Search / openssf/osps-baseline-to-samm
mapping
OSPS Baseline to OWASP SAMM Mapping Mapping Document
openssf/osps-baseline-to-samm
Cross-walk from the Open Source Project Security (OSPS) Baseline controls to OWASP SAMM. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.
Published by OSPS Baseline Authors
License No license declared
Pull latest (v0.0.0-dev-671f23f)
$grcli unpack --repository openssf/osps-baseline-to-samm --version v0.0.0-dev-671f23f Releases
1 live| Version | Manifest digest | Published | License | Status | |
|---|---|---|---|---|---|
| v0.0.0-dev-671f23f | ce70d6a976b3fe… | 1mo ago | No license declared | Live unsigned | Details → |
Mapping references
external standards this artifact maps to (v0.0.0-dev-671f23f)-
The Open Source Project Security (OSPS) Baseline is a set of security criteria that projects should meet to demonstrate a strong security posture.
-
The mission of OWASP Software Assurance Maturity Model (SAMM) is to be the prime maturity model for software assurance that provides an effective and measurable way for all types of organizations to analyze and improve their software security posture. OWASP SAMM supports the complete software lifecycle, including development and acquisition, and is technology and process agnostic. It is intentionally built to be evolutive and risk-driven in nature.
Builds upon
artifacts this one extends, imports, or shares a lexicon withNo upstream references yet
This artifact doesn't extend, import, or share a lexicon with anything else in the registry.
Extended or imported by
other artifacts that build upon this oneNo dependents yet
Published artifacts that extend or import this one will appear here.