Cyber Security

CISA may be safe by design. Will the private sector make good commitments?

Before the design discussion on Secure at RSAC 2025, CSO and senior research scholar Jason Healey, Columbia University’s School of International and Public Affairs, and Chris Wysopal, co-founder and chief security evangelical missionary of Veracode, caught up with their CISA program forecasts.

Both sides agreed that the security designed was a concept that predates CISA and will continue in the private sector even if CISA abandons its plans. “There may not be a CISA office that does a great job with this, but the idea that we have to do it remains, and hopefully we will continue to be in a hurry even if we don’t have Bob and Lauren to cheer for it,” Healey told the CSO.

Indicators indicate that software security should be gradually improved

Healey and Wysopal are loyalists of design-by-one principles, but they acknowledge that few measurements can directly demonstrate that additional effort in software creation will lead to safer products. “How do we have more transfers to security software in terms of consequences or impact in metrics of threat or vulnerability”? Healy asked.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button