CIO Influence
Industry Perspectives IT and DevOps Machine Learning Security

Rules for AI in Software Development: The Four-point Framework CISOs Can Adopt Today

Rules for AI in Software Development: The Four-point Framework CISOs Can Adopt Today

The question facing software development shops isnโ€™t whether Generative AI should be used to create software code, or whether the percentage of code generated by GenAI will increase in the near future. That horse bolted in the last 24 months. The question is how to maintain security and compliance while GenAI and artificial intelligence agents are putting software code in play.

While teams look to make the most of GenAIโ€™s benefits (not to mention unlocking the power of MCP technology), a four-point foundational framework has emerged as the new gold standard for immediate adoption. It details what enterprises can do to ensure safe, secure code development both now and as GenAI and agentic AI become increasingly bigger factors in future code development.

As any developer knows, AI coding tools are extremely powerful, but how those tools are used makes all the difference in how well they support security and compliance. Security-proficient developers who follow the framework and safely leverage AI coding tools to generate accurate, secure code from the start of the development cycle can increase the quality and security of their code by a factor of 10. Developers who fail to follow such a framework will inevitably see their projects go off the rails, likely producing a tenfold increase in security flaws.

Also Read:ย CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight

The Risks of AI Coding Loom Large

Ever since GenAI became an easily accessible tool for a wide array of business and personal uses, with the release of ChatGPT in November 2022, quickly followed by other large language models (LLMs), its utility for code generation has been a hot topic. Almost immediately, developers began working with GenAI to some degree, whether for business or personal use. Both sides of AIโ€™s double-edged sword soon became apparent. The productivity boost was significant, but even though some studies determined that AI-generated code was as secure or even more secure than code generated by humans, that still left plenty of room for error (humans arenโ€™t perfect either). The real risk was how often and how quickly those errors could propagate into the software ecosystem.

That risk continues to lurk, even as companies try to pace themselves by keeping many of their overall AI projects in the pilot phase. Gartner research has found that 52% of IT leaders expect that GenAI will be used to generate software for their organizations soon, if it isnโ€™t already.

The Foundation for Safe AI Code

My take on a framework for secure use of AI coding tools isnโ€™t a final destination but a starting point that organizations can adopt immediately. Gartner, meanwhile, offers a similar four-phase roadmap (five phases, actually, since it includes a Phase 0 on evaluating your AI inventory, which should already be a priority to prevent the risks associated with shadow AI). Gartnerโ€™s guidelines, which include lists of specific steps, break its four phases into:

  • Phase 1: Address cybersecurity debt.
  • Phase 2: Strategically expand existing cybersecurity controls.
  • Phase 3: Extend controls to AI-specific requirements.
  • Phase 4: Develop a forward-looking plan to secure the future use of AI.

The nomenclature may differ, but the steps in the two sets of guidelines are similar and often overlap. No matter what specific guides you follow, a foundational framework should include:

The Rules of the Road. Developers need clear guidance on using AI coding tools. A list of trusted (and cost-effective) LLMs with a trusted AI Security Rule File, provides structured guidance for developers working with AI coding tools like GitHub Copilot, Cline, Roo, Cursor, Aider and Windsurf. They focus on foundational security best practices and the observability and traceability of developer security skills. The rules are:

  • Organized by domain, including web frontend, backend and mobile.
  • Security-focused, covering recurring issues like injection flaws, unsafe handling, cross-site request forgery (CSRF) protection, weak authentication flows and more.
  • Lightweight by design, intended to be a practical starting point rather than an exhaustive rulebook.

The Right AI Tools. Organizations need to focus on the security efficacy of the AI tools they use, ensuring that they are built to meet the demands of a secure environment. For instance, you should be able to leverage AI tools for developer-led threat modeling, not just code output. The right AI tools, used the right way, can enhance security while also preventing many errors from slipping into the pipeline.

Good Governance. A lack of visibility and governance can breed “shadow AI” and the spread of insecure code. A tool that provides deep observability into the AI tools in use (including when generated code is being committed) and MCPs being utilized can enable organizations to effectively manage AI adoption, for example, by correlating AI tool and MCP usage with developers’ secure coding skills. Upskilling developers via an ongoing learning program helps ensure safe and secure use of AI early in the software development lifecycle (SDLC), allowing organizations to innovate faster and more securely.

Learning Pathways. CISOs can empower their developers through educational programs that provide hands-on, real-world upskilling in secure coding, while also measuring their progress in acquiring new skills and observing their commits to see how well they apply those skills on a daily basis, including their ability to check the work of AI tools. Using benchmarks to establish the required skills and measure educational progress helps organizations effectively manage their use of AI in software development.

AI coding tools like Copilot, Cursor, and others are quickly becoming entrenched in software development, boosting productivity and innovation across practically every sector. But because of AIโ€™s ubiquity, security canโ€™t be an afterthought. It must be part of the SDLC from the get-go. The four-point plan for putting AI tools to their best use is the right way to get started.

About The Author Of This Article

Pieter Danhieux, is CEO & Co-Founder at Secure Code Warrior

About Secure Code Warrior

Secure Code Warrior helps organizations adopt AI-assisted software development securely.

Catch more CIO Insights:ย How Are CIOs Aligning Technology with Workforce Agility?

[To share your insights with us, please write toย psen@itechseries.com ]

Related posts

Deepfence Announces Open Source Availability Of Threatmapper Cloud Native Security Observability Platform

CIO Influence News Desk

Zscaler VPN Report Finds Nearly Half of Organizations Are Concerned About Enterprise Security Due to Unsafe VPNs

GlobeNewswire

Contrast Security Director of Cloud Engineering to Keynote DevOpsDays Austin 10 Year Class Reunion