SlideShare a Scribd company logo
http://digitalcatharsis.files.wordpress.com/2008/10/sleeping-man_ml.jpg

Good Morning
openSAMM

{

Why & How?
http://api.ning.com/files/OMGuiScfW0WEzLqgZ-vEG1Gocfg9TzXJ*3p8tfJVh6piUZb380lsGCXDJa0aFePIDX7qFwM16dSET5kxHSYqOcFNjdBtZiK/elephant.jpg
http://30dom.com/wp-content/uploads/2013/11/olympic-weight-lifting-wallpaperli-xueying-weightlifting-olympic--china-photos-and-wallpapers-nusxdel.jpg
http://www.veracode.com/blog/wp-content/uploads/2013/06/bug-bounty-programs.jpg
https://www.owasp.org/images/thumb/f/ff/Security_in_the_SDLC_Process.png/600px-Security_in_the_SDLC_Process.png
http://devpolicy.org/wp-content/uploads/2013/08/Value-for-money.jpg
http://www.rms.net/roi_investreturn.gif
http://www.shipulski.com/wp-content/uploads/2012/06/Impossible.jpeg
https://s3.amazonaws.com/pbblogassets/uploads/2013/04/donkey-pulling-cart.jpg
http://www.you-stylish-barcelona-apartments.com/blog/wp-content/uploads/2010/09/what-to-do.JPG.jpeg






Classification system for a set of processes /
function
Shows characteristics of processes over
different levels
Examples




CMMI (DEV, SVC, ACQ)
SSE-CMM
BSIMM, openSAMM, etc

Maturity Models
Owasp hyd 28_dec2013_opensamm




Open Software Assurance Maturity Model
OWASP Project
Open framework to help organizations





Formulate
Implement
Strategy for software security
Tailored to the specific risks facing the
organization

openSAMM




Recognizes 4 type of
business functions
Any organization
performing software
development would
have these (names
could be different)

openSAMM



3 business practices for each function
3 objectives (for levels) under each practice






0 (implied starting point, not included)
1 (initial understanding and ad hoc provision of practice)
2 (increase efficiency / effectiveness of practice)
3 (comprehensive mastery of the practice)

openSAMM - Security
Practices
openSAMM - Example


For every level, SAMM defines








Objective
Activities
Results
Success Metrics
Costs
Personnel
Related Levels

openSAMM
http://creativeconstruction.files.wordpress.com/2013/02/how_to_do_one_thing_at_a_time.jpg
http://www.jasonshen.com/wp-content/uploads/2012/04/buy-in-image-560x355.jpg
Step 2 - Perform Gap
Assessment
Step 3 - Create Roadmap /
Assurance Program



Perform practices / activities for level 1
Keep assessing it till you are satisfied and the
scorecard tells you to




Inform management with the updated roadmap
in a periodic manner

Move to next level after you are done with the
previous one

Step 4 - Execute with
periodic reviews



www.sripati.info
http://in.linkedin.com/in/sripati

Who Am I



http://www.opensamm.org/downloads/resources/OpenSAMM-1.0.ppt
http://www.opensamm.org/downloads/resources/20090602Software%20Assurance%20Maturity%20Model.ppt

Credits

More Related Content

DOCX
Task 3 mood board
DOCX
Cite sources
TXT
PPTX
smartwatch
PPTX
Abstracciones configuraciones
PPTX
Slide show koby
DOCX
Mood board
DOCX
Robot moodboard word
Task 3 mood board
Cite sources
smartwatch
Abstracciones configuraciones
Slide show koby
Mood board
Robot moodboard word

What's hot (19)

PPTX
Water and Life
PPT
Expansion & Industrialization
DOCX
Research referance images
PDF
Usability testing and Silverback (in Japanese)
DOCX
Works cited
PPTX
E6 motion graphic research
PPTX
Portfolio1
PPTX
C17 gm
PDF
Dream Jobs
DOCX
Moodboard
DOCX
PPTX
Photographic elements
PPTX
Abstracciones
KEY
French Power Point
PPT
Emily Imbrogno HIST 3ES3
PPTX
PPTX
Task 1 aptureure
PPTX
Symbiosis mutualism
PPT
Darius williamsvisual resume
Water and Life
Expansion & Industrialization
Research referance images
Usability testing and Silverback (in Japanese)
Works cited
E6 motion graphic research
Portfolio1
C17 gm
Dream Jobs
Moodboard
Photographic elements
Abstracciones
French Power Point
Emily Imbrogno HIST 3ES3
Task 1 aptureure
Symbiosis mutualism
Darius williamsvisual resume
Ad

Similar to Owasp hyd 28_dec2013_opensamm (20)

PDF
OWASP San Antonio: Open Software Assurance Maturity Model (OpenSAMM)
PDF
Running a Software Security Program with Open Source Tools (Course)
PDF
Running a Software Security Program with Open Source Tools
PPTX
How is Your AppSec Program Doing Compared to Others
PPTX
HouSecCon 2019: Offensive Security - Starting from Scratch
PDF
Introduction to Software Security Initiative
PDF
Giving your AppSec program the edge - using OpenSAMM for benchmarking and sof...
PPTX
OWASP Open SAMM
PPT
Software Security in the Real World
PPT
3830100.ppt
PDF
Application Risk Prioritization - Overview - Secure360 2015 - Part 1 of 2
PPTX
Security in an Interconnected and Complex World of Software
PDF
PDF
Building a Modern Security Engineering Organization. Zane Lackey
PPTX
Bootstrapping an Open-Source Program Office at Blue Cross NC
PPTX
Open Source Defense for Edge 2017
PPT
Secure SDLC for Software
PDF
Software Security Engineering (Learnings from the past to fix the future) - B...
PDF
"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008
OWASP San Antonio: Open Software Assurance Maturity Model (OpenSAMM)
Running a Software Security Program with Open Source Tools (Course)
Running a Software Security Program with Open Source Tools
How is Your AppSec Program Doing Compared to Others
HouSecCon 2019: Offensive Security - Starting from Scratch
Introduction to Software Security Initiative
Giving your AppSec program the edge - using OpenSAMM for benchmarking and sof...
OWASP Open SAMM
Software Security in the Real World
3830100.ppt
Application Risk Prioritization - Overview - Secure360 2015 - Part 1 of 2
Security in an Interconnected and Complex World of Software
Building a Modern Security Engineering Organization. Zane Lackey
Bootstrapping an Open-Source Program Office at Blue Cross NC
Open Source Defense for Edge 2017
Secure SDLC for Software
Software Security Engineering (Learnings from the past to fix the future) - B...
"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008
Ad

Recently uploaded (20)

PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
cuic standard and advanced reporting.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Empathic Computing: Creating Shared Understanding
PDF
A comparative analysis of optical character recognition models for extracting...
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
1. Introduction to Computer Programming.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Spectroscopy.pptx food analysis technology
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PPT
Teaching material agriculture food technology
Network Security Unit 5.pdf for BCA BBA.
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Unlocking AI with Model Context Protocol (MCP)
Digital-Transformation-Roadmap-for-Companies.pptx
cuic standard and advanced reporting.pdf
Assigned Numbers - 2025 - Bluetooth® Document
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Empathic Computing: Creating Shared Understanding
A comparative analysis of optical character recognition models for extracting...
Encapsulation_ Review paper, used for researhc scholars
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
1. Introduction to Computer Programming.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
Spectroscopy.pptx food analysis technology
Per capita expenditure prediction using model stacking based on satellite ima...
20250228 LYD VKU AI Blended-Learning.pptx
The Rise and Fall of 3GPP – Time for a Sabbatical?
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Teaching material agriculture food technology

Owasp hyd 28_dec2013_opensamm

Editor's Notes

  • #8: Management View of secure SDLC
  • #10: This is what management usually expects people to implement security
  • #11: An organization changes over time, as a result of which, business prefers indicators that show progress across various areas of implementation to gauge where we are going