Motivation and overview
Why a secure development process is worthwhile and how it is structured.
- Security development lifecycle concept
- Secure development with OWASP SAMM
- Place within software development models
Training
Your team needs to build security into software development from the start. The workshop teaches the security development lifecycle concept and secure development with OWASP SAMM.
Two mornings as an interactive webinar, for development, product and project owners as well as security managers, information security officers and CISOs.
Free of charge and without obligation.

Your situation
The penetration test shortly before go-live finds vulnerabilities whose cause was laid weeks or months earlier: in missing security requirements, in the design or in the implementation. At the same time, clients, standards and regulation increasingly demand a demonstrably secure development process – for example in line with IEC 62443-4-1, BSI TR-03185 or under the Cyber Resilience Act.
The OWASP Software Assurance Maturity Model (SAMM) describes how organisations anchor security across the entire software lifecycle. The workshop works through this lifecycle stage by stage: from protection goals and threat modelling through security by design and secure coding guidelines to testing and patch management.
Unlike the other OWASP modules, it is aimed not only at development and product owners but also at security managers, information security officers and CISOs who steer the process. The trainers themselves support manufacturers with secure development processes and product certifications, including under IEC 62443 and BSI TR-03185.
Services & results
Your team works through a secure software lifecycle based on OWASP SAMM stage by stage: protection goals, threat modelling with STRIDE and PASTA, security by design, secure coding guidelines, testing and patch management. For development and product owners as well as for security managers, information security officers and CISOs, with examples from the trainers' real projects. The training is available in German or English.
The workshop follows the lifecycle of a software product – from the motivation to responding to vulnerabilities after release. Two mornings, each from 9:00 to 12:30.
Why a secure development process is worthwhile and how it is structured.
Protection goals and threats are turned into requirements for the product. The trainers demonstrate threat modelling using examples from products they have supported in projects.
How requirements can be adopted from standards or formulated for your own product – from the perspective of the evaluation facility that evaluates under Common Criteria and IEC 62443.
How security gets into the architecture before the first line of code is written.
Guidelines and tools with which development teams avoid and find errors in code.
From testing individual security requirements to the penetration test. We take up your participants' scenarios and requirements for testing tools.
What happens after release: how reported vulnerabilities are handled and updates are delivered.
Result
Your team knows all stages of a security development lifecycle and can judge where your own development process should be tightened.
The SAMM workshop is delivered by trainers who not only teach secure development processes but also introduce and evaluate them at manufacturers. Luise Werner advises on secure development lifecycles and OT security at secuvera, accompanies manufacturers towards certification under IEC 62443-4-1 and carries out threat modelling with clients. She is a member of the TeleTrusT working group Smart Grids / Industrial Security. Ruben Konrad is a penetration tester and advises and evaluates under Common Criteria and IEC 62443 in our Product Security team. The pool of trainers also includes Sebastian Fritsch, head of secuvera's BSI evaluation facility for Common Criteria.
The practice behind it: we successfully accompanied Red Lion Europe to certification under IEC 62443-4-1. For BSI TR-03185 on secure software lifecycles, we are one of the first evaluation facilities with concrete projects and certification procedures. We have largely standardised our TARA process, and in the OVVL research project we work on threat modelling methods. We carry out static code analysis (SAST) and penetration tests ourselves.
Getting started
From 9:00 to 12:30 on each of two days, as an interactive webinar via Zoom – or via your platform, such as Webex or Teams. On site on request; in that case you provide the room and presentation equipment. Instead of a script, you receive slides to follow along and show notes for each session, and a certificate of attendance on request.
You decide the number. For didactic reasons, we recommend up to 15 participants; with more than 20, the results suffer.

The training is offered by secuvera and teaches OWASP methods. It is not a training course of the OWASP® Foundation.
Over two mornings from 9:00 to 12:30 as an interactive webinar: theory, joint technical demonstrations, polls and discussion. 95% of participants prefer this format to a full training day. Zoom is the standard; Webex, Teams or your own platform also work, and on request the training takes place on site.
You decide. We recommend up to 15 participants; with more than 20, the results suffer. The price applies per session, regardless of the number of participants.
No. The modules are standard training courses that we continue to develop across all sessions. If you wish, send us a list of your internal requirements in advance, such as development guidelines – the titles are sufficient.
No. The workshop teaches the security development lifecycle based on OWASP SAMM. Assessing your process is a separate project, for example a gap analysis under IEC 62443-4-1 or BSI TR-03185.
It teaches the building blocks of a secure development process that are also required there, such as threat modelling, security testing and vulnerability management. For the detailed requirements of the standard, there is our training “IEC 62443 for the CRA in practice”.