OWASP Maturity Models
OWASP has developed the Software Assurance Maturity Model (SAMM) that focuses on the use of CMM processes and thinking to achieve greater quality, stability, and security for software systems.
3 slides · 1 min read · Domain 8
- The OWASP SAMM, as with all OWASP's projects, provides an open framework approach for measuring and improving secure software development.
- The OWASP SAMM Model is guided by the business functions: governance, design, implementation, verification, and operations. It can be tailored to the specific risks for each organization.
- For more information, see https://owasp.org/www-project-samm/
- OWASP's DevSecOps Maturity Model (DSOMM) is a relatively new project that brings CMM thinking to DevSecOps. https://owasp.org/www-projectdevsecops-maturity-model/
