Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

9/20/2017
09:25 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Benchmarking Critical Exercise in Early Stages of Software Security: BSIMM8

Latest iteration of the building security in maturity model shows more organizations jumpstarting their software security initiatives with assessments and improving over time.

MOUNTAIN VIEW, Calif., Sept. 20, 2017 -- Synopsys, Inc. (Nasdaq:  SNPS) today released BSIMM8, the latest version of a leading software security maturity model, which is based on real-world data and helps organizations plan, execute, and measure their software security initiatives (SSIs). The eighth iteration of the Building Security in Maturity Model (BSIMM) is based on data collected from the largest community to date. BSIMM8 shows that software security is becoming a critical business priority with more organizations benchmarking their efforts early in their SSI lifecycle and using the results strategically to improve their risk posture over time. To download the report, visit https://www.bsimm.com/download.html.

"With the rise of widely distributed and increasingly disruptive attacks targeting vulnerable software, we're seeing a shift from the reactive 'penetrate and patch' approach toward more proactive strategies that empower organizations to build secure software systematically from the ground up," said Dr. Gary McGraw, vice president of security technology at Synopsys. "Organizations are beginning to understand that they can mitigate risk more effectively by establishing a software security initiative, assessing their strengths and weaknesses early on through instruments like the BSIMM, and focusing their efforts on the most appropriate practices and activities."

BSIMM8 includes data collected from 109 firms and describes the work of 4,769 software security professionals. Their work guides and maximizes the security efforts of almost 300,000 developers across approximately 95,000 applications. BSIMM8 firms represent industry verticals including financial services, independent software vendors (ISVs), cloud, healthcare, Internet of Things (IoT), and insurance.

Key findings from the BSIMM8 study:

  • Organizations use the BSIMM to jumpstart their SSIs. BSIMM8 introduces firms in the early stages of the SSI lifecycle, as evidenced by a slight decrease in the average maturity score1 (33.1, down from 33.9 in BSIMM7) and average software security group age (3.88 years, down from 3.94 in BSIMM7) of the BSIMM population. SSI benchmarking is one of the pivotal first steps in the software security journey.
  • BSIMM firms mature over time. Firms that have participated in multiple BSIMM assessments show a clear trend of improvement, with scores increasing by an average of 10.3, or 33.4 percent. Benchmarking is an effective exercise in guiding organizations along the optimal path toward building secure software consistently.
  • Maturity varies by industry. Each industry prioritizes certain activities over others, and every industry and individual organization has a different path toward building security in. On average, cloud, financial services, and ISV firms are more mature than firms in healthcare, IoT, and insurance. Financial services and cloud firms have notably higher scores in compliance and policy practices, while IoT firms have the most mature software environment practices.

According to Gartner, "Application security requires a structured, programmatic approach to deal with the seeming chaos of new technology and an evolving threat landscape. A successful application security program must be a balanced combination of people, process, and technology."2

The BSIMM observes firms that have established real software security initiatives, quantifying the occurrence of 113 activities to show the common ground shared by many initiatives as well as the variations that make each initiative unique. The BSIMM data show that high-maturity initiatives are well-rounded—carrying out numerous activities in all 12 of the practices described by the model. Organizations can use the BSIMM to compare initiatives and determine which additional activities might be useful.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3154
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
CVE-2019-17190
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
CVE-2014-8161
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2014-9481
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
CVE-2015-0241
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...