
OWASP SAMM
Software Assurance Maturity Model for measuring and improving secure development practices.
Overview
OWASP SAMM (Software Assurance Maturity Model) is an open framework maintained by the OWASP Foundation. It provides a measurable way for organizations to analyze and improve their software security posture. The model covers five business functions (Governance, Design, Implementation, Verification, and Operations), each with three security practices measured across three maturity levels. CodeMiners uses SAMM to assess, benchmark, and continuously improve software security practices across all projects.
Governing Body
OWASP Foundation (Open Worldwide Application Security Project)
Scope of Certification
Covers five business functions: Governance (strategy, metrics, policy, compliance), Design (threat assessment, security requirements, security architecture), Implementation (secure build, secure deployment, defect management), Verification (architecture assessment, requirements-driven testing, security testing), and Operations (incident management, environment management, operational management).
Audit and Assessment Process
Organizations conduct self-assessments or engage external assessors to evaluate maturity across all 15 practices. Each practice is scored at Level 0 (implicit), Level 1 (initial), Level 2 (managed), or Level 3 (defined/measured). Results produce a maturity scorecard and improvement roadmap.
Key Requirements
- Security governance with defined strategy and metrics
- Threat modeling integrated into design processes
- Secure coding standards and automated security testing
- Security requirements derived from threat assessments
- Vulnerability management with defined SLAs
- Incident response procedures for application-level incidents
Compliance Entitlements
- Structured software security maturity assessment across 15 practices
- Measurable improvement roadmap from Level 1 to Level 3 maturity
- Coverage of governance, design, implementation, verification, and operations
- Industry-standard framework used by enterprises and government agencies
Client Benefits
- Provides a quantified view of CodeMiners' software security maturity
- Demonstrates continuous improvement commitment through measurable benchmarks
- Ensures security is integrated into every phase of the development lifecycle
Related Certifications
Build With an Award-Winning Team
65+ Clutch badges. 20+ certifications. 200+ verified reviews.
Start Your Project