Lessons Learned with the Systems Security Engineering Capability Maturity Model

This paper describes the principles upon which the SSECMM is based, the structure of the model, and its use in appraisals. The paper discusses ex-periences in developing and piloting the model and method, and comments on the potential for using the model in process-based assurance.