Jim Reavis CEO and Co-founder of Cloud Security Alliance: AI and Community Collaboration
Jim Reavis, shares his journey from a small-town IT manager to CEO of the Cloud Security Alliance. He highlights the importance of community collaboration in tackling security challenges and discusses recent initiatives focused on AI governance. Jim introduces a trustworthy pledge for ethical AI practices and a validated initiative for assessing AI systems. He emphasizes the need for human oversight in AI integration within cybersecurity and encourages exploration of CSA’s resources.
Transcript
Hey, everyone. Welcome back here to Tech Drunk tv. You know, my, my next guest just reminded me, I didn't see him at RSA this year for the first time in 20 something years, he wasn't there.
He was out celebrating a, a big, a big day, a big year in his life. Let me introduce you to my friend Jim Revis. Jim is the CEO and co-founder of course, of the Cloud Security Alliance.
He's almost become synonymous with the CSA. Jim, it's good to see you. I'm sorry, I didn't see at RSA, but welcome to Tech Drunk tv.
Oh, it's, it's my pleasure. And I'm, I'm sure it would've been worse for RSA if you weren't there, because you are an icon at the coffin. Ah, stop.
Thank you. But eh, it, it, you know, it'll, it'll go on without both of us shiv, let's face it. Right.
Um, anyway, Jim, you know, I, I said your co-founder, I still remember the initial CSA kind of formation meeting at RSA, you know, and, and coming together with the working groups and everything. But beyond CSA, there was the Jim Rivas before there was the CSA tell, give people a sense of kind of your, your, your life journey. Yeah.
So, you know, a small town kid, um, you know, working class roots, went to the local public university up here in Washington State. Loved computers. Had computer first one.
Um, I had when I was 12, which, um, was a commodore. And, um, so I did, did the computer science thing and then went to work for a bank. Um, and they made me the IT manager, which ended up being how I started, like having to get involved with security, which was in 1988.
And I decided, hey, I really like tech and security more than banks and finance. And so I just went through this, uh, journey of, of where the interesting security issues. And then in, in the early nineties, you could see, well, the big security problem for the rest of our lives is gonna be this internet thing.
And like the first time I actually saw the internet was in college, and it wasn't called, I think it was called NSF net, that iteration. And the first use case I saw was that people in computer science would go download a program from a hospital, which for some reason was designed to change the dates on object code. And I found out the reason they were doing that is so they could back date, Back bill, Their compiled code is so that the professor on the due date would pass.
He would post the perfect source code, and then they would just take it, compile it, turn it in before he noticed get a hundred percent. Uh, the professor figured that out. But the lesson, like later when I found out, hey, that was the internet, is that it was, it had a bad, had an evil use case from the beginning.
And so, um, so, you know, just, just from there and, you know, I did a startup and I've done a lot of, like, consulting for a lot of the, the startups that make up the cybersecurity industry now, we call it. I just, I've always loved the community aspect of cybersecurity and people like knowing they've gotta help each other. They're very much a first responder mentality.
And that was part of like, what had me create cloud security alliances. Like, let's, let's really capture that first responder mentality in communities and help each other. Let's raise each each other up in different communities.
Just be better. And by doing that we'll raise the baseline of security, get the bad guys. And so that's kind of, it's, it's been, you know, it's, it's, it's been some twists and turns, but a pretty sort of consistent theme of like loving the, the art and science of cybersecurity and then loving, like the collaboration that happens within it.
Absolutely. You know, Jim, I'm sitting here listening to you talk about security in the late eighties, the onset of the internet, the commercial internet, I, I realized, and you probably realized this too, a lot of people out here watching it, watching this video, the Cloud Security Alliance has been a constant in, in the industry since they first got involved in the industry, right. They're, they've been in the industry for decades.
Yep. Yep. We have.
And and you know, I had a, a conversation with a mutual friend last year, Tony Sager at Center for Internet. Sure. At NSA.
Yeah. Yeah. Used to be at NSA And, and he said, you know, Jim, the, the nonprofits we're actually the really conservative choice, because you have regime changes, you have government changes, you have all these things that will change in, in the corporate world, but us nonprofits, we actually stick around in our best practices are the, the most enduring, and that's always my, my aspiration.
You know, I want, I want CSA to be a hundred year old company, and, you know, maybe my chat bot will be around to observe that, my digital twin. But yeah, I'm open to Get Yeah, we'll, we'll download you. There you go.
And let's not even laugh about it. It, it's, it's coming. Uh, so Jim, you know, the CSA charter and mission, of course kind of changes with what, what, what we're dealing with, with the attack surface, so to speak, of, of, of the world out there, you know, the whole cloud.
Like when we first started with the CSA, I don't know if we really thought about hybrid cloud and multi-cloud and, and all of these, you know, different flavors, the edge, you know, we were still talking about perimeters, remember, right? The Jericho, uh, uh, uh, I forgot the organization, but they were all about the shrinking perimeters and stuff like that. But, you know, ai, I don't know.
I mean, we, we talked about AI maybe, but it, it seemed very sci-fi Skynet ish, and you know, what the heck. But it's real. It's having a tremendous impact.
You guys recently, uh, announced, announced two different initiatives around AI governance and security, and, and God knows we need it. Tell us about them, if you don't mind. Yeah, ab, absolutely.
So, you know, I, I like to say to people that, uh, the, the cloud and AI got together and had a baby and called it chat, GPT. And it was the fact that ai, I like to talk about was sci-fi forever. And this was actually the sort of democratization and the opening up of AI technologies, which big companies have had for decades, and not, not what we have now.
Not this generat ai, which is amazing, but now it was available to everyone, which very transformative. But also with that obviously comes with a lot of risks. So, so we started our AI safety initiative kind of the same way we started CSA, almost like a company within a company.
And we've been cranking out like research like crazy. And we've been using that to sort of formulate what the strategy is around how we think about governing this and how we communicate to the whole world that people who are developing or highly leveraging AI systems in their businesses can actually communicate that they're doing the right thing. And so, so, so one of the things we are doing is to say, I trustworthy pledge, which now I'm shameless, um, theft of other ideas.
And I really liked what Jen Easterly did at CISA with the Secure by design pledge. Me, Me too. It's, yeah, it's like we, we, we don't always, um, need to audit every little detail, and there can be different ways you do things, but it's really important that we capture the commitment and the earnestness that people and organizations have towards doing the right thing.
And so I really liked how she did that. And so it's, well as, as we are, as we are rolling out all the programs that we need, let's, let's make sure that we build a community of committed individuals. And so it's just, it's really simple.
It's about safety and compliance is one of the, the pillars of it. Committing to that, committing to ethics a about how you are rolling out AI systems, transparency is really important. So that's the third one, because we have to be transparent knowing that, hey, if even the inventors of these AI systems can't predict and are often very surprised by what it's able to do, how can anyone else?
And so we should be really transparent so we can go back and look at why did the AI system do what it's, it's, it actually did. So transparency is really important. And then the fourth one is privacy protecting.
Let's just have this commitment to the privacy of citizens, employees, customers, everyone as we go through this journey. So, so we, we've put that out there. Uh, last I checked it was, it's, it's only, it's been, I think less than a month.
And we've, uh, already got over a hundred companies that have committed to it from all, all walks of life. And so that's great to see. And so hope to see a lot more.
And it's really, it's a precursor to then what we're gonna be doing is, is updating our whole star program. So we have all of the audits and all of the, uh, controls ad uh, adherence inside of the, uh, the AI assurance systems. We have that, that we can measure this in a more quantitative way, in addition to this sort of qualitative pledge.
So all those things are coming, but the trustworthy pledge, it's, it's good for people to stand up and, and be accountable. So, so we're real appreciative of that. And so the, the other thing we just announced, which is kind of on the different, different side of the spectrum, but all sort of leading towards the same direction is something we're, we're calling validated.
And, um, it's spelled a little bit different. Valid. A I, Ted, so valid is good.
You got AI in the middle, and Ted, they have those TED conferences, smart people. So I just thought that's a good name. Anyway, Uhhuh, um, the, the idea we had was that hey, as these, these large language models get very sophisticated, and they're very good at doing a lot of language tasks.
If you gave them, you train them with very specific auditor guidance, implementation, guidance on how to implement systems securely that they would actually do in a very fast and, and low cost way. They'd be able to analyze, uh, uh, assessment and information, self-assessments, and be able to provide guidance on, hey, are, are we doing the right thing? So, so we launched that.
We were really surprised at, um, how good, actually the first iterations of this are on how it's able to analyze and give you really detailed guidance and, Hey, this is not really a good explanation of value to key management. Have you thought about like, doing this? And so, uh, so a lot of companies going through it.
I know that Google has had their star entry in our program validated, and I know there's several more, several more working on it, several more waiting to get approval to be able to announce that. But, um, you know, I see this as being something that as we talk about cybersecurity risk management audit, we, we are going to have this technology. It's going to do some automation, it's gonna do assistive things.
We need the human in the loop, but we need to embrace it because I think cybersecurity people, they need to know more about ai and they need to be the best AI experts in their company. That's how we're gonna do, do things, right? And that's what I'm encouraging cybersecurity people.
So, so this validated, uh, capability, it's something that it exists somewhere on the spectrum between a company doing a self-assessment of their security controls and then having a really good experienced auditor somewhere in, in that middle ground. But hey, that's all about that, that mission of let's raise the baseline of security, uh, everywhere, everywhere we go. So right now that's working on our cloud assessments, and then we're finishing up our AI controls framework next month, or actually later this month, it's gonna be released.
And then we are going to, uh, start doing the same thing for AI companies. Let them, um, um, get assessed with this technology. So we're, we're pretty excited about that.
We're pretty excited about, let's, let's go, let's go secure ai, let's embrace it to help secure it as well. You're telling me you guys are not really very busy on this AI front, huh? And that don't, Don't talk to me about the robots yet, because Yeah, no, it, I don't have an answer to that.
We don, we that's physical ai. Yep. Yep.
Right. That's physical. So gotta Think about next.
We gonna, it's this is, we're gonna have to go figure, figure that out. How do we like, have the controls for catastrophic things when it gets kinetic? So, you know, we don't have the solutions for that though.
Well, we'll, you know, can't make wine before it's time. We'll get there. That's right.
We'll get there. Jim, we gave people a lot of information here, fast and furious. Where can they go to maybe digest it at a one spoonful at a time and, and think on it, what, what's the best place on the CS a, uh, sites to go to?
org/star. ai has got, um, a good launching point there. We're not too hard to find.
And as always, research is all free. Please use it, consume it. There's a lot of the questions you have in your mind or the pain points.
Someone's already figured it out and solved it, so don't, don't reinvent the wheel. Go, go look into the research that's already there. Agreed.
Jim Rivas, thanks for coming up here on techstrong TV and, and giving us a little education about what the CSA, the Cloud Security Alliance is doing around ai. Just like it seems everyone else, AI is having a major impact in, in the CSA world as well. And you guys are, as one would expect responding to, to the challenge.
Well, thank, thank, thank you for that, Alan, and, and thank you for what you do and amplifying the voices that are out there in the community, it's really important that like what, what you are providing is a lot of great information for people from all, all walks of life here. So keep doing what you're doing. I appreciate it.
Hey, who would think I can make a living doing this? It's all good. Anyway, Jim, I hope to see a black hat.
We'll definitely see you at RSA, God willing, everybody's there. But until then, keep doing what you're doing seriously. And keep, and feel free to come on and keep us posted with any new news out of, uh, the Cloud Security Alliance.
I won't turn down an invite. I'll tell you. I'll hold you to that.
All righty. Alright, Jim, this CEO co-founder Cloud Security Alliance here on Tech Drug tv. We're gonna take a break.
We've got more coming at you, so stay tuned.