27 March 2009

Software Assurance Maturity Model (SAMM)

The Software Assurance Maturity Model version 1.0 was released on Wednesday after a recent period of review and updating.

Partial page view in the Software Assurance Maturity Model (SAMM) document summarising the verification business function practices

The Software Assurance Maturity Model (SAMM) describes a reasonable and practical approach to building security into the software development lifecycle, for organisations of all sizes. The model, available as a free PDF download, can be used with a particular software project, software development team or a whole software development company.

SAMM specifies four business functions (governance, construction, verification and deployment) critical to building security in, each with three security practices. Within the twelve security practices SAMM defines three maturity levels as objectives, each with more stringent success metrics than the previous level. The security practices can be improved independently, giving a maturity fingerprint snapshot across the business functions.

One of the best uses will be to compare existing practices against the framework—and then choosing activities to improve which suit the particular organisation's culture and needs. SAMM is not prescriptive in how it can be used.

Additionally, the document is extremely well-designed making the content much more accessible than many others. Join the project mailing list if you want to contribute to its continuing development.

Posted on: 27 March 2009 at 12:50 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter


Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Software Assurance Maturity Model (SAMM)
ISO/IEC 18004:2006 QR code for https://clerkendweller.uk

Page https://www.clerkendweller.uk/2009/3/27/Software-Assurance-Maturity-Model-SAMM
Requested by on Monday, 30 November 2015 at 15:09 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use https://www.clerkendweller.uk/page/terms
Privacy statement https://www.clerkendweller.uk/page/privacy
© 2009-2015 clerkendweller.uk