BSIMM Self-Assessment Example Report

Illustrative sample report based on public BSIMM materials
Illustrative overall indicator
2.23/3.0
This page is a sample report layout that can be adapted for internal self-assessment. It is intentionally written in a board-friendly style with concise observations, prioritized actions, and evidence-oriented language.

Strengths

Gaps

Top priorities

  1. Raise consistency of architecture analysis and attack modeling.
  2. Tighten executive reporting around exposure, exceptions, and overdue critical fixes.
  3. Expand self-service verification patterns without losing quality.

Practice view

DomainPracticeExample ScoreIllustrative Observation
GovernanceStrategy and Metrics2.50Metrics exist for coverage, MTTR, and review gates; board narrative could be tighter.
GovernanceCompliance and Policy2.30Policies are defined and periodically reviewed; evidence automation is partial.
GovernanceTraining2.00Champions network exists but role-based depth varies by org.
IntelligenceAttack Models2.10Threat models exist for crown jewels; adversary simulation is selective.
IntelligenceSecurity Features & Design2.20Reusable authn/authz and logging patterns exist, but crypto guidance needs consolidation.
IntelligenceStandards and Requirements2.40Standards are well documented; enforcement is stronger in modern platforms than legacy.
SSDL TouchpointsArchitecture Analysis2.00Architecture review is effective when triggered, but not all changes are routed through it.
SSDL TouchpointsCode Review2.50Strong review practice with scoped security heuristics and diff-based triage.
SSDL TouchpointsSecurity Testing2.30Tooling is good; manual abuse-case testing is still capacity constrained.
DeploymentPenetration Testing1.90Targeted testing exists for major launches; cadence is below ambition.
DeploymentSoftware Environment2.40Cloud guardrails and runner controls are solid; ephemeral environments need more coverage.
DeploymentConfiguration Management & Vulnerability Management2.20Inventory and SLA tracking are in place; exception debt remains visible.

References