Dated: 03-12-2024
Ch03. Software Security Hardening Fundamentals - Owasp Samm - 1
- Software Assurance Maturity Model (SAMM) developed by OWASP
- OWASP Software Assurance Maturity Model (SAMM)
- Strategy & Metrics:
- Education & Guidance:
- Focused on arming personnel involved in the software lifecycle with knowledge and resources to design, develop, and deploy secure software
- With improved access to information, project teams will be better able to proactively identify and mitigate the specific security risks that apply to their organization.
- Policy & Compliance:
- Focused on understanding and meeting external legal and regulatory requirements while also driving internal security standards to ensure compliance in a way that's aligned with the business purpose of the org.
- A driving theme for improvement within this Practice is focus on project-level audits that gather information about the organization's behavior in order to check that expectations are being met.
- Lets look at SAMM Construction Phase in the next module
Post Assessments
_ is the main goal of the Education & Guidance phase in SAMMs Governance.
- Providing knowledge and resources for secure software development
- Establishing a framework for software security assurance
- Conducting project-level audits for compliance
- Meeting external legal requirements
In the Strategy & Metrics phase of SAMMs Governance, what is the primary focus?
- Establishing a framework for software security assurance
- Identifying external legal requirement
- Conducting project-level audits
- Enhancing access to information for project teams
In the context of software security: SAMM stands for _
- Security Assurance Management Model
- Secure Application Management Method
- Software Assurance Maturity Model
- Systematic Application Security Model