CARVIEW |
Select Language
HTTP/2 200
date: Thu, 09 Oct 2025 09:49:41 GMT
content-type: text/html;charset=utf-8
content-encoding: gzip
x-vhost: blackduck
content-security-policy: default-src 'self' 'unsafe-hashes' 'unsafe-inline' 'unsafe-eval' data: blob: edge.adobedc.net adobedc.demdex.net *.adobe.com *.adobe.io cdn.cookielaw.org assets.adobedtm.com kit.fontawesome.com ka-p.fontawesome.com munchkin.marketo.net adobedc.demdex.net snap.licdn.com *.drift.com js.driftt.com js.zi-scripts.com j.6sc.co geolocation.onetrust.com ipv6.6sc.co c.6sc.co b.6sc.co epsilon.6sense.com px.ads.linkedin.com static.cloud.coveo.com boards.greenhouse.io *.mktoresp.com ws.zoominfo.com job-boards.greenhouse.io api.company-target.com *.org.coveo.com synopsysnonproduction2yln023as.analytics.org.coveo.com *.brighttalk.com brighttalk.com js.zi-scripts.com *.blackduck.com blackduck.com players.brightcove.net *.brightcove.com manifest.prod.boltdns.net *.brightcovecdn.com googletagmanager.com *.googletagmanager.com *.google.com *.google.ca *.google.co.uk google.co.in google.com *.google-analytics.com google-analytics.com googleads.g.doubleclick.net td.doubleclick.net *.googleapis.com *.gstatic.com *.leadspace.com *.clarity.ms *.bing.com *.bing.net *.bing-int.com *.6sc.co *.6sense.co 846-esg-342.mktoutil.com *.youtube.com;
cache-control: max-age=300
expires: Thu, 09 Oct 2025 09:54:41 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
strict-transport-security: max-age=31536000
set-cookie: affinity="293a8b35e9e3dcfe"; Path=/; HttpOnly; secure
x-served-by: cache-bom-vanm7210036-BOM
x-cache: MISS
x-timer: S1760003380.403629,VS0,VS0,VE1230
vary: Accept-Encoding,User-Agent
cf-cache-status: BYPASS
server: cloudflare
cf-ray: 98bcf8263a07b9d7-BLR
BSIMM Software Security Assessment Report | Black Duck
BSIMM15 Report
Detailed analysis of the top software security initiatives.
We analyzed the software security practices of 121 organizations to see how they secure their applications. Our annual report identifies key trends and activities for you to benchmark your own program against. Learn how top companies are addressing trends such as
- "Shift everywhere" testing and integrations
- AI adoption in software development
- Software supply chain risk management
- Cloud security efforts
- Other considerations for improving software security
Download the latest BSIMM
What's Inside
Building Security in Maturity Model (BSIMM) is the world’s leading model for software security initiatives. Built on 15-plus years of real-world analysis, BSIMM offers you the best measuring stick against your peers across a variety of industries.
BSIMM15, published in January 2025, provides the latest analysis of 121 organizations. It reveals:
- The top 10 software security activities being used today
- Notable growth in the creation and use of Software Bills of Materials (SBOMs)
- New focus on supply chain security, open collaboration, and “shift everywhere” testing and integrations
- New standards to control and guide AI adoption in software development
- Key actions leading organizations are taking to evolve their application security programs
