icon-carat-right menu search cmu-wordmark
Our Research

Cybersecurity Engineering

The Software Engineering Institute (SEI) stands on the front lines of defense against cyber adversaries. Our cybersecurity engineering (CSE) research protects and defends national security systems, software components, and data from unauthorized access, cyberattacks, and other malicious activities.

With new vulnerabilities emerging daily, staying ahead of threats in today’s fast-paced cybersecurity landscape is a race against time. At the SEI, our mission-driven focus is to strengthen our nation's cybersecurity infrastructure by securing the country's most critical systems and protecting agencies and systems from a loss of confidentiality, integrity, or availability (CIA) due to cyber threats.

It's vital to balance opportunities, such as shared resources and capabilities, third-party tools, and cloud capacity, with the increased cybersecurity risk that these opportunities introduce to the defense industrial base (DIB). To reduce risk, it's imperative to implement effective and repeatable practices that can respond to changing technology needs, discover vulnerabilities before attackers do, manage the growing threats against software products that support critical infrastructure, enable warfighters, monitor and manage money, and control physical resources, buildings, and transportation.

The SEI’s CSE researchers aim to ensure that the acquisition and development process is secure from the start. Our mission success is dependent on making sure that stakeholders make choices that protect them against legacy or weak supply chain management (SCRM), software acquisition, or development practices and strengthen cybersecurity resilience. With a deep, scalable understanding of how to detect and defend against security weaknesses and exploitation, our cybersecurity professionals are driven to harden the nation’s vulnerability surface and protect national security interests.

Advance Cybersecurity Resilience

The goal of CSE is to ensure that the software the Department of Defense (DoD) and federal agencies develop or acquire delivers the expected functionality and blocks actions that might introduce risk. To achieve this goal, the SEI helps prepare managers, engineers, developers, testers, and other groups involved in lifecycle tasks, to build and field effective cybersecurity in current and future software acquisition and development, validate and sustain cybersecurity in systems and software, and deliver the mission impact your organization expects of its software.

Build Security into Application Lifecycles

The SEI’s CSE team leverages expertise in system and software engineering, risk management, program management, measurement, and cybersecurity to create methods and solutions that you can integrate into your existing acquisition and development lifecycle practices. To this end, the SEI offers many tools and approaches to help engineering, development, acquisition, and sustainment groups that work in or with your organization.

The SEI continues to expand CSE research through engagements with the DoD and other federal agencies to address real-world challenges. Over the years, we have shared our findings in many notable publications, including a book on cybersecurity, a paper on assessing DoD risk in acquisition, and a program manager’s guidebook for software assurance.

What We Offer

Additional Resources

The Latest from the SEI Blog

How to Align Security Requirements and Controls to Express System Threats

Blog Post
and

This blog post presents a method that combines information about security requirements, controls, and capabilities with analysis regarding cyber threats to enable more effective risk-guided system planning.

READ

Enhancing Security with Cloud Flow Logs

Blog Post

The SEI has a history of support for flow log analysis, including its 2025 releases (for Azure or AWS) of open-source scripts to facilitate cloud flow log analysis. This blog explores challenges with correlating events across multiple CSPs.

READ

The Latest from the Digital Library

Preliminary Architectural Analysis

Presentation

In this presentation, the author gives a foundational analysis of enterprise architecture utilizing MBSE.

Learn More

Model-Based Systems Engineering (MBSE) in Practice 2025

Collection
Software Engineering Institute

Model-Based Systems Engineering (MBSE) offers a powerful solution, promising improved communication, enhanced productivity, and higher-quality designs.

Learn More

Explore Our Cybersecurity Engineering Projects

Our Vision for the Future of Cybersecurity Engineering

The SEI’s cybersecurity professionals are working to expand available CSE options to bolster national security. We are currently developing and tailoring archetypes to support agencies in identifying cybersecurity risks improving evaluation of mission impact.

To collaborate on these new projects in the field of cybersecurity engineering, contact us.

contact us