The Application Security Maturity (ASM) model was developed based on over 10 years of data analyzing how organizations approach software security. The ASM model plots organizations on a grid based on their investments in tools/technology and people/processes. Most organizations follow a typical maturity curve through three stages: 1) The Panic Scramble, where organizations react to events with tool purchases but see little impact. 2) The Pit of Despair, where organizations reduce tool usage and ponder next steps. 3) Security as a Core Business Process, where security is integrated throughout the organization with balanced investments in tools/technology and people/processes. The ASM model can help organizations understand their current maturity level and guide investments to accelerate progress along the