Software Assurance Maturity models
April 12, 2011 Leave a comment
I came across links to Software Assurance maturity models in the current issue of
Crosstalk.
There are so many maturity models to choose from but to the uninitiated they might
seem to be too theoretical.
- “Build Security In Maturity Model (BSIMM): www.bsimm2.com
- Capability Maturity Model Integration (CMMI): www.sei.cmu.edu/cmmi/index.cfm
- Open Software Assurance Maturity Model (OSAMM): www.opensamm.org
- Assurance Focus for CMMI: https://buildsecurityin.us-cert.gov/swa/downloads/Assurance_for_CMMI_Pilot_version_March_2009.pdf
- CERT Resilience Management Model (RMM): www.cert.org/resilience/rmm.html
- Build Security In website: https://buildsecurityin.us-cert.gov/bsi/home.html
- SwA Community Resources and Information Clearninghouse: https://buildsecurityin.us-cert.gov/swa/
- Making Security Measurable website: measurablesecurity.mitre.org/“
They serve as good points of reference and cover governance. As far as practical technical guidance is concerned I would look elsewhere.
They drive home the point that security has to be built into the product and have suggestions to address different compliance requirements like PCI-DSS using a process.