The software security group is conducting a maturity assessment using the Open Web Application Security Project Software Assurance Maturity Model (OWASP OpenSAMM). They are currently focused on reviewing design artifacts to ensure they comply with organizational security standards. Which OpenSAMM business function is being assessed?
Select an option, then click Submit answer.
Reference / correct answer:
Most accepted answer: C. Verification
Community votes: C=1
Selected Answer: C Key aspects of OWASP SAMM include: Purpose: It helps build a balanced software security program, measure progress, and demonstrate concrete improvements in security assurance. Structure: The model (specifically SAMM v2) consists of 5 core business functions, each with 3 security practices, evaluated across 3 maturity levels (plus a baseline level 0). Core Functions: Governance: Strategy and metrics, policy and compliance, education and guidance. Design: Threat assessment, security requirements, secure architecture. Implementation: Secure build, secure deployment, defect management. Verification: Architecture assessment, requirements-driven testing, security testing. Operations: Incident management, environment management, operational enablement. upvoted 1 times