>
[https://github.com/OWASP/samm/blob/master/v1.5/Final/SAMM_Assessment_Toolbox_v1.5_FINAL.xlsx SAMM Toolbox] <br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.5/Final/SAMM_Assessment_Toolbox_v1.5_FINAL.xlsx SAMM Toolbox] <br>
[https://github.com/OWASP/samm/blob/master/v1.5/Final/SAMM_Assessment_Toolbox_v1.5-Example_FINAL.xlsx SAMM Toolbox Example] <br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.5/Final/SAMM_Assessment_Toolbox_v1.5-Example_FINAL.xlsx SAMM Toolbox Example] <br>
 
[https://github.com/OWASP/samm/ OWASP SAMM on GitHub]
 
[https://github.com/OWASP/samm/ OWASP SAMM on GitHub]
  
 
== Quick Download v1.1.1 ==
 
== Quick Download v1.1.1 ==
  
[https://github.com/OWASP/samm/blob/master/v1.1/Final/SAMM_Core_V1-1-Final-1page.pdf SAMM Core Model]<br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.1/Final/SAMM_Core_V1-1-Final-1page.pdf SAMM Core Model]<br>
[https://github.com/OWASP/samm/blob/master/v1.1/Final/SAMM_How_To_V1-1-Final-1page.pdf How-To Guide] <br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.1/Final/SAMM_How_To_V1-1-Final-1page.pdf How-To Guide] <br>
[https://github.com/OWASP/samm/blob/master/v1.1/Final/SAMM_Quick_Start_V1-1-Final-1page.pdf Quick-Start Guide] <br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.1/Final/SAMM_Quick_Start_V1-1-Final-1page.pdf Quick-Start Guide] <br>
[https://github.com/OWASP/samm/blob/master/v1.1/Final/SAMM_Assessment_Toolbox_v1-1-Final.xlsx Updated SAMM Tool Box]<br>
+
[https://github.com/OWASP/samm/raw/master/Supporting%20Resources/v1.1/Final/SAMM_Assessment_Toolbox_v1-1-Final.xlsx Updated SAMM Tool Box]<br>
 
[https://github.com/OWASP/samm OWASP SAMM on GitHub]
 
[https://github.com/OWASP/samm OWASP SAMM on GitHub]
  
Line 220: Line 233:
  
 
[[Image:OwaspSAMM.png|right]]
 
[[Image:OwaspSAMM.png|right]]
 +
 +
'''Join us at the Open Security Summit next June'''<br>
 +
We have a dedicated [https://opensecuritysummit.org/tracks/owasp-samm/ SAMM track] at the upcoming Open Security Summit (supported by OWASP)!<br>
 +
You can register for on-site or remote participation [https://opensecuritysummit.org/tickets/ here].<br>
 +
 +
We organised a core team summit in November 2018 in Minneapolis, check out the results [https://github.com/OWASP/samm/blob/master/Supporting%20Resources/v2.0/summit-201810-Minneapolis/Summit-outcomes.md here].
  
 
In 2016 we organized our second OWASP SAMM Summit in New York on 20-21 April, details [https://www.owasp.org/index.php/OWASP_SAMM_Summit_2016 >here<] !!
 
In 2016 we organized our second OWASP SAMM Summit in New York on 20-21 April, details [https://www.owasp.org/index.php/OWASP_SAMM_Summit_2016 >here<] !!
Line 367: Line 386:
 
We are seeking sponsors to support OWASP SAMM. All proceeds from the sponsorship support the mission of the OWASP Foundation and the further development of SAMM. Supporting the project drives the funding for research grants, SAMM hosting, tools, templates, documents, promotion, and more.
 
We are seeking sponsors to support OWASP SAMM. All proceeds from the sponsorship support the mission of the OWASP Foundation and the further development of SAMM. Supporting the project drives the funding for research grants, SAMM hosting, tools, templates, documents, promotion, and more.
  
By sponsoring SAMM, you not only support an important and flagship OWASP project, you will also get visibility during the next SAMM Summit (part of the OWASP Summit 2018) and recognition on the OWASP SAMM project web site and the next release of SAMM (version 2.0).
+
By sponsoring SAMM, you not only support an important and flagship OWASP project, you will also get visibility during the next SAMM Summit (part of the [https://open-security-summit.org/ Open Security Summit 2019]) and recognition on the OWASP SAMM [https://owaspsamm.org/ web site] and the next release of SAMM (version 2.0).
  
For more information: Download our [https://www.owasp.org/images/f/fb/OWASP_SAMM2_Sponsorship_Form_v20170212.pdf SAMM2 sponsorship brochure].
+
For more information: Contact [mailto:seba@owasp.org seba@owasp.org]
 
 
Contact [mailto:seba@owasp.org seba@owasp.org] to activate your sponsorship.
 
  
 
==== Acknowledgements ====
 
==== Acknowledgements ====
 
 
  
 
We would like to thank the following sponsors who donated funds to our project:
 
We would like to thank the following sponsors who donated funds to our project:
  
[[File:OWASP-NoVA-Chapter-Logo.PNG|250px|link=https://www.owasp.org/index.php/Virginia]]
+
[[File:Imageedit_15_5335623074.png|frameless]][[File:Fortify blue 800px.png|250px|link=https://www.microfocus.com/en-us/solutions/application-security]][[File:1280px-NCC Group logo.svg.png|frameless]][[File:Splunk copy.png|frameless]]  
[[File:Belgium_Chapter.PNG|250px|link=https://www.owasp.org/index.php/Belgium]]
 
[[File:London_Chapter.PNG|250px|link=https://www.owasp.org/index.php/London]]
 
 
 
[[File:Aspectsecurity.png|250px|link=http://www.aspectsecurity.com]]
 
[[File:Astech_Consulting_logo.png|250px|link=http://www.astechconsulting.com/]]
 
[[File:Denim_Group_logo.jpg|250px|link=http://www.denimgroup.com/]]  
 
[[File:Gotham_Digital_Science_logo.jpg|250px|link=http://www.gdssecurity.com/]]
 
 
 
{{MemberLinksv2|link=http://www.hpenterprisesecurity.com|logo=HP_Blue_RGB_150_SM.png|size=300px90px}}
 
[[File:NetSPI_logo.png|250px|link=http://www.netspi.com/]]
 
[[Image:PwC_logo_4colourprint_(2)_Resized_good_one.jpg|150px|link=http://www.pwc.com]]
 
[[File:SI_Logo_Stacked_Application_Security.jpg|250px|link=http://www.securityinnovation.com/]]
 
[[File:LogoToreon.jpg|250px|link=http://www.toreon.com]]  
 
[[File:Veracode-samm.png|250px|link=http://www.veracode.com]]  
 
  
  

Latest revision as of 06:42, 10 May 2019

Flagship big.jpg

Join us at the Open Security Summit next June
We have a dedicated SAMM track at the upcoming Open Security Summit (supported by OWASP)!
You can register for on-site or remote participation here.

OWASP SAMMv2 beta released for community review
We are very proud to announce a new version of SAMM!
Check it out on our new website: https://owaspsamm.org/.
Please, read our notes on how to provide feedback.

OWASP SAMM v1.5 available in the downloads section!
We are now working on the Beta release of OWASP SAMMv2, our work in progress is available online on our new web site.

Join our monthly calls

  • The monthly call is on each 2nd Wednesday of the month at 21h30 CEST / 3:30pm EST.
  • Please join our GoToMeeting: https://global.gotomeeting.com/join/262891661
  • The call is open for everybody interested in SAMM or who wants to work on SAMM.

Join us on the OWASP SAMM project Slack channel

2019 OWASP SAMM Summit (3-7 JUNE 2019, Bedford, UK)

  • Join our 2019 OWASP SAMM Summit at Woburn Forest, Bedfordshire as part of the Open Security Summit.
  • We will organize working sessions in a 5-day sprint to draft SAMM v2.0.
  • Register online here
  • Sponsor the SAMM2, more details here

The Software Assurance Maturity Model (SAMM) is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. SAMM helps you:

  • Evaluate an organization’s existing software security practices
  • Build a balanced software security assurance program in well-defined iterations
  • Demonstrate concrete improvements to a security assurance program
  • Define and measure security-related activities throughout an organization


Dell uses OWASP’s Software Assurance Maturity Model (Owasp SAMM) to help focus our resources and determine which components of our secure application development program to prioritize., (Michael J. Craigue, Information Security & Compliance, Dell, Inc.)

Follow OWASP SAMM on twitter: @owaspsamm


Quick Download v1.5

All SAMM v1.5 files (.zip)
SAMM Core Model
How-To Guide
Quick Start Guide
SAMM Toolbox
SAMM Toolbox Example
OWASP SAMM on GitHub

Quick Download v1.1.1

SAMM Core Model
How-To Guide
Quick-Start Guide
Updated SAMM Tool Box
OWASP SAMM on GitHub

News and Events

Please see the News and Talks tabs

Change Log

Email List

Questions? Please ask on the SAMM Mailing List

Project Leaders

Seba Deleersnyder
Bart De Win

Related Projects


Classifications

Owasp-flagship-trans-85.png Owasp-defenders-small.png
Owasp-builders-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg


OWASP Books logo.png This project has produced a book that can be downloaded or purchased.
Feel free to browse the full catalog of available OWASP books.

Retrieved from "https://wiki.owasp.org/index.php?title=OWASP_SAMM_Project&oldid=251306"