Software Engineering Institute (SEI) Podcast Series

Members of Technical Staff at the Software Engineering Institute
undefined
Apr 17, 2025 • 26min

Updating Risk Assessment in the CERT Secure Coding Standard

Evaluating source code to ensure secure coding qualities costs time and effort and often involves static analysis. But those who are familiar with static analysis tools know that the alerts are not always reliable and produce false positives that must be detected and disregarded. This year, we plan on making some exciting updates to the SEI CERT C Coding Standard to better harmonize with the current state of the art for static analysis tools as well as simplify the process of source code security auditing. In this SEI podcast, David Svobodaand Joseph Sible, both engineers in CERT's Applied Systems Group and primary developers and maintainers of the standard, sit down with Robert Schiela, deputy technical director of the Cybersecurity Foundations Directorate in CERT, to discuss the proposed changes, specifically in the area of risk assessment.
undefined
Apr 15, 2025 • 27min

Delivering Next Generation Cyber Capabilities to the DoD Warfighter

In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Gregory Touhill, director of the SEI CERT Division, sits down with Matthew Butkovic, technical director of Cyber Risk and Resilience at CERT, to discuss ways in which CERT researchers and technologists are working to deliver rapid capability to warfighters in the Department of Defense.
undefined
Mar 26, 2025 • 39min

Getting the Most Out of Your Insider Risk Data with IIDES

Insider incidents cause around 35 percent of data breaches, creating financial and security risks for organizations. In this podcast from the Carnegie Mellon University Software Engineering Institute, Austin Whisnant and Dan Costa discuss the Insider Incident Data Expression Standard (IIDES), a new schema for collecting and sharing data about insider incidents. IIDES facilitates insider incident information handling to help organizations better protect themselves against the compromise of sensitive information and mission-critical systems, which is essential to maintaining national security and defense.
undefined
Mar 11, 2025 • 18min

Grace Lewis Outlines Vision for IEEE Computer Society Presidency

Grace Lewis, a principal researcher at Carnegie Mellon University's SEI and future IEEE Computer Society president, shares her vision for a thriving tech community. She discusses the transformative role of AI in software engineering and the importance of engaging volunteers and students in tech initiatives. Lewis also introduces the Continuum project, aimed at enhancing machine learning testing for the Department of Defense, while promoting the open-source MELT tool for better evaluation processes. It's an inspiring look at the future of computing.
undefined
Mar 3, 2025 • 29min

Improving Machine Learning Test and Evaluation with MLTE

Machine learning (ML) models commonly experience issues when integrated into production systems. In this podcast, researchers from the Carnegie Mellon University Software Engineering Institute and the U.S. Army AI Integration Center (AI2C) discuss Machine Learning Test and Evaluation (MLTE), a new tool that provides a process and infrastructure for ML test and evaluation. MLTE can aid organizations across the DoD in more effectively negotiating, documenting, and evaluating model and system qualities.
undefined
Feb 25, 2025 • 27min

DOD Software Modernization: SEI Impact and Innovation

As software size, complexity, and interconnectedness has grown, software modernization within the Department of Defense (DoD) has become more important than ever. In this discussion moderated by Matthew Butkovic, technical director of risk and resilience in the SEI CERT Division, SEI director Paul Nielsen outlines the SEI's work with the DoD on software modernization, including controlling the attack surface, incorporating industry practices such as DevSecOps, and the interplay between software, cybersecurity, and AI.
undefined
Dec 16, 2024 • 39min

Securing Docker Containers: Techniques, Challenges, and Tools

Containerization allows developers to run individual software applications in an isolated, controlled, repeatable way. With the increasing prevalence of cloud computing environments, containers are providing more and more of their underlying architecture. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Sasank Venkata Vishnubhatla and Maxwell Trdina, both engineers in the SEI CERT Division, sit down with Tim Chick, technical manager of the Applied Systems Group, to explore issues surrounding containerization, including recent vulnerabilities.
undefined
Dec 4, 2024 • 23min

An Introduction to Software Cost Estimation

Software cost estimation is an important first step when beginning a project. It addresses important questions regarding budget, staffing, scheduling, and determining if the current environment will support the project. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Anandi Hira, a data scientist on the SEI's Software Engineering Measurement and Analysis team sits down with Bill Nichols, principal engineer and SEI data science team lead, to discuss software cost estimation including various metrics, best practices, and common challenges when developing or building a model.
undefined
Oct 11, 2024 • 27min

Cybersecurity Metrics: Protecting Data and Understanding Threats

One of the biggest challenges in collecting cybersecurity metrics is scoping down objectives and determining what kinds of data to gather. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Bill Nichols, who leads the SEI's Software Engineering Measurements and Analysis Group, discusses the importance of cybersecurity measurement, what kinds of measurements are used in cybersecurity, and what those metrics can tell us about cyber systems.
undefined
Oct 2, 2024 • 36min

3 Key Elements for Designing Secure Systems

Timothy A. Chick, technical manager at the SEI CERT Division, shares his expertise in building secure systems. He stresses the importance of embedding security into every phase of the software development lifecycle to counteract vulnerabilities. Chick discusses the balance between enhancing cybersecurity and user experience, advocating for integration of user feedback. He emphasizes the need for robust testing strategies for third-party software and the evolution of principles like 'secure by design' to equip engineers with necessary tools from the start.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app