<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenSAMM &#187; 1.0</title>
	<atom:link href="http://www.opensamm.org/tag/10/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.opensamm.org</link>
	<description>A guide to building security into software development</description>
	<lastBuildDate>Tue, 24 Aug 2010 09:16:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Resources posted and SAMM in XML</title>
		<link>http://www.opensamm.org/2010/08/resources-posted-and-samm-in-xml/</link>
		<comments>http://www.opensamm.org/2010/08/resources-posted-and-samm-in-xml/#comments</comments>
		<pubDate>Sun, 22 Aug 2010 05:30:03 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[translation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=618</guid>
		<description><![CDATA[Over the course of the past year, many people have contributed resources related to SAMM (via the mailing list primarily) and we haven&#8217;t had them in an easy-to-find place. Well, that&#8217;s all changed now. The new Download page now has all the resources neatly organized for people to download, use, and extend. If you have [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.opensamm.org/download"><img class="alignright size-medium wp-image-620" title="Downloads-Screenshot" src="http://www.opensamm.org/wp-content/uploads/2010/08/Picture-2-300x217.png" alt="download" width="300" height="217" /></a>Over the course of the past year, many people have contributed resources related to SAMM (via <a href="http://www.opensamm.org/2009/03/samm-mailing-list/">the mailing list</a> primarily) and we haven&#8217;t had them in an easy-to-find place. Well, that&#8217;s all changed now. The new <a href="http://opensamm.org/download">Download</a> page now has all the resources neatly organized for people to download, use, and extend. If you have created any other resources (or made improvements to any that we have posted) please to ping the mailing list with the updates and we&#8217;ll link them from this page.</p>
<p>One of the other new items is a full XML version of the SAMM 1.0 framework document. It includes all the content from the whole SAMM document, so now it should be a lot simpler to build tools and automation around the model itself (not to mention making translations into other languages a lot simpler).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2010/08/resources-posted-and-samm-in-xml/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSAMM 1.0 in Japanese</title>
		<link>http://www.opensamm.org/2010/04/opensamm-1-0-in-japanese/</link>
		<comments>http://www.opensamm.org/2010/04/opensamm-1-0-in-japanese/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 13:14:10 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[japanese]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[translation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=283</guid>
		<description><![CDATA[Masaki Kubo at JPCERT undertook the great effort to translate the SAMM 1.0 document into Japanese. It&#8217;s available here. I&#8217;d like to thank him and JPCERT very much for the effort and the motivation to drive this to completion. Fantastic work! It&#8217;s been a little while since I&#8217;ve posted anything to the site, but don&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.opensamm.org/wp-content/uploads/2010/04/SAMM_jp.png"><img class="alignright size-medium wp-image-284" title="SAMM_jp" src="http://www.opensamm.org/wp-content/uploads/2010/04/SAMM_jp-212x300.png" alt="" width="212" height="300" /></a></p>
<p>Masaki Kubo at <a title="JPCERT" href="http://www.jpcert.or.jp" target="_blank">JPCERT</a> undertook the great effort to translate the SAMM 1.0 document into Japanese. It&#8217;s <a title="SAMM 1.0 JP" href="http://www.jpcert.or.jp/research/2010/SAMM_20100407.pdf" target="_blank">available here</a>. I&#8217;d like to thank him and JPCERT very much for the effort and the motivation to drive this to completion. Fantastic work!</p>
<p>It&#8217;s been a little while since I&#8217;ve posted anything to the site, but don&#8217;t mistake that for lack of activity! There&#8217;s actually a backlog of contributed resources that I&#8217;ve been meaning to post here but haven&#8217;t had the time to get it done yet. They&#8217;re all available via the mailing list with a little digging, but in the next week or two, we&#8217;ll try to get them all up here.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2010/04/opensamm-1-0-in-japanese/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browse the model online</title>
		<link>http://www.opensamm.org/2009/05/browse-the-model-online/</link>
		<comments>http://www.opensamm.org/2009/05/browse-the-model-online/#comments</comments>
		<pubDate>Mon, 04 May 2009 19:43:44 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=251</guid>
		<description><![CDATA[Over the weekend, we managed to get large parts of the SAMM content imported into the OWASP wiki so that folks can browse the model online. This will also support community contributions for additional material that maps under the SAMM activities. It&#8217;ll also help for folks making mappings to existing regulatory standards. The official SAMM [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.owasp.org/index.php/SAMM#tab=Browse_Online"><img class="size-medium wp-image-252 alignright" title="picture-1" src="http://www.opensamm.org/wp-content/uploads/2009/05/picture-1-224x299.png" alt="picture-1" width="224" height="299" /></a></p>
<p>Over the weekend, we managed to get large parts of the SAMM content imported into the OWASP wiki so that folks can browse the model online. This will also support community contributions for additional material that maps under the SAMM activities. It&#8217;ll also help for folks making mappings to existing regulatory standards.</p>
<p>The official SAMM releases going forward will still be made in PDF form for mass distribution.  The wiki version will syndicate some of the content for easy online referencing, but the PDF version is still the authoritative source of SAMM information.</p>
<p><a href="http://www.owasp.org/index.php/SAMM#tab=Browse_Online" target="_blank">Check it out on the OWASP wiki</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/05/browse-the-model-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAMM helps with real software development</title>
		<link>http://www.opensamm.org/2009/04/samm-helps-with-real-software-development/</link>
		<comments>http://www.opensamm.org/2009/04/samm-helps-with-real-software-development/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 01:36:35 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Press]]></category>
		<category><![CDATA[1.0]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=249</guid>
		<description><![CDATA[The Real Software blog by Jim Bird has a good post about how his software security assurance program has evolved over time, and now, SAMM is helping out. Give it a read here.]]></description>
			<content:encoded><![CDATA[<p>The Real Software blog by Jim Bird has a good post about how his software security assurance program has evolved over time, and now, SAMM is helping out. <a href="http://swreflections.blogspot.com/2009/04/opensamm-shows-way.html" target="_blank">Give it a read here.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/04/samm-helps-with-real-software-development/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hardcopies available on Lulu.com</title>
		<link>http://www.opensamm.org/2009/04/hardcopies-available-on-lulucom/</link>
		<comments>http://www.opensamm.org/2009/04/hardcopies-available-on-lulucom/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 21:18:13 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=177</guid>
		<description><![CDATA[In preparation for the upcoming OWASP conference in Poland, we were asked to help get the 1.0 release up on Lulu.com so that a copy can be printed for each attendee! So, we&#8217;ve put up the SAMM 1.0 release and it&#8217;s now available for purchase. That means you can purchase professional hardcopies, delivered right to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.lulu.com/content/6888083"><img class="alignright size-medium wp-image-178" title="lulu.com" src="http://www.opensamm.org/wp-content/uploads/2009/04/lulucom-300x104.jpg" alt="lulu.com" width="240" height="83" /></a>In preparation for the upcoming <a href="http://www.owasp.org/index.php/OWASP_AppSec_Europe_2009_-_Poland" target="_blank">OWASP conference in Poland</a>, we were asked to help get the 1.0 release up on Lulu.com so that a copy can be printed for each attendee! So, we&#8217;ve put up the SAMM 1.0 release and it&#8217;s now available for purchase. That means you can purchase professional hardcopies, delivered right to your door, which is pretty handy. Even though I&#8217;m partial to <a href="http://www.lulu.com/content/6888083" target="_blank">the color version</a>, there&#8217;s a more economical <a href="http://www.lulu.com/content/6899402" target="_blank">black &amp; white version</a> available too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/04/hardcopies-available-on-lulucom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Model changes between the Beta and 1.0</title>
		<link>http://www.opensamm.org/2009/03/model-changes-between-the-beta-and-10/</link>
		<comments>http://www.opensamm.org/2009/03/model-changes-between-the-beta-and-10/#comments</comments>
		<pubDate>Sun, 29 Mar 2009 05:41:49 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Changes]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[beta]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=171</guid>
		<description><![CDATA[From reviewer and user feedback, there&#8217;s a few noticeable changes in the model itself between the Beta and 1.0 releases. Here&#8217;s a recap of the major changes to the model. Disciplines became Business Functions &#8211; The term &#8216;disciple&#8217; used for the four high-level categories didn&#8217;t accurately capture their intent. After several discussions, it made more [...]]]></description>
			<content:encoded><![CDATA[<p>From reviewer and user feedback, there&#8217;s a few noticeable changes in the model itself between the Beta and 1.0 releases. Here&#8217;s a recap of the major changes to the model.</p>
<ul>
<li><em>Disciplines became Business Functions</em> &#8211; The term &#8216;disciple&#8217; used for the four high-level categories didn&#8217;t accurately capture their intent. After several discussions, it made more sense to rephrase them as the core business functions of software development and draw the security-related practices down from those.</li>
<p/>
<li><em>Strategic Planning became Strategy &amp; Metrics</em> &#8211; These changes were made to place more emphasis on the measurement of the overall software security assurance program. Even though example metrics were given for each maturity level, feedback indicated this wasn&#8217;t explicit enough</li>
<p/>
<li><em>Standards &amp; Compliance became Policy &amp; Compliance</em> &#8211; Feedback showed the term &#8216;standard&#8217; wasn&#8217;t as popularly used as the term &#8216;policy&#8217; for referring to the normative requirements an organization places on software development. Standards are still included here, but as an extension of policies.</li>
<p/>
<li><em>Threat Modeling became Threat Assessment</em> &#8211; Feedback indicated this section was too specific to usage of attack trees, so the language was loosened to allow other methodologies for the threat modeling activities. Also, the name was changed to avoid collision with existing notions of the term &#8216;threat modeling&#8217; (e.g. Microsoft&#8217;s methodology). Further, abuse-case modeling activities were moved from Security Requirements into this practice since many felt it was more suited here.</li>
<p/>
<li><em>Defensive Design became Secure Architecture</em> &#8211; The term &#8216;defensive design&#8217; didn&#8217;t resonate with reviewers at all, so the activities were re-evaluated and recast as organization-wide augmentations to the design process that emphasize centralized application architectures. Activities related to creating access control matrices were moved into Security Requirements since feedback showed this was more of a specifying activity rather than an architecture-related one. A new activity was added here to require promotion of centralized infrastructure and services since most reviewers felt that activity was missing from the Beta.</li>
<p/>
<li><em>Architecture Review became Design Review</em> &#8211; This change was made to ensure the terms &#8216;architecture&#8217; and &#8216;design&#8217; were being used more consistently. This practice discussed reviewing detailed design, so &#8216;design review&#8217; seemed a more agreeable title.</li>
<p/>
<li><em>Infrastructure Hardening became Environment Hardening</em> &#8211; Since the term &#8216;infrastructure&#8217; can easily be interpreted to include network devices and other appliances, the title and associated activities were changed to indicate specific focus on bolstering the security posture of the software&#8217;s environment.</li>
<p/>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/03/model-changes-between-the-beta-and-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Press release about SAMM</title>
		<link>http://www.opensamm.org/2009/03/press-release-about-samm/</link>
		<comments>http://www.opensamm.org/2009/03/press-release-about-samm/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 14:22:35 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Press]]></category>
		<category><![CDATA[1.0]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=158</guid>
		<description><![CDATA[The awesome folks at Gotham Digital Science, namely Matt Bartoldus and Mara Clarke, worked with me to put together a fantastic press release about the SAMM 1.0 release. It went out yesterday and has been picked up and syndicated on a number of different news wire services. Here is a link to the press release [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.emediawire.com/releases/2009/3/prweb2258814.htm"><img class="alignright size-full wp-image-159" title="gds_small" src="http://www.opensamm.org/wp-content/uploads/2009/03/gds_small.jpg" alt="gds_small" width="300" /></a>The awesome folks at Gotham Digital Science, namely Matt Bartoldus and Mara Clarke, worked with me to put together a fantastic press release about the SAMM 1.0 release. It went out yesterday and has been picked up and syndicated on a number of different news wire services. Here is a link to the <a href="http://www.emediawire.com/releases/2009/3/prweb2258814.htm" target="_blank">press release on eMediaWire</a> and <a href="http://news.yahoo.com/s/prweb/20090325/bs_prweb/prweb2258814_1" target="_blank">Yahoo News</a>, and I&#8217;m sure there are <a href="http://www.google.com/search?q=opensamm+launched+build+security+into+software+development" target="_blank">several others too</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/03/press-release-about-samm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP Podcast about SAMM</title>
		<link>http://www.opensamm.org/2009/03/owasp-podcast-about-samm/</link>
		<comments>http://www.opensamm.org/2009/03/owasp-podcast-about-samm/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 01:14:17 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Press]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[bsimm]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=154</guid>
		<description><![CDATA[I recorded an OWASP Podcast episode with Jim Manico and it just went live. We discuss the new SAMM release, some of the project&#8217;s history, and, of course, some other favorite projects of mine. Jim is a great host and I can&#8217;t wait to get invited for another!]]></description>
			<content:encoded><![CDATA[<p><a href="http://manicode.blogspot.com/2009/03/owasp-podcast-14-pravir-chandra-and.html"><img class="alignright" title="owasp podcast" src="http://www.owasp.org/download/lcasey/OWASP_Podcast_300x300.jpg" alt="" width="200" height="200" /></a>I recorded an OWASP Podcast episode with Jim Manico and <a href="http://manicode.blogspot.com/2009/03/owasp-podcast-14-pravir-chandra-and.html" target="_blank">it just went live</a>. We discuss the new SAMM release, some of the project&#8217;s history, and, of course, some other favorite projects of mine. Jim is a great host and I can&#8217;t wait to get invited for another!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/03/owasp-podcast-about-samm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SAMM 1.0 Released!</title>
		<link>http://www.opensamm.org/2009/03/samm-10-released/</link>
		<comments>http://www.opensamm.org/2009/03/samm-10-released/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 12:55:44 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Releases]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=91</guid>
		<description><![CDATA[The Beta release has been out for quite a while now (since August 2008) and lots of organizations and individuals have provided excellent feedback to help improve the model. I&#8217;ve heard lots of stories from people using SAMM (some are consulting firms, and some are development organizations) and that feedback has been some of the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.opensamm.org/download/"><img class="alignright size-full wp-image-93" title="samm-cover" src="http://www.opensamm.org/wp-content/uploads/2009/03/picture-1.png" alt="samm-cover" width="200" height="259" /></a>The Beta release has been out for quite a while now (since August 2008) and lots of organizations and individuals have provided excellent feedback to help improve the model. I&#8217;ve heard lots of stories from people using SAMM (some are consulting firms, and some are development organizations) and that feedback has been some of the most valuable. This release marks the official 1.0 version of SAMM and there&#8217;s a few new pieces added:</p>
<ul>
<li>Executive summary and introduction to the model</li>
<li>Improved details on applying the model to solve problems</li>
<li>Assessment worksheets for evaluating existing programs</li>
<li>Roadmaps for financial services and government organizations</li>
<li>Improvements and refinements to the model (I&#8217;ll cover changes individually in separate posts)</li>
</ul>
<p>Many thanks to the individual reviewers and the organizations that have volunteered time to help improve SAMM. I look forward to more active participants as we push forward with some of the future development plans for SAMM.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/03/samm-10-released/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Next SAMM release coming this week</title>
		<link>http://www.opensamm.org/2009/03/next-samm-release-imminent/</link>
		<comments>http://www.opensamm.org/2009/03/next-samm-release-imminent/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 17:11:12 +0000</pubDate>
		<dc:creator>Pravir Chandra</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[1.0]]></category>
		<category><![CDATA[beta]]></category>

		<guid isPermaLink="false">http://www.opensamm.org/?p=82</guid>
		<description><![CDATA[There&#8217;s been a huge amount of feedback and lots of refinement to SAMM since the Beta was release last August. I&#8217;m happy to report that we&#8217;re putting the finishing touches and reviews on the next release as I write. I&#8217;ll put together some separate posts that discuss the rationale behind the major changes, but in [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s been a huge amount of feedback and lots of refinement to SAMM since the Beta was release last August. I&#8217;m happy to report that we&#8217;re putting the finishing touches and reviews on the next release as I write. I&#8217;ll put together some separate posts that discuss the rationale behind the major changes, but in general, here are some new features in the next release:</p>
<ul>
<li>Better introduction &#8211; there&#8217;s a proper Executive Summary and a section describing the structure of the model before diving into the details</li>
<li>A section on assessing an existing assurance program &#8211; this should help folks that need to map an existing software security program into SAMM (or anyone just performing an assessment of a software security program in general)</li>
<li>Better guidance on building assurance programs &#8211; the Beta had some short text, but the next release includes a bigger section on and building a roadmap for a particular organization</li>
<li>New layout and design &#8211; revamped the ordering of SAMM materials based on feedback from users and there&#8217;s a new topical table of contents (to better route people through the resource provided)</li>
</ul>
<p>I&#8217;m looking forward to feedback on the 1.0 release once it&#8217;s out this week&#8230; stay tuned!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opensamm.org/2009/03/next-samm-release-imminent/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
