SEI Digital Library
Latest Publications
Getting Your Software Supply Chain In Tune with SBOM Harmonization
• Podcast
Software bills of materials or SBOMs are critical to software security and supply chain risk management. Regardless of the SBOM tool, the output should be consistent for a given piece …
Listen5 Essential Questions for Implementing the Software Acquisition Pathway and the Tools to Tackle Them
• Webcast
In this webcast, Eileen Wrubel and Brigid O’Hearn discuss the launch of the Software Acquisition Go Bag. Our SEI team has helped hundreds of DoD programs deliver software-enabled capability through …
WatchMinimally Viable Architecture: Architecture Early in Development
• Technical Note
This technical note explores MVAs and offers guidance on what teams should do with an MVA to get their certificate to field and authorization to operate.
ReadQ-Day Countdown: Are You Prepared?
• Webcast
In this webcast, Brett Tucker, Dan Justice, and Matthew Butkovic discuss the challenges to be expected with the realization of quantum computing capabilities.
WatchAPI Security: An Emerging Concern in Zero Trust Implementations
• Podcast
Application programming interfaces (APIs) are the engine behind most internet traffic. Recent vulnerabilities due to design flaws and incorrect deployments have made APIs a target for attacks.
ListenStandardization of Return on Risk Investment Computation
• White Paper
In this paper, Brett Tucker proposes standardizing how ROI is calculated and applied to quantitative risk-based decision making to enhance security resilience.
ReadDelivering Next-Generation AI Capabilities
• Podcast
Matt Gaston and Matt Butkovic discuss ongoing and future work in AI, including test and evaluation, the importance of hands-on experience with AI systems, and why government needs to continue …
ListenUsing LLMs to Evaluate Code
• Webcast
In this webcast, Dr. Mark Sherman summarizes the results of experiments that were conducted to see if various large language models (LLMs) could correctly identify problems with source code.
WatchAutomated Code Repair for C/C++ Static Analysis
• Technical Report
This engineering experience paper details the application of design, development, and performance testing to an automated program repair tool we built that repairs C/C++ code.
ReadDesign of Enhanced Pointer Ownership Model for C
• Technical Report
This report describes the design for a new temporal memory safety model for C code and an implementation to enforce it.
Read