

Software Engineering Institute (SEI) Podcast Series
Members of Technical Staff at the Software Engineering Institute
The SEI Podcast Series presents conversations in software engineering, cybersecurity, and future technologies.
Episodes
Mentioned books

Apr 17, 2025 • 26min
Updating Risk Assessment in the CERT Secure Coding Standard
Evaluating source code to ensure secure coding qualities costs time and effort and often involves static analysis. But those who are familiar with static analysis tools know that the alerts are not always reliable and produce false positives that must be detected and disregarded. This year, we plan on making some exciting updates to the SEI CERT C Coding Standard to better harmonize with the current state of the art for static analysis tools as well as simplify the process of source code security auditing. In this SEI podcast, David Svobodaand Joseph Sible, both engineers in CERT's Applied Systems Group and primary developers and maintainers of the standard, sit down with Robert Schiela, deputy technical director of the Cybersecurity Foundations Directorate in CERT, to discuss the proposed changes, specifically in the area of risk assessment.

Apr 15, 2025 • 27min
Delivering Next Generation Cyber Capabilities to the DoD Warfighter
In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Gregory Touhill, director of the SEI CERT Division, sits down with Matthew Butkovic, technical director of Cyber Risk and Resilience at CERT, to discuss ways in which CERT researchers and technologists are working to deliver rapid capability to warfighters in the Department of Defense.

Mar 26, 2025 • 39min
Getting the Most Out of Your Insider Risk Data with IIDES
Insider incidents cause around 35 percent of data breaches, creating financial and security risks for organizations. In this podcast from the Carnegie Mellon University Software Engineering Institute, Austin Whisnant and Dan Costa discuss the Insider Incident Data Expression Standard (IIDES), a new schema for collecting and sharing data about insider incidents. IIDES facilitates insider incident information handling to help organizations better protect themselves against the compromise of sensitive information and mission-critical systems, which is essential to maintaining national security and defense.

Mar 11, 2025 • 18min
Grace Lewis Outlines Vision for IEEE Computer Society Presidency
Grace Lewis, a principal researcher at Carnegie Mellon University's SEI and future IEEE Computer Society president, shares her vision for a thriving tech community. She discusses the transformative role of AI in software engineering and the importance of engaging volunteers and students in tech initiatives. Lewis also introduces the Continuum project, aimed at enhancing machine learning testing for the Department of Defense, while promoting the open-source MELT tool for better evaluation processes. It's an inspiring look at the future of computing.

Mar 3, 2025 • 29min
Improving Machine Learning Test and Evaluation with MLTE
Machine learning (ML) models commonly experience issues when integrated into production systems. In this podcast, researchers from the Carnegie Mellon University Software Engineering Institute and the U.S. Army AI Integration Center (AI2C) discuss Machine Learning Test and Evaluation (MLTE), a new tool that provides a process and infrastructure for ML test and evaluation. MLTE can aid organizations across the DoD in more effectively negotiating, documenting, and evaluating model and system qualities.

Feb 25, 2025 • 27min
DOD Software Modernization: SEI Impact and Innovation
As software size, complexity, and interconnectedness has grown, software modernization within the Department of Defense (DoD) has become more important than ever. In this discussion moderated by Matthew Butkovic, technical director of risk and resilience in the SEI CERT Division, SEI director Paul Nielsen outlines the SEI's work with the DoD on software modernization, including controlling the attack surface, incorporating industry practices such as DevSecOps, and the interplay between software, cybersecurity, and AI.

Dec 16, 2024 • 39min
Securing Docker Containers: Techniques, Challenges, and Tools
Containerization allows developers to run individual software applications in an isolated, controlled, repeatable way. With the increasing prevalence of cloud computing environments, containers are providing more and more of their underlying architecture. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Sasank Venkata Vishnubhatla and Maxwell Trdina, both engineers in the SEI CERT Division, sit down with Tim Chick, technical manager of the Applied Systems Group, to explore issues surrounding containerization, including recent vulnerabilities.

Dec 4, 2024 • 23min
An Introduction to Software Cost Estimation
Software cost estimation is an important first step when beginning a project. It addresses important questions regarding budget, staffing, scheduling, and determining if the current environment will support the project. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Anandi Hira, a data scientist on the SEI's Software Engineering Measurement and Analysis team sits down with Bill Nichols, principal engineer and SEI data science team lead, to discuss software cost estimation including various metrics, best practices, and common challenges when developing or building a model.

Oct 11, 2024 • 27min
Cybersecurity Metrics: Protecting Data and Understanding Threats
One of the biggest challenges in collecting cybersecurity metrics is scoping down objectives and determining what kinds of data to gather. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Bill Nichols, who leads the SEI's Software Engineering Measurements and Analysis Group, discusses the importance of cybersecurity measurement, what kinds of measurements are used in cybersecurity, and what those metrics can tell us about cyber systems.

Oct 2, 2024 • 36min
3 Key Elements for Designing Secure Systems
Timothy A. Chick, technical manager at the SEI CERT Division, shares his expertise in building secure systems. He stresses the importance of embedding security into every phase of the software development lifecycle to counteract vulnerabilities. Chick discusses the balance between enhancing cybersecurity and user experience, advocating for integration of user feedback. He emphasizes the need for robust testing strategies for third-party software and the evolution of principles like 'secure by design' to equip engineers with necessary tools from the start.


