🌐
Scribd
scribd.com › document › 701015992 › BSIMM-12
Bsimm 12 | PDF | Computer Security | Security
This document provides an executive summary and table of contents for the BSIMM12 2021 Insights & Trends Report. The report examines software security activities from 128 organizations across various industries. Key findings include the top 10 software security activities, comparisons of activities between industries like financial services and healthcare, and emerging trends in areas like DevSecOps practices, governance-as-code, and continuous security improvement.
🌐
University of Edinburgh
inf.ed.ac.uk › teaching › courses › sp › 2015 › lecs › BSIMM6.pdf
SP: Secure Programming | Open Course Materials
Security maintainance of deployed software systems, including "penetrate-and-patch", vulnerability enumeration (CVE IDs) and classification (CWE taxonomy). Software security lifecycles and security activities (e.g., as in BSIMM).
🌐
Black Duck
blackduck.com › resources › analyst-reports › bsimm.html
BSIMM16 Software Security Assessment Report | Black Duck
February 13, 2026 - Throughout the evaluation, assessors map your activities to the BSIMM framework’s maturity levels. The assessment delivers a comprehensive scorecard showing which of the 128 activities your organization currently performs, your maturity level within each of the 12 practices, and how you compare ...
People also ask

How does BSIMM measure the maturity of software security practices?
The BSIMM employs a framework of 116 activities categorized into 12 practices allowing organizations to quantitatively assess their security maturity over time. Notably, firms participating in BSIMM have reported an average score increase of 10.3 activities (39.8%) across remeasurements, reflecting their growing maturity.
🌐
academia.edu
academia.edu › 39202305 › Bsimm
(PDF) Bsimm
In which industries have software security initiatives advanced most significantly?
The BSIMM has noted substantial improvements in regulated industries, particularly financial services, which showcased an average SSG maturity of 5.4 years compared to just 2.5 years in healthcare firms. This highlights how regulatory pressures can accelerate the development and implementation of robust security practices.
🌐
academia.edu
academia.edu › 39202305 › Bsimm
(PDF) Bsimm
What roles are essential for a successful software security initiative?
The data emphasizes the importance of establishing a Software Security Group (SSG) led by a senior executive, typically a CISO, to orchestrate efforts across development and operational teams. Firms with defined SSG structures demonstrated significantly higher maturity scores, suggesting a direct correlation between SSG governance and program success.
🌐
academia.edu
academia.edu › 39202305 › Bsimm
(PDF) Bsimm
🌐
Medium
armerding.medium.com › bsimm14-your-crowd-sourced-guidebook-to-better-software-security-fd02c1e58e08
BSIMM14: Crowd-sourced guidebook to better software security | by Taylor Armerding | Medium
December 11, 2023 - The BSIMM14 “skeleton” contains 126 activities organized under 12 practices that are in turn grouped under four domains. And the report doesn’t dictate exactly which activities your organization should implement to improve its software ...
🌐
Software Engineering Institute
sei.cmu.edu › documents › 5032 › 2016_016_100_450816.pdf pdf
Building Security In Maturity Model (BSIMM)
the first time healthcare organizations have been part of the BSIMM data set, can you talk · about the significance of that and possibly why compliance regulations like HIPAA haven't ... Gary McGraw: Sure. Regulation and compliance is very tricky. And it's important to talk about. And in fact, one of the practices, one of the 12 practices in the BSIMM, is about compliance
🌐
Software Engineering Institute
sei.cmu.edu › library › build-security-in-maturity-model-bsimm-practices-from-seventy-eight-organizations
Build Security In Maturity Model (BSIMM) – Practices from Seventy Eight Organizations | CMU Software Engineering Institute
February 3, 2016 - The best way to use the BSIMM is to compare and contrast your own initiative with the data about what other organizations are doing as described in the model. You can then identify goals and objectives and refer to the BSIMM to determine which additional activities make sense for you. The BSIMM data show that high maturity initiatives are well-rounded—carrying out numerous activities in all 12 of the practices ...
🌐
Academia.edu
academia.edu › 39202305 › Bsimm
(PDF) Bsimm
May 20, 2019 - Historically, penetration testing used to identify vulnerabilities in isolation, but recent trends show a shift towards integrating security practices within continuous development cycles, such as CI/CD and DevOps. This evolution indicates an urgent need for adaptive security measures that evolve alongside rapid technological advancements. In which industries have software security initiatives advanced most significantly?add · The BSIMM has noted substantial improvements in regulated industries, particularly financial services, which showcased an average SSG maturity of 5.4 years compared to just 2.5 years in healthcare firms.
🌐
DTIC
apps.dtic.mil › sti › trecms › pdf › AD1147155.pdf pdf
Building Security In Maturity Model (BSIMM) - DTIC
the first time healthcare organizations have been part of the BSIMM data set, can you talk · about the significance of that and possibly why compliance regulations like HIPAA haven't ... Gary McGraw: Sure. Regulation and compliance is very tricky. And it's important to talk about. And in fact, one of the practices, one of the 12 practices in the BSIMM, is about compliance
🌐
Synopsys
synopsys.com › content › dam › bsimm › reports › bsimm13-foundations.pdf pdf
1 BSIMM FOUNDATIONS REPORT – VERSION 13 FOUNDATIONS REPORT 2022
September 19, 2022 - FIGURE 1. THE BSIMM SKELETON. Within the SSF, the 125 activities are organized into the 12 BSIMM practices, which are within four domains.
Find elsewhere
🌐
Bsimm
bsimm.com › content › dam › bsimm › ebook › everything-know-bsimm-eb.pdf pdf
Bsimm
Based on research with companies such as Aetna, HSBC, Cisco and more, the Building Security In Maturity Model (BSIMM) measures software security.
🌐
Bsimm
bsimm.com › content › dam › bsimm › reports › bsimm12.pdf
We cannot provide a description for this page right now
🌐
Black Duck
blackduck.com › content › dam › black-duck › en-us › reports › bsimm-report.pdf pdf
bsimm-report.pdf
Practice. A grouping of BSIMM activities. The SSF is · organized into 12 practices, three in each of four domains.
🌐
Codific
codific.com › home › appsec › bsimm (building security in maturity model): a complete guide
BSIMM (Building Security In Maturity Model): A Complete Guide - Codific
September 2, 2025 - The Building Security In Maturity Model (BSIMM) operates as an observational framework designed to evaluate and improve an organization’s software security initiatives. At its core, BSIMM defines a Software Security Framework (SSF) of 12 practices across four domains.
🌐
Scribd
scribd.com › document › 404136030 › bsimm8-pdf
BSIMM Version 8: Software Security Insights | PDF | Software Testing | Penetration Test
The document summarizes the Building ... security practices across organizations. It presents the BSIMM8 model based on data from 109 software security initiatives. The BSIMM can be used by organizations to measure their own initiatives and identify goals and additional activities. High maturity initiatives perform numerous activities across all 12 practices ...
🌐
SEI
resources.sei.cmu.edu › asset_files › Podcast › 2016_016_100_450816.pdf pdf
Copyright 2016 by Carnegie Mellon University
the first time healthcare organizations have been part of the BSIMM data set, can you talk · about the significance of that and possibly why compliance regulations like HIPAA haven't ... Gary McGraw: Sure. Regulation and compliance is very tricky. And it's important to talk about. And in fact, one of the practices, one of the 12 practices in the BSIMM, is about compliance
🌐
Checkmarx
checkmarx.com › blog › understanding-the-development-best-practices-landscape-for-modern-secure-application-development
Understanding the Development Best Practices Landscape for Modern Secure Application Development - Checkmarx.com
November 22, 2025 - BSIMM collects information from around 128 firms spanning several business categories. The core of the BSIMM framework consists of 122 tasks divided into 12 practices that are organized into four domains:
🌐
Apothecaryshed
apothecaryshed.com › wp-content › uploads › 2025 › 09 › bsimm.pdf pdf
Building Security In Maturity Model
he Building Security In Maturity Model (BSIMM) described in this document is designed to help you understand
🌐
Software Engineering Institute
sei.cmu.edu › documents › 4687 › 2010_016_102_67841.pdf pdf
CERT'S PODCASTS: SECURITY FOR BUSINESS LEADERS: SHOW NOTES
It describes observed practice but does not recommend what organizations ... BSIMM is available for anyone to use under the Creative Commons license and is available for download from the · BSIMM web site. BSIMM is primarily intended for people who are leading a software security group or initiative ... The BSIMM Software Security Framework (SSF) comprises 12 practices that represent aggregations of 109 observed
🌐
Synopsys
synopsys.com › blogs › software-security › bsimm-software-security-activities.html
Top 5 BSIMM Software Security Activities for Trustworthy Software | Black Duck Blog
October 6, 2021 - Those activities are grouped into 12 practices that are, in turn, grouped into 4 domains: governance, intelligence, secure software development life cycle (SSDL) touchpoints, and deployment.