WeAreDevelopers LIVE • Feb 1, 2022

Maturity assessment for technicians or how I learned to love OWASP SAMM

Mathias Tausig

Are you still waiting for late-stage penetration tests to catch critical vulnerabilities? Discover how OWASP SAMM empowers developers to shift security left directly into the IDE.

Pause
Mute Enter Fullscreen
#1 about 6 min

Introduction to secure development and OWASP SAMM

Why focusing purely on secure coding is insufficient without a comprehensive secure development lifecycle.

#2 about 5 min

Common consequences of secure development lifecycle failures

How undefined responsibilities and missing threat models lead to expensive production vulnerabilities.

#3 about 6 min

Exploring the structure of the OWASP SAMM framework

The core business functions, security practices, streams, and maturity levels that make up SAMM.

#4 about 4 min

Mapping production vulnerabilities to OWASP SAMM domains

Finding the root cause of component vulnerabilities and missing designs within specific assessment streams.

#5 about 4 min

Generating granular scores and creating improvement roadmaps

Using assessment results to identify organizational blind spots rather than fixating on absolute metrics.

#6 about 10 min

Conducting an effective SAMM interview and self-assessment

The logistics of setting up external interviews, guided self-assessments, and utilizing the provided spreadsheet toolbox.

#7 about 6 min

Common pitfalls to avoid during maturity assessments

Why organizations should refrain from comparing teams directly and instead focus on application-specific contexts.

#8 about 6 min

Audience Q&A on maturity assessments and external consultants

Audience questions around team size requirements and mitigating bias during internal security assessments.

#9 about 7 min

Embracing DevSecOps and automating the software development lifecycle

Shifting security left by integrating early automated feedback across code, containers, and infrastructure.

#10 about 5 min

Analyzing risks in open source and transitive dependencies

Understanding how the scale of nested project dependencies expands the vulnerable surface area of applications.

#11 about 10 min

Demonstrating a cross-site scripting attack on vulnerable inputs

Bypassing a markdown library's basic sanitization logic to execute a malicious payload.

#12 about 10 min

Fixer automation and in-editor software composition analysis

How developer-focused tools integrate directly into the IDE to detect and remediate vulnerabilities instantly.

#13 about 7 min

Integrating SAST and container security into developer workflows

Scanning proprietary code logic and base container images to block vulnerabilities before entering production.

#14 about 5 min

Securing environments by scanning infrastructure as code

Preventing exploitation by continuously monitoring configuration files and tracking infrastructure drift over time.

#15 about 6 min

Using financial data to advocate for security integration

Convincing technical leadership that fixing vulnerabilities early is exponentially cheaper than managing production breaches.

#16 about 13 min

Q&A on security automation and building champions programs

Final questions covering vulnerability capability, log4j tracking, and cultivating an organic security culture.

Matching moments

13:13 min

Answering audience questions on practical application security

Thomas Konrad · WWC 2021

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans