Understanding the Software Assurance Maturity Model (SAMM)
N2K NetworksJuly 21, 20256 min59 views
11 connectionsΒ·16 entities in this videoβWhat is SAMM?
- π‘ SAMM stands for Software Assurance Maturity Model, a prescriptive, open-source model designed to guide strategies tailored to an organization's specific risks.
- π― The framework consists of 15 security practices structured into three maturity levels, helping organizations measure their progress against best practices.
Origin and Evolution of SAMM
- π Initially developed by Pravir Chandra in 2009, SAMM provides a way to measure how well practitioners are doing across five business functions: governance, design, implementation, verification, and operations.
- π In 2016, Chandra donated SAMM to the Open Web Application Security Project (OWASP), leading to the release of version 1.5 in 2017 with improved scoring granularity.
- π OWASP released version 2.0 in 2020, upgrading maturity criteria to favor automation and better alignment with development teams.
SAMM vs. BSIMM
- π§© SAMM prescribes what organizations should be doing to improve software security.
- π In contrast, the BSIMM (Build Security In Maturity Model) reports what organizations are actually doing based on observed initiatives and activities.
Benefits of a Maturity Model
- π§ A maturity model like SAMM helps quantify improvements in software development security, moving beyond a vague sense of 'better'.
- π It defines concretely how to perform individual security activities and, crucially, how to measure them for consistent efficacy across the organization.
- β This approach ensures a focus on the quality of execution rather than a mere "checkbox approach" to security tasks like code review.
Knowledge graph16 entities Β· 11 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
16 entities
Chapters3 moments
Key Moments
Transcript20 segments
Full Transcript
Topics11 themes
Whatβs Discussed
Software Assurance Maturity ModelSAMMOWASPSoftware SecurityMaturity ModelRisk ManagementSecurity PracticesPravir ChandraBSIMMAutomationCode Review
Smart Objects16 Β· 11 links
ConceptsΒ· 8
PeopleΒ· 2
CompaniesΒ· 4
EventΒ· 1
ProductΒ· 1