<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenSAMM &#187; Pravir Chandra</title>
	<atom:link href="http://www.opensamm.org/author/chandra/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.opensamm.org</link>
	<description>A guide to building security into software development</description>
	<lastBuildDate>Tue, 26 Jul 2011 16:25:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Todo en español</title>
		<link>http://www.opensamm.org/2011/07/todo-en-espanol/</link>
		<comments>http://www.opensamm.org/2011/07/todo-en-espanol/#comments</comments>
		<pubDate>Tue, 26 Jul 2011 16:25:10 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[spanish]]></category>
		<category><![CDATA[translation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=882</guid>
		<description><![CDATA[Thanks to the team led by Juan Carlos Calderon, we have a complete translation of the SAMM 1.0 into Spanish available now on the downloads page. This would not have been possible without the translation work performed by the team of Francisco Aldrete, Luis Martínez Bacha, Miguel Pérez-Milicua, Alvaro Muñoz, and Aldo Salas. Also, Joaquin Crespo from the Spain contingent [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.opensamm.org/downloads/SAMM-1.0-es_MX.pdf"><img class="alignright size-medium wp-image-883" title="SAMM en español" src="http://www.opensamm.org/wp-content/uploads/2011/07/SAMM-1.0-es_MX-231x300.jpg" alt="" width="231" height="300" /></a>Thanks to the team led by Juan Carlos Calderon, we have a complete translation of the SAMM 1.0 into Spanish <a href="http://www.opensamm.org/download/">available now on the downloads page</a>. This would not have been possible without the translation work performed by the team of Francisco Aldrete, Luis Martínez Bacha, Miguel Pérez-Milicua, Alvaro Muñoz, and Aldo Salas.</p>
<p>Also, Joaquin Crespo from the Spain contingent of OWASP contributed a full translation of the OpenSAMM 1.0 overview presentation. That&#8217;s also available on the <a href="http://www.opensamm.org/download/">downloads page</a>.</p>
<p>To everyone involved in the translation work, I would like to personally extend my thanks and gratitude to each one of you for this valuable contribution to the project. If anyone reading this would like to lead a translation to your language of choice, just <a href="mailto:samm@lists.owasp.org">post a message</a> to the <a href="http://www.opensamm.org/2009/03/samm-mailing-list/">SAMM mailing list</a> and we&#8217;d be glad to help you get started.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2011/07/todo-en-espanol/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>BSIMM activities mapped to SAMM</title>
		<link>http://www.opensamm.org/2011/03/bsimm-activities-mapped-to-samm/</link>
		<comments>http://www.opensamm.org/2011/03/bsimm-activities-mapped-to-samm/#comments</comments>
		<pubDate>Thu, 03 Mar 2011 14:00:56 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Changes]]></category>
		<category><![CDATA[Discussion]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[bsimm]]></category>
		<category><![CDATA[mapping]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=816</guid>
		<description><![CDATA[For the impatient, click here to download the mapping spreadsheet. For those still reading&#8230; Firstly, many thanks to the OWASP community for hosting the fantastic OWASP Summit 2011 in Lisbon, Portugal a few weeks back. This was a fantastic forum for us to hold OpenSAMM working sessions to discuss experiences and potential improvements to the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-820" title="MappingPic" src="http://www.opensamm.org/wp-content/uploads/2011/03/MappingPic-278x300.png" alt="" width="278" height="300" />For the impatient, <a title="OpenSAMM-BSIMM Mapping" href="http://www.opensamm.org/downloads/resources/20110301-OpenSAMM-BSIMM-Mapping.xlsx">click here to download the mapping spreadsheet</a>. For those still reading&#8230; Firstly, many thanks to the OWASP community for hosting the fantastic <a title="OWASP Summit 2011" href="http://www.owasp.org/index.php/Summit_2011" target="_blank">OWASP Summit 2011 in Lisbon, Portugal</a> a few weeks back. This was a fantastic forum for us to hold OpenSAMM working sessions to discuss experiences and potential improvements to the model. Over the course of the week, we were able to build up a list of additions/changes we&#8217;d like to make in the next release, but I&#8217;ll cover those in more detail under separate cover.</p>
<p>The main thing I want to share now is <a title="OpenSAMM-BSIMM Maping" href="http://www.opensamm.org/downloads/resources/20110301-OpenSAMM-BSIMM-Mapping.xlsx">an activity-level mapping of the ~110 BSIMM2 activities to the corresponding 72 activities in SAMM</a>. Obviously, this means that in some cases, more than one BSIMM activity may be mapped to a single SAMM activity. That being said, the overlap spots seem to make sense when we (the ~10 people that worked on it) looked at them in detail. Don&#8217;t take our word for it, though, please do review and send any feedback (mailing list or just comment below). And before you ask, yes, you probably will have to go read the respective BSIMM and SAMM activity descriptions in order to see the linkage for some of them (given the occasionally imprecise nature of written language, it&#8217;s not always obvious from the activity names alone).</p>
<p>It&#8217;s worth noting that we did leave two BSIMM activities unmapped. They are SM 3.2 &#8220;run external marketing program&#8221; and T 3.3 &#8220;host external software security events&#8221;. Based on the experience of the working group participants, these activities did not appear to directly improve an organization&#8217;s software assurance posture, rather, they appeared to be evidence that the organization was using its (presumably mature) software assurance posture to bolster its public perception or generate additional value in the business. Again, this is totally up for debate if anyone has an argument the other way, so please do share your thoughts.</p>
<p>Last, but certainly not least, I&#8217;d like to thank all the people at the Summit for the detailed and thoughtful conversations about using SAMM and about what we can do to make it even better.  Specifically, those that contributed and helped review this mapping (in no particular order):</p>
<ul>
<li>Colin Watson</li>
<li>Seba Deleersnyder</li>
<li>Steven van der Baan</li>
<li>Bart De Win</li>
<li>Justin Clarke</li>
<li>Dan Cornell</li>
<li>Sherif Koussa</li>
<li>Brian Chess</li>
</ul>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2011/03/bsimm-activities-mapped-to-samm/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>OpenSAMM Overview Presentation in French</title>
		<link>http://www.opensamm.org/2010/10/opensamm-overview-presentation-in-french/</link>
		<comments>http://www.opensamm.org/2010/10/opensamm-overview-presentation-in-french/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 16:04:14 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[french]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[translation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=798</guid>
		<description><![CDATA[Thanks to Hubert Grégoire and Sebastien Gioria, we now have a French translation of the OpenSAMM 1.0 Overview presentation available for download. You can get it from the download tab or there is a direct link here. If anyone else has translated the presentation to other languages for local chapter presentations, please feel free to [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-799" title="OpenSAMM Preso in French" src="http://www.opensamm.org/wp-content/uploads/2010/10/Picture-1.png" alt="" width="300" height="226" />Thanks to Hubert Grégoire and Sebastien Gioria, we now have a French translation of the OpenSAMM 1.0 Overview presentation available for download. You can get it from the <a href="http://www.opensamm.org/download/">download tab</a> or there is a <a href="http://www.opensamm.org/downloads/resources/OpenSAMM-1.0-fr_FR.ppt">direct link here</a>.</p>
<p>If anyone else has translated the presentation to other languages for local chapter presentations, please feel free to send them to me (or the mailing list) and we&#8217;ll get them posted for all to access.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2010/10/opensamm-overview-presentation-in-french/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Resources posted and SAMM in XML</title>
		<link>http://www.opensamm.org/2010/08/resources-posted-and-samm-in-xml/</link>
		<comments>http://www.opensamm.org/2010/08/resources-posted-and-samm-in-xml/#comments</comments>
		<pubDate>Sun, 22 Aug 2010 05:30:03 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[translation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=618</guid>
		<description><![CDATA[Over the course of the past year, many people have contributed resources related to SAMM (via the mailing list primarily) and we haven&#8217;t had them in an easy-to-find place. Well, that&#8217;s all changed now. The new Download page now has all the resources neatly organized for people to download, use, and extend. If you have [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.opensamm.org/download"><img class="alignright size-medium wp-image-620" title="Downloads-Screenshot" src="http://www.opensamm.org/wp-content/uploads/2010/08/Picture-2-300x217.png" alt="download" width="300" height="217" /></a>Over the course of the past year, many people have contributed resources related to SAMM (via <a href="http://www.opensamm.org/2009/03/samm-mailing-list/">the mailing list</a> primarily) and we haven&#8217;t had them in an easy-to-find place. Well, that&#8217;s all changed now. The new <a href="http://opensamm.org/download">Download</a> page now has all the resources neatly organized for people to download, use, and extend. If you have created any other resources (or made improvements to any that we have posted) please to ping the mailing list with the updates and we&#8217;ll link them from this page.</p>
<p>One of the other new items is a full XML version of the SAMM 1.0 framework document. It includes all the content from the whole SAMM document, so now it should be a lot simpler to build tools and automation around the model itself (not to mention making translations into other languages a lot simpler).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2010/08/resources-posted-and-samm-in-xml/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OpenSAMM 1.0 in Japanese</title>
		<link>http://www.opensamm.org/2010/04/opensamm-1-0-in-japanese/</link>
		<comments>http://www.opensamm.org/2010/04/opensamm-1-0-in-japanese/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 13:14:10 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[japanese]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[translation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=283</guid>
		<description><![CDATA[Masaki Kubo at JPCERT undertook the great effort to translate the SAMM 1.0 document into Japanese. It&#8217;s available here. I&#8217;d like to thank him and JPCERT very much for the effort and the motivation to drive this to completion. Fantastic work! It&#8217;s been a little while since I&#8217;ve posted anything to the site, but don&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.opensamm.org/wp-content/uploads/2010/04/SAMM_jp.png"><img class="alignright size-medium wp-image-284" title="SAMM_jp" src="http://www.opensamm.org/wp-content/uploads/2010/04/SAMM_jp-212x300.png" alt="" width="212" height="300" /></a></p>
<p>Masaki Kubo at <a title="JPCERT" href="http://www.jpcert.or.jp" target="_blank">JPCERT</a> undertook the great effort to translate the SAMM 1.0 document into Japanese. It&#8217;s <a title="SAMM 1.0 JP" href="http://www.jpcert.or.jp/research/2010/SAMM_20100407.pdf" target="_blank">available here</a>. I&#8217;d like to thank him and JPCERT very much for the effort and the motivation to drive this to completion. Fantastic work!</p>
<p>It&#8217;s been a little while since I&#8217;ve posted anything to the site, but don&#8217;t mistake that for lack of activity! There&#8217;s actually a backlog of contributed resources that I&#8217;ve been meaning to post here but haven&#8217;t had the time to get it done yet. They&#8217;re all available via the mailing list with a little digging, but in the next week or two, we&#8217;ll try to get them all up here.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2010/04/opensamm-1-0-in-japanese/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gartner talks about OpenSAMM</title>
		<link>http://www.opensamm.org/2009/08/gartner-talks-about-opensamm/</link>
		<comments>http://www.opensamm.org/2009/08/gartner-talks-about-opensamm/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 15:04:40 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=277</guid>
		<description><![CDATA[Several folks have sent over links to a recent Gartner post discussing OpenSAMM written by Neil McDonald, a VP and Gartner Research Fellow. Glad to see them taking notice of our project, and further, they like it! Feel free to send in other blog posts about OpenSAMM (either in comments here or to our mailing [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blogs.gartner.com/neil_macdonald/2009/08/04/another-excellent-application-security-maturity-model/"><img class="alignright size-medium wp-image-278" title="Gartner talks about OpenSAMM" src="http://www.opensamm.org/wp-content/uploads/2009/08/Picture-3-300x185.png" alt="Gartner talks about OpenSAMM" width="300" height="185" /></a>Several folks have sent over links to a recent <a title="Gartner talks about OpenSAMM" href="http://blogs.gartner.com/neil_macdonald/2009/08/04/another-excellent-application-security-maturity-model/" target="_blank">Gartner post discussing OpenSAMM</a> written by Neil McDonald, a VP and Gartner Research Fellow. Glad to see them taking notice of our project, and further, they like it! Feel free to send in other blog posts about OpenSAMM (either in comments here or to our mailing list) and we&#8217;ll put up links.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/08/gartner-talks-about-opensamm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browse the model online</title>
		<link>http://www.opensamm.org/2009/05/browse-the-model-online/</link>
		<comments>http://www.opensamm.org/2009/05/browse-the-model-online/#comments</comments>
		<pubDate>Mon, 04 May 2009 19:43:44 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=251</guid>
		<description><![CDATA[Over the weekend, we managed to get large parts of the SAMM content imported into the OWASP wiki so that folks can browse the model online. This will also support community contributions for additional material that maps under the SAMM activities. It&#8217;ll also help for folks making mappings to existing regulatory standards. The official SAMM [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.owasp.org/index.php/SAMM#tab=Browse_Online"><img class="size-medium wp-image-252 alignright" title="picture-1" src="http://www.opensamm.org/wp-content/uploads/2009/05/picture-1-224x299.png" alt="picture-1" width="224" height="299" /></a></p>
<p>Over the weekend, we managed to get large parts of the SAMM content imported into the OWASP wiki so that folks can browse the model online. This will also support community contributions for additional material that maps under the SAMM activities. It&#8217;ll also help for folks making mappings to existing regulatory standards.</p>
<p>The official SAMM releases going forward will still be made in PDF form for mass distribution.  The wiki version will syndicate some of the content for easy online referencing, but the PDF version is still the authoritative source of SAMM information.</p>
<p><a href="http://www.owasp.org/index.php/SAMM#tab=Browse_Online" target="_blank">Check it out on the OWASP wiki</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/05/browse-the-model-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAMM helps with real software development</title>
		<link>http://www.opensamm.org/2009/04/samm-helps-with-real-software-development/</link>
		<comments>http://www.opensamm.org/2009/04/samm-helps-with-real-software-development/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 01:36:35 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Press]]></category>
		<category><![CDATA[1.0]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=249</guid>
		<description><![CDATA[The Real Software blog by Jim Bird has a good post about how his software security assurance program has evolved over time, and now, SAMM is helping out. Give it a read here.]]></description>
			<content:encoded><![CDATA[<p>The Real Software blog by Jim Bird has a good post about how his software security assurance program has evolved over time, and now, SAMM is helping out. <a href="http://swreflections.blogspot.com/2009/04/opensamm-shows-way.html" target="_blank">Give it a read here.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/04/samm-helps-with-real-software-development/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SEP-001 Extract content into editable format</title>
		<link>http://www.opensamm.org/2009/04/sep-001-extract-content-into-editable-format/</link>
		<comments>http://www.opensamm.org/2009/04/sep-001-extract-content-into-editable-format/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 15:06:58 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Changes]]></category>
		<category><![CDATA[SEP]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=225</guid>
		<description><![CDATA[Description: Several users and many organizations have requested the SAMM content in an editable format. This facilitates content editing and is a core requirement for translation of SAMM into other languages. The solution must also allow for easy integration of edits back into the layout/publish workflow. Owner(s): Pravir Chandra Estimated completion: 2009-05-11 Updates: 2009-04-22 &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Description:</strong> Several users and many organizations have requested the SAMM content in an editable format. This facilitates content editing and is a core requirement for translation of SAMM into other languages. The solution must also allow for easy integration of edits back into the layout/publish workflow.</p>
<p><strong>Owner(s):</strong> Pravir Chandra</p>
<p><strong>Estimated completion:</strong> 2009-05-11</p>
<p><strong>Updates:</strong></p>
<ul>
<li>2009-04-22 &#8211; Looked into using XML-based content. This can allow SAMM content to be separated from the graphic layout, thereby cleaning up the workflow a bit. More over, it will also simply translations into other languages as well. Perhaps the biggest win is that applications and tools could also programmatically include SAMM content. So far, this seems the best option.</li>
</ul>
<p><br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/04/sep-001-extract-content-into-editable-format/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The SAMM enhancement process</title>
		<link>http://www.opensamm.org/2009/04/the-samm-enhancement-process/</link>
		<comments>http://www.opensamm.org/2009/04/the-samm-enhancement-process/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 14:56:03 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Changes]]></category>
		<category><![CDATA[administrivia]]></category>
		<category><![CDATA[SEP]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=227</guid>
		<description><![CDATA[Since release of the 1.0, I&#8217;ve received a huge amount of email from volunteers and supporters. It quickly became evident that we&#8217;d need to adopt a lightweight process for managing future community contributions. Today, we&#8217;ve put the straw-man process up. Like everything, its mechanics are up for discussion, so just hit the mailing list if [...]]]></description>
			<content:encoded><![CDATA[<p>Since release of the 1.0, I&#8217;ve received a huge amount of email from volunteers and supporters. It quickly became evident that we&#8217;d need to adopt a lightweight process for managing future community contributions. Today, we&#8217;ve put the straw-man process up. Like everything, its mechanics are up for discussion, so just hit the <a href="http://www.opensamm.org/2009/03/samm-mailing-list/">mailing list</a> if you&#8217;ve got strong feelings.</p>
<p>The process is based around the concept of a <a href="http://www.opensamm.org/roadmap/enhancement-list/">SAMM Enhancement Proposal (SEP)</a>. Each should represent a logical change or addition to the SAMM material. And, each SEP is numbered so that we can sanely discuss and debate the pros/cons of the proposed change.</p>
<p>Overall, the master plan is to have volunteers send ideas to the mailing list first, and then after initial discussion, we&#8217;ll create a SEP for tracking and posterity. The website has been updated to reflect this process under the <a href="http://www.opensamm.org/roadmap/">Roadmap tab</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/04/the-samm-enhancement-process/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

