Real-world data on software security initiatives

Cigital and Fortify Software released the Building Security In Maturity Model for Europe or “BSIMM Europe,” an application of the industry’s first-ever set of benchmarks for developing and growing an enterprise-wide software security program to the European market.

BSIMM Europe illuminates the software security practices of some of the most advanced organizations in Europe, including Nokia, SWIFT, Standard Life, Telecom Italia, and Thomson Reuters, and four companies that chose to remain anonymous.

Released in March 2009, the original BSIMM study was based on in-depth interviews with leading enterprises including Adobe, EMC, Google, Microsoft, QUALCOMM, Wells Fargo, and Depository Trust & Clearing Corporation (DTCC). BSIMM Europe describes a set of activities practiced by nine European firms chosen from among the 56 most successful software security initiatives in the world. Unlike some industry standards, BSIMM is a structured set of practices based on real-world data rather than philosophy and ideas. BSIMM provides insight on what successful organizations actually do to build security into their software and mitigate the business risk associated with insecure applications.

“Nokia’s participation in the BSIMM Europe project reflects a mutual, ongoing interest in setting, updating, and maintaining the highest standards in software security,” said Janne Uusilehto, Head of Product Security, Nokia. “The insights gained from the BSIMM project will doubtlessly further the definition of standards, which will not only serve as critical tools for measuring and comparing, but will also for enable the evolution of software security initiatives.”

“Software security is a world-wide phenomenon. We are very grateful to the European participants in the BSIMM Europe study, and for the chance to compare and contrast large-scale software security initiatives in different geographies,” said Dr. Gary McGraw, CTO of Cigital. “Using BSIMM, an organization can determine where its software security initiative stands, figure out how to evolve its initiative strategically, or even get a brand new initiative off the ground. BSIMM is a tool for identifying realistic business goals and implementing those technical software security activities that make the most sense for an organization.”

“Software is essential to business throughout the world, and at the same time the threat to that software is at an all-time high,” said Dr. Brian Chess, co-founder and Chief Scientist of Fortify Software. “European businesses need software that doesn’t leak millions of identity records, gin up huge legal liabilities, or allow secrets to fall into the wrong hands.”

The authors collected data on each European firm’s software security activities for strategy and metrics, training, standards and requirements, security testing, code review, etc., and uncovered a number of common themes among each of the successful initiatives, including:

  • In general, European approaches to software security have many activities in common with US initiatives. European software security approaches place more emphasis on process than do their US counterparts, and also emphasize privacy to a greater extent.
  • We observed eleven activities that all European firms practice, including publishing a process, identifying gates, creating secure coding standards, and identifying PII obligations.
  • There are fifteen BSIMM activities (of 110) not observed in Europe at all.