Owasp hyd 28_dec2013_opensamm

25
ood Morning http://digitalcatharsis.files.wordpress.com/2008/10/s leeping-man_ml.jpg

description

 

Transcript of Owasp hyd 28_dec2013_opensamm

Page 2: Owasp hyd 28_dec2013_opensamm

{openSAMM

Why & How?

Page 5: Owasp hyd 28_dec2013_opensamm

http://www.veracode.com/blog/wp-content/uploads/2013/06/bug-bounty-programs.jpg

Page 6: Owasp hyd 28_dec2013_opensamm

https://www.owasp.org/images/thumb/f/ff/Security_in_the_SDLC_Process.png/600px-Security_in_the_SDLC_Process.png

Page 8: Owasp hyd 28_dec2013_opensamm

http://www.rms.net/roi_investreturn.gif

Page 10: Owasp hyd 28_dec2013_opensamm

https://s3.amazonaws.com/pbblogassets/uploads/2013/04/donkey-pulling-cart.jpg

Page 11: Owasp hyd 28_dec2013_opensamm

http://www.you-stylish-barcelona-apartments.com/blog/wp-content/uploads/2010/09/what-to-do.JPG.jpeg

Page 12: Owasp hyd 28_dec2013_opensamm

Classification system for a set of processes / function

Shows characteristics of processes over different levels

Examples CMMI (DEV, SVC, ACQ) SSE-CMM BSIMM, openSAMM, etc

Maturity Models

Page 13: Owasp hyd 28_dec2013_opensamm
Page 14: Owasp hyd 28_dec2013_opensamm

Open Software Assurance Maturity Model

OWASP Project Open framework to help organizations

Formulate Implement Strategy for software security Tailored to the specific risks facing the

organization

openSAMM

Page 15: Owasp hyd 28_dec2013_opensamm

openSAMM

Recognizes 4 type of business functions

Any organization performing software development would have these (names could be different)

Page 16: Owasp hyd 28_dec2013_opensamm

3 business practices for each function 3 objectives (for levels) under each practice

0 (implied starting point, not included) 1 (initial understanding and ad hoc provision of practice) 2 (increase efficiency / effectiveness of practice) 3 (comprehensive mastery of the practice)

openSAMM - Security Practices

Page 17: Owasp hyd 28_dec2013_opensamm

openSAMM - Example

Page 18: Owasp hyd 28_dec2013_opensamm

For every level, SAMM defines Objective Activities Results Success Metrics Costs Personnel Related Levels

openSAMM

Page 21: Owasp hyd 28_dec2013_opensamm

Step 2 - Perform Gap Assessment

Page 22: Owasp hyd 28_dec2013_opensamm

Step 3 - Create Roadmap / Assurance Program

Page 23: Owasp hyd 28_dec2013_opensamm

Perform practices / activities for level 1 Keep assessing it till you are satisfied

and the scorecard tells you to Inform management with the updated

roadmap in a periodic manner Move to next level after you are done

with the previous one

Step 4 - Execute with periodic reviews

Page 24: Owasp hyd 28_dec2013_opensamm

www.sripati.info http://in.linkedin.com/in/sripati

Who Am I