6. Next Steps
The NCCoE project team, in conjunction with the project’s collaborators, defined a notional model for DevSecOps to demonstrate the application of NIST SSDF practices. The team is implementing the model through multiple cloud-based example implementations using commercially available technologies contributed by collaborators.
To date, the team has successfully built the first two example implementations, showcasing the architecture and products used to implement secure DevSecOps practices using Generative AI and Zero Trust principles. The team has also demonstrated relevant use cases for both example implementations. Additionally, the project demonstrated the alignment between the SSDF and the project’s Notional Reference Model for DevSecOps.
Next, the project is now scoping Build 3 to demonstrate the use of agentic AI capabilities to develop, build, and test code. In support of Build 3, the DevSecOps and Software and AI Agent Identity and Authorization teams will work together on a single implementation to demonstrate how AI agents can be identified, authenticated, and authorized within the SDLC.