Skip to content
Cyber Horizon
All frameworks

// Security

OWASP Software Assurance Maturity Model Compliance Software

OWASP maturity model with 15 security practices across five business functions.

Framework at a glance

Short name

OWASP SAMM

Version

2.0

Category

Security

Controls

15

What OWASP SAMM covers

15 controls across 5 domains — every one tracked, owned and evidenced in Cyber Horizon.

Governance

3 controls
  • SAMM-G-SM Strategy & Metrics
  • SAMM-G-PC Policy & Compliance
  • SAMM-G-EG Education & Guidance

Design

3 controls
  • SAMM-D-TA Threat Assessment
  • SAMM-D-SR Security Requirements
  • SAMM-D-SA Secure Architecture

Implementation

3 controls
  • SAMM-I-SB Secure Build
  • SAMM-I-SD Secure Deployment
  • SAMM-I-DM Defect Management

Verification

3 controls
  • SAMM-V-AA Architecture Assessment
  • SAMM-V-RT Requirements-driven Testing
  • SAMM-V-ST Security Testing

Operations

3 controls
  • SAMM-O-IM Incident Management
  • SAMM-O-EM Environment Management
  • SAMM-O-OM Operational Management

How Cyber Horizon automates OWASP SAMM

Every OWASP SAMM control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is OWASP Software Assurance Maturity Model?

OWASP maturity model with 15 security practices across five business functions.

How many controls does OWASP Software Assurance Maturity Model have?

OWASP Software Assurance Maturity Model (2.0) has 15 controls in Cyber Horizon's catalogue, organised across 5 domains.

How does Cyber Horizon help with OWASP Software Assurance Maturity Model?

Cyber Horizon maps OWASP Software Assurance Maturity Model into a shared control library alongside every other framework you run, so evidence collected once counts towards OWASP SAMM and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See OWASP SAMM mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of OWASP SAMM in Cyber Horizon.