---
title: "BSIMM"
date: "2016-04-11T10:39:15+00:00"
url: "https://checkmarx.com/chapter-six/bsimm/"
---

# BSIMM

Build Security in Maturity Model (BSIMM) is a software security measurement framework that helps organizations gauge their software security and build a maturity model based on actual data gathered from real-world software security initiatives. What is inside the BSIMM? It describes 112 activities that have been organized in 12 different practices according to a [software security framework](https://informit.com/articles/article.aspx?p=1271382). A scorecard is eventually generated.’

**Additional Reading:**

- [Building Security in Maturity Model (BSIMM)](https://bsimm.com/)
- Read more about BSIMM on CheckMarx blog: [Building Secure Applications: How Mature Are You?](https://checkmarx.com/blog/)
- CheckMarx solution for compliance and risk management – [Click Here](https://checkmarx.com/appsec-services/).

**Continue to [AppSec Beginners Guide: OpenSAMM](https://checkmarx.com/chapter-six/opensamm/)**
