IRS RFI: AI Tools for Application Security Scanning and Testing

Notice ID: 24-68-A-PMO-OITA

The IRS is seeking information on AI- and/or ML-based application security testing tools’ functionalities and capabilities, including these and more:

  1. Provide just-in-time identification of vulnerabilities and easy-to-understand remediation assistance to developers during coding and unit testing.
  2. Recommend secure coding practices and strategies for mitigating identified vulnerabilities.
  3. Produce real-time, actionable, and trusted findings.
  4. Automate and perform rapid testing.
  5. Identify potential security threats and automate security policy enforcement.
  6. Automate risk analysis and threat modeling.
  7. Support Continuous Authorization to Operate (cATO) process.
  8. Scalable and easy to integrate, deploy, and maintain.

Description of Contemplated Services

The IRS performs application security testing of mission-critical IRS applications.  This RFI is being issued with a goal of enabling cATO process by identifying AI- and/or ML-based application security testing capabilities that are available now or have a defined General Availability (GA) date within the next year.  These capabilities must improve upon legacy application security testing tools, such as Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). Significant AI or ML improvement on Interactive Application Security Testing (IAST) and/or Software Composition Analysis (SCA) tools also is desired.

More here.

Ad



Not Yet a Premium Partner/Sponsor? Learn more about the OS AI Premium Corporate and Individual Plans here. Plans start at $295 annually.

LEAVE A REPLY

Please enter your comment!
Please enter your name here