Software Assurance Maturity models

I came across links to Software Assurance maturity models in the current issue of
Crosstalk.

There are so many maturity models to choose from but to the uninitiated they might
seem to be too theoretical.

  1. “Build Security In Maturity Model (BSIMM): www.bsimm2.com
  2. Capability Maturity Model Integration (CMMI): www.sei.cmu.edu/cmmi/index.cfm
  3. Open Software Assurance Maturity Model (OSAMM): www.opensamm.org
  4. Assurance Focus for CMMI: https://buildsecurityin.us-cert.gov/swa/downloads/Assurance_for_CMMI_Pilot_version_March_2009.pdf
  5. CERT Resilience Management Model (RMM): www.cert.org/resilience/rmm.html
  6. Build Security In website: https://buildsecurityin.us-cert.gov/bsi/home.html
  7. SwA Community Resources and Information Clearninghouse: https://buildsecurityin.us-cert.gov/swa/
  8. Making Security Measurable website: measurablesecurity.mitre.org/

They serve as good points of reference and cover governance. As far as practical technical guidance is concerned I would look elsewhere.

They drive home the point that security has to be built into the product and have suggestions to address different compliance requirements like PCI-DSS using a process.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: