Agencies Shift Security, Compliance Left to Deliver Software Faster
Officials are shifting compliance and AI governance earlier in the development to match commercial software speed and maintain security.
General Services Administration’s (GSA) Login.gov is piloting continuous risk assessments over the next fiscal quarter as a part of integrating security earlier in the software development lifecycle, Platform and Product Security Director Ed McLaughlin said Tuesday at the Carahsoft DevSecOps Conference in Reston, Virginia.
McLaughlin described Login.gov as an agile delivery organization, but a waterfall compliance organization. Both the delivery and acquisition pipelines need to operate under the principles of DevSecOps to reduce assessment times from months to weeks.
McLaughlin said he wants to speed up the current software release time of three to five months, which is slower than commercial competitors.
“With the current landscape, it could take three to five months for [an update] to reach the market, and that is certainly not market speed,” said McLaughlin. “We’re hoping that we can go from code to complete to assessment on a three- to five-week basis, and that will be a significant game changer for us.”
McLaughlin said by leveraging in-house assessors under the CISO, developers and engineers will be able to rapidly and consistently achieve “code complete” or planned, functional code that is ready for testing.
“Our security processes have already shifted left. We are a DevSecOps operation. What we are shifting left now is our compliance operations,” said McLaughlin. “We have embedded our security analysts into each delivery team and into our platform team, and keep pace with significant changes as they develop.”
At the Air Force Software Directorate, CTO Kurt Jarvis is looking to grow the capabilities of engineers, developers and AI systems as the threat landscape is putting increased pressure on what the workforce can currently handle. He said, however, that AI can help fill in gaps to secure the development pipeline.
“I need to train up my engineer, my developer, and I’ve also got to train up my AI, so they grow together. And so they look at AI as an engineering partner,” said Jarvis. “It’s going to increase my capacity and allow my engineers and developers to abstract up just a bit and see the broader picture, solve the more complex problems, and allow us to move the whole Air Force forward.”
McLaughlin sees software engineers shifting to more of a software architect role to keep a human engineer in the loop. McLaughlin added that engineers on his team use sequence diagrams to inform their development workflow and help clearly define the fuzzy line between requirements and design.
“Having those artifacts up front, having use cases, having sequence diagrams, having data flows and data models, having those things defined up front, as opposed to winging it, is going to produce better results for you,” said McLaughlin.
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
What Battery Recycling Could Tell Us About AI's Role in Experimentation
A Genesis Mission project tests how AI agents can reduce physical experiments and accelerate critical mineral recovery from used batteries.
4m read -
AI Summit
The 2027 AI Summit convenes government and industry leaders to examine the next generation of artificial intelligence shaping federal missions.
Washington, D.C. -
Federal AI Forum
The 2027 AI Forum brings together federal AI leaders, practitioners and industry experts to examine how artificial intelligence is being applied to real-world government missions.
Reston, VA -
Federal Tech Leaders Summit
The 2027 Federal Tech Leaders Summit convenes federal CIOs, CTOs and other technology leaders to discuss the priorities shaping the future of government IT.
Washington, D.C.