History

Origin of the model

Refined through decades of experience,
the original model evolved in several ways.

It takes your experience and judgement to build an effective information security program for your organization. This set of guides will add some insight on topics to consider as your program evolves. It started with OpenSAMM, and evolved into a few important derivatives.

OpenSAMM

The lineage begins with the Software Assurance Maturity Model, released as OpenSAMM in 2009 by Pravir Chandra. Sponsored by Fortify and later donated to the OWASP Foundation, OpenSAMM gave organizations an open, vendor-neutral way to measure where their software-security practices stood and to improve them in deliberate, iterative steps. Its shape — four Business Functions, twelve Security Practices, and three Maturity Levels — has proven durable enough that everything since has built on it.

Improvements on the model: OWASP SAMM and BSIMM

From that common root, two influential models grew, each with a distinct philosophy — and both, by design, focused on software security:

The original

OpenSAMM 1.0

The model that started it all — still available as the historical, software-centric foundation the others share.

opensamm.org →
Open · Prescriptive

OWASP SAMM

The open-source continuation of OpenSAMM under OWASP, now a flagship project. It is prescriptive: it tells you how to implement each activity, scores practices on a maturity scale, and prioritizes improvement by risk.

owaspsamm.org →
Proprietary · Descriptive

BSIMM

The Building Security In Maturity Model, now maintained by Black Duck. Rather than prescribing what to do, BSIMM observes and reports what a large set of real firms actually do, producing an industry benchmark you can measure yourself against.

Black Duck · BSIMM →

Why BSAMM

BSAMM — Building Security Assurance Maturity Model is the next step, from the author of the original OpenSAMM. Where OpenSAMM and its descendants concentrate on software, BSAMM zooms out. Software is only one of the ways an organization is exposed through technology; real assurance also has to account for the endpoints people use, the infrastructure you run, the data you hold, the vendors you depend on, and the human processes that tie it all together.

BSAMM keeps the shape that made OpenSAMM work — four Business Functions, twelve Security Practices, three Maturity Levels, improved in iterations — and applies it across six domains, as a library of guides that help you reason about each area and decide for yourself what “better” should mean next. It is a model to think with, not a standard to be audited against.

Browse the six domain guides and the Introduction →