Home
Browse frameworks
Contact us
SAMMY premium
Login
SAMMY UI is optimized for resolutions with a width 1024px and higher.
DSOMM
Browse DSOMM
SAMM
OpenSAMM1.5
Cybersecurity Fundamentals
NIST CSF 2.0
NIST SSDF
NIST 800-34
DSOMM
BSIMM 14
ISO 27001:2022 CMMI
CIS Critical Security Controls
Build and Deployment
Build
Deployment
Patch Management
Culture and Organization
Design
Education and Guidance
Process
Implementation
Application Hardening
Development and Source Code Control
Infrastructure Hardening
Information Gathering
Logging
Monitoring
Test and Verification
Test KPI
Application Tests
Consolidation
Dynamic Depth For Applications
Dynamic Depth For Infrastructure
Static Depth for Applications
Static Depth for Infrastructure
Test Intensity
O-EG-1-1: Ad-Hoc Security trainings for software developers
O-EG-1-2: Security consulting on request
O-EG-2-1: Each team has a security champion
O-EG-2-2: Regular security training for all
O-EG-2-3: Regular security training of security champions
O-EG-2-4: Reward of good communication
O-EG-2-5: Security code review
O-EG-3-1: Conduction of build-it, break-it, fix-it contests
O-EG-3-2: Security Coaching
O-EG-3-3: Security-Lessoned-Learned
O-EG-3-4: Simple mob hacking
O-EG-4-1: Aligning security in teams
O-EG-4-2: Conduction of collaborative team security checks
O-EG-4-3: Conduction of war games
O-EG-4-4: Regular security training for externals
O-EG-5-1: Conduction of collaborative security checks with developers and system administrators
Ad-Hoc Security trainings for software developers
O-EG-1-1: Ad-Hoc Security trainings for software developers
Provide security awareness training for all personnel involved in software development Ad-Hoc.
Not implemented
Partially implemented
Half implemented
Fully implemented