About 4 years ago I have joined the OWASP Software Assurance Maturity Model (SAMM) project […]
Modern software development moves fast, and so do the security challenges that come with it. […]
Understanding OWASP SAMM is only the beginning. The real value comes from using it to […]
Over the past year, our SAMMY tool has grown significantly. It now supports not just OWASP Software Assurance Maturity Model (SAMM) but also many other frameworks and standards. Whether you need a cybersecurity framework, quality framework, maturity model, or compliance standard, SAMMY unifies them all. This versatility often raises a key question: “Which framework is best for an application security program?” OWASP SAMM stands out, but what about Building Security In Maturity Model (BSIMM) or NIST Secure Software Development Framework (SSDF)? SAMM looks excellent on paper, but SSDF comes from NIST, a highly respected organization. Meanwhile, BSIMM is popular among large enterprises. I have already written a blog on BSIMM vs SAMM. BSIMM is not cheap and even if your organization has the budget, SAMM is likely a better pick. In this post, I will focus on comparing OWASP SAMM and NIST SSDF. Key Takeaways Reputable Frameworks: Both SAMM and SSDF[…]
Whether you are getting started with OWASP SAMM assessments at your organization, or you are starting to do SAMM assessments for your clients, there are lots of resources scattered around the internet that provide guidance and practical tips. On this page we gather the most valuable of these OWASP SAMM resources: The Whitepaper on effective SAMM Assessment Strategies: This whitepaper was created in the context of Global AppSec 2024 in Lisbon, it is a collaboration between Toreon and Codific. The paper is written by professional SAMM assessors and OWASP SAMM core team members, specifically from their practical experience running SAMM assessments at companies large and small. The paper covers: General introduction to SAMM Assessment tools Assessment types Interview planning The interview process Post interview validation Sample interview questions And much more Download the white paper on Effective SAMM Assessment strategies. The podcast on SAMM assessments Also in[…]
OWASP Software Assurance Maturity Model (SAMM) is one of the only comprehensive frameworks available for application security program management. Aside from BSIMM, there’s not much else around. Moreover, SAMM is open-source, making it accessible to everyone with zero barriers to entry. However there’s a catch: implementing OWASP SAMM comes with a learning curve. Beginner and even intermediate users seem to struggle with certain aspects of the model. Based on my experience, users have the hardest time figuring out: How to deal with quality criteria (or the “definition of done”) and what they mean; How to come up with a meaningful prioritization for the improvement roadmap; What type of evidence is required for demonstrating “compliance”; How to interpret the model for domains other than web application development; How can SAMM help for a smaller company. In this blog, I will offer 12 foolproof ways to ensure your SAMM assessments and improvement[…]









