Secure by Design: Turning Software Security into Measurable Practice

CIS Controls

Thursday, October 8, 2026 | 2:00 PM ET

Security claims are easy to make. Proving them is another matter entirely.

In this webinar, we'll explore the updated Secure by Design v1.1: A Guide to Assessing Software Security Practices, the latest release from CIS and SAFECode. The guide helps organizations move beyond self-attestation and demonstrate real, evidence-based security practices throughout the software development lifecycle.

As government agencies, regulators, and customers increasingly expect software manufacturers to take ownership of security outcomes, the need to show, not just tell, has never been greater. Version 1.1 addresses that challenge with refined assessment approaches, expanded guidance for AI-enabled systems, and alignment with today's evolving regulatory landscape, including CISA Secure by Design initiatives, NIST SSDF, Executive Order 14306, and the EU Cyber Resilience Act.

What We'll Cover:

  • What's new in v1.1 and why these updates matter now
  • How AI fits into a Secure by Design program and the risks of assuming AI-generated code is inherently secure
  • The six core Secure by Design principles and how to assess maturity across each
  • How to build an evidence-based assessment using development artifacts like threat models, vulnerability data, and testing results
  • How v1.1 maps to CIS Critical Security Controls and NIST SSDF practices
  • An Industry perspective in meeting the requirements of Secure by Design
Register

About Our Presenters

Curt Dukes
Executive Vice President and General Manager, Security Best Practices

Curtis W Dukes

Curt Dukes  joined CIS as the Executive Vice President and General Manager of the Best Practices and Automation Group in January 2017. The CIS Benchmarks® and CIS Controls® program provides vendor-agnostic, consensus-based best practices to help organizations assess and improve their security. Prior to CIS, he served as the Director, Information Assurance for the National Security Agency, Central Security Service. In that role Curt was responsible for securing systems that handle classified and critical information for military and intelligence activities. Dukes earned a Bachelor’s Degree in Computer Science from the University of Florida, and a Master’s Degree in Computer Science from Johns Hopkins University. He is a 2004 graduate of the Intelligence Community Officer Training Program.

Phyllis Lee
Vice President of Security Best Practices Content Development

Phyllis Lee thumbnailPhyllis Lee has over 25 years of experience in information assurance and has performed vulnerability assessments, virtualization research, and worked in security automation. Prior to joining CIS, Lee worked at the National Security Agency (NSA) focusing on the intersection between malware and virtualization, which included collaboration with MIT Lincoln Labs. Lee also participated in a variety of security automation standardization efforts and led the security automation strategy for the NSA Information Assurance Directorate (IAD). She graduated from Johns Hopkins University with a Master of Science in computer science.

Steve Lipner
Executive Director, SAFECode

Steve Lipner headshotSteve Lipner is the executive director of SAFECode, an industry nonprofit focused on software security assurance. He was previously partner director of software security at Microsoft where he was the creator and long-time leader of the Security Development Lifecycle (SDL) and was responsible for software integrity policies and government security evaluations. Lipner also serves as the chair of the U.S. Government’s Information Security and Privacy Advisory Board. He has more than a half century of experience in cybersecurity as researcher, engineer, and development manager and is named as coinventor on twelve U.S. patents. He is a member of the National Academy of Engineering and the National Cybersecurity Hall of Fame.

Robert E. Johnson, III
President, CEO, and co-founder of Cimcor, Inc.

Robert E. Johnson, III is the President, CEO, and co-founder of Cimcor, Inc., where he has spent nearly three decades building technology that helps organizations protect the integrity of critical systems. An entrepreneur, inventor, and cybersecurity leader, he has guided the development of commercial software and patented technologies spanning integrity assurance, real-time change control, and cyber resilience. Robert is also a speaker, educator, and active community leader whose service has reached higher education, healthcare, banking, economic development, and public advisory organizations. His governance service includes roles as chairman of The Methodist Hospitals, chair of the risk committee at Nasdaq-traded Finward Bancorp/Peoples Bank, and past chairman of Legacy Foundation, the region’s largest community foundation. A Purdue University alumnus and former instructor in operating-system internals, he brings an engineer's curiosity and a civic leader's sense of responsibility to every challenge: build what is next, protect what matters, and create progress that reaches beyond the technology itself.