Former CISA official Cable presses DoD on secure-by-design AI coding guardrails
CISA’s old point follows the code generator: security becomes useful only when it constrains the first draft.
TL;DR
Former CISA senior official Jack Cable, now co-founder of Corridor Security, told Inside Cybersecurity that DoD should apply secure by design principles as it scales AI-assisted coding, including its Feb. 19 call for AI-enabled coding capabilities. The advice has a business model attached. It still lands cleanly on developers, acquisition teams and reviewers who must guide AI agents before generated code reaches defense software pipelines.
Cable is making a point that looks simple only after procurement starts. Inside Cybersecurity reported that he urged DoD to build secure-by-design guardrails into AI-assisted coding as the Pentagon seeks to expand AI-enabled software development. He is also now co-founder of Corridor Security, a firm focused on applying those principles to AI-generated code, so his advice comes with a commercial interest. The underlying claim still holds.
CISA’s secure by design program says technology providers should treat customer security as a core business requirement and own it at the executive level (https://www.cisa.gov/securebydesign). CISA has separately said AI is software and should be built secure by design, even as AI-specific practices continue to mature (https://www.cisa.gov/news-events/news/software-must-be-secure-design-and-artificial-intelligence-no-exception). That matters because AI coding tools change the first draft: reviewers may be evaluating code produced by agents that followed instructions the organization never disciplined.
For DoD, the compliance anchor is nearby. OMB’s M-23-16 reaffirmed that agencies must use software from producers that can attest to government-specified minimum secure development practices under NIST’s Secure Software Development Framework (SSDF), SP 800-218, and related supply-chain guidance (https://www.cisa.gov/sites/default/files/2024-07/M-23-16_Enhancing_the_Security_of_Software_Supply_Chain_via_Secure_Software_Practices.pdf). The Pentagon’s AI coding work should connect to that existing secure software development machinery from the start.
The Monday work is deliberately plain: decide which tools can touch which repositories, what libraries agents may pull, how generated code is labeled, what tests run before merge, and who can accept the output. Cable’s warning is about control placement. If DoD scales the tool first and bolts review on later, secure by design becomes a label for a faster version of the same defect problem.
Published ·Deep Fathom