Revised guide offers "measuring stick" for software security

Dark Reading Staff, Dark Reading

September 29, 2011

1 Min Read

Cigital this week announced the third major release of its Building Security In Maturity Model (BSIMM) study.

BSIMM3 is a multi-year study of real-world software security initiatives, based on in-depth measurement of major enterprises. The BSIMM3 study provides insight into forty-two software security initiatives, identifying activities used by these organizations to effectively plan, structure, and execute the evolution of a software security initiative.

The current release includes 109 thoroughly updated activity descriptions and a longitudinal study describing the evolution of eleven of the forty-two firms over time.

"We have moved well past discussion of technical bugs and into the meat of how to change the development culture in a sizeable organization, and more importantly, how to measure results objectively," says Gary McGraw, co-author of the study and CTO of Cigital.

The BSIMM3 data set offers 81 distinct measurements of secure software development. The study states that leading firms on average employ two full time software security specialists for every 100 developers.

Have a comment on this story? Please click "Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

About the Author(s)

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights