/
Security Assessment Models

Security Assessment Models

As part of preparation for the ONAP Assessment, we are looking at several available Models.  We want to create an assessment model that results in data oriented results and allows us to identify opportunity for improvements across all aspects of ONAP (governance, design, development, quality assurance etc).  Some of the aspects that we need to evaluate are outside the core development team working on a specific software capability and some aspects focus on assessing core software development team's practices.



Ask for reviewers:  please take a look at the models and suggest what may be relevant to ONAP/OSS project and also indicate what assessing criteria should be ONAP wide vs core dev team of a SW capability.  For OWASP SAMM, a spreadsheet is attached, it provides questionnaire and report generating tools.  



Following Assessment Models were presented to SECOM on Tuesday 4/12/2022:



OWASP SAMM model was discussed in details.



Slides are attached:

Model Comparison Slides



OWASP SAMM Assessment tool (spreadsheet)

Related content

PF - ONAP Security Review Questionnaire
PF - ONAP Security Review Questionnaire
More like this
Project Maturity Review for AAA - EXAMPLE-PURPOSES-ONLY
Project Maturity Review for AAA - EXAMPLE-PURPOSES-ONLY
More like this
Project Maturity Review for ONAP Portal
Project Maturity Review for ONAP Portal
More like this
Application Security Documentation Model Template
Application Security Documentation Model Template
More like this
ONAP Security Best Practices.
ONAP Security Best Practices.
More like this
ONAP Security coordination
ONAP Security coordination
More like this