Here is the honest situation. BSIMM is how the most mature organizations benchmark and grow their software security. It is a descriptive model, twelve practices across governance, intelligence, the secure development lifecycle and deployment, observed from real programs and refreshed every year. Standing up a software security group, the champions, the touchpoints and the deployment practices, and evidencing that the activities are real rather than aspirational, is a program of work, and a software security effort with a policy but no operating activities is exactly where it stalls.
This Kit removes that guesswork. It is every BSIMM practice written as an adopt-ready activity you personalize in a weekend, with the evidence the activity is real.
What you get, the moment you buy
Grounded in the BSIMM (Building Security In Maturity Model), a descriptive, data-driven model of twelve practices across four domains, with the software security group, the SSDL touchpoints and the deployment practices called out. Editable Word and Excel files.
What one control looks like
This is a governance activity, publishing a software security strategy and metrics. All 34 are built to this depth.
Why this is not another template pack
- The evidence is the point. A software security activity you cannot evidence is aspiration. This tells you the records that show it operates and where software security stalls, for every practice.
- The SSG and the touchpoints built in. The software security group, the satellite champions and the SSDL touchpoints, architecture analysis, code review and security testing, are written into the activities, the spine of a mature program.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. BSIMM complements the NIST SSDF and the PCI Secure SLC, so this work feeds your whole software security program.
Who buys this
Software producers building or maturing a software security initiative, the application security leads who own it, and consultants standing one up. Whether it is a first program or a maturity benchmark, you save time and walk in with the practices and evidence structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is BSIMM a standard? No. It is a descriptive, data-driven maturity model that benchmarks observed software security activities. This Kit turns its practices into adopt-ready activities to grow your program.
Does it cover the SSDL touchpoints? Yes. Architecture analysis, code review and security testing are their own control groups.
Does it cover vulnerability management? Yes. The deployment practices, including configuration and vulnerability management and incident response, are built as activities.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com