> Markdown version of [/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm?t=2543](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm?t=2543). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Maturity assessment for technicians or how I learned to love OWASP SAMM Are you still waiting for late-stage penetration tests to catch critical vulnerabilities? Discover how OWASP SAMM empowers developers to shift security left directly into the IDE. - **Speakers:** Mathias Tausig - **Event:** WeAreDevelopers LIVE - **Published:** February 1, 2022 - **Duration:** 1:41:05 - **URL:** https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm ## Summary Moving beyond basic secure coding to a holistic secure software development lifecycle (SDLC) is critical for modern engineering teams. The initial focus of this presentation revolves around the OWASP Software Assurance Maturity Model (SAMM), an adaptable framework designed to evaluate development processes and identify security blind spots. Rather than using maturity scores to drive competition, teams can leverage SAMM interview assessments to construct practical, phased roadmaps that prioritize high-impact improvements and integrate security directly into the planning and design phases. The strategy then transitions from high-level maturity assessment to pragmatic DevSecOps execution, emphasizing the importance of shifting security left in the development cycle. Developers must account for their entire application surface area, which consists largely of third-party open-source code and transitive dependencies. Tools like Software Composition Analysis (SCA) and Static Application Security Testing (SAST) empower developers by surfacing vulnerabilities—like cross-site scripting (XSS)—directly within their familiar IDEs. This immediate feedback loop enables rapid, automated remediation via pull requests, rather than waiting for late-stage penetration testing. Furthermore, as application infrastructure increasingly relies on containers and Infrastructure as Code (IaC), these components must also be scanned for misconfigurations and drift. By coupling continuous automated scanning with grassroots security champion programs, organizations can foster a developer-first security culture. Integrating threat modeling early and empowering engineering teams to take ownership of dependency security significantly reduces both the cost and technical debt associated with catching vulnerabilities in production. **Keywords:** OWASP SAMM assessment, secure SDLC implementation, devsecops integration, software composition analysis, static application security testing, IaC drift monitoring, security champion programs, cross-site scripting remediation, third-party dependency vulnerabilities, container image scanning, transitive dependencies, vulnerability reachability, threat modeling process, automated pull request remediation ## Chapters 1. **Introduction to secure development and OWASP SAMM** (00:02) — Why focusing purely on secure coding is insufficient without a comprehensive secure development lifecycle. 1. **Common consequences of secure development lifecycle failures** (05:28) — How undefined responsibilities and missing threat models lead to expensive production vulnerabilities. 1. **Exploring the structure of the OWASP SAMM framework** (10:04) — The core business functions, security practices, streams, and maturity levels that make up SAMM. 1. **Mapping production vulnerabilities to OWASP SAMM domains** (15:46) — Finding the root cause of component vulnerabilities and missing designs within specific assessment streams. 1. **Generating granular scores and creating improvement roadmaps** (19:04) — Using assessment results to identify organizational blind spots rather than fixating on absolute metrics. 1. **Conducting an effective SAMM interview and self-assessment** (22:19) — The logistics of setting up external interviews, guided self-assessments, and utilizing the provided spreadsheet toolbox. 1. **Common pitfalls to avoid during maturity assessments** (31:46) — Why organizations should refrain from comparing teams directly and instead focus on application-specific contexts. 1. **Audience Q&A on maturity assessments and external consultants** (37:10) — Audience questions around team size requirements and mitigating bias during internal security assessments. 1. **Embracing DevSecOps and automating the software development lifecycle** (42:23) — Shifting security left by integrating early automated feedback across code, containers, and infrastructure. 1. **Analyzing risks in open source and transitive dependencies** (48:56) — Understanding how the scale of nested project dependencies expands the vulnerable surface area of applications. 1. **Demonstrating a cross-site scripting attack on vulnerable inputs** (53:10) — Bypassing a markdown library's basic sanitization logic to execute a malicious payload. 1. **Fixer automation and in-editor software composition analysis** (62:34) — How developer-focused tools integrate directly into the IDE to detect and remediate vulnerabilities instantly. 1. **Integrating SAST and container security into developer workflows** (71:54) — Scanning proprietary code logic and base container images to block vulnerabilities before entering production. 1. **Securing environments by scanning infrastructure as code** (78:27) — Preventing exploitation by continuously monitoring configuration files and tracking infrastructure drift over time. 1. **Using financial data to advocate for security integration** (82:51) — Convincing technical leadership that fixing vulnerabilities early is exponentially cheaper than managing production breaches. 1. **Q&A on security automation and building champions programs** (88:27) — Final questions covering vulnerability capability, log4j tracking, and cultivating an organic security culture. ## Related Moments - [Answering audience questions on practical application security](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) (from "Software Security 101: Secure Coding Basics") - [Transitioning toward DevSecOps with dynamic scanning and secrets management](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) (from "Enabling automated 1-click customer deployments with built-in quality and security") - [Shifting left and creating internal security champion programs](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Identifying non-coding software vulnerabilities and organizational risks](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) (from "Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?") - [Exploring pathways to application security careers and research workflows](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Introduction to security advocacy and automation testing](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) (from "WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/293774-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [Senior Open Source Advisor](https://www.wearedevelopers.com/jobs/ext/1278113-senior-open-source-advisor) at **ZEISS Group** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio** - [Senior Threat Intelligence Analyst](https://www.wearedevelopers.com/jobs/ext/1684162-senior-threat-intelligence-analyst) at **ZEISS Group**