Hacker News new | ask | show | jobs
by ellingsworth 1281 days ago
You might take a look at the OWASP Software Assurance Maturity Model (SAMM) for guidance on prescriptive activities you can take to improve your security posture over time. [1] There is a toolkit available that you can use to evaluate your team(s) and establish a phased roadmap. [2]

The data you gather from the assessment can help you prioritize activities for your team/org as well as provide metrics for your leadership.

You can also resource your activities with some of the OSS available from OWASP as well as join any of the projects/discussions to learn more. [3] Feel free to DM for more.

1. https://owaspsamm.org/ 2. https://owaspsamm.org/assessment/ 3. https://owasp.org/

1 comments

Yes, SAMM. I also refer to it as a list of questions to ask if you don't want the job, although some of the questions are good to ask when you get to the negotiation stage.