Search / openssf/osps-baseline-to-samm / v0.0.0-dev-671f23f

Release · v0.0.0-dev-671f23f

openssf/osps-baseline-to-samm Mapping Document

openssf/osps-baseline-to-samm

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to OWASP SAMM. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

Published by OSPS Baseline Authors

License No license declared

Install

OCI v1.1
$grcli unpack --repository openssf/osps-baseline-to-samm --version v0.0.0-dev-671f23f

grcli unpack verifies this signature against the recorded identity below and fails closed before writing any files — no separate verify step needed. Pass --no-verify to skip.

Coordinate
oci.grc.store/openssf/osps-baseline-to-samm:v0.0.0-dev-671f23f
Manifest digest
sha256:ce70d6a976b3fe2755bbf329ac3f9579331a7ce397f34e59b5bc1e6b61ffecae
Signed by
no signature recorded

Identity recorded by this hub when the version was published; unpack (above) checks the signature against it.

Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-samm --version v0.0.0-dev-671f23f

Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.

Provenance

1 layer
Digest Media type Size
b41f605e5beb… application/vnd.gemara.artifact.v1+yaml 6.5 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "1.2.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "osps-baseline-to-samm",
            "type": "MappingDocument"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "openssf/osps-baseline-to-samm",
            "tag": "v0.0.0-dev-671f23f"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "eddie-knight/security-baseline",
          "GITHUB_RUN_ATTEMPT": "1",
          "GITHUB_RUN_ID": "26617016306",
          "GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
          "GITHUB_WORKFLOW": "Publish to grc.store",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "/home/runner/work/_temp/staged/osps-to-samm.yaml",
            "uri": "file:///home/runner/work/_temp/staged/osps-to-samm.yaml",
            "digest": {
              "sha256": "b41f605e5beb6a8d9a8eb57f13e44295f38f8a4608ceb05a7651be34b02042cf"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
            "digest": {
              "gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.2.2"
          }
        },
        "metadata": {
          "invocationId": "26617016306-1",
          "startedOn": "2026-05-29T03:57:20.196064038Z",
          "finishedOn": "2026-05-29T03:57:20.289370757Z"
        },
        "byproducts": [
          {
            "name": "osps-to-samm.yaml",
            "digest": {
              "sha256": "b41f605e5beb6a8d9a8eb57f13e44295f38f8a4608ceb05a7651be34b02042cf"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "osps-to-samm.yaml",
      "type": "MappingDocument",
      "id": "osps-baseline-to-samm",
      "role": "artifact"
    }
  ]
}

No rich preview yet

This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.

mappings:
  - id: M-OSPS-AC-01-SAMM
    relationship: relates-to
    source: OSPS-AC-01
    targets:
      - entry-id: Operations -Environment Management -Configuration Hardening Lvl1
  - id: M-OSPS-AC-04-SAMM
    relationship: relates-to
    source: OSPS-AC-04
    targets:
      - entry-id: Operations -Environment Management -Configuration Hardening Lvl1
  - id: M-OSPS-BR-05-SAMM
    relationship: relates-to
    source: OSPS-BR-05
    targets:
      - entry-id: Implementation -Secure Build -Build Process Lvl2
  - id: M-OSPS-BR-06-SAMM
    relationship: relates-to
    source: OSPS-BR-06
    targets:
      - entry-id: Implementation -Secure Deployment -Deployment Process Lvl3
  - id: M-OSPS-DO-02-SAMM
    relationship: relates-to
    source: OSPS-DO-02
    targets:
      - entry-id: Implementation -Defect Management -Defect Tracking Lvl1
      - entry-id: Implementation -Defect Management -Defect Tracking Lvl2
  - id: M-OSPS-DO-04-SAMM
    relationship: relates-to
    source: OSPS-DO-04
    targets:
      - entry-id: Operations -Operational Management -System Decommissioning -Legacy
          Management Lvl1
  - id: M-OSPS-DO-05-SAMM
    relationship: relates-to
    source: OSPS-DO-05
    targets:
      - entry-id: Operations -Operational Management -System Decommissioning -Legacy
          Management Lvl1
      - entry-id: Operations -Operational Management -System Decommissioning -Legacy
          Management Lvl2
  - id: M-OSPS-DO-06-SAMM
    relationship: relates-to
    source: OSPS-DO-06
    targets:
      - entry-id: Design -Security Requirements -Supplier Security Lvl2
  - id: M-OSPS-QA-01-SAMM
    relationship: relates-to
    source: OSPS-QA-01
    targets:
      - entry-id: Implementation -Secure Build -Build Process Lvl1
  - id: M-OSPS-QA-02-SAMM
    relationship: relates-to
    source: OSPS-QA-02
    targets:
      - entry-id: Implementation -Secure Build -Software Dependencies Lvl1
  - id: M-OSPS-QA-03-SAMM
    relationship: relates-to
    source: OSPS-QA-03
    targets:
      - entry-id: Implementation -Secure Build -Build Process Lvl3
      - entry-id: Implementation -Secure Build -Software Dependencies Lvl3
      - entry-id: Verification -Requirements Testing -Control Verification Lvl1
      - entry-id: Verification -Requirements Testing -Control Verification Lvl2
      - entry-id: Verification -Requirements Testing -Control Verification Lvl3
  - id: M-OSPS-QA-06-SAMM
    relationship: relates-to
    source: OSPS-QA-06
    targets:
      - entry-id: Verification-Requirements -Testing -Control Verification Lvl1
      - entry-id: Verification-Requirements -Testing -Control Verification Lvl2
      - entry-id: Verification-Requirements -Testing -Control Verification Lvl3
      - entry-id: Verification -Security Testing -Scalable Baseline Lvl3
  - id: M-OSPS-SA-01-SAMM
    relationship: relates-to
    source: OSPS-SA-01
    targets:
      - entry-id: Operations -Operational Management -Data Protection Lvl2
  - id: M-OSPS-SA-03-SAMM
    relationship: relates-to
    source: OSPS-SA-03
    targets:
      - entry-id: Governance -Create and Promote Lvl1
      - entry-id: Design -Threat Assessment -Application Risk Profile Lvl1
      - entry-id: Design -Threat Assessment -Threat Modeling Lvl1
      - entry-id: Verification -Architecture Assessment -Architecture Mitigation Lvl2
  - id: M-OSPS-VM-01-SAMM
    relationship: relates-to
    source: OSPS-VM-01
    targets:
      - entry-id: Governance -Create and Promote Lvl2
      - entry-id: Governance -Policy & Compliance -Policy & Standards Lvl1
      - entry-id: Implementation -Defect Management -Defect Tracking Lvl1
      - entry-id: Implementation -Defect Management -Defect Tracking Lvl2
      - entry-id: Implementation -Defect Management -Defect Tracking Lvl3
      - entry-id: Operations -Incident Management -Incident Response Lvl1
      - entry-id: Operations -Incident Management -Incident Response Lvl2
      - entry-id: Operations -Incident Management -Incident Response Lvl3
  - id: M-OSPS-VM-02-SAMM
    relationship: relates-to
    source: OSPS-VM-02
    targets:
      - entry-id: Governance -Policy&Compliance -Policy&Standards Lvl2
  - id: M-OSPS-VM-03-SAMM
    relationship: relates-to
    source: OSPS-VM-03
    targets:
      - entry-id: Operations -Incident Management -Incident Response Lvl3
  - id: M-OSPS-VM-05-SAMM
    relationship: relates-to
    source: OSPS-VM-05
    targets:
      - entry-id: Implementation -Secure Build-Build Process Lvl3
      - entry-id: Implementation -Software Dependencies Lvl3
      - entry-id: Verification -Security Testing -Scalable Baseline Lvl1
      - entry-id: Verification -Security Testing -Scalable Baseline Lvl3
  - id: M-OSPS-VM-06-SAMM
    relationship: relates-to
    source: OSPS-VM-06
    targets:
      - entry-id: Implementation -Secure Build-Build Process Lvl3
      - entry-id: Implementation -Software Dependencies Lvl3
      - entry-id: Verification -Security Testing -Scalable Baseline Lvl1
      - entry-id: Verification -Security Testing -Scalable Baseline Lvl3
metadata:
  author:
    id: openssf
    name: OSPS Baseline Authors
    type: Human
  description: |
    Cross-walk from the Open Source Project Security (OSPS) Baseline
    controls to OWASP SAMM. Each mapping asserts a "relates-to"
    relationship; strength, confidence-level, and rationale are left
    unset and should be added as the mappings are individually
    reviewed.
  draft: true
  gemara-version: 1.2.0
  id: osps-baseline-to-samm
  mapping-references:
    - description: |
        The Open Source Project Security (OSPS) Baseline is a set of security
        criteria that projects should meet to demonstrate a strong security
        posture.
      id: osps-baseline
      title: Open Source Project Security Baseline
      url: https://github.com/ossf/security-baseline
      version: draft
    - description: The mission of OWASP Software Assurance Maturity Model (SAMM) is to
        be the prime maturity model for software assurance that provides an
        effective and measurable way for all types of organizations to analyze
        and improve their software security posture. OWASP SAMM supports the
        complete software lifecycle, including development and acquisition, and
        is technology and process agnostic. It is intentionally built to be
        evolutive and risk-driven in nature.
      id: SAMM
      title: OWASP Software Assurance Maturity Model
      url: https://owaspsamm.org/model/
      version: "2.0"
  type: MappingDocument
  version: v0.0.0-dev-671f23f
source-reference:
  entry-type: Control
  reference-id: osps-baseline
target-reference:
  entry-type: Guideline
  reference-id: SAMM
title: OSPS Baseline to OWASP SAMM Mapping