This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP SAMM Project"

From OWASP
Jump to: navigation, search
m (Updated github link)
m (Minor updates to bring information current)
Line 244: Line 244:
 
<div style="font-size:120%;border:none;margin: 0;color:#000">
 
<div style="font-size:120%;border:none;margin: 0;color:#000">
  
'''SAMM is available in the following languages:'''
+
'''SAMM v1.0 is available in the following languages:'''
  
 
* English
 
* English
Line 262: Line 262:
  
 
Updated roadmap:
 
Updated roadmap:
Next 1.2 release, updated scoring:
+
Next 1.5 release, updated scoring:
* Recover source and move it to an asciidoctor based document.
 
 
* Clarification of maturity levels (syntactic changes to keep the text consistent)
 
* Clarification of maturity levels (syntactic changes to keep the text consistent)
 
* Not change activities but try to impose the current scoring system on existing activities, i.e. move from binary yes/no to the multi-tiered questions/answers of the current proposal.  
 
* Not change activities but try to impose the current scoring system on existing activities, i.e. move from binary yes/no to the multi-tiered questions/answers of the current proposal.  
Line 271: Line 270:
 
* Review and where necessary clarify current questions
 
* Review and where necessary clarify current questions
 
* Consider v1.1 remarks that were not withheld for the previous release
 
* Consider v1.1 remarks that were not withheld for the previous release
Targeted completion date: end of september in time for Appsec USA (October 11, 2016)
+
Targeted completion date: February 28, 2017
  
 
SAMM version 2.0
 
SAMM version 2.0
Line 278: Line 277:
 
* Update quickstart guide, TB, HTG.  
 
* Update quickstart guide, TB, HTG.  
 
* Success metrics: How well does the model work: Linked to the benchmarking project.
 
* Success metrics: How well does the model work: Linked to the benchmarking project.
Timing: Target release appseceu 2017. Target rc release for samm summit 2017
+
Timing: Workshops as part of OWASP Project Summit June 2017
  
 
</div>
 
</div>

Revision as of 02:41, 28 February 2017

Flagship big.jpg

OWASP SAMM v1.1 available in the downloads section! (Press Release)

The Software Assurance Maturity Model (SAMM) is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. SAMM helps you:

  • Evaluate an organization’s existing software security practices
  • Build a balanced software security assurance program in well-defined iterations
  • Demonstrate concrete improvements to a security assurance program
  • Define and measure security-related activities throughout an organization


Dell uses OWASP’s Software Assurance Maturity Model (Owasp SAMM) to help focus our resources and determine which components of our secure application development program to prioritize., (Michael J. Craigue, Information Security & Compliance, Dell, Inc.)

Follow OWASP SAMM on twitter: @owaspsamm


Quick Download v1.5

All SAMM files (.zip)
SAMM Core Model
How-To Guide
Quick Start Guide
SAMM Toolbox
SAMM Toolbox Example
OWASP SAMM on GitHub

Quick Download v1.1.1

SAMM Core Model
How-To Guide
Quick-Start Guide
Updated SAMM Tool Box
OWASP SAMM on GitHub

News and Events

Please see the News and Talks tabs

Change Log


Email List

Questions? Please ask on the SAMM Mailing List

Project Leaders

Seba Deleersnyder
Bart De Win
Brian Glas

Related Projects


Classifications

Owasp-flagship-trans-85.png Owasp-defenders-small.png
Owasp-builders-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg


OWASP Books logo.png This project has produced a book that can be downloaded or purchased.
Feel free to browse the full catalog of available OWASP books.

Retrieved from "https://wiki.owasp.org/index.php?title=OWASP_SAMM_Project&oldid=226836"