OWASP DevSecOps Maturity Model (DSOMM)
Metrics and Improvement

OWASP DevSecOps Maturity Model (DSOMM) DSOMM-6: Metrics, Maturity Measurement, and Continuous Improvement

Per OWASP DSOMM Metrics and Improvement: measure security maturity + drive continuous improvement. Requirements include (a) define security metrics covering culture + implementation + build + test + monitoring dimensions + (b) measure DSOMM maturity levels per dimension + per sub-area + over time + (c) operate security risk scoring + dashboards visible to engineering + product + leadership + (d) implement compliance monitoring + reporting + (e) drive continuous improvement via retrospective + post-incident review + benchmark + (f) align metrics to business outcomes + with regular review + and improvement planning.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 49 controls across 44 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

MTCS (Singapore) · 2 controls

  • MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles
  • MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

Bahrain PDPL · 1 control

  • LOPDP-EC-Enforcement-Sanctions-Articles-66-76-SPDP-Investigation-Administrative-Fines-Tiered-Penalty-Habeas-Data Ecuador LOPDP Enforcement + Sanctions + Articles 66-76 + SPDP + Habeas Data

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution
  • GLI33-Sports-Integrity-DataProviders-Compliance GLI-33 Sports Event Data Integrity, Provider Certification and Regulatory Reporting

GRI Standards · 1 control

IEEE 7000 · 1 control

  • IEEE7000-Scope-VBE-EAD-IEEE7000Family-EUAIAct-NIST-ISO42001-Coord IEEE 7000-2021 - Scope + Value-Based Engineering (VBE) + Ethically Aligned Design + IEEE 7000 Family + Coordination EU AI Act + NIST AI RMF + ISO/IEC 42001

ISMAP (Japan) · 1 control

ISSB Standards · 1 control

  • ISSB-IFRS-S1-Sources-SASB-Industry-Disclosures-Connected-Information-Reporting-Boundary ISSB IFRS S1 Sources of Guidance + SASB Standards Industry-Specific Disclosures + Connected Information + Reporting Boundary + Time of Reporting + Comparative Information + 11 SASB Sectors
  • INCDPA-Enforcement-30DayCure-AttorneyGeneralOnly-NoPrivateRight-CivilPenalties-7500-PerViolation Indiana CDPA Enforcement - Attorney General Exclusive + 30-Day Cure Period + No Private Right of Action + Civil Penalties Up to USD 7500 Per Violation + Investigation + Compliance

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

  • JP-AIG-Accountability-Governance-AI-Inventory-Stakeholder-Engagement-Board-Reporting-Tone-at-Top Japan AI Guidelines Accountability + Governance + AI Inventory + Stakeholder Engagement + Board Reporting + Tone at Top + AI Ethics Committee + DPO + AI Officer + Regulatory Compliance + Multi-Stakeholder

LGPD · 1 control

  • LGPD-BR-Enforcement-Sanctions-ANPD-Article-52-55-Administrative-Sanctions-2-Percent-Turnover-50M-BRL Brazil LGPD Enforcement + Sanctions + Article 52 + 2% Turnover + 50M BRL + ANPD

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Enforcement-PDPC-Investigation-RM1M-Fine-3-Year-Prison-Class-Action-Section-104-2024-Amendment Malaysia PDPA Enforcement + PDPC Investigation + RM1M Fine + 3 Year Prison + Class Action + 2024 Amendment

Mauritius DPA · 1 control

  • MU-DPA-Enforcement-Commissioner-Section-41-43-MUR-200K-5-Year-Prison-ICT-Appeal-Tribunal-Supreme-Court Mauritius DPA Enforcement + Commissioner + Section 41 + Section 43 + MUR 200K + 5 Year Prison + ICT Appeal Tribunal + Supreme Court

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN
  • MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
  • MT-CDPA-Processor-Contract-Security-MCA-30-14-2809-30-14-2811-Pseudonymisation-De-Identification Montana CDPA Processor + MCA 30-14-2809 + Security + Pseudonymisation + MCA 30-14-2811 + De-Identification
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-1 On-Demand Self-Service and Broad Network Access Characteristics

NIST SP 800-146 · 1 control

  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NZISM-2 Certification and Accreditation (C&A) for Government Systems
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition

OECD AI Principles · 1 control

  • OECDAI-8 AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 49 it maps to, and the evidence behind each claim, over MCP and REST.