Training

OWASP SAMM: secure software lifecycle

Your team needs to build security into software development from the start. The workshop teaches the security development lifecycle concept and secure development with OWASP SAMM.

Two mornings as an interactive webinar, for development, product and project owners as well as security managers, information security officers and CISOs.

Free of charge and without obligation.

  • OWASP Corporate Member · Silver Sponsor
  • Trainers are experts in secure software development and requirements such as the CRA
Top view of joint map work with notes, compasses and navigation instruments
OWASP SAMM: anchoring security firmly in the software lifecycle.

Your situation

You want to build security into your development process – not just in the pentest before release?

The penetration test shortly before go-live finds vulnerabilities whose cause was laid weeks or months earlier: in missing security requirements, in the design or in the implementation. At the same time, clients, standards and regulation increasingly demand a demonstrably secure development process – for example in line with IEC 62443-4-1, BSI TR-03185 or under the Cyber Resilience Act.

The OWASP Software Assurance Maturity Model (SAMM) describes how organisations anchor security across the entire software lifecycle. The workshop works through this lifecycle stage by stage: from protection goals and threat modelling through security by design and secure coding guidelines to testing and patch management.

Unlike the other OWASP modules, it is aimed not only at development and product owners but also at security managers, information security officers and CISOs who steer the process. The trainers themselves support manufacturers with secure development processes and product certifications, including under IEC 62443 and BSI TR-03185.

Services & results

Seven stages of the security development lifecycle based on OWASP SAMM

Your team works through a secure software lifecycle based on OWASP SAMM stage by stage: protection goals, threat modelling with STRIDE and PASTA, security by design, secure coding guidelines, testing and patch management. For development and product owners as well as for security managers, information security officers and CISOs, with examples from the trainers' real projects. The training is available in German or English.

The workshop follows the lifecycle of a software product – from the motivation to responding to vulnerabilities after release. Two mornings, each from 9:00 to 12:30.

Motivation and overview

Why a secure development process is worthwhile and how it is structured.

  • Security development lifecycle concept
  • Secure development with OWASP SAMM
  • Place within software development models

Deriving security requirements

Protection goals and threats are turned into requirements for the product. The trainers demonstrate threat modelling using examples from products they have supported in projects.

  • IT protection goals
  • Threat modelling with STRIDE and PASTA
  • Example based on client products

Describing security requirements

How requirements can be adopted from standards or formulated for your own product – from the perspective of the evaluation facility that evaluates under Common Criteria and IEC 62443.

  • A look at standards, e.g. protection profiles
  • Methodology for custom requirements
  • Mitigation as part of a TARA (threat and risk analysis)

Secure design

How security gets into the architecture before the first line of code is written.

  • Security by design concept
  • Defence in depth
  • Proven practices: secure design patterns

Secure implementation

Guidelines and tools with which development teams avoid and find errors in code.

  • Secure coding guidelines
  • Static code analysis
  • Proven practices
  • Reviewing secure implementation

Verification and testing

From testing individual security requirements to the penetration test. We take up your participants' scenarios and requirements for testing tools.

  • Testing security-relevant requirements
  • Vulnerability testing
  • Penetration tests
  • Solutions for verification and testing
  • Participants' scenarios and requirements for testing tools

Release and response to vulnerabilities

What happens after release: how reported vulnerabilities are handled and updates are delivered.

  • Handling vulnerabilities
  • Security-relevant policies
  • Patch management

Result

Your team knows all stages of a security development lifecycle and can judge where your own development process should be tightened.

Our expertise

The SAMM workshop is delivered by trainers who not only teach secure development processes but also introduce and evaluate them at manufacturers. Luise Werner advises on secure development lifecycles and OT security at secuvera, accompanies manufacturers towards certification under IEC 62443-4-1 and carries out threat modelling with clients. She is a member of the TeleTrusT working group Smart Grids / Industrial Security. Ruben Konrad is a penetration tester and advises and evaluates under Common Criteria and IEC 62443 in our Product Security team. The pool of trainers also includes Sebastian Fritsch, head of secuvera's BSI evaluation facility for Common Criteria.

The practice behind it: we successfully accompanied Red Lion Europe to certification under IEC 62443-4-1. For BSI TR-03185 on secure software lifecycles, we are one of the first evaluation facilities with concrete projects and certification procedures. We have largely standardised our TARA process, and in the OVVL research project we work on threat modelling methods. We carry out static code analysis (SAST) and penetration tests ourselves.

Getting started

Format and schedule

Two mornings, remote

From 9:00 to 12:30 on each of two days, as an interactive webinar via Zoom – or via your platform, such as Webex or Teams. On site on request; in that case you provide the room and presentation equipment. Instead of a script, you receive slides to follow along and show notes for each session, and a certificate of attendance on request.

Up to 15 participants

You decide the number. For didactic reasons, we recommend up to 15 participants; with more than 20, the results suffer.

Plan OWASP training
Hands writing notes next to a compass and navigation instruments on a map
Determining maturity and planning the next steps.

secuvera is the training provider

The training is offered by secuvera and teaches OWASP methods. It is not a training course of the OWASP® Foundation.

Questions about the SAMM workshop

How is the training structured?

Over two mornings from 9:00 to 12:30 as an interactive webinar: theory, joint technical demonstrations, polls and discussion. 95% of participants prefer this format to a full training day. Zoom is the standard; Webex, Teams or your own platform also work, and on request the training takes place on site.

How many people can take part?

You decide. We recommend up to 15 participants; with more than 20, the results suffer. The price applies per session, regardless of the number of participants.

Is the training adapted to our applications?

No. The modules are standard training courses that we continue to develop across all sessions. If you wish, send us a list of your internal requirements in advance, such as development guidelines – the titles are sufficient.

Is the workshop a SAMM assessment of our development process?

No. The workshop teaches the security development lifecycle based on OWASP SAMM. Assessing your process is a separate project, for example a gap analysis under IEC 62443-4-1 or BSI TR-03185.

Does the workshop help with IEC 62443-4-1 or the Cyber Resilience Act?

It teaches the building blocks of a secure development process that are also required there, such as threat modelling, security testing and vulnerability management. For the detailed requirements of the standard, there is our training “IEC 62443 for the CRA in practice”.

How can we support you with OWASP SAMM?