An initial evaluation of CAMM was conducted by Julian Hohm as part of his master’s thesis together with a partner company.
Semi-structured interviews were conducted with two inhouse-experts (one Security Officer and one Consultant Systemsoftware Architect) with regard to the comprehensibility of CAMM. Both experts confirmed its comprehensibility and appreciated the sound structure. On the other hand, both assume that CAMM must be brought into use so that more experience can be gained with the model. They assume that especially level 4 requirements may be be extended or modified.
We want to hear about your experiences using CAMM in practice.