GitHub - scadastrangelove/asamm: Agentic SAMM - An OWASP SAMM Extension for AI-Driven Development
Agentic SAMM is an extension to the OWASP Software Assurance Maturity Model (SAMM) for AI‑driven development. It addresses security assurance for systems where context (documents, issues, tool descriptions, retrieved web pages, CI logs) becomes part of the control plane, tool calls are security boundaries, and the development workflow itself is an attack surface. The framework introduces a threat taxonomy organized by entry points (not consequences), a two‑path adoption model (migration for existing SAMM programs / greenfield for new builds), 21 controls across five SAMM function families (Governance, Design, Implementation, Verification, Operations) with evidence‑based maturity levels (L1/L2/L3), and a structured audit methodology with three audit tracks. Current version is v0.3.0‑draft (May 2026), with recent additions including trust grading, delegation calibration, two new controls (AG‑04 Inter‑Agent Trust Protocol, AI‑06 Agent Identity and Credential Governance), delegated evidence rules, and bounded severity guidelines. The framework is licensed under CC BY‑SA 4.0, is authored by Sergey Gordeychik (CyberOK, 2026), and has 9 stars and 2 forks. It positions itself alongside the OWASP Top 10 for Agentic Applications and the OWASP AI Testing Guide.
Comments
Post a Comment