CIS and SAFECode release Secure by Design v1.1 with expanded AI guidance
Original title: Secure by Design: A Guide to Assessing Software Security Practices v1.1
CIS and SAFECode have published version 1.1 of Secure by Design: A Guide to Assessing Software Security Practices, updating the original framework to address evolving software development practices and regulatory expectations. The update expands guidance on artificial intelligence in development, including risks of AI-generated code and security considerations for large language models and agentic AI systems. Organizations must maintain existing Secure by Design principles while demonstrating implementation through measurable evidence such as threat models, vulnerability management data, and testing results aligned with NIST SSDF practices and CIS Critical Security Controls.
What changed
- Introduced dedicated guidance on AI's role in software development and security, including how organizations can use AI for threat modeling and vulnerability identification while ensuring AI-generated code undergoes the same review and validation as human-written software
- Updated policy and regulatory references to reflect ongoing CISA Secure by Design initiatives, NIST Secure Software Development Framework activities, Executive Order 14306, and the European Union Cyber Resilience Act
- Enhanced assessment materials and resources strengthening the connection between Secure by Design principles and measurable evidence, with clearer mapping of NIST SSDF practices to CIS Critical Security Controls and SAFECode Development Groups
- Maintained six core foundational principles: Secure Software Design, Secure Development, Secure Default Configuration, Supply Chain Security, Code Integrity, and Vulnerability Remediation
- Reinforced emphasis on evidence-based assessment through development artifacts rather than self-attestation, requiring organizations to demonstrate adoption through threat models, workflow records, vulnerability management data, testing results, and source code analysis
Who is affected
Software developers, organizations building and maintaining software products, software vendors, customers evaluating software security, assessors conducting security evaluations, and policymakers developing cybersecurity regulations globally
- Action
- Action required
- Language
- EN