CIS Expands Secure-by-Design Guide With AI Agent Safeguards
The Center for Internet Security, or CIS, and SAFECode have developed a framework for assessing whether secure software practices are embedded in everyday development. The approach relies on evidence generated through routine work, including version control, testing and code reviews, rather than a one-time security check before release. The framework is increasingly relevant as companies deploy AI-assisted development tools and autonomous agents whose output can introduce risks that conventional governance processes may not fully address.
CIS and SAFECode recently released version 1.1 of the Secure by Design: Software Security Practice Evaluation Guide, expanding its requirements for AI-generated code and AI agents. The update says code produced with AI should still undergo checks using established security tools and human review. For AI agent systems that generate probabilistic results, the guide recommends human verification or deterministic controls in critical applications to constrain behavior and validate outputs before they can affect sensitive operations.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.