Embedding security in every stage of software development — including pipelines that leverage AI code generation. This session will outline how security leaders can design, govern and validate secure-by-design development in the age of AI.
Key Topics:
- Mapping NIST SP 800-218 (SSDF) to AI-enabled DevSecOps workflows
- Integrating static (SAST), dynamic (DAST) and composition (SCA) testing to validate both human- and AI-authored code
- Detecting AI-introduced patterns (e.g., insecure libraries, unvalidated inputs, exposed keys)
- Governance for AI code tools — ensuring provenance, data protection and human review checkpoints
- Leveraging automation and ML to improve precision and reduce false positives