Bounded Autonomy for Campus SOCs: Making AI 'Secure by Default' without Breaking Privacy

Wednesday, April 29, 2026 | 8:00AM–8:45AM PT | Pacific Ballroom B, Second Floor
Session Type: Breakout Session
Delivery Format: Presentation/Panel
As campuses adopt AI copilots for detection, triage, and response, the question no longer is, “should we use AI?” but rather, “how do we keep it secure by default and privacy-preserving by design?” This session introduces bounded autonomy for resource-constrained campus SOCs: a practical operating model where AI can accelerate routine work. Decision rights, data minimization, and auditability are engineered into the workflow from day one. We’ll share a reference pattern that combines (1) identity-centered access controls and Zero Trust principles (verify explicitly, least privilege, assume breach); (2) privacy-aware telemetry (purpose limitation, retention controls, and role-based visibility); and (3) governance hooks aligned to NIST CSF 2.0’s emphasis on the Govern function alongside Identify–Recover. Participants will leave with a lightweight “decision-rights matrix” for what AI may do autonomously, what requires human approval, and how to document the privacy and risk rationale for each automation.

Presenters

  • Samuel Addington

    Lecturer, California State University, Long Beach

Resources & Downloads

  • Bounded Autonomy for Campus SOCs Making AI Secure by Default without Breaking Privacy

    Updated on 7/24/2026
  • Attendee Activity Worksheet

    Updated on 7/24/2026