A CISO is comparing BSIMM with the OWASP Software Assurance Maturity Model (SAMM) before recommending one to the board as the basis for a software security improvement programme. Which statement BEST describes the difference in how the two models are constructed?
- ABSIMM measures application runtime behaviour during penetration tests, while SAMM measures static code quality through automated tooling.
- BBSIMM is a descriptive model derived from observed activities across participating firms, whereas SAMM is a prescriptive framework that defines target practices and maturity levels. Correct
- CBoth models are prescriptive, but BSIMM is aligned to ISO 27034 while SAMM is aligned to NIST SP 800-53.
- DSAMM is a closed proprietary benchmark sold to member firms, whereas BSIMM is released openly under a Creative Commons licence.
Why A is wrong: Neither model is a testing tool. Both describe organisational software security programmes rather than runtime or static analysis findings. A candidate who confuses maturity models with assessment tools picks this.
Why B is correct: BSIMM is explicitly an observational instrument: its content is a measurement of what real firms actually do, summarised into a software security framework. SAMM, by contrast, prescribes business functions, security practices, and maturity levels an organisation should aim for. This is the textbook distinction.
Why C is wrong: BSIMM is descriptive, not prescriptive, and neither model is formally aligned to those standards in the way described. The framework attributions in this option are invented and a candidate should reject them.
Why D is wrong: This reverses the openness story: SAMM is the openly published OWASP model, and BSIMM publishes its report openly while drawing data from participating firms. Candidates relying on vague impressions of vendor backing pick this.