OWASP SAMM
OWASP Software Assurance Maturity Model
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
OWASP content is used under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0). Original material © OWASP Foundation. See owasp.org for the authoritative source.
Framework Domains (11)
Design
| Code | Title |
|---|---|
| SAMM-D-SA | Security Architecture |
| SAMM-D-SR | Security Requirements |
| SAMM-D-SR2 | Supplier Security Requirements |
| SAMM-D-TA | Threat Assessment |
Governance
| Code | Title |
|---|---|
| SAMM-G-EG | Education and Guidance |
| SAMM-G-EG2 | Security Champions |
| SAMM-G-PC | Policy and Compliance |
| SAMM-G-SM | Strategy and Metrics |
| SAMM-G-SM2 | Application Risk Profile |
Implementation
| Code | Title |
|---|---|
| SAMM-I-DM | Defect Management |
| SAMM-I-SB | Secure Build |
| SAMM-I-SD | Secure Deployment |
OWASP SAMM: Access Control
Logical and physical access controls (OWASP SAMM)
| Code | Title |
|---|---|
| SAMM-11 | Access control policy and enforcement |
| SAMM-12 | User access management and provisioning |
| SAMM-13 | Authentication and password management |
| SAMM-14 | Privileged access management |
| SAMM-15 | Access review and recertification |
OWASP SAMM: Asset Management
Information asset management (OWASP SAMM)
| Code | Title |
|---|---|
| SAMM-06 | Asset inventory and ownership |
| SAMM-07 | Acceptable use of assets |
| SAMM-08 | Information classification and labeling |
| SAMM-09 | Asset handling procedures |
| SAMM-10 | Media management and disposal |
OWASP SAMM: Communications Security
Network and communications security (OWASP SAMM)
| Code | Title |
|---|---|
| SAMM-27 | Network security management |
| SAMM-28 | Network service security |
| SAMM-29 | Segregation in networks |
| SAMM-30 | Information transfer policies |
| SAMM-31 | Secure messaging |
OWASP SAMM: Cryptography
Cryptographic controls (OWASP SAMM)
| Code | Title |
|---|---|
| SAMM-16 | Cryptographic policy and key management |
| SAMM-17 | Encryption of data at rest |
| SAMM-18 | Encryption of data in transit |
| SAMM-19 | Certificate management |
| SAMM-20 | Key lifecycle management |
OWASP SAMM: Information Security Policies
Organizational information security policies (OWASP SAMM)
| Code | Title |
|---|---|
| SAMM-01 | Information security policy framework |
| SAMM-02 | Management direction and commitment |
| SAMM-03 | Policy review and update procedures |
| SAMM-04 | Roles and responsibilities definition |
| SAMM-05 | Contact with authorities and special interest groups |
OWASP SAMM: Operations Security
Secure operations and monitoring (OWASP SAMM)
| Code | Title |
|---|---|
| SAMM-21 | Operational procedures and responsibilities |
| SAMM-22 | Protection from malware |
| SAMM-23 | Backup and recovery procedures |
| SAMM-24 | Logging and monitoring |
| SAMM-25 | Technical vulnerability management |
| SAMM-26 | Audit considerations |
Operations
| Code | Title |
|---|---|
| SAMM-O-EM | Environment Management |
| SAMM-O-IM | Incident Management |
| SAMM-O-IM2 | Forensic Readiness |
| SAMM-O-OM | Operational Management |
Verification
| Code | Title |
|---|---|
| SAMM-V-AA | Architecture Assessment |
| SAMM-V-RT | Requirements-Driven Testing |
| SAMM-V-ST | Security Testing |
| SAMM-V-ST2 | Penetration Testing |
Your Compliance Coverage
If you comply with OWASP SAMM, you already cover:
3GPP Security
31%
16 controls mapped
Compare →NIST SP 800-161
31%
16 controls mapped
Compare →BSIMM
31%
16 controls mapped
Compare →+ 607 more: NIST SP 800-183 (31%), NIST SP 800-187 (31%)
See all 610 mapped frameworks ↓Maps to 610 other frameworks
Frequently Asked Questions
What is OWASP SAMM?
OWASP SAMM is a compliance framework from International with 11 domains and 51 controls. OWASP Software Assurance Maturity Model It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does OWASP SAMM have?
OWASP SAMM has 51 controls organised across 11 domains. The largest domains are OWASP SAMM: Operations Security (6 controls), Governance (5 controls), OWASP SAMM: Access Control (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does OWASP SAMM map to?
OWASP SAMM maps to 610 other compliance frameworks. The top mapping partners are 3GPP Security (31% coverage), NIST SP 800-161 (31% coverage), BSIMM (31% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with OWASP SAMM compliance?
Start your OWASP SAMM compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about OWASP SAMM requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 51 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required