Skip to content

Conversation

@johnnyrenaissance
Copy link

This change includes updates to the GitHub Install.md and Readme.md docs for updated usage as well as reformating so the information isn't in a single long page.

Also updated the About Us and Usage pages in the DSOMM app to be consistent with latest usage information. Seperated the usage and install instructions from the About Us page and kept them solely in the Usage page.

@johnnyrenaissance johnnyrenaissance marked this pull request as draft January 9, 2026 23:18
@johnnyrenaissance johnnyrenaissance marked this pull request as ready for review January 9, 2026 23:20

[![Timo Pagel IT-Consulting](https://raw.githubusercontent.com/DefectDojo/Documentation/master/doc/img/timo-pagel-logo.png)](https://pagel.pro)

[![Apprio Inc](https://github.com/wurstbrot/DevSecOps-MaturityModel/raw/master-old/assets/images/Apiiro_black_logo.png)](https://apiiro.com/)
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OWASP sponsors in the past donated money to a project with the benefit of getting listed. I am not sure at which time we are allowed to remove them. Therefore, they need to stay.
Heroku sponsored hosting once, now I am paying from my own money, so they can be removed.

@wurstbrot
Copy link
Collaborator

To remind myself how the html will look like in the application:
image

Copy link
Collaborator

@wurstbrot wurstbrot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @johnnyrenaissance ,
thank you for your valuable contributions.

Please let us know how you want to continue (e.g. you perform changes or we merge and I adjust).

I think we should remove duplicated content. As said, you can do that now or I do it afterwards.

- How do we systematically improve security without slowing delivery?

To do that, you need to install your own local DSOMM application.
The model focuses on **concrete, technical activities** that integrate security directly into DevOps workflows such as CI/CD pipelines, containerization, infrastructure provisioning, and testing.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

From my point of view DSOMM also offers process related activities like threat modeling. That could be mentioned in a sentence afterwards.

- Written primarily by security specialists for security programs
- Takes a broad, organization-wide perspective

**DSOMM**:
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

-Easy to tailor

**DSOMM**:
- Focuses on embedding security directly into DevOps workflows
- Operates lower in the technical stack (pipelines, containers, tooling)
- Provides concrete implementation guidance for engineering teams
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Provides overviews to guide technical management decisions


For organizations that require evidence (e.g., for CISOs or auditors), DSOMM supports attaching evidence directly in YAML files.

Evidence is defined in `generated.yaml` or `team-progress.yaml` files using the `teamsEvidence` attribute. Markdown is supported, and multi-line evidence can be provided using YAML block syntax.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we do not need to support old versions.
generated.yaml can be removed. correct @vbakke ?

@@ -1,103 +1,391 @@
# Install DSOMM
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we do not need to keep redundant parts.
E.g. Running DSOMM as a Docker Container (Recommended) or the SAMM overview

@wurstbrot wurstbrot requested a review from vbakke January 10, 2026 09:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants