Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Presentation

OSCAL Monthly Workshop Series - Event #33: OSCAL-based AI-augmented CISO Agent

March 19, 2025

Presenters

Anca Sailer - Distinguished Engineer , IBM
Yuji Watanabe - Research Senior Technical , IBM Tokyo
Hirokuni Kitahara - Research Scientist , IBM Tokyo
Takumi Yanagawa - Research Advisory , IBM Tokyo
Saki Takano - Research Scientist , IBM Tokyo

Description

This OSCAL Monthly Workshop presented by our OSCAL adaptors from IBM, focuses on leveraging OSCAL (Open Security Controls Assessment Language) to enhance compliance automation, particularly in AI-driven environments. This workshop detailed a five-year journey applying OSCAL for compliance management, covering its use in defining and enforcing security requirements across various domains, including infrastructure, data, AI, and applications. Emphasizing the integration of compliance as code with policy enforcement tools, such as Ansible and Kyverno, to automate and validate compliance checks. Introducing the concept of Compliance-to-Policy (C2P), C2P bridges OSCAL-defined controls with policy validation tools. This workshop also highlighted the potential for Gen-AI and Large Language Models (LLMs) to automate the generation of policy code, simplifying the traditionally human-intensive task of policy creation.

Downloads

Related Topics

Security and Privacy: security & behavior, security automation

Technologies: artificial intelligence

Created April 03, 2025, Updated April 11, 2025