The Building Security In Maturity Model

The Building Security In Maturity Model (BSIMM, pronounced “bee simm”) is designed to help you understand, measure, and plan a software security initiative. The BSIMM was created by observing and analyzing real-world data from thirty leading software security initiatives. The BSIMM can help you determine how your organization compares to other real-world software security initiatives and what steps can be taken to make your approach more effective.

Download the BSIMM document or Use the clickable web-version.

The most important use of the BSIMM is as a measuring stick to determine where your approach to software security currently stands relative to other firms.


For more about the BSIMM, see BSIMM2: Measuring the Emergence of a Software Security Community or the other articles listed under Resources.

BSIMM is licensed under the Creative Commons Attribution-Share Alike 3.0 License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/ or send a letter to Creative Commons, 171 Second Street, Suite 300, San Francisco, California, 94105, USA.