AGL builds AI agent for security architecture reviews

By
Follow google news

Getting to first draft faster.

Key points

  • AGL has built an AI agent that automatically produces an initial draft of security architecture review documents.
  • The agent, currently used by AGL's security architecture team, consumes internal Confluence documents and PDFs to generate output based on threat modeling frameworks.
  • AGL is also assessing AI features in existing vendor tools against its risk appetite, examining where underlying models are deployed and data is stored, processed and inferenced.
AGL builds AI agent for security architecture reviews
Image credit: AGL

AGL has built and is using an AI agent to streamline the process of performing security architecture reviews of systems by automatically producing an initial draft document.

Head of architecture for security and corporate technology Yaso Addanki told an IBM-run session at Gartner’s IT Symposium/Xpo that the agent has initially been given to the energy company’s security architecture team.

Security architecture reviews are structured assessments of a system's design and data flows, and are typically run to detect and mitigate design or control weaknesses early in a project.

“We have developed our own security architecture review agent, [which] automatically generates a security architecture review document based on some threat modeling frameworks that we are incorporating,” Addanki said.

“We just get the initial draft [from the agent, which] consumes internal Confluence documents, PDFs and whatnot, and generates the output.

“That [draft] makes it much easier for the security architects to review, update and provide [a review] back to their business so that they can work on [progressing] their initiatives much faster.”

Addanki said the idea for the agent came about as a way for the security architecture team to do their bit to “help the organisation move faster with deploying their initiatives”, by reducing the time taken to perform their contribution.

While the AI agent is for the security architecture team now, it could eventually be put into the hands of “solution architects”.

“Eventually, [our] thinking is that we could potentially ‘shift left’ and give that to the solution architects themselves so that they can build in [required security] controls,” Addanki said.

AI risk assessments

Addanki said that AGL is approaching AI adoption from a number of different angles, although one of the most common pathways to adoption is by using AI features and capabilities that have been introduced into software tools that the company already uses.

Through these “existing technologies and tools”, the company is hoping “to develop some agents to help with some of our business workflows,” Addanki said.

It is rigorously assessing the various use cases based on these platforms against its risk appetite and security requirements.

“Especially with some of the vendor tools and technologies that come with AI tools that we’re utilising, we really need to understand where the underlying models are being deployed, whether our data is stored, where it is processed and inferenced - what are the data sovereignty issues? 

“We really need to understand the nuances involved with the tools,” she said.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

ASD says prompt injection in AI cannot be fixed

ASD says prompt injection in AI cannot be fixed

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Optus may ban smart glasses in stores, offices

Optus may ban smart glasses in stores, offices

Security researcher says don't install Meta's Muse AI assistant

Security researcher says don't install Meta's Muse AI assistant

Log In

  |  Forgot your password?