BSAMM · Building Security Assurance Maturity Model

Security is justified confidence, built across your technical exposures

Information security is a complicated subject, but we can chip it apart by building assurance in small pieces — earned, measurable confidence. This cuts across several technology domains, and these are guides to think about it the right way.

Evaluate your risks,
take the next step forward

BSAMM is not a checklist or a certification. There are no boxes to tick and no benchmarks to measure against. It is a way to reason about where you stand in each area and to decide, for yourself, what "better" should mean next — improving in iterations, choosing what your organization actually needs each cycle.

Learn each area

Understand how security really works in each domain, from first principles rather than controls lists.

Decide for yourself

Judge where you are and where you want to be. The model informs the decision; it does not make it for you.

Improve iteratively

Advance one Maturity Level at a time, in the domains that carry the most risk for you right now.

Improve your company's security posture, with specific steps

Your technical exposure falls into six domains. Within every domain the same structure applies: four Business Functions, each with three Security Practices, each measured across three Maturity Levels.

Governance
SMStrategy & Metrics
involves the overall strategic direction of the security assurance program and instrumentation of processes to collect metrics about the organization’s security posture.
PCPolicy & Compliance
involves setting up a security and compliance control and audit framework across the organization to achieve increased assurance in the assets and activities it is responsible for.
EGEducation & Guidance
involves increasing security knowledge amongst personnel through training and guidance on security topics relevant to their individual roles.
Construction
TAThreat Assessment
involves accurately identifying and characterizing potential attacks upon the organization in order to better understand the risks and facilitate risk management.
SRSecurity Requirements
involves promoting the inclusion of security-related requirements during design and planning in order to specify correct behavior from inception.
SASecure Architecture
involves bolstering the design process with activities that promote secure-by-default choices and control over the technologies and arrangements the organization relies on.
Verification
DRDesign Review
involves inspecting the artifacts of the design process to ensure they provide adequate security mechanisms and meet the organization’s expectations for security.
IRImplementation Review
involves assessing what the organization has actually built or configured to aid weakness discovery and establish a baseline for secure practice.
STSecurity Testing
involves testing the organization’s assets in their operating environment to discover weaknesses and establish a minimum standard for release.
Operations
IMIssue Management
involves establishing consistent processes for managing internal and external vulnerability reports to limit exposure and gather data to enhance the assurance program.
EHEnvironment Hardening
involves implementing controls for the operating environment surrounding an organization’s assets to bolster the security posture of what has been deployed.
MMMonitoring & Maintenance
involves identifying and capturing the security-relevant information an operator needs to properly configure, run and sustain the organization’s assets over time.

The four Functions and twelve Practices are the same in every domain — only the specific activities beneath them change. Learn them once and every guide reads the same way.

Library

Read any guide online or download it.

Introduction guide cover
Start here

Introduction

A guide to building security across the whole organization. It sets out the shared framework every domain guide builds on — the four Business Functions, the twelve Security Practices and the three Maturity Levels — and how to assess where you stand and build an assurance program. Read it first.

Domain Guides

Six companion guides, one per domain. Each applies the shared framework to a specific area of technical exposure — read the Introduction first, then whichever domains matter most to you.

Endpoints guide cover
Endpoints
A guide to building security into the devices people use
Infrastructure guide cover
Infrastructure
A guide to building security into the systems you operate
Data guide cover
Data
A guide to building security around the data you hold
Process guide cover
Process
A guide to building security into your operational processes
Vendor guide cover
Vendor
A guide to building security into your business relationships
Software guide cover
Software
A guide to building security into software development