{"id":193,"date":"2021-04-27T10:25:22","date_gmt":"2021-04-27T02:25:22","guid":{"rendered":"https:\/\/choson_steven.lifenet.com.tw\/?p=193"},"modified":"2023-03-29T16:57:40","modified_gmt":"2023-03-29T08:57:40","slug":"owasp-samm","status":"publish","type":"post","link":"https:\/\/choson.lifenet.com.tw\/?p=193","title":{"rendered":"OWASP SAMM"},"content":{"rendered":"\n<p><strong>\u4ec0\u9ebc\u662fOWASP SAMM\uff1f<\/strong><br>\u4ee5\u4e0b\u662fOWASP SAMM\u7684\u6458\u8981 \uff1a<br>. SAMM\u4ee3\u8868\u8edf\u9ad4\u4fdd\u969c\u6210\u719f\u5ea6\u6a21\u578b\u3002<br>. \u6211\u5011\u7684\u4f7f\u547d\u662f\u70ba\u6240\u6709\u985e\u578b \u7684\u7d44\u7e54\u63d0\u4f9b\u4e00\u7a2e\u6709\u6548\u4e14\u53ef\u8861\u91cf\u7684\u65b9\u6cd5\uff0c \u4ee5\u5206\u6790\u548c\u6539\u5584\u5176 \u8edf\u9ad4\u5b89\u5168\u72c0\u6cc1\u3002<br>. \u6211\u5011\u60f3\u901a\u904e\u6211\u5011\u7684\u81ea\u6211\u8a55\u4f30\u6a21\u578b\u4f86\u63d0\u9ad8\u8a8d\u8b58\u4e26\u6559\u80b2\u7d44\u7e54\u5982\u4f55\u8a2d\u8a08\uff0c\u958b\u767c\u548c\u90e8\u7f72\u5b89\u5168\u8edf\u4ef6\u3002<br>. SAMM\u652f\u6301 \u5b8c\u6574\u7684\u8edf\u9ad4\u751f\u547d\u9031\u671f\uff0c \u4e26\u4e14\u8207 \u6280\u8853\u548c\u904e\u7a0b\u7121\u95dc\u3002<br>. \u6211\u5011\u5efa\u7acb\u4e86SAMM\uff0c\u4f7f\u5176\u672c\u8cea\u4e0a\u5177\u6709\u767c\u5c55\u6027\u548c\u98a8\u96aa\u9a45\u52d5\u6027\uff0c\u56e0\u70ba\u6c92\u6709\u4e00\u7a2e\u9069\u7528\u65bc\u6240\u6709\u7d44\u7e54\u7684\u65b9\u6cd5\u3002<\/p>\n\n\n\n<p><strong>SAMM\u6210\u719f\u5ea6\u7d1a\u5225<\/strong><br>SAMM\u5c07\u4e09\u500b\u6210\u719f\u5ea6\u7d1a\u5225\u5b9a\u7fa9\u70ba\u76ee\u6a19\u3002<br><img decoding=\"async\" src=\"https:\/\/ithelp.ithome.com.tw\/upload\/images\/20210427\/20132160HXdkoxVYeY.png\" alt=\"https:\/\/ithelp.ithome.com.tw\/upload\/images\/20210427\/20132160HXdkoxVYeY.png\"><br>-SAMM\u6a21\u578b\u7d50\u69cb<\/p>\n\n\n\n<p><strong>OWASP SAMM\u6a21\u578b2.0<\/strong><br>SAMM\u662f\u4e00\u7a2e\u898f\u7bc4\u6027\u6a21\u578b\uff0c\u662f\u4e00\u7a2e\u6613\u65bc\u4f7f\u7528\uff0c\u5b8c\u5168\u5b9a\u7fa9\u4e14\u53ef\u6e2c\u91cf\u7684\u958b\u653e\u6846\u67b6\u3002\u5373\u4f7f\u5c0d\u65bc\u975e\u5b89\u5168\u4eba\u54e1\uff0c\u89e3\u6c7a\u65b9\u6848\u8a73\u7d30\u4fe1\u606f\u4e5f\u5f88\u5bb9\u6613\u9075\u5faa\u3002\u5b83\u53ef\u5e6b\u52a9\u7d44\u7e54\u5206\u6790\u5176\u7576\u524d\u7684\u8edf\u4ef6\u5b89\u5168\u6027\u5be6\u8e10\uff0c\u6309\u5b9a\u7fa9\u7684\u8fed\u4ee3\u69cb\u5efa\u5b89\u5168\u6027\u7a0b\u5e8f\uff0c\u986f\u793a\u5b89\u5168\u6027\u5be6\u8e10\u7684\u9010\u6b65\u6539\u9032\uff0c\u5b9a\u7fa9\u548c\u8a55\u4f30\u8207\u5b89\u5168\u6027\u76f8\u95dc\u7684\u6d3b\u52d5\u3002<br>\u5b9a\u7fa9SAMM\u6642\u8981\u8003\u616e\u5230\u9748\u6d3b\u6027\uff0c\u4ee5\u4fbf\u4f7f\u7528\u4efb\u4f55\u958b\u767c\u98a8\u683c\u7684\u5c0f\u578b\uff0c\u4e2d\u578b\u548c\u5927\u578b\u7d44\u7e54\u90fd\u53ef\u4ee5\u81ea\u5b9a\u7fa9\u548c\u63a1\u7528\u5b83\u3002\u5b83\u63d0\u4f9b\u4e86\u4e00\u7a2e\u65b9\u6cd5\uff0c\u53ef\u4ee5\u4e86\u89e3\u60a8\u7684\u7d44\u7e54\u5728\u5be6\u73fe\u8edf\u4ef6\u4fdd\u8b49\u7684\u904e\u7a0b\u4e2d\u6240\u8655\u7684\u4f4d\u7f6e\uff0c\u4e26\u4e86\u89e3\u70ba\u9054\u5230\u4e0b\u4e00\u500b\u6210\u719f\u6c34\u5e73\u800c\u5efa\u8b70\u63a1\u53d6\u7684\u63aa\u65bd\u3002<br>SAMM\u4e26\u4e0d\u5805\u6301\u8981\u6c42\u6240\u6709\u7d44\u7e54\u5728\u6bcf\u500b\u985e\u5225\u4e2d\u90fd\u9054\u5230\u6700\u5927\u6210\u719f\u5ea6\u3002\u6bcf\u500b\u7d44\u7e54\u90fd\u53ef\u4ee5\u78ba\u5b9a\u6700\u9069\u5408\u548c\u9069\u61c9\u6bcf\u500b\u5b89\u5168\u5be6\u8e10\u7684\u76ee\u6a19\u6210\u719f\u5ea6\u7d1a\u5225<br>\u8cc7\u6599\u4f86\u6e90\uff1a<a href=\"https:\/\/github.com\/OWASP\/samm\/blob\/master\/Supporting%20Resources\/v2.0\/OWASP-SAMM-v2.0.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP SAMM 2.0<\/a><\/p>\n\n\n\n<p><strong>SAMM\u7684\u7531\u4f86<\/strong><br>\u8edf\u4ef6\u4fdd\u969c\u6210\u719f\u5ea6\u6a21\u578b\uff08SAMM\uff09\u6700\u521d\u662f\u7531\u7368\u7acb\u8edf\u4ef6\u5b89\u5168\u9867\u554fPravir Chandra\uff08chandra-at-owasp-dot-org\uff09\u958b\u767c\uff0c\u8a2d\u8a08\u548c\u7de8\u5beb\u7684\u3002\u901a\u904eFortify Software\uff0cInc.\u7684\u8cc7\u52a9\uff0c\u53ef\u4ee5\u5275\u5efa\u7b2c\u4e00\u7a3f\u3002\u76ee\u524d\uff0c\u6b64\u6587\u4ef6\u662f\u901a\u904ePravir Chandra\u9818\u5c0e\u7684OpenSAMM\u9805\u76ee\u9032\u884c\u7dad\u8b77\u548c\u66f4\u65b0\u7684\u3002\u5f9eSAMM\u7684\u6700\u521d\u767c\u884c\u7248\u958b\u59cb\uff0c\u8a72\u9805\u76ee\u5df2\u6210\u70baOpen Web Application Security Project\uff08OWASP\uff09\u7684\u4e00\u90e8\u5206\u3002<br>\u8cc7\u6599\u4f86\u6e90\uff1a<a href=\"https:\/\/www.opensamm.org\/about\/\" target=\"_blank\" rel=\"noreferrer noopener\">OpenSAMM<\/a><\/p>\n\n\n\n<p><strong>Pravir Chandra\uff08\u5f37\u5316\u8edf\u9ad4\uff09<\/strong><br>Pravir Chandra\u662fFortify\u6230\u7565\u670d\u52d9\u7e3d\u76e3\uff0c\u4ed6\u8207\u5ba2\u6236\u5408\u4f5c\u5efa\u7acb\u548c\u512a\u5316\u8edf\u4ef6\u5b89\u5168\u4fdd\u8b49\u7a0b\u5e8f\u3002Pravir\u4ee5\u5176\u5728\u8edf\u4ef6\u5b89\u5168\u6027\u548c\u4ee3\u78bc\u5206\u6790\u65b9\u9762\u7684\u5c08\u696d\u77e5\u8b58\u4ee5\u53ca\u5f9e\u696d\u52d9\u89d2\u5ea6\u6230\u7565\u6027\u5730\u61c9\u7528\u6280\u8853\u77e5\u8b58\u7684\u80fd\u529b\u800c\u5728\u696d\u754c\u7372\u5f97\u5ee3\u6cdb\u8a8d\u53ef\u3002\u5728\u52a0\u5165Fortify\u4e4b\u524d\uff0c\u4ed6\u662fCigital\u7684\u9996\u5e2d\u9867\u554f\uff0c\u5728\u90a3\u88e1\u4ed6\u9818\u5c0e\u4e86\u300a\u8ca1\u5bcc\u300b 500\u5f37\u516c\u53f8\u7684\u5927\u578b\u8edf\u4ef6\u5b89\u5168\u8a08\u5283\u3002\u5728\u88abFortify Software\u6536\u8cfc\u4e4b\u524d\uff0cPravir\u9084\u662fSecure Software\uff0cInc.\u7684\u806f\u5408\u5275\u59cb\u4eba\u517c\u9996\u5e2d\u5b89\u5168\u67b6\u69cb\u5e2b\u3002\u4ed6\u7684\u66f8\u300a\u4f7f\u7528OpenSSL\u7684\u7db2\u7d61\u5b89\u5168\u300b\u662f\u6709\u95dc\u901a\u904e\u52a0\u5bc6\u548c\u5b89\u5168\u901a\u4fe1\u4fdd\u8b77\u8edf\u4ef6\u61c9\u7528\u7a0b\u5e8f\u7684\u71b1\u9580\u53c3\u8003\u3002\u4ed6\u7684\u5404\u7a2e\u7279\u6b8a\u9805\u76ee\u7d93\u9a57\u5305\u62ec\u8207\u958b\u653eWeb\u61c9\u7528\u7a0b\u5e8f\u5b89\u5168\u6027\u9805\u76ee\uff08OWASP\uff09\u57fa\u91d1\u6703\u4e00\u8d77\u5275\u5efa\u548c\u9818\u5c0e\u958b\u653e\u8edf\u4ef6\u4fdd\u8b49\u6210\u719f\u5ea6\u6a21\u578b\uff08OpenSAMM\uff09\u9805\u76ee\u3002\u6b64\u5916\uff0c\u666e\u62c9\u7dad\u723e\u76ee\u524d\u9084\u662fOWASP\u5168\u7403\u9805\u76ee\u59d4\u54e1\u6703\u7684\u6210\u54e1\u3002<br>\u8cc7\u6599\u4f86\u6e90\uff1a<a href=\"https:\/\/resources.sei.cmu.edu\/library\/author.cfm?authorid=35212\" target=\"_blank\" rel=\"noreferrer noopener\">CMU-SEI<\/a><\/p>\n\n\n\n<p>OWASP SAMM\u7248\u672c<br>.&nbsp;<a href=\"https:\/\/owaspsamm.org\/blog\/2020\/01\/31\/samm2-release\/\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP SAMM\u7248\u672c2 \u2013\u516c\u958b\u767c\u5e03<\/a><br>.&nbsp;<a href=\"https:\/\/owasp.org\/2020\/02\/11\/SAMM-v2\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP SAMM v2.0\u65bc2020\u5e742\u670811\u65e5\u661f\u671f\u4e8c\u767c\u5e03<\/a><br>.&nbsp;<a href=\"https:\/\/www.opensamm.org\/2017\/04\/owasp-samm-v1-5-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP SAMM v1.5\u767c\u5e03\uff0c2017\u5e744\u670813\u65e5<\/a><br>.&nbsp;<a href=\"https:\/\/www.opensamm.org\/2016\/04\/owasp-sammv1-1-available\/\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP SAMM v1.1\u767c\u5e03\uff0c2016\u5e743\u670816\u65e5<\/a><br>.&nbsp;<a href=\"https:\/\/www.opensamm.org\/2009\/03\/samm-10-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">OpenSAMM\u7684\u539f\u59cb\u7248\u672c\uff0c2009\u5e743\u670825\u65e5<\/a><\/p>\n\n\n\n<p>\u53c3\u8003<br>.&nbsp;<a href=\"https:\/\/en.wikipedia.org\/wiki\/Maturity_model\" target=\"_blank\" rel=\"noreferrer noopener\">\u6210\u719f\u5ea6\u6a21\u578b<\/a><br>.&nbsp;<a href=\"https:\/\/owasp.org\/2020\/02\/11\/SAMM-v2\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP SAMM v2.0\u767c\u5e03<\/a><br>.&nbsp;<a href=\"https:\/\/www.opensamm.org\/about\/\" target=\"_blank\" rel=\"noreferrer noopener\">OpenSAMM\u9805\u76ee<\/a><\/p>\n\n\n\n<p>\u8cc7\u6599\u4f86\u6e90\uff1a\u00a0<a rel=\"noreferrer noopener\" href=\"https:\/\/wentzwu.com\/2021\/03\/03\/owasp-samm\/\" target=\"_blank\">Wentz Wu \u7db2\u7ad9<\/a><\/p>\n\n\n\n<p>PS:\u6b64\u6587\u7ae0\u7d93\u904e\u4f5c\u8005\u540c\u610f\u520a\u767b \u4e26\u4e14\u6388\u6b0a\u53ef\u4ee5\u7ffb\u8b6f\u6210\u4e2d\u6587<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4ec0\u9ebc\u662fOWASP SAMM\uff1f\u4ee5\u4e0b\u662fOWASP SAMM\u7684\u6458\u8981 \uff1a. SAMM\u4ee3\u8868\u8edf\u9ad4\u4fdd\u969c\u6210\u719f\u5ea6\u6a21\u578b\u3002. \u6211\u5011\u7684 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":true,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-193","post","type-post","status-publish","format-standard","hentry","category-cisspcertified-information-systems-security-professional"],"_links":{"self":[{"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/193","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=193"}],"version-history":[{"count":2,"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/193\/revisions"}],"predecessor-version":[{"id":2896,"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/193\/revisions\/2896"}],"wp:attachment":[{"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=193"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=193"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/choson.lifenet.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}