{"product_id":"nist-ssdf-secure-software-for-the-ai-era","title":"NIST SSDF: Secure Software for the AI Era","description":"\u003cdiv\u003e\n\u003cp\u003eGain practical, forward-looking skills for applying the NIST Secure Software Development Framework (SSDF) to assess, improve, and secure modern software, including AI-enabled systems. Learn to navigate SSDF practices and tasks, map existing development activities to the framework, evaluate implementation effectiveness, identify security gaps, and prioritize meaningful improvements across the software development lifecycle.\u003c\/p\u003e\r\n\u003cp\u003eThrough progressive, real-world scenarios involving legacy software, distributed systems, software supply chain vulnerabilities, and AI-driven automation, you will put the SSDF into practice. You will also explore the NIST SSDF AI Community Profile and apply its guidance to models, training data, AI development assets, and non-deterministic behavior—building the skills to investigate vulnerabilities, develop improvement roadmaps, and assess the operational readiness of AI-enabled systems.\u003c\/p\u003e\n\u003c\/div\u003e\u003cdiv\u003e\n\u003ch3\u003eNIST SSDF: Secure Software for the AI Era Benefits\u003c\/h3\u003e\n\u003cul\u003e\u003cli\u003e\n\u003cp\u003e\u003cb\u003eCourse Benefits\u003c\/b\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eNavigate and apply NIST SSDF practices and tasks\u003c\/li\u003e\n\u003cli\u003eMap existing software development activities to the SSDF\u003c\/li\u003e\n\u003cli\u003eAssess SSDF adoption and identify meaningful security gaps\u003c\/li\u003e\n\u003cli\u003eEvaluate claims, evidence, and the effectiveness of secure development practices\u003c\/li\u003e\n\u003cli\u003ePrioritize improvements and build an SSDF improvement roadmap\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003ePrerequisites\u003c\/b\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eKnowledge at the level of foundation course 3695, Secure DevOps (SecDevOps)\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eOr\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eUnderstanding of software development and life-cycle processes\u003c\/li\u003e\n\u003cli\u003eFundamental knowledge of cybersecurity concepts and practices\u003c\/li\u003e\n\u003cli\u003eAwareness of AI usage, benefits, and challenges\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\u003c\/ul\u003e\n\u003c\/div\u003e\u003cdiv\u003e\u003ch3\u003eNIST SSDF for Secure AI Software Course Outline\u003c\/h3\u003e\u003c\/div\u003e\u003cdiv\u003e\n\u003ch4\u003eLearning Objectives\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003eModule 1: Applying the NIST SSDF\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e  The Secure Software Challenge\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSoftware as an organizational and operational dependency\u003c\/li\u003e\n\u003cli\u003eSecurity weaknesses throughout the software lifecycle\u003c\/li\u003e\n\u003cli\u003eMoving from finding vulnerabilities to preventing them\u003c\/li\u003e\n\u003cli\u003eSecure software development as an organizational capability\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Introducing the NIST SSDF\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003ePurpose and scope\u003c\/li\u003e\n\u003cli\u003eGuidance not a prescribed methodology\u003c\/li\u003e\n\u003cli\u003eIntegrating with existing development approaches such as SecDevOps\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Navigating the SSDF\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003ePractices, tasks, implementation examples, and references\u003c\/li\u003e\n\u003cli\u003eIdentifiers and terminology – a common security vocabulary\u003c\/li\u003e\n\u003cli\u003eFinding applicable SSDF guidance\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Activity 1.1 Individual\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSSDF Scavenger Hunt - find and report to the class\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eModule 2: the Four SSDF Practice Groups\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e  Prepare Organization (PO)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDefining security requirements\u003c\/li\u003e\n\u003cli\u003eRoles and responsibilities and the NICE Framework\u003c\/li\u003e\n\u003cli\u003ePreparing people, processes, and technology\u003c\/li\u003e\n\u003cli\u003eEstablishing and maintaining secure development environments\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Protect Software (PS)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eProtecting software from unauthorized access\u003c\/li\u003e\n\u003cli\u003eProtecting source code and development assets\u003c\/li\u003e\n\u003cli\u003eProtecting software releases\u003c\/li\u003e\n\u003cli\u003ePreserving software integrity\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Produce Well-Secured Software (PW)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDesigning software to meet security requirements\u003c\/li\u003e\n\u003cli\u003eReviewing designs and assessing risk\u003c\/li\u003e\n\u003cli\u003eSecuring reusable and third-party components\u003c\/li\u003e\n\u003cli\u003eReviewing, analyzing, and testing software\u003c\/li\u003e\n\u003cli\u003eConfiguring software securely\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Respond to Vulnerabilities (RV)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentifying and confirming vulnerabilities\u003c\/li\u003e\n\u003cli\u003eAssessing and prioritizing vulnerabilities\u003c\/li\u003e\n\u003cli\u003eRemediating vulnerabilities\u003c\/li\u003e\n\u003cli\u003eAnalyzing root causes and preventing recurrence\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Activity 2.1 Group Discussion\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eWhere Does It Belong?\u003c\/li\u003e\n\u003cli\u003eTeams classify security activities as primarily PO, PS, PW, or RV and defend ambiguous decisions\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eModule 3: Applying SSDF to Legacy Software\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e  Introducing the Northstar case study\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSafety-critical software environment\u003c\/li\u003e\n\u003cli\u003eProblem domain concepts and vocabulary\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  The VECTOR Legacy System\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLong-lived software and technical debt\u003c\/li\u003e\n\u003cli\u003eIncomplete documentation and organizational knowledge\u003c\/li\u003e\n\u003cli\u003eLimited automation and legacy development practices\u003c\/li\u003e\n\u003cli\u003eSecurity practices that predate the SSDF\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Assessing Existing Practices\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentifying implicit secure development activities\u003c\/li\u003e\n\u003cli\u003eMapping existing activities to SSDF tasks\u003c\/li\u003e\n\u003cli\u003eRecognizing partial implementation\u003c\/li\u003e\n\u003cli\u003eDistinguishing gaps from acceptable risk decisions\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Activity 3.1 Group Discussion\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eShould Northstar Rewrite the VECTOR system?\u003c\/li\u003e\n\u003cli\u003eSSDF Archaeology – identify practices that already align with SSDF\u003c\/li\u003e\n\u003cli\u003eRisk, operational impact, technical debt, and the danger of compromising safety\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eModule 4: Applying SSDF to Current-Time Software\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e   Northstar's Modern Development Environment\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eModern languages, APIs, and distributed systems\u003c\/li\u003e\n\u003cli\u003eOpen-source and third-party components\u003c\/li\u003e\n\u003cli\u003eMultiple development and supplier teams\u003c\/li\u003e\n\u003cli\u003eAutomated build, test, and release capabilities\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Mapping Organizational Practices to SSDF\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentifying applicable SSDF tasks\u003c\/li\u003e\n\u003cli\u003eMapping one activity to multiple practices\u003c\/li\u003e\n\u003cli\u003eRecognizing overlapping security activities\u003c\/li\u003e\n\u003cli\u003eIdentifying unmapped activities and missing capabilities\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Activity 4.1 Independent – Assess Northstar\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eStudents map current Northstar development activities to specific SSDF practices and tasks.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Evaluating SSDF Implementation\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDocumented practice versus actual practice\u003c\/li\u003e\n\u003cli\u003eClaims versus evidence\u003c\/li\u003e\n\u003cli\u003eImplemented, partially implemented, and not implemented\u003c\/li\u003e\n\u003cli\u003eAssessing effectiveness rather than presence\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Activity 4.2 Group Discussion – Sounds Secure to Me?\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eTeams identify statements that sound reassuring, but are they?\n\u003cul style=\"list-style-type: circle;\"\u003e\n\u003cli\u003e\n\u003ci\u003e“We perform annual security training”\u003c\/i\u003e or\u003c\/li\u003e\n\u003cli\u003e\u003ci\u003e“SAST is used before release”\u003c\/i\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eModule 5: Learning from Vulnerabilities\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e   Northstar's Component Vulnerability\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDiscovery of a vulnerable software component\u003c\/li\u003e\n\u003cli\u003eIdentifying affected products and versions\u003c\/li\u003e\n\u003cli\u003eSupplier and dependency complications\u003c\/li\u003e\n\u003cli\u003eRemediation creates operational consequences\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Responding to Vulnerabilities\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eVulnerability identification and confirmation\u003c\/li\u003e\n\u003cli\u003ePrioritization and response\u003c\/li\u003e\n\u003cli\u003eRemediation and verification\u003c\/li\u003e\n\u003cli\u003eCommunicating vulnerability information\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Beyond the Vulnerability\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRoot cause analysis\u003c\/li\u003e\n\u003cli\u003eIdentifying failures in PO, PS, and PW\u003c\/li\u003e\n\u003cli\u003eFeeding lessons back into development\u003c\/li\u003e\n\u003cli\u003ePreventing recurrence\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Activity 5.1 Progressive Group Activity – The Northstar Vulnerability\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eInformation is revealed in stages. Teams initially respond to vulnerability\u003c\/li\u003e\n\u003cli\u003eThen discover that Northstar cannot reliably identify affected products, component versions, or supplier exposure.\u003c\/li\u003e\n\u003cli\u003eCourse theme: RV often exposes yesterday's failure in PO, PS, or PW.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eModule 6: Building an SSDF Improvement Program\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e   Performing an SSDF Gap Assessment\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eEstablishing the current state by gathering evidence\u003c\/li\u003e\n\u003cli\u003eDocumenting capability gaps\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Prioritizing SSDF Improvements\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRisk and operational impact\u003c\/li\u003e\n\u003cli\u003eEffort and organizational readiness\u003c\/li\u003e\n\u003cli\u003eDependencies between SSDF practices\u003c\/li\u003e\n\u003cli\u003eQuick wins and strategic improvements\u003c\/li\u003e\n\u003cli\u003eCreating an SSDF Improvement Roadmap\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e   Activity 6.1 Independent Activity – Northstar 90-Day Roadmap\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eStudents select priority SSDF improvements and create a sequenced 90-day improvement plan\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eModule 7: Applying SSDF to Future Software\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e   Northstar TAACT project vision – Going to School\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eFrom Algorithmic Automation to AI\u003c\/li\u003e\n\u003cli\u003eDeterministic software and rule-based automation\u003c\/li\u003e\n\u003cli\u003eAI-assisted decision support\u003c\/li\u003e\n\u003cli\u003eLearned behavior and non-deterministic outcomes\u003c\/li\u003e\n\u003cli\u003eIncreasing software autonomy\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Applying the SSDF to AI\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eAI systems as software\u003c\/li\u003e\n\u003cli\u003eModels, data, and AI dependencies\u003c\/li\u003e\n\u003cli\u003eLimits of traditional secure development practices\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Activity 7.1 Group Discussion – Why Not Monday Morning?\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eStudents consider existing AI capability and identify why a seemingly successful AI system cannot simply be deployed into operational production\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eModule 8. Extending the SSDF for AI Systems\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e  The SSDF AI Community Profile\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003ePurpose of SP 800-218A to augment not replace SSDF\u003c\/li\u003e\n\u003cli\u003eAI-specific practices and considerations\u003c\/li\u003e\n\u003cli\u003eApplying SSDF guidance across the AI lifecycle\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Protecting AI Development Assets\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eTraining and evaluation data\u003c\/li\u003e\n\u003cli\u003eModels and model versions\u003c\/li\u003e\n\u003cli\u003eAI development environments\u003c\/li\u003e\n\u003cli\u003eProvenance, integrity, and traceability\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Measuring Secure Software Development\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eActivity metrics versus outcome metrics\u003c\/li\u003e\n\u003cli\u003eLeading and lagging indicators\u003c\/li\u003e\n\u003cli\u003eVanity Metrics\u003c\/li\u003e\n\u003cli\u003eMeasuring effectiveness and assurance evidence\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e  Activity 8.1 Group Activity – What evidence demonstrates that an AI system is ready?\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eNorthstar claims TAATC has successfully completed ten million simulated scenarios and is ready for operational trials.\u003c\/li\u003e\n\u003cli\u003eTeams address training, examination and evaluation, continuing qualification, security and protection.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eModule 9: Course Summary and Capstone:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e    Activity 9.1 Northstar 2035\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIs TAATC ready for operational trials?\u003c\/li\u003e\n\u003cli\u003eTeams present one of three recommendations: proceed, proceed with conditions, do not proceed\u003c\/li\u003e\n\u003cli\u003eEvery recommendation must be defended using specific SSDF and AI Community Profile guidance and supporting evidence.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/div\u003e","brand":"Learning Tree","offers":[{"title":"26BD51US \/ 2026-11-16T09:00:00 \/ Herndon, VA","offer_id":42918733250640,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"26CA49CN \/ 2026-12-14T09:00:00 \/ Ottawa","offer_id":42918733283408,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"271D19US \/ 2027-01-11T09:00:00 \/ Herndon, VA","offer_id":42918733316176,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"272A57CN \/ 2027-02-08T09:00:00 \/ Ottawa","offer_id":42918733414480,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"273C61US \/ 2027-03-08T09:00:00 \/ Herndon, VA","offer_id":42918733447248,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"274A68CN \/ 2027-04-05T09:00:00 \/ Ottawa","offer_id":42918733480016,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"275C92US \/ 2027-05-03T09:00:00 \/ Herndon, VA","offer_id":42918733512784,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"276A89CN \/ 2027-06-03T09:00:00 \/ Ottawa","offer_id":42918733545552,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"276D02US \/ 2027-06-28T09:00:00 \/ Herndon, VA","offer_id":42918733578320,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"277A21CN \/ 2027-07-28T09:00:00 \/ Ottawa","offer_id":42918733611088,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true},{"title":"278B82US \/ 2027-08-23T09:00:00 \/ Herndon, VA","offer_id":42918733643856,"sku":"US-2083-IL","price":1357.0,"currency_code":"USD","in_stock":true}],"url":"https:\/\/kpit-store.instructionforest.com\/products\/nist-ssdf-secure-software-for-the-ai-era","provider":"Learning Tree International","version":"1.0","type":"link"}