Difference between revisions of "OWASP SAMM Project"

From OWASP
Jump to: navigation, search
Line 124: Line 124:
 
= Downloads =
 
= Downloads =
  
[https://www.owasp.org/images/c/c0/SAMM-1.0.pdf Download OWASP SAMM v1.0 (English)]
+
Download SAMM v1.0:
 +
* in [https://www.owasp.org/images/c/c0/SAMM-1.0.pdf English - PDF], English - XML
 +
* in [https://www.owasp.org/images/a/a9/SAMM-1.0-es_MX.pdf Spanish - PDF], Spanish - XML
 +
* in [https://www.owasp.org/images/a/a9/SAMM-1.0-ja_JP.pdf Japanese - PDF], not available as XML
  
 +
 +
Trainings:
 
* Recent OWASP SAMM 1-Day training slide deck delivered by Bart De Win and Sebastien Deleersnyder at AppSec Europe 2014 in Cambridge
 
* Recent OWASP SAMM 1-Day training slide deck delivered by Bart De Win and Sebastien Deleersnyder at AppSec Europe 2014 in Cambridge
 
** Slide deck download [https://www.owasp.org/images/d/df/OpenSAMM_Training_vFINAL.pptx here]
 
** Slide deck download [https://www.owasp.org/images/d/df/OpenSAMM_Training_vFINAL.pptx here]
 
** Training description download [https://www.owasp.org/images/7/7c/Training_-_Bootstrap_and_improve_your_SDLC_with_OpenSAMM.docx here]
 
** Training description download [https://www.owasp.org/images/7/7c/Training_-_Bootstrap_and_improve_your_SDLC_with_OpenSAMM.docx here]
  
 +
Mappings:
 
* BSIMM-V mapping to SAMM activities:
 
* BSIMM-V mapping to SAMM activities:
 
** Spreadsheet download [https://www.owasp.org/images/f/f9/OpenSAMM-BSIMM-V-Mapping-data.xlsx here]
 
** Spreadsheet download [https://www.owasp.org/images/f/f9/OpenSAMM-BSIMM-V-Mapping-data.xlsx here]
 
** Presentation with start of analysis download [https://www.owasp.org/images/6/66/OpenSAMM_-_BSIMM-V_mapping.pptx here]
 
** Presentation with start of analysis download [https://www.owasp.org/images/6/66/OpenSAMM_-_BSIMM-V_mapping.pptx here]
  
 
+
Tools:
* Tools:
 
 
** Javascript visualization framework for SAMM on [https://github.com/qudosoft-labs/SAMMCharts github]
 
** Javascript visualization framework for SAMM on [https://github.com/qudosoft-labs/SAMMCharts github]
  

Revision as of 10:46, 10 January 2016

OWASP Project Header.jpg

The Software Assurance Maturity Model (SAMM) is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. SAMM helps you:

  • Evaluate an organization’s existing software security practices
  • Build a balanced software security assurance program in well-defined iterations
  • Demonstrate concrete improvements to a security assurance program
  • Define and measure security-related activities throughout an organization


DownloadButton.png


Dell uses OWASP’s Software Assurance Maturity Model (OpenSAMM) to help focus our resources and determine which components of our secure application development program to prioritize., (Michael J. Craigue, Information Security & Compliance, Dell, Inc.)



Quick Download

Download OWASP SAMM!

News and Events

Please see the News and Talks tabs

Change Log


Email List

Questions? Please ask on the SAMM Mailing List

Project Leaders

Project Leaders
Seba Deleersnyder Pravir Chandra Kuai Hinojosa Bart De Win

Related Projects


Classifications

Midlevel projects.png Owasp-defenders-small.png
Owasp-builders-small.png
C C A-S Alike 3.0
Project Type Files DOC.jpg


OwaspSAMM.png

The foundation of the model is built upon the core business functions of software development with security practices tied to each (see diagram below). The building blocks of the model are the three maturity levels defined for each of the twelve security practices. These define a wide variety of activities in which an organization could engage to reduce security risks and increase software assurance. Additional details are included to measure successful activity performance, understand the associated assurance benefits, estimate personnel and other costs.

SAMM-Overview.png

Click on any badge to learn more
G.png
Strategy & Metrics
SM1.png SM2.png SM3.png
Policy & Compliance
PC1.png PC2.png PC3.png
Education & Guidance
EG1.png EG2.png EG3.png
C.png
Threat Assessment
TA1.png TA2.png TA3.png
Security Requirements
SR1.png SR2.png SR3.png
Secure Architecture
SA1.png SA2.png SA3.png
V.png
Design Review
DR1.png DR2.png DR3.png
Code Review
CR1.png CR2.png CR3.png
Security Testing
ST1.png ST2.png ST3.png
D.png
Vulnerability Management
VM1.png VM2.png VM3.png
Environment Hardening
EH1.png EH2.png EH3.png
Operational Enablement
OE1.png OE2.png OE3.png

Download SAMM v1.0:


Trainings:

  • Recent OWASP SAMM 1-Day training slide deck delivered by Bart De Win and Sebastien Deleersnyder at AppSec Europe 2014 in Cambridge
    • Slide deck download here
    • Training description download here

Mappings:

  • BSIMM-V mapping to SAMM activities:
    • Spreadsheet download here
    • Presentation with start of analysis download here

Tools:

    • Javascript visualization framework for SAMM on github


OwaspSAMM.png

Upcoming SAMM Meetings

We now have weekly SAMM - summit preparation calls on Wednesdays at 21h30 CEST / 3:30pm ET.

The current DRAFT SAMM schedule is available here: https://open-security-summit.org/tracks/owaspsamm/

Preparation notes: https://docs.google.com/document/d/1piN4De5FGVUqpC-Q_wabRxWfAbjfaF90bYYzugtJM3k/edit#

The monthly call is on each 2nd Wednesday of the month at 21h30 CEST / 3:30pm EST.
Please join our GoToMeeting: https://global.gotomeeting.com/join/262891661
The call is open for everybody interested in SAMM or who wants to work on SAMM.

Previous SAMM Meetings

OwaspSAMM.png

In 2015 we organized our the first OWASP SAMM Summit in Dublin on 27-28 March, details >here< !!

Summit Notes:

"The SAMM summit provided an opportunity to breathe new life into a framework that I use to facilitate my day-to-day work and support my customers." Bruce C Jenkins, Fortify Security Lead, Hewlett-Packard Company

Previous workshop Notes:

During the AppSec conferences, the SAMM project team organises workshops for you to influence the direction SAMM evolves.

This is also an excellent opportunity to exchange experiences with your peers.

If you plan on attending http://appsec.eu be sure to get involved in the SAMM workshop (scheduled on Jun-23).

  • The agenda for the SAMM Workshop in Cambridge on 23-Jun-2014 is available here.

Previous workshop notes:

  • The notes for the SAMM Workshop in New York on 21-Nov-2013 are available here.
  • The notes for the SAMM Workshop in Hamburg on 21-Aug-2013 are available here.


OwaspSAMM.png

upcoming talks will be listed here:

  • OWASP DC - Software Assurance Maturity Model (SAMM) with Brian Glas! (2017-03-15)
  • OWASP NoVA - SAMM 1.5, what's changed and how it impacts you (2017-03-16)
  • InfoSec World - Software Assurance Maturity Model Evolutions (2017-04-03)

past talks:

  • OWASP 24/7 - Seba Deleersnyder discussing the upcoming SAMM Summit (listen - here) - 2015
  • OWASP Germany Day 2014: Seba Deleersnyder: OpenSAMM Best Practices: Lessons from the Trenches (download presentation) - 2014
  • AppSecEU14: Seba Deleersnyder & Bart De Win: OpenSAMM Best Practices: Lessons from the Trenches OpenSAMM Best Practices: Lessons from the Trenches (download presentation, see video) - 2014
  • AppSecEU13 - Hamburg: Seba Deleersnyder presenting a project update (download presentation) - 2013
  • OWASP Europe Tour 2013 - Geneva: Seba Deleersnyder presenting OpenSAMM and the renewed project (download presentation) - 2013
  • AppSecEU11 - Athens: Colin Watson presenting SAMM Training (download presentation) - 2011
  • AppSecEU09: Pravir Chandra presenting OpenSAMM v1.0 (download presentation) - 2009
  • Matt Bartoldus presentation on new SAMM project during OWASP London chapter (download presentation) - 2009
  • Pravir Chandra - first presentation discussing the next generation to the CLASP Project- a complete working of the details into a Software Assurance Maturity Model (SAMM). (download presentation) - 2009


OwaspSAMM.png

Latest News on SAMM

OwaspSAMM.png

SAMM is available in the following languages:

  • English
  • Spanish
  • Japanese
  • German

Carlos Allendes created a presentation in Spanish on SAMM during the 2011 LatAm tour, download the presentation.

You can use Crowdin to help improve these translations or add new ones right now!

OwaspSAMM.png

Project Roadmap:
Is available via this link


Release 1.1

The major features we are currently working on include:

  • Add quick start guide
  • Add tools & OWASP resources
  • Add use cases, experience
  • Revamp SAMM wiki

The date and exact items that will be included in 2.0 have not been finalized. The list of requested improvements is here

OwaspSAMM.png

Involvement in the development of SAMM is actively encouraged!

You do not have to be a security expert in order to contribute.

Some of the ways you can help:

Feedback

Please use the Mailing List for feedback:

  • What do like?
  • What don't you like?
  • How can we make SAMM easier to use?
  • How could SAMM be improved?


Localization

Are you fluent in another language? Can you help translate SAMM into that language?

You can use Crowdin to do that!

OwaspSAMM.png

SAMM Adopters

Current list of OpenSAMM adopters


SAMM is developed and maintained by a worldwide team of volunteers.

But we have also been helped by many organizations, either financially or by encouraging their employees to work on SAMM:

Acknowledgements

We would like to thank the following sponsors who donated funds to our project:


Belgium Chapter.PNG London Chapter.PNG

Aspectsecurity.png Astech Consulting logo.png Denim Group logo.jpg Gotham Digital Science logo.jpg

300px90px       NetSPI logo.png SI Logo Stacked Application Security.jpg LogoToreon.jpg Veracode-samm.png



OWASP Books logo.png This project has produced a book that can be downloaded or purchased.
Feel free to browse the full catalog of available OWASP books.

Retrieved from "https://www.owasp.org/index.php?title=OWASP_SAMM_Project&oldid=206177"