StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 8: Software development security

Maturity models: CMM, SAMM; operations, maintenance and change management

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Maturity models measure how well developed and repeatable an organization's processes are, and they give a roadmap for improvement. For software security, the exam focuses on the Capability Maturity Model (CMM) lineage and on the OWASP Software Assurance Maturity Model (SAMM), and it links them to the discipline of operating and changing software safely after release. The core idea is that mature, defined and measured processes produce more predictable, higher-quality and more secure software than heroic individual effort.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan