OWASP SAMM
Implementation

OWASP SAMM OWASPSAMM-3: Implementation: Secure Build, Secure Deployment, Defect Management

Per OWASP SAMM v2 Implementation business function: secure implementation practices. Security Practices: (1) Secure Build including build process security + software dependencies management + (2) Secure Deployment including deployment process security + secret management + (3) Defect Management including defect tracking + metrics + remediation prioritisation. Requirements include (a) maintain secure build process including signed artefacts + isolated build environments + integrity verification + (b) maintain software dependencies inventory including SBOM + vulnerability scanning + provenance verification + (c) maintain secure deployment process including artifact signing + deployment approvals + rollback + (d) operate secrets management including dedicated secret store + rotation + access control + (e) maintain defect tracking + categorisation + metrics including time-to-remediate + (f) prioritise remediation based on risk.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.