BSIMM Begin

We are interested in increasing the number of observations covering software security initiatives that are just getting started. To do that, we introduce BSIMM Begin, a Web-based study focused on 40 of the 110 activities covered in the full BSIMM.

Even if your organization is just getting started with a software security initiative, we hope that you will participate in the BSIMM Begin study yourself. Not only will you help make the study more thorough, you’ll also come away with some idea of how your basic software security activities stack up against those practiced by others.

In fact, do what you can to get your friends and colleagues in other companies to take it too. The more data we gather the better off we’ll all be.

Note that BSIMM Begin does not take the place of a full BSIMM assessment in any way. The full study focuses on activities that can be used to measure and compare fairly mature, large-scale software security initiatives. By contrast, BSIMM Begin focuses on new initiatives that are just getting off the ground. BSIMM Begin data will be segregated in a separate set of results and analyzed accordingly. For more about the BSIMM Begin study, see this article.

TAKE THE SURVEY NOW

Who should complete this survey?

This survey is best completed by someone with a working knowledge of the spectrum of software security activities actually being performed within a firm. As you continue to the next page and begin the survey, please remember the following about SurveyMonkey. You will have to run JavaScript and should accept www.surveymonkey.com cookies for the survey to work correctly. Please proceed to the survey when you have about 90 minutes to dedicate to its completion. You will not be able to leave and reenter the survey. Clicking Done on the last page will submit the results. This is contrary to our previous guidance that surveys could be re-entered and we apologize for the mistake.

You are welcome to peruse the survey itself prior to proceeding.

Thanks to CSO Magazine and the SANS Institute for helping with data collection.

CSO SANS Institute