OWASP SAMM

OWASP SAMM categorizes security practices into four key business functions—governance, construction, verification, and operations. It's a very practical guide for any organization to follow for self-assessment of the security maturity level. Microsoft SDL defines security practices during the development process while OWASP SAMM defines security practices based on business functions and the four levels of security maturity:

Business functions

Security practices

Governance

  • Strategy and metrics
  • Policy and compliance
  • Education and guidance

Construction

  • Threat assessment
  • Security requirements
  • Secure architecture

Verification

  • Design review
  • Implementation review
  • Security testing

Operations

  • Issue management ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.