Uploaded September 2025 | Updated September 2026, 4 hours ago
AI is a new workload for many platform engineers, developers, security people, and, well, just about everyone. When it comes to minding security and compliance needs, what needs to get done? In this discussion, @thecote talks with Chris Cropper and David Zendzian about just this. Chris draws on his experience working with the US military's Software Factory, and David draws from his long history in security. Among other things, they talk about how AI can enhance cybersecurity practices, the significance of continuous compliance, and the necessity of legal and security oversight.
Check out the Tanzu AI Starter Kit: go-vmware.broadcom.com/ai-starter-kit-for-tanzu-platform
00:00 Introduction and Setting the Stage
00:48 Meet the Experts: Chris and David
01:56 The Role of AI in Security and Compliance
03:43 Generative AI: Use Cases and Applications
04:25 How are people using AI?
06:43 What will the apps be, just chat?
12:20 Data Aggregation and Risk Management
16:49 Policy and Procedures for AI Implementation
18:47 Are organizations ready?
32:02 The Cost of Technical Debt
32:16 Introduction to RMF and Its Evolution
33:48 Software Factory Model and Continuous Compliance
34:53 Inheritance and Simplifying Developer Processes
36:06 Building a Software Factory Kit
37:09 Continuous Compliance and Monitoring
41:54 AI's Role in Enhancing Cybersecurity
43:28 AI replacing people or helping people
45:14 Challenges and Opportunities with AI Policy
48:52 AI Policy Boards
56:04 Final Thoughts and Recommendations
56:21 Tanzu AI Starter Kit
AI is a new workload for many platform engineers, developers, security people, and, well, just about everyone. When it comes to minding security and compliance needs, what needs to get done? In this discussion, @thecote talks with Chris Cropper and David Zendzian about just this. Chris draws on his experience working with the US military's Software Factory, and David draws from his long history in security. Among other things, they talk about how AI can enhance cybersecurity practices, the significance of continuous compliance, and the necessity of legal and security oversight.
Check out the Tanzu AI Starter Kit: go-vmware.broadcom.com/ai-starter-kit-for-tanzu-platform
00:00 Introduction and Setting the Stage
00:48 Meet the Experts: Chris and David
01:56 The Role of AI in Security and Compliance
03:43 Generative AI: Use Cases and Applications
04:25 How are people using AI?
06:43 What will the apps be, just chat?
12:20 Data Aggregation and Risk Management
16:49 Policy and Procedures for AI Implementation
18:47 Are organizations ready?
32:02 The Cost of Technical Debt
32:16 Introduction to RMF and Its Evolution
33:48 Software Factory Model and Continuous Compliance
34:53 Inheritance and Simplifying Developer Processes
36:06 Building a Software Factory Kit
37:09 Continuous Compliance and Monitoring
41:54 AI's Role in Enhancing Cybersecurity
43:28 AI replacing people or helping people
45:14 Challenges and Opportunities with AI Policy
48:52 AI Policy Boards
56:04 Final Thoughts and Recommendations
56:21 Tanzu AI Starter Kit










