4 ms·
What does this framework offer over established open source security frameworks, like the OWASP SAMM? Why not contribute your efforts back to those projects ins
by hardnose 4y ago
What does this framework offer over established open source security frameworks, like the OWASP SAMM? Why not contribute your efforts back to those projects instead of proliferating an additional standard?
I always worry when I see a project like this debut with very little meat on the bones, but a HUGE fleshed out "Code of Conduct" for contributors. What's driving this?
- xnorswap 4y agoThis appears to be more literally a schema for information sharing based on https://schema.ocsf.io/ https://schema.ocsf.io/ which is probably a better link for the original submission.
- breadchris 4y agoit is cool to see someone mention SAMM. I have been obsessed with this framework since it’s inception and am hoping more and more companies adopt it over time (and let it grow with their company). Often times these frameworks are only feasible to use once you have a pretty large security team at your company that can spend their entire job to parse schemas like the one posted. I wrote a post recently talking about how to make SAMM more obtainable to smaller companies starting out thinking about security https://www.lunasec.io/docs/blog/security-guide-for-startups/ https://www.lunasec.io/docs/blog/security-guide-for-startups...
- mdaniel 4y agoto save others the search, since I hadn't heard of it before > OWASP SAMM "Software Assurance Maturity Model" https://owaspsamm.org/ https://owaspsamm.org/
- zsims 4y agoAnd the commercial fork: https://www.bsimm.com/ https://www.bsimm.com/