Episode 205: Secure by Design — Now Updated for AI

 

 

In episode 205 of Cybersecurity Where You Are, Tony Sager speaks with Phyllis Lee, VP of SBP Content Development at the Center for Internet Security®(CIS®), and Steve Lipner, Executive Director of SAFECode. Together, they discuss how updated guidance from CIS and SAFECode gives concrete guidance on what artificial intelligence (AI) means for your Secure by Design process.

Here are some highlights from our episode:

  • 02:17. A refresher on making Secure by Design digestible for end organizations
  • 02:57. Distillation and prescriptive guidance: The value provided by CIS
  • 06:53. An overview of Butler Lampson's "Gold Standard of Security"
  • 07:03. How a shift in approach to Secure by Design led to the founding of SAFECode
  • 09:42. The importance of verification requirements for what developers have done
  • 12:54. A product of CIS pragmatism: Prioritization relative to the development environment
  • 20:06. Artifacts as evidence of secure software development at work
  • 30:15. How the updated document provides guidance around AI
  • 30:45. What AI creates instead of new classes of vulnerabilities

Resources

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.