OWASP SAMM
Design

OWASP SAMM OWASPSAMM-2: Design: Threat Assessment, Security Requirements, Security Architecture

Per OWASP SAMM v2 Design business function: secure design practices. Security Practices: (1) Threat Assessment including application threat modelling + risk assessment + (2) Security Requirements including functional security requirements + supplier security requirements + (3) Security Architecture including reference architecture + secure design patterns + technology controls. Requirements include (a) conduct threat modelling at design phase + revise on significant change + (b) maintain documented security requirements per application + (c) maintain supplier + third-party security requirements + (d) define + maintain reference security architecture + secure design patterns + (e) provide technology controls + secure libraries + frameworks + (f) integrate design-time security activities into SDLC.

What else in your programme already covers this

This control maps to 335 controls across 103 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 13 controls

ISO 27043 · 12 controls

ISO/SAE 21434 · 11 controls

BSI IT-Grundschutz · 7 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-15 Security categorization

ISO 13485 · 7 controls

ISO 27799 · 6 controls

  • 3.10 Encrypt Sensitive Data in Transit
  • 3.7 Establish and Maintain a Data Classification Scheme
  • 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity
  • 6.4 Logging and Monitoring
  • 6.5 Preparing and Distributing Audit Report
  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up
  • ISO-15189-6.2 Personnel

ISO 27017 · 5 controls

ISO 27018 · 5 controls

ISO/IEC 27010:2015 · 5 controls

NIST SP 800-190 · 5 controls

OWASP Top 10:2025 · 5 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures

South Korea ISMS-P · 5 controls

API 1164 · 4 controls

  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)

IEC 62443 · 4 controls

ISO 19011 · 4 controls

  • 6.4 Logging and Monitoring
  • 6.5 Preparing and Distributing Audit Report
  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 27019 · 4 controls

NIST SP 1800-32 · 4 controls

  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)
  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

ISO/IEC 27011:2024 · 3 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

PTES · 3 controls

APPI · 2 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 2 controls

  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management

ISO 20000-1 · 2 controls

  • 9.1 Risk communication and consultation
  • ISO20000-15 Access management for services

ISO 31000:2018 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO/IEC 27400:2022 · 2 controls

  • PASONE-1 Security Triage Process, Asset Sensitivity Classification, and Threat Assessment
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements

Saudi Arabia PDPL · 2 controls

  • QMSR-820.45 Device labelling and packaging controls (§820.45)

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ITIL 4 · 1 control

  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • RCEPEC-1 Online Personal Information Protection (12.13)
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection

Vietnam PDPD · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 335 it maps to, and the evidence behind each claim, over MCP and REST.