OWASP SAMM
Verification

OWASP SAMM OWASPSAMM-4: Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing

Per OWASP SAMM v2 Verification business function: verify security through assessment + testing. Security Practices: (1) Architecture Assessment including architecture validation + compliance + (2) Requirements-Driven Testing including security testing per requirements + misuse + abuse case testing + (3) Security Testing including scalable baseline (automated SAST + DAST + SCA + dependency scanning) + deep understanding (penetration testing + red team). Requirements include (a) conduct architecture assessment validating implementation against design + secure architecture + (b) implement requirements-driven testing including misuse + abuse case testing + (c) operate scalable baseline security testing via automated SAST + DAST + SCA + IAST in CI/CD + (d) conduct penetration testing + red team + bug bounty for deep understanding + (e) maintain test coverage + measurement + remediation tracking + (f) integrate findings into defect management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 37 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

NIST SP 800-53 Rev 5 · 2 controls

BSI IT-Grundschutz · 1 control

  • BSI-14 Vulnerability scanning and management
  • CPG-5.A Vulnerability Disclosure Program
  • CAT-D3-3 Corrective controls
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27043:2015 · 1 control

  • ISO27043-25 Technical vulnerability management

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations

ISO/SAE 21434 · 1 control

  • ISO21434-25 Technical vulnerability management

NIST SP 800-190 · 1 control

  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning

PTES · 1 control

  • PTESPHASE-4 Vulnerability Analysis
  • SAEIGHT-1 Child Labour and Young Worker Protection
  • IM8-SEC.4 Vulnerability Management

South Korea ISMS-P · 1 control

  • ISMSP-SYS-04 Vulnerability Management
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.