Capability maturity levels – Continuous security
Figure 4.7 presents a continuous security CMM with five levels, each addressing aspects of people, process, technology, and metrics:
- Level 1: Manual & Unmeasured (Chaos) – Highlights limited security awareness and collaboration, ad hoc processes, basic tools, and minimal metrics:
- People: Limited communication about quality. Reactive approach.
- Process: Manual quality checks. No integration into the development life cycle.
- Technology: Disparate, non-integrated quality tools.
- Metrics: Few, if any, quality metrics. Minimal tracking.
- Level 2: Continuous Integration (CI) – Some collaboration in security, initial integration of security checks during CI, basic automated tools, and basic metrics for vulnerability identification:
- People: Some collaboration between development and QA teams on quality.
- Process: Automated quality checks integrated into CI.
- Technology: Basic automated testing tools integrated with CI...