Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Pavel Radchuk - SAMM: Understanding Agile in Security

December 03, 2017

Pavel Radchuk - SAMM: Understanding Agile in Security

Video: https://youtu.be/nOrlK4p7QA8
OWASP Kyiv Winter 2017 Meetup, Dec 2, 2017


December 03, 2017

More Decks by OWASP Kyiv

Other Decks in Technology


  1. MS SDL for Agile MS Security Development Lifecycle (SDL) is

    a software development process that helps developers build more secure software and address security compliance requirements while reducing development cost
  2. MS SDL is it THAT Agile? • Needs to be

    fully implemented • All functions are necessary • Doesn’t deal with business restrictions
  3. OWASP SAMM The Software Assurance Maturity Model (SAMM) is an

    open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization
  4. SAMM. Business function • Objective • Activities • Assessment •

    Results • Success Metrics • Costs • Personnel • Related Levels
  5. SAMM 2.0. Adjusting to devops SAMM Overview Business Function Security

    Practices Software Assurance Lifecycle Governance Construction Build & Deploy Verification Operations Threat Assessment Security Requirements Secure Architecture Strategy & Metrics Policy & Compliance Education & Guidance Issue Management Environment Hardening Operational Enablement Design Analysis Implementation Review Security Testing Secure Build Secure Deployment Defect Management
  6. SAMM 2.0 SAMM 2.0 is planned to be presented on

    OWASP 2018 Summer Summit OWASP SAMM repository: https://github.com/OWASP/samm/tree/master/v2.0
  7. SAMM. Get involved Special thanks to Yan Kravchenko – one

    of the SAMM developers If you want to contribute to the project or you just have some interesting opinions – contact OWASP members
  8. Q&A