EPISODE · May 26, 2020 · 40 MIN
Sebastien Deleersnyder and Bart De Win — OWASP SAMM
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How does an organization improve software security without reducing maturity to a checklist? Sebastien Deleersnyder and Bart De Win join Chris and Robert to explain OWASP SAMM, the open framework for assessing and evolving a software assurance program. They trace the project’s history, explain the model’s business functions, practices, streams, and maturity levels, and show how teams can turn an assessment into a realistic roadmap. The conversation also covers version 2, companion resources, education, community events, and how SAMM differs from commercial maturity models. The result is a practical introduction for organizations that want a shared language for improvement without prescribing one identical program for everyone.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Sebastien Deleersnyder and Bart De Win:→ OWASP SAMM→ ToreonMentioned in this episode:→ OWASP SAMM→ OWASP SAMM project→ BSIMM→ Gary McGrawFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introducing OWASP SAMM02:07 Sebastien and Bart’s paths to the project05:08 The name behind the model06:22 How SAMM began09:00 What SAMM measures13:00 Using SAMM inside an organization13:56 What changed in SAMM version 217:35 Turning an assessment into a roadmap22:00 Business functions, practices, and streams23:00 Companion projects and supporting resources27:00 Education and community adoption31:00 How SAMM versioning works33:00 SAMM user days and community feedback35:00 The cost of using an open model37:00 Getting started with SAMM
Embed this episode
What this episode covers
How does an organization improve software security without reducing maturity to a checklist? Sebastien Deleersnyder and Bart De Win join Chris and Robert to explain OWASP SAMM, the open framework for assessing and evolving a software assurance program. They trace the project’s history, explain the model’s business functions, practices, streams, and maturity levels, and show how teams can turn an assessment into a realistic roadmap. The conversation also covers version 2, companion resources, ...
Ready to play
Sebastien Deleersnyder and Bart De Win — OWASP SAMM
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.