《How AI Will Help Us Be More Secure.pdf》由会员分享,可在线阅读,更多相关《How AI Will Help Us Be More Secure.pdf(16页珍藏版)》请在三个皮匠报告上搜索。
1、AI is the Key to CISOs Top ChallengesUnlocking the Future2Some AI Fundamentals FirstAI Strengths:Reasoning and logic Communication skills Synthesizing information Pattern identification Creative problem-solving Translation Unstructured DataAI Limitations:Non-deterministic behaviorAccuracy Repeatabil
2、ity challengesLimited memory retentionSpeed&cost efficiency“Genius 13-year-old.Overconfident with short attention span and no street smarts”3What is Here Today but Coming TomorrowExpanded Context AwarenessContinuous Self-Improvement*Localized IntelligenceDeciding&Acting(Agents)Low Cost&High Performi
3、ng4AIs Impact on the EnterpriseOrganizationLocal agents(oracles)focused on each area of expertise(identity,cloud,emails,Jira)All meetings and communication will be analyzed and searchableSelf updating documentation&wikisAutomated management status reportsEngineeringLocalized models will monitor syst
4、ems&help remediate(self healing)Code and Cloud will become self documentingRequirements-driven code generation(requirements as code)Integrations will be automaticCISOs Top Challenges6CISOs top SECURITY challengesDetection&ResponseReportingVulnerability managementLeast privilegeCompliance and Measure
5、ment3rd party Incident Management7Fundamental Underlying Issues:The three CsCoverageCommunicationContext3C8Vulnerability ManagementContext-Who?What?Where?Why?How?Is it exploitable?If so by whom?Is there compensating controls?How hard/easy is it to remediate?Is it a critical system or area?Who owns t
6、he remediation?9Coverage Width&Depth Account Takeover(ATO)Missing logs,fields/Stopped logsThousands of vulnerabilities&alerts that need triagedConfiguration changesArchitecture ReviewsUser/System permissions10Communication Most Important&Waste of TimeWhy did we not fix that issue?How are we doing on