null - opensamm

25
Good Morning http://digitalcatharsis.files.wordpress.com/2008/10/s leeping-man_ml.jpg

Upload: sripati-ms

Post on 23-Jan-2015

259 views

Category:

Technology


5 download

DESCRIPTION

A presentation about processes, Secure SDLC processes, OpenSAMM and how to go about implement it

TRANSCRIPT

Page 2: NULL - OpenSAMM

{openSAMM

Why & How?

Page 5: NULL - OpenSAMM

http://www.veracode.com/blog/wp-content/uploads/2013/06/bug-bounty-programs.jpg

Page 6: NULL - OpenSAMM

https://www.owasp.org/images/thumb/f/ff/Security_in_the_SDLC_Process.png/600px-Security_in_the_SDLC_Process.png

Page 8: NULL - OpenSAMM

https://s3.amazonaws.com/pbblogassets/uploads/2013/04/donkey-pulling-cart.jpg

Page 10: NULL - OpenSAMM

http://www.rms.net/roi_investreturn.gif

Page 11: NULL - OpenSAMM

http://www.you-stylish-barcelona-apartments.com/blog/wp-content/uploads/2010/09/what-to-do.JPG.jpeg

Page 12: NULL - OpenSAMM

Classification system for a set of processes / function

Shows characteristics of processes over different levels

Examples CMMI (DEV, SVC, ACQ) SSE-CMM BSIMM, openSAMM, etc

Maturity Models

Page 13: NULL - OpenSAMM
Page 14: NULL - OpenSAMM

Open Software Assurance Maturity Model

OWASP Project Open framework to help organizations

Formulate Implement Strategy for software security Tailored to the specific risks facing the

organization

openSAMM

Page 15: NULL - OpenSAMM

openSAMM

Recognizes 4 type of business functions

Any organization performing software development would have these (names could be different)

Page 16: NULL - OpenSAMM

3 business practices for each function 3 objectives (for levels) under each practice

0 (implied starting point, not included) 1 (initial understanding and ad hoc provision of practice) 2 (increase efficiency / effectiveness of practice) 3 (comprehensive mastery of the practice)

openSAMM - Security Practices

Page 17: NULL - OpenSAMM

openSAMM - Example

Page 18: NULL - OpenSAMM

For every level, SAMM defines Objective Activities Results Success Metrics Costs Personnel Related Levels

openSAMM

Page 21: NULL - OpenSAMM

Step 2 - Perform Gap Assessment

Page 22: NULL - OpenSAMM

Step 3 - Create Roadmap / Assurance Program

Page 23: NULL - OpenSAMM

Perform practices / activities for level 1 Keep assessing it till you are satisfied

and the scorecard tells you to Inform management with the updated

roadmap in a periodic manner Move to next level after you are done

with the previous one

Step 4 - Execute with periodic reviews

Page 24: NULL - OpenSAMM

www.sripati.info http://in.linkedin.com/in/sripati

Who Am I