Sie sind auf Seite 1von 7

Software Assurance Maturity Model (SAMM) Roadmap Chart Template

Version: 0.6

Author: Colin Watson, Watson Hall Ltd


colin(at)watsonhall.com
http://www.watsonhall.com/

Description: One aim of the Software Assurance Maturity Model (SAMM) is to help organizations build software security assurance
programs. The current position and future targets can be charted and the SAMM document includes roadmap templates
for different industries. This spreadsheet helps produce roadmaps once the plan is known. It is structured with four
phases of improvement, like in SAMM, although could be altered to suit any number of stages.

Contributors: Aidan Lynch

License: Creative Commons Attribution-ShareAlike 3.0 License


This work is licensed under the Creative Commons Attribution-Share Alike 3.0 License. To view a copy of this license, visit
http://creativecommons.org/licenses/by-sa/3.0/legalcode; or, (b) send a letter to Creative Commons, 171 2nd Street,
Suite 300, San Francisco, California, 94105, USA.

SAMM The Software Assurance Maturity Model (SAMM) was created by Pravir Chandra and is now an Open Web Application
Security Project (OWASP) project.
SAMM is licensed under the Creative Commons Attribution-Share Alike 3.0 License
http://www.opensamm.org
Software Assurance Maturity Model (SAMM) Roadmap
<Org Name Here>
<Project Name Here>
<Version Here>

Security Practice Phase

One Two Three Four


3

1
Strategy & metrics
0
3 1 2 3 4 5 6 7 8 9

1
Policy & Compliance
0
3 1 2 3 4 5 6 7 8 9

1
Education & Guidance
0
3 1 2 3 4 5 6 7 8 9

1
Threat Assessment
0
3 1 2 3 4 5 6 7 8 9

1
Security Requirements
0
1 2 3 4 5 6 7 8 9

1
Secure Architecture
0
1 2 3 4 5 6 7 8 9

1
Design Analysis
0
1 2 3 4 5 6 7 8 9

1
Code Review

0
1 2 3 4 5 6 7 8 9

1
Security Testing

0
1 2 3 4 5 6 7 8 9

1
Vulnerability Management

0
1 2 3 4 5 6 7 8 9

1
Environment Hardening

0
1 2 3 4 5 6 7 8 9

1
Operational Enablement

0
1 2 3 4 5 6 7 8 9
Software Assurance Maturity Model (SAMM) Roadmap Chart Template Notes
1 The chart template assumes four stages.

2 To update the charts, enter your own target levels for each of the security practices over the four phases. Take care, there are partially obscured cells
(white text) to the right of the phases in the data table - these are necessary for the correct formatting of the charts. They contain a formula that simply
duplicates the maturity level in the cell to their left.

3 Valid values for maturity levels are The values should be 0, 1, 2 or 3 only.

4 The charts are constructed using multiple Excel area charts, each with a single line of data - one for each security practice. The charts use background
pictures to provide the striping effect, and there is an empty chart with the grey striping in the background of all of these. Unfortunately it was also
necessary to add two white rectangle objects to mask the right and bottom borders of the latter empty chart.

5 The print area is set on the chart page only to include the charts, not the source data.

6 If you need fewer or more than four phases, you'll need to spend some time adding columns, altering charts and creating new background images (see
separate worksheet).

7 Most cells are locked and have protection turned on (without a password) - use Tools | Protection | Unprotect Sheet to turn off

8 See also the SAMM Interview template v1.0


http://nickcoblentz.blogspot.com/2009/06/samm-inteview-template-version-10.html
Software Assurance Maturity Model (SAMM) Roadmap Chart Tem

Das könnte Ihnen auch gefallen