Skip to main content
Image coming soon

BSIMM Software Security Maturity Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
BSIMM · Building Security In Maturity Model · Evidence & Implementation Kit
Mature your software security initiative with BSIMM, without turning the model into activities yourself.
Every BSIMM practice handed to you as an adopt-ready activity, across governance, intelligence, the secure development lifecycle and deployment, with the evidence the activity is real.
Software-security-mature in a weekend, not a fiscal year.

Here is the honest situation. BSIMM is how the most mature organizations benchmark and grow their software security. It is a descriptive model, twelve practices across governance, intelligence, the secure development lifecycle and deployment, observed from real programs and refreshed every year. Standing up a software security group, the champions, the touchpoints and the deployment practices, and evidencing that the activities are real rather than aspirational, is a program of work, and a software security effort with a policy but no operating activities is exactly where it stalls.

This Kit removes that guesswork. It is every BSIMM practice written as an adopt-ready activity you personalize in a weekend, with the evidence the activity is real.

What you get, the moment you buy

34
Practices as adopt-ready activities. Every BSIMM practice across the four domains, from governance and intelligence through the secure development lifecycle touchpoints and deployment, written so you personalize and run it.
34
Evidence-it-is-real checklists. For each activity, exactly the records that show it operates, plus where software security stalls, so you build a real program not a policy.
1
Software Security Control Matrix, pre-built. Every activity in a working spreadsheet, ready to record maturity level, status and evidence location.
1
Maturity & Readiness Assessment. Score each activity and the workbook returns your software security maturity as a single percentage, and exactly what to build next.

Grounded in the BSIMM (Building Security In Maturity Model), a descriptive, data-driven model of twelve practices across four domains, with the software security group, the SSDL touchpoints and the deployment practices called out. Editable Word and Excel files.

A software security group is the spine
Every mature software security program has a software security group and a network of satellite champions driving the work. BSIMM makes that structure explicit. This Kit builds the software security group, the champions and the practices they run, so your initiative has an owner and momentum, not just a policy.

What one control looks like

This is a governance activity, publishing a software security strategy and metrics. All 34 are built to this depth.

BSIMM-1 Establish a software security group (SSG) GOVERNANCE
Adopt this activity

[Organization] shall stand up a dedicated software security group (SSG) staffed with people whose primary job is software security, giving it a named leader, a funded charter, and executive sponsorship so it can drive the initiative, own the secure SDLC, and act as the internal authority that other roles turn to for guidance.

Maturity note.

BSIMM observes that every mature initiative it studies is anchored by an SSG; this is the foundational commonly-observed activity.

Evidence the activity is real
  • SSG charter document naming leader, reporting line, and executive sponsor
  • Organization chart showing SSG headcount and roles
  • Funding or budget approval records for the software security initiative
  • Meeting minutes where the SSG reports initiative status to leadership
Common finding they raise: Software security work is scattered across engineers as a side duty with no dedicated owner or funded charter.

Why this is not another template pack

  • The evidence is the point. A software security activity you cannot evidence is aspiration. This tells you the records that show it operates and where software security stalls, for every practice.
  • The SSG and the touchpoints built in. The software security group, the satellite champions and the SSDL touchpoints, architecture analysis, code review and security testing, are written into the activities, the spine of a mature program.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. BSIMM complements the NIST SSDF and the PCI Secure SLC, so this work feeds your whole software security program.

Who buys this

Software producers building or maturing a software security initiative, the application security leads who own it, and consultants standing one up. Whether it is a first program or a maturity benchmark, you save time and walk in with the practices and evidence structured.

By the end of the weekend you will have
✓  An adopt-ready activity for all 34 items
✓  A completed software security control matrix
✓  The evidence the activity is real
✓  Your software security group and touchpoints defined
✓  A maturity percentage and a build plan
✓  The stall points designed out

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is BSIMM a standard? No. It is a descriptive, data-driven maturity model that benchmarks observed software security activities. This Kit turns its practices into adopt-ready activities to grow your program.

Does it cover the SSDL touchpoints? Yes. Architecture analysis, code review and security testing are their own control groups.

Does it cover vulnerability management? Yes. The deployment practices, including configuration and vulnerability management and incident response, are built as activities.

What if it is not for me? A 30-day money-back guarantee.

Do not run a software security policy with no activities behind it.
Every BSIMM practice is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and mature your software security this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com