The Lawfare Podcast cover image

The Lawfare Podcast

Three CISA Senior Advisers on Secure by Design

Dec 22, 2023
Three senior advisors from CISA discuss the importance of secure software code and explore the ongoing research and open questions for establishing a secure-by-design standard. They delve into the concept of secure-by-design, the lack of security training in top schools, and the importance of field tests. The application of principles, gaps in knowledge, measuring security, and the need for data are also discussed.
53:57

Podcast summary created with Snipd AI

Quick takeaways

  • Software manufacturers need to take ownership of customer security outcomes and prioritize cybersecurity at the senior business leader level.
  • Collaborative efforts and partnerships among stakeholders are crucial in defining secure-by-design best practices.

Deep dives

Understanding Secure-by-Design: Principles and Implementation

In this Lawfare podcast episode, senior advisors from the Cybersecurity and Infrastructure Security Agency (CISA) discuss the concept of secure-by-design in relation to President Biden's Cybersecurity Strategy. They emphasize the need for software manufacturers to take ownership of customer security outcomes, promote radical transparency, and ensure that senior business leaders prioritize cybersecurity. They highlight the importance of understanding the cost of defects and the benefits of adopting secure-by-design practices. The discussion also explores the role of metrics in measuring security and the need for data collection, including a database of vulnerabilities and incidents. Overall, the episode underscores the importance of collaborative efforts in achieving secure-by-design standards.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner