OWASP DevSecOps Maturity Model (DSOMM) - Timo Pagel @OWASPGLOBAL
OWASP DevSecOps Maturity Model (DSOMM) - Timo Pagel  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 3 weeks ago
Achieving an Application Security Program with DSOMM

In this talk, Timo Pagel outlines a practical approach to building and optimizing application security (AppSec) programs for organizations of all sizes. While briefly touching on foundational elements, Timo's presentation focuses on developing and implementing a custom organizational maturity model based on DSOMM that resonates with development and operations teams.

Moving beyond traditional frameworks, Timo will teach attendees get most out of DSOMM by designing tailored models that account for diverse operating environments. The talk provides strategies for avoiding common pitfalls, implementing effective metrics, and creating a scalable AppSec approach adaptable to an organization's evolving needs. Through actionable advice and real-world examples, Timo will offer participants insights applicable to both new and existing AppSec programs.

-

Managed by the OWASP® Foundation
owasp.org
OWASP DevSecOps Maturity Model (DSOMM) - Timo PagelAutomating Security Test Cases Based On ASVS - Aram HovsepyanOWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement analysis - Track 1Uncovering 100k Security ViolationsSupercharge Your APPSEC Program with OWASP - Appdome Consumer Mobile Security Report and OWASP MASVSOWASP Global AppSec EU 2025 Closing CeremonyPractical Software Supply Chain Security Solutions - Robert MarionDay In the Life Of Supply Chain Security ResearcherOWASP VXDF: Is that really vulnerable? Show me the VXDF!Closing the AI Visibility Gap: Why SBOM Alone is No Longer Enough  - Track 1OWASP Global Board of Directors - March 2026 Public MeetingOWASP Global Board of Directors Meeting - June 2025
OWASP Foundation |

OWASP DevSecOps Maturity Model (DSOMM) - Timo Pagel

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER