『Can We Automate Trust? The Future of FIPS 140 and Common Criteria』のカバーアート

Can We Automate Trust? The Future of FIPS 140 and Common Criteria

Can We Automate Trust? The Future of FIPS 140 and Common Criteria

無料で聴く

ポッドキャストの詳細を見る

Can we automate trust? And if we can, what happens to cybersecurity certification as we know it?In this episode of Trust & Turbulence, I’m joined by longtime colleagues Ashit Vora and Shawn Geddis, who are both building technologies designed to rethink how security certification gets done — but they’re approaching the problem in very different ways.Ashit is using AI to automate Common Criteria certification, with an eye toward expanding into areas such as the EU Cyber Resilience Act. Shawn is taking an intelligent automation (IA) approach to FIPS 140 and other assurance processes, emphasizing deterministic testing, standardized data, and machine-to-machine evidence exchange.We dig into some big questions:• What’s actually broken in today’s FIPS 140 and Common Criteria processes? • What’s the difference between AI and intelligent automation — and where does each belong? • Can automated testing and evidence ever earn the same trust as traditional human-driven evaluation? • What happens to certification labs as more of the work becomes automated? • Could continuous certification replace today’s point-in-time model? • Will the EU Cyber Resilience Act (CRA) accelerate automation simply because traditional compliance cannot scale? • How should Common Criteria and the broader standards community deal with AI? • And what happens when increasingly fragmented global requirements undermine the old goal of “evaluate once, sell everywhere”? This is also a conversation among three people who have worked together in the FIPS and Common Criteria community for well over a decade, so we get into some history, war stories, disagreements, and more than a few analogies — including teddy bears, taxes, Britney Spears and building a house.Can we really automate trust? Or does human judgment always have to remain at the center of cybersecurity assurance?That’s what we explore in this episode.If you enjoy Trust & Turbulence, please like, subscribe, and share your thoughts in the comments — particularly where you think AI and automation belong in the future of cybersecurity certification.About the GuestsShawn GeddisShawn Geddis spent more than 25 years at Apple, where he built the first Apple Platform Security Certifications Program and led engineering work for global platform certifications. He also built Apple’s SECLAB, its NVLAP-accredited first-party cryptographic laboratory, serving as lab manager, tooling developer, and—in his words—“evidence whisperer.” Shawn has since founded Katalyst LLC, focused on developing approachable automation and tooling for security certification.Ashit VoraAshit Vora is Co-Founder of Autonomi, an AI-enabled automation platform focused on transforming standards-based product security certification. Previously, Ashit co-founded Acumen Security, which grew into a leading product security certification provider before being acquired by Intertek. Earlier, he led Cisco’s U.S. government certification business supporting programs enabling approximately $1.5 billion in annual revenue. His work spans more than two decades of product security, certification, testing, standards, and commercialization. Music by Mikhail Smusev from PixabayLogo

adbl_web_anon_alc_button_suppression_t1
まだレビューはありません