
Sebastien Deleersnyder and Bart De Win — OWASP SAMM
Om avsnittet
How does an organization improve software security without reducing maturity to a checklist? Sebastien Deleersnyder and Bart De Win join Chris and Robert to explain OWASP SAMM, the open framework for assessing and evolving a software assurance program. They trace the project’s history, explain the model’s business functions, practices, streams, and maturity levels, and show how teams can turn an assessment into a realistic roadmap. The conversation also covers version 2, companion resources, education, community events, and how SAMM differs from commercial maturity models. The result is a practical introduction for organizations that want a shared language for improvement without prescribing one identical program for everyone.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Sebastien Deleersnyder and Bart De Win:
→ OWASP SAMM
→ Toreon
Mentioned in this episode:
→ OWASP SAMM
→ OWASP SAMM project
→ BSIMM
→ Gary McGraw
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Introducing OWASP SAMM
02:07 Sebastien and Bart’s paths to the project
05:08 The name behind the model
06:22 How SAMM began
09:00 What SAMM measures
13:00 Using SAMM inside an organization
13:56 What changed in SAMM version 2
17:35 Turning an assessment into a roadmap
22:00 Business functions, practices, and streams
23:00 Companion projects and supporting resources
27:00 Education and community adoption
31:00 How SAMM versioning works
33:00 SAMM user days and community feedback
35:00 The cost of using an open model
37:00 Getting started with SAMM
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.