Sebastien Deleersnyder and Bart De Win — OWASP SAMM
With Bart De Win and Sebastien Deleersnyder
How does an organization improve software security without reducing maturity to a checklist? Sebastien Deleersnyder and Bart De Win join Chris and Robert to explain OWASP SAMM, the open framework for assessing and evolving a software assurance program.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 15 chapters
- 00:00Introducing OWASP SAMMAudioVideo ↗
- 02:07Sebastien and Bart’s paths to the projectAudioVideo ↗
- 05:08The name behind the modelAudioVideo ↗
- 06:22How SAMM beganAudioVideo ↗
- 09:00What SAMM measuresAudioVideo ↗
- 13:00Using SAMM inside an organizationAudioVideo ↗
- 13:56What changed in SAMM version 2AudioVideo ↗
- 17:35Turning an assessment into a roadmapAudioVideo ↗
- 22:00Business functions, practices, and streamsAudioVideo ↗
- 23:00Companion projects and supporting resourcesAudioVideo ↗
- 27:00Education and community adoptionAudioVideo ↗
- 31:00How SAMM versioning worksAudioVideo ↗
- 33:00SAMM user days and community feedbackAudioVideo ↗
- 35:00The cost of using an open modelAudioVideo ↗
- 37:00Getting started with SAMMAudioVideo ↗
About this episode
How does an organization improve software security without reducing maturity to a checklist? Sebastien Deleersnyder and Bart De Win join Chris and Robert to explain OWASP SAMM, the open framework for assessing and evolving a software assurance program. They trace the project’s history, explain the model’s business functions, practices, streams, and maturity levels, and show how teams can turn an assessment into a realistic roadmap. The conversation also covers version 2, companion resources, education, community events, and how SAMM differs from commercial maturity models. The result is a practical introduction for organizations that want a shared language for improvement without prescribing one identical program for everyone.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Sebastien Deleersnyder and Bart De Win:
→ OWASP SAMM
→ Toreon
Resources
→ OWASP SAMM
→ OWASP SAMM project
→ BSIMM
→ Gary McGraw
Actionable
From this conversation
- 10:44
Assess secure-development practices
You want to use the model to do an assessment of your software development practices, secure development practices in the organization.
- 28:02
Align maturity work with modern development
First of all, I think from a content perspective, I think it's, it's important that we are in line with modern development practices in an organization.
- 37:53
Apply SAMM to your company
We organize a lot of trainings and discussions with people, and they start seeing the value once they apply it to their company.
Transcript · 40 min conversation
0:00Chris RomeoSebastien Dieler-Snyder is co-founder CEO of Torian, and Bart de Wynne is a director within PwC Belgium. They work together to co-lead both the OWASP Belgium chapter and the OWASP SAM project. Sebastien and Bart join us to introduce OWASP SAM 2.0. OWASP SAM is the Software Assurance Maturity Model. It's the OWASP framework to help organizations assess, formulate, and implement a strategy for improving software security. We explore where it came from and walk you through the framework. For season 7 and beyond, we've launched our YouTube channel, Application Security Podcast, where we post the video feeds for all of our episodes. You'll want to check it out as many interviews now have demos included where we capture screen during the interview. For example, in this interview, we put up a picture of all the different pieces of SAM 2.0, and Sebastien and Bart walked us through the picture. We We hope you enjoy this conversation with Sebastien and Bart.
0:58At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term, sustainable security culture amongst all their developers. Our approach is to provide security education that's conversational, quick, hands-on, and fun.
1:16Chris RomeoWe don't do lectures.
1:17Instead, we let the experts talk about what's important. Modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow your developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo. I am the CEO of Security Journey and also co-host of said podcast.
2:03Chris RomeoI'm joined today by Robert Herold.
2:05But hey, Robert.
2:05Hey, Chris.
2:06Chris RomeoYeah, good to be here. Threat modeling architect. Threat modeling architect, one of our favorite topics. But today we're going to talk about, well, kind of another favorite topic of ours, and that is OWASP, but a specific project. But as our audience knows, when we have any new guests, we first have to hear their origin story or how they got started in the world of security. So, Siba, we're going to come to you first and say What is your security origin story?
2:34Hi, Chris. Well, thanks for inviting us. So the way I, I would say, accidentally stumbled into security is kind of a long time ago. It's about 20 years ago. I was working at a bank as an analyst developer, and in a specific project had a security issue or a problem to solve. And one of my coworkers gave me a book of Bruce Schneier. And then with lots of crypto in there, and that just, it raised my interest and I read it and I used it. I also got involved in the Security Competence Center at the company I was working then. And from there on, only did that security. And with my background as a developer, quickly started doing security, software security, got involved also in OWASP since 2004.
3:26Chris RomeoWow.
3:26So, and since then I've been doing lots of software security.
3:31Chris RomeoOkay. And you're the CEO of Taurian?
3:34Yeah, I co-founded it with a couple of other guys and I'm now CEO.
3:39Awesome.
3:39Chris RomeoSo Bart, how did you get involved in this crazy world that we call security as a job?
3:46Yeah. Okay. Thanks, Chris. Around the same time as Seba, I think. It's a bit more than 20 years now. I started my career in university, academic world. where one of the professors asked me to do a PhD and the topic, I was thinking a bit about the topic. And since my brother at the time was very interested into cryptography, I more took the approach like, okay, suppose you now have cryptography, but what can you do to actually protect applications? What should you do inside the applications to do, to build security in basically? So I spent more than 10 years at university, did a PhD, did a postdoc, a lot of projects. And then after that, I went into the commercial space. And since now, since the last 8 or 9 years, I'm working for PwC as a security, software security specialist, basically.
4:41Chris RomeoOkay, Robert, I'm a little intimidated. We have 2 crypto people on the line here with us. So crypto is something I've kind of ran away from. Sam was like, a little, little.
4:55I just, I know enough of it that I'm pretty sure I should never Create any crypto code myself.
5:02Chris RomeoI think same.
5:03You know enough to say I know not to do it, right?
5:07Exactly.
5:08Chris RomeoThat's a good that's a good public service announcement for for everybody in our listening audience. Don't roll your own crypto. Okay, you heard it here. You didn't hear it here first, but you've heard it here often. So so the topic that we specifically have for for today is OWASP SAM, which I know that both of you are heavily involved in that, and so we want to hear all about OWASP SAM. But Bart, I thought we would start. just by level setting for some of our audience members who may not have ever heard of OWASP SAM before. At a high level, what is OWASP SAM?
5:41Okay, Chris, I'll try to explain it in a nutshell. OWASP SAM is actually a maturity model for software security, meaning that you can use the model to try to measure and to help you to reason about how good am I doing, how well am I doing in my organization regarding security of software. That can be software that you're building, It can be software that you're buying, whatever software that you're using in the company. If you wanna reason about it, how well am I doing about around it? You can use OWASP SAM to measure it and to reason about how to get better.
6:15Chris RomeoOkay, great, great.
6:17So, Sibo, where did OWASP SAM come from?
6:22Chris RomeoOr what's the origin story of this project?
6:24Yeah, SAM is already there for a long time. Actually, it was created by a guy, Praveer Chandra. And he's still in security, but he's not involved in the project anymore. It was around, so Pravir was already active in OWASP around 2005, 2006. He first created Clasp, which was kind of a lightweight application security framework. It was really not lightweight, but a lot of stuff in there. And then he got some time from Fortify where he was working for to restructure everything. And he, from there and his experience, he created OWASP. Yeah. OpenSAM actually, it was, so the first version was called OpenSAM and he created it basically by his own based on his experience as a software security consultant, but also already got a lot of feedback from people that were involved including Bart and myself and published that around 2007 and he donated it to basically, and together with Fortify to OWASP. And from there on, it started as an OWASP project as itself, as the version 1, was a really good framework. And over the years, oh, Praveer, I would say, went for another job. He's still working with Bloomberg, if I'm not mistaken. But he didn't have time anymore for the OWASP project itself. So Bart and I took over. Incidentally, we're both from Belgium, but that's more coincidence. Actually, we could have been from the other part of the world. You were both interested in the project. And we took it over from Praveer, first created really a community around it of people that were also interested in it, in the project as such, and then gradually like added improvements to it. Created version 1.1, changed a little bit, did some tweaking around with the model and the way we measure maturity in the model with version 1.5. And then certainly over the last 3 to 4 years, we spent a lot of time together with 20, 30 people in different workshops and different conferences over the world to improve the model itself. And then beginning of this year, by January, end of January, we released OWASP ZAM version 2. So it took us, I would say it took us more than 10 years to create the next version, but it is really based on what Pravir started.
9:05Chris RomeoAnd just, just to confirm, so the proper name of this project now is OWASP SAM?
9:13It's not OpenSAM anymore. So OpenSAM indeed is a version 1 from Praveer, and since we've created version 1.1, 1.5, it's— I would say it's an official OWASP fork as such, and we call it, or we refer to it, as OWASP SAM. And you can also find it online on owasp.sam.org.
9:33Chris RomeoI'm gonna have to reprogram my brain. I've been calling it OpenSAM for as long as I can remember, and I've just learned in this moment that I was incorrect for the last number of years.
9:42But it's not incorrect, it's just that it's a follow-up version. Yes.
9:46Chris RomeoYeah, yeah. And I mean, I can say I, as a practitioner, I've actually used OWASP SAM. I got a chance to go in and assess a startup out in San Francisco a couple of years ago, and I had never used it before that, but it was, it was fascinating to me to actually apply it. I went in over 2 days and interviewed a whole bunch of people and ask them questions from different sections. It was so eye-opening to see how you can actually take this maturity model, and at the end of the day, you can give somebody a statement of, here's where you are now, and then I was able to use OWASP SAM to say, here's where you need to go in the future. Here's some areas that you really need to improve. It was interesting because it was an organization that was— it was a DevOps-first organization from their first day they opened. And so they had some parts of OWASP SAM that they were mature on, but then others that they had never done anything with. And so it was, it was just fascinating to see how that, how that kind of came together.
10:41So Bart, what are the use cases then for OWASP SAM?
10:44Well, I think you already nailed it quite well in your experience there. I think the first use case, the primary use case that everybody starts with, is an assessment. So you want to use the model to do an assessment of your software development practices, secure development practices in the organization. So what you do is you take the model, you do a number of interviews, and you try to gauge how well you are doing in the organization. Very important in that perspective is to take into account the scope of the assessment that you're doing, because very— a lot of companies have different teams that work in a different way. So sometimes it's not so easy to do a single assessment for the entire company. You might want to split up the company in different parts and do several assessments. But that's kind of the starting point, and that's where everybody gets started. That's the That's a primary use case, I would say. But then the model is very well suited in defining the future, sort of to-be for the organization. Where do you want to go in 1 year's time, 3 years' time, 5 years' time? So what's my to-be model for the organization? That would be the second primary use case because it helps you think in a structured way about the different practices and elements that you should be thinking about in your organization. And then the model can help you in a structured way of getting there. So getting from point A, where you are today, to point B, where you should be in a couple of years' time, in a structured way. Typically, that will be organized in a number of phases, phases of 6 months to 1 year, every phase around that to get you from point A to point B. And then as a final use case, I would say SAM helps you a lot in in providing you instruments in implementing the different practices that you would be implementing and improving in your organization. So it gives you a lot of resources, a lot of description, guidance in what you should be doing in implementing those practices in your organization. But it's all about improving the maturity, getting you from point A, the as-is of today, to point B, the future where you want to go as an organization. That's basically the primary use cases of what SAM can deliver you as a company.
13:02Chris RomeoHave either of you seen OWASP SAM ever used as a contractual vehicle? Like, is anybody using this as a— in an RFP or something like that to say kind of here's some of the practices that you have to do? I would think that would be another use case for the project.
13:20Yeah, definitely. I've already seen that in public tenders, even by governments. I've been involved in a couple of them, and that's where BSIMM— sorry, SAM itself has the possibility to be used as a maturity model. But since there is a measurement aspect in it, it can easily be used to also set like a minimum level of maturity of a software provider whenever you're buying software.
13:51Chris RomeoThat's great.
13:52So you mentioned BSIMM there.
13:55Chris RomeoThat's going to be one of the— I think one of the big questions from a lot of people. A lot of people are familiar with BSIMM and they may be new to OWASP SAM. What's the difference then between SAM and BSIMM?
14:07There is, there's a big difference, but it's interesting to also understand how BSIMM started. It's actually also, it has the same origin story. When Pravir created OpenSAM, he was doing that paid by Fortify, and he presented his result on the Fortify board of advisors. And at that time, Gary McGraw was on that same board and was very interested in the project as such, wanted to collaborate on that together with Pravir. And let us say that there was some, I would say, differences in opinion between Pravir and Gary on how to do it. And so Gary, I would say, took I would say the same kind of structure that SAM was based on, because certainly when you look at the first versions of VSim, you see a lot of similarities. But the way Gary took it, and when he started using VSim at Synopsys, was different. What they did, and not Gary himself, but everyone who was involved with software or SDL projects at Digital, is they did interviews at companies practically, well, and basically their customers, what they were doing in terms of software security activities. And based on that, they grouped that together in their, I would say, reports because they have like BSIM 1, 2, and until now 10, BSIM 10. It's more like kind of a report of what Sigil and now Synopsys, as Sigil was acquired by Synopsys, what their customers are doing. And I think there's now about 120 companies in there that are, I would say, calculated up, and it's a representation or like an overview of what I would say the top 120 companies are doing in that sphere. But you have to take into account that these are companies that I would say have the pockets and the budgets to pay a Cegital or Synopsys to do or to set up an SDL.
16:21Chris RomeoYeah.
16:21And that itself, it's interesting to know what they're doing, but where SAM takes that a step further, SAM is much more, I would say, prescriptive in the sense that we describe more the activities, what you should be doing to actually have that particular maturity at the certain security practices. And that's something you don't have in BSIMM. So you don't have really roadmaps in there neither. There is something similar. But what BSIMM has done and what they're really good at is that they've used that as a, I would say, a marketing machine to promote the, I would say, the SDL consulting, obviously, of Sigitial itself. So, and that's where it's most known for. But it has the same kind of background. The big difference, obviously, is that BSIMM, it's a public report, but OWASP SUM is, I would say, a collaborative and open-source project.
17:16Chris RomeoYeah, when I think of BSIMM versus SAM, I think of BSIMM as more of a statement of where all of these companies are. So there's 120 companies that are playing into it. Doesn't necessarily mean that where all of them are is where we should go in the future.
17:34Mm-hmm.
17:35Chris RomeoWhereas when I think about SAM, I think about the roadmaps and thinking about the prescriptive guidance on where we want to get to in the future, that we as a community can come together and agree, kind of setting the standard for, hey, in 5 years we want to be doing these new innovative things, whereas BSIMM, I feel like, is a measurement of where these 120 big companies are, but it doesn't necessarily have a quality metric to say they're doing the right things. It just says they're all doing these things. That's kind of how I— that's how I see it as well. Bart, how is OWASP SAM organized in this actual model itself?
18:11Okay, that's a good question, Chris, and I'll try to explain it as clearly as possible. Actually, it's not that hard to explain once you understand the structure behind it. But it's actually a multi-layer model that actually is used to structure a lot of activities that are being used to measure your maturity, basically. Because again, it's all about measuring maturity. So we want to measure the maturity of activities. Are you doing activity X? Are you doing activity Y? Okay. Structure all this is a multi-level structure. At the highest level, there is a layer which is called business functions, and in SAM 2.0, there are 5 business functions. There you have functions like governance, design, implementation, verification, operations. These are groups of things where we see a very direct link with how activities are being organized in a company. So you typically in an organization would have a team that is working around governance. You would have teams that are doing design implementations. You would have testing teams, you would have operation teams. Of course, with waterfall or DevOps, this might change a bit, but still, these are typical roles in an organization. So this is kind of providing you the link with how things are going on in an organization.
19:35Okay.
19:36Then underneath that business function, every business function then has 3 security practices, and I'm sharing this picture here. So for instance, in the governance business function, you see 3 security practices. One is strategy and metrics, one is policy and compliance, and one is education and guidance. So under these security practices, again, there are these number of activities that will be used to measure how things are going. And so every business function itself has 3 security practices linked to that particular role of governance or design or implementation. Okay, when we then look at the previous version of the model, version 1.x, 1.5 for instance, under that security practices we just had a bunch of activities, a set of activities, and these activities are grouped in maturity levels. So we would have a level 1, there would be level 1 activities, you would have a level 2, level 2 activities, and level 3, level 3 activities. Now we did see that in level— in version 1.5 of the model, there were actually some activities that were logically a bit, a bit unlinked in these security practices. And so that's why we in version 2, we created a new concept called the stream, and that's actually also represented in this picture. That is under the strategy and metrics security practice, for instance, there is a stream create and promote and a stream measure and improve. And that's actually something to logically group again activities together under that security practice. So again, let me rephrase, it's a multi-layered structure. At the highest layer, there are business functions which are typically roles in an organization. Underneath that, there is a security practice, and in the security practice, it actually contains 2 streams that actually contain a number of activities. Every stream contains an activity per maturity level, and that actually combines everything together. So in— if you would calculate, uh, the, the number of activities, it's— I think we're at 96 at the moment. Seba, is that correct? I, I lost track of the number of activities.
21:45Times 50, times 2. So yeah, a lot of them.
21:50Yeah, a lot of them indeed.
21:51If you'd be doing all of them, but there is— I don't think there's any company that's actually doing all of the activities.
21:58Yeah, but so at the bottom layer, it's just a bunch of activities that are structured in this multi-layer structure. That's overall how everything is set together, basically. Does that make sense?
22:11Yeah, but the one question I have is on the streams.
22:15Chris RomeoSo stream A, is there a commonality between stream A across all of the business functions and all the security practices? Like if you had to define, like what's the difference between stream A and stream B, not at the individual activity level, but in general?
22:32Yeah, there's not really a link between the streams. So there is no— because indeed that's a question that we get from time to time. Does stream A take priority over stream B, or is there a link between stream A in one security practice and stream B in another security practice? There's actually not really a relationship. It's just a way to again give more structure to what we're doing because we saw in the previous versions that sometimes we had like at level 1 an activity that was linked to, for instance, creating a strategy. At level 3, there was an activity linked to creating a strategy, and we saw at level 2 somehow there was nothing linked to creating a strategy. So we saw that there were gaps in the maturity level of creating that strategy. And we wanted to force ourselves to make sure that at all the levels of maturity, there was some kind of representation of an activity of creating that strategy. And that's why we set up those streams to force ourselves to make sure that it's consistent throughout the entire model. But so there's no priority between streams, between stream A or stream B, or there's no real links between stream A for one business function and stream A for another business function. There's no direct link between them.
23:48Chris RomeoOkay, so Siva, there's another companion project to OWASP SAM in regards to benchmarking. Can you tell us about this, this idea of benchmarking and how that fits in with OWASP SAM?
24:04Yeah, most certainly. So whenever, whenever we introduce some to a new team or whenever I talk to it, like to another person that's active in software security, one of the first questions is, okay, that's all good and well, we can use SAM as a framework to measure our maturity or to see what we should be doing, but how can I compare what we are doing to another organization? And we all want to know, okay, am I doing the right thing? But also, am I doing enough compared with peers in my same industry or like a company or a team that's doing something similar. And that's obviously, that's hard to do that comparison. And hence the idea to actually create a benchmark project. We've already tried it a couple of years ago where together with a couple of other organizations, we started to create like a critical mass of measurements to create like the, I would say, the first datasets of some measurements so that you could start comparing with that baseline. Unfortunately, that was not successful. We didn't have, I would say, enough measurements. But we're now with the release of SUM version 2, we have rebooted that initiative. And we are also very happy that Brian Glass is taking that on as a separate track within the SUM project. Brian has done or has gotten a lot of experience also with, I would say, putting together a lot of data into a dataset because he has done the same thing for the OWASP Top 10, the latest version. So the idea is now that we invite organizations that have done some assessments or that are doing some assessments to share those, I would say, measurements in an anonymous way. Obviously, you don't have to share your name or you link your company with that. But the idea is that we could or we should be able to see, okay, if we measure, for instance, how are we doing in terms of security testing? And say that we are a measurement like in terms of maturity, we are at 1.5 on a maximum of 3, and that you're active in, I would say, banking or financial or fintech-like sector. Is that enough? compared with other similar kind of organizations. So, and our end goal or vision is that we should have enough data for us to be able to say that, okay, you're on par or you're below or you're ahead of your peers. That's what the benchmarking initiative is about.
26:45Chris RomeoYeah, I think that's going to be a big companion to OWASP SAM because that's the question I've heard people ask even as well is You know, this is a great maturity model, but how do I stack up against other companies? And that's one of the things BeStim does give you today, is it does give you that kind of level set against other companies in the same industry as me. Am I doing better? Am I doing worse? And so I'm, yeah, I'm excited to see this benchmarking come together because I'd like to see the results. I want to see how are we doing as an industry? How are we, you know, where do we need to improve?
27:22Yeah.
27:22Chris RomeoYou know, for somebody like me who builds education, that information is going to help me figure out where should we be investing more time in developing new content to teach people about things that everybody's struggling with. And so that's, that's why I'm kind of— I'm excited about this. So Bart, what does the future hold for OWASP SAM? Like, when you look into the future, I know you just got version 2— you guys just got version 2 out the door, so you're probably thinking about like I'm gonna take an OWASP SAM vacation for a couple of years or something. But what— when you start to— when you think big about 5 years in the future, what's, what's kind of on the roadmap for OWASP SAM? Where do you guys want to go with this?
28:02Well, I think there's, there's a number of elements to add to the table there. First of all, I think from, from a content perspective, I think it's, it's really important that we are in line with modern development practices in an organization. And that's also something that we— why we really wanted to get version 2 out as soon as possible is that we noticed that the original version, version 1 or 1.x, it was not always fitting very well with modern development organizations anymore. And so, for instance, if you look at version 2, we created this new business function implementation. It's a totally new function, but you will see there are things like secure build, secure deployments, which were really necessary to be able to measure what modern companies are doing. So I think if you're looking forward, I think one of the main goals is that we should always be striving for having a model that is able to represent what companies are doing. Does that mean that for version 3, we will need 6 business functions or maybe 4 again? At this point in time, it's difficult to say, but that's really our goal, to really make sure that we are really aligned with what companies are doing on the floor. Then, from a process perspective, what we really try to do is to have a model that we— that can evolve in a very agile way. And by that, I mean, in the past, whenever we did release, we always had to spend quite some time to get the release out and it took us— people had to wait for that release to be out. With version 2 and going forward, we really wanted to make it a community and agile process in a sense that when we see that there is a flaw or a particular issue in the model, we want to be able to improve that model very quickly, push a fix as soon as possible. And so we've done a lot in setting up version 2 to be able to very quickly build new versions of the model. So going forward, what I would— what we would like as a project team is really to be able to release very— in a very flexible and agile way. In that sense, we don't want to wait another 5 years to create version 3. No, we want to continuously update the model to make sure that it's in line with what companies are doing. And that's actually where we want to go towards, is a very fluid model that's in line with what companies are doing. And that might mean that in the future, we might want to release another version 3 if we really say, okay, this change is so disruptive that it doesn't make sense to do a small change to the model anymore. That will happen. But in the meantime, we will have had a lot of updates and improvements to the model that did make sense and that were backward compatible, I would say, to make it fully functional for our users. And we want to stay as close as possible to our users, to our companies with the model, basically.
31:12Chris RomeoAre you still versioning all of those changes? So I'm just curious, like, I love the idea of— it's almost like a DevOps for a maturity model where you're committing new versions and changes and pushing to production all the time. The only question I have is, how do you version that though so that when we start doing a comparison between Company A and Company B, we know this version was 2.1.7 and this was 2.1.5 in case there's some discrepancy that could skew the data?
31:44That's a very good question, and it's actually something that we haven't figured out totally. We have our ideas around it, but it's still an ongoing discussion. discussions. Because of course, indeed, if you do an assessment, you have to be able to compare to a similar assessment, to a similar model. So we will have to have some kind of versioning inside the model. But we want that versioning to work and not to restrict us in improving the model in a flexible way. So indeed, these are discussions that are ongoing and will for sure need some, some kind of version, major version, minor versioning. to be present, to make sure that at least we can take those steps up in terms of versioning. And that's something we're currently heavily discussing in the project team as well.
32:30But as long as, I would say, as long as the major frame or the major framework doesn't change and there's no, I would say, additional activities or the maturity levels don't significantly change, there's currently no reason actually to increase, I would say, the release version. So we've now come into a situation that everything is in GitHub. All the whole model itself are YAML files that we've automatically publishing towards the website whenever we do a change. And that has allowed us to collaboratively create some version 2 where we are, and we can gradually gradually now improve and iterate over that. And it's only when there's, I would say, major structural changes that we're going to bump up the release versions.
33:19Chris RomeoSo I guess on June 16th you have this OWASP SAM User Day coming up. What's going to happen on this User Day?
33:28So we've been working on some, a lot of, over the last couple of years, but we've always had a strong tie with the community. And so each year we've organized little, I would say, like SAM summits. Now currently with corona, we can't do a physical one, but we're organizing a virtual user day for everyone who is using OWASP SAM or considering to use OWASP SAM in the near future. And so, and on June 16th, we're probably going to start in about in the afternoon I would say Europe time and in early morning US time, we're going to do an online conference covering SAM topics. So there will be people talking about content, we'll have a couple of workshops, we'll have a couple of work, I would say roundtables, where you can share your experience actually of how you used SAM, what went good, what went wrong, some what kind of toolings you were using, And so we've just now, I would say, started the website. So you can find it on whatsappsum.org/userday. There's a call for topics and we invite everyone who has used Sum to fill in the, I would say, the call for topics and to propose a topic. The idea here is really that we want the community to share and that you can learn from from other people on how they're using SAM. You hear a lot individually stories from people who are using SAM, who are really happy with it, or who have failed miserably as well. And there we can also do some lessons learned. So, and we want to create like a platform to share those kinds of experiences.
35:16Chris RomeoIs it free or is there a registration charge?
35:19It's going to be completely free. Like anything within OWASP, It's open source, it's free. We have structural sponsors who have, I would say, pay our bills for the technical editing, the hosting, the layout, and the support we need. But everything we do and everything we publish is completely free, including the user data.
35:44Yeah, and I just wanted to add to that, SAMI is a model that's driven by the community. And build for the community. And so we're actually trying a lot to involve as much as possible the community, among others, for instance, by providing guidance on how to use the model. And that guidance can, for instance, we're currently building with Rob van der Weer, a guidance on how can you build, how can you use OWASP ZAM for agile development, or how could you use it for DevOps-oriented companies. Because again, this is like a theoretical structure, but you have to apply to a particular context of your organization. Just as everybody, every company doesn't need to get all 3 for all practices or activities, you don't need— the way you apply it in your organization differs depending on your context. So we want to give as much as possible guidance and advice from from within the project to companies, how can you actually apply this? And this is why we're having these user conferences to share experiences. And because we know the more you talk about it, the clearer it becomes on how to use this model at best in your organization. And that's why we think this user day is so important. And we invite everybody to join forces and to collaborate on this.
37:05Chris RomeoYeah, that's great. So Siebe, if you had a key takeaway or a kind of a final remark here, concluding remark for our audience, what would you leave our audience with?
37:16I'd say if you've never heard of it, visit it. So it lives online, awaspsum.org. Have a look at it. You click through to the model, you can discover the model there, and be sure to subscribe to the newsletter. That way you get We're not spamming. We regularly send an update of what we're doing. So you get at least like once per month or every 2 months an update on what we're doing. So if you want to keep up to date with what we're doing, subscribe to the newsletter.
37:49Chris RomeoAll right, Bart, what would you leave the audience with?
37:53For me, it would be the proof of the pudding is in the eating because we see that actually Actually, the OWASP SAM model is a bit of a jewel, at least we think it's a jewel. But it's— it only— you only start to appreciate the real content and the real value of it once you start using it. And so we organize a lot of trainings and discussions with people, and they really start seeing the value once they apply it to their company. So my suggestion would be, try it. It doesn't cost you a lot of time. Just give it a go and you will see that by trying it out, you will start to realize the value that actually is in the model and it's totally free. So it's out there for everybody. So my takeaway would be, give it a try and share feedback or give us questions if you have any.
38:41Chris RomeoVery, very good. So Siva and Bart, thank you very much from us. We're going to offer thank yous from the community as well working on OWASP SAM and making this project such a success. And I know there's a— there's got to be a team of tens if not hundreds of people that are collaborating and directly providing you feedback. And so we want to thank all of those folks that are, that are putting forth all of these volunteer efforts. A lot of people don't realize OWASP does not pay anything. Like, this is— these are volunteers that are building these things because they want to see the world be a better place in the future where we have better security across the board, regardless of what company you're from, what country you're from. Doesn't matter. OWASP is open. And so we just want to thank you guys for putting forth literally the hundreds, if not thousands of hours you've invested into this. Thank you for doing that. And thank you for sharing with our audience today.
39:34Thank you, Chris. And indeed, thanks also to the, to the rest of the team.
39:38Yeah, definitely.
39:42Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, security is a journey, not a destination.
6,612 words · transcript by assemblyai
More like this
View all episodes →- October 27, 2021 · 32 minTimo Pagel -- DevSecOps Maturity Model
- June 12, 2018 · 29 minConclusion: All the Pieces You Need for an #AppSec Program
- July 21, 2020 · 41 minElie Saad — OWASP WSTG, Cheat Sheets, and Integration