Beruflich Dokumente
Kultur Dokumente
Version: 0.6
Description: One aim of the Software Assurance Maturity Model (SAMM) is to help organizations build software security assurance
programs. The current position and future targets can be charted and the SAMM document includes roadmap templates
for different industries. This spreadsheet helps produce roadmaps once the plan is known. It is structured with four
phases of improvement, like in SAMM, although could be altered to suit any number of stages.
SAMM The Software Assurance Maturity Model (SAMM) was created by Pravir Chandra and is now an Open Web Application
Security Project (OWASP) project.
SAMM is licensed under the Creative Commons Attribution-Share Alike 3.0 License
http://www.opensamm.org
Software Assurance Maturity Model (SAMM) Roadmap
<Org Name Here>
<Project Name Here>
<Version Here>
1
Strategy & metrics
0
3 1 2 3 4 5 6 7 8 9
1
Policy & Compliance
0
3 1 2 3 4 5 6 7 8 9
1
Education & Guidance
0
3 1 2 3 4 5 6 7 8 9
1
Threat Assessment
0
3 1 2 3 4 5 6 7 8 9
1
Security Requirements
0
1 2 3 4 5 6 7 8 9
1
Secure Architecture
0
1 2 3 4 5 6 7 8 9
1
Design Analysis
0
1 2 3 4 5 6 7 8 9
1
Code Review
0
1 2 3 4 5 6 7 8 9
1
Security Testing
0
1 2 3 4 5 6 7 8 9
1
Vulnerability Management
0
1 2 3 4 5 6 7 8 9
1
Environment Hardening
0
1 2 3 4 5 6 7 8 9
1
Operational Enablement
0
1 2 3 4 5 6 7 8 9
Software Assurance Maturity Model (SAMM) Roadmap Chart Template Notes
1 The chart template assumes four stages.
2 To update the charts, enter your own target levels for each of the security practices over the four phases. Take care, there are partially obscured cells
(white text) to the right of the phases in the data table - these are necessary for the correct formatting of the charts. They contain a formula that simply
duplicates the maturity level in the cell to their left.
3 Valid values for maturity levels are The values should be 0, 1, 2 or 3 only.
4 The charts are constructed using multiple Excel area charts, each with a single line of data - one for each security practice. The charts use background
pictures to provide the striping effect, and there is an empty chart with the grey striping in the background of all of these. Unfortunately it was also
necessary to add two white rectangle objects to mask the right and bottom borders of the latter empty chart.
5 The print area is set on the chart page only to include the charts, not the source data.
6 If you need fewer or more than four phases, you'll need to spend some time adding columns, altering charts and creating new background images (see
separate worksheet).
7 Most cells are locked and have protection turned on (without a password) - use Tools | Protection | Unprotect Sheet to turn off