The Software Security Framework (SSF)

The table below is a clickable version of the Software Security Framework. There are twelve practices organized into four domains. These practices are used to organize the 109 BSIMM activities. Click on a practice to see the “skeleton” or a practice and dig into particular activities. Note that all examples are real examples drawn from field observation.

The Software Security Framework (SSF)
Governance Intelligence SSDL Touchpoints Deployment
Strategy and Metrics Attack Models Architecture Analysis Penetration Testing
Compliance and Policy Security Features and Design Code Review Software Environment
Training Standards and Requirements Security Testing Configuration Management and Vulnerability Management