GitHub - scadastrangelove/asamm: Agentic SAMM - An OWASP SAMM Extension for AI-Driven Development

Agentic SAMM is an extension to the OWASP Software Assurance Maturity Model (SAMM) for AI‑driven development. It addresses security assurance for systems where context (documents, issues, tool descriptions, retrieved web pages, CI logs) becomes part of the control plane, tool calls are security boundaries, and the development workflow itself is an attack surface. The framework introduces a threat taxonomy organized by entry points (not consequences), a two‑path adoption model (migration for existing SAMM programs / greenfield for new builds), 21 controls across five SAMM function families (Governance, Design, Implementation, Verification, Operations) with evidence‑based maturity levels (L1/L2/L3), and a structured audit methodology with three audit tracks. Current version is v0.3.0‑draft (May 2026), with recent additions including trust grading, delegation calibration, two new controls (AG‑04 Inter‑Agent Trust Protocol, AI‑06 Agent Identity and Credential Governance), delegated evidence rules, and bounded severity guidelines. The framework is licensed under CC BY‑SA 4.0, is authored by Sergey Gordeychik (CyberOK, 2026), and has 9 stars and 2 forks. It positions itself alongside the OWASP Top 10 for Agentic Applications and the OWASP AI Testing Guide. 

https://github.com/scadastrangelove/asamm

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

SecObserve: Simplified Vulnerability and License Management for CI/CD Pipelines

Top Post-Quantum Cryptography Solutions and Vendors Ranked for Quantum-Safe Security