Bounded Autonomy for Campus SOCs: Making AI 'Secure by Default' without Breaking Privacy
Bounded Autonomy for Campus SOCs: Making AI 'Secure by Default' without Breaking Privacy
Wednesday, April 29, 2026 | 8:00AM–8:45AM PT | Pacific Ballroom B, Second Floor
Session Type:
Breakout Session
Delivery Format:
Presentation/Panel
As campuses adopt AI copilots for detection, triage, and response, the question no longer is, “should we use AI?” but rather, “how do we keep it secure by default and privacy-preserving by design?” This session introduces bounded autonomy for resource-constrained campus SOCs: a practical operating model where AI can accelerate routine work. Decision rights, data minimization, and auditability are engineered into the workflow from day one. We’ll share a reference pattern that combines (1) identity-centered access controls and Zero Trust principles (verify explicitly, least privilege, assume breach); (2) privacy-aware telemetry (purpose limitation, retention controls, and role-based visibility); and (3) governance hooks aligned to NIST CSF 2.0’s emphasis on the Govern function alongside Identify–Recover. Participants will leave with a lightweight “decision-rights matrix” for what AI may do autonomously, what requires human approval, and how to document the privacy and risk rationale for each automation.
Presenters
Samuel Addington
Lecturer, California State University, Long Beach
Resources & Downloads
Bounded Autonomy for Campus SOCs Making AI Secure by Default without Breaking Privacy