ISO/IEC 42001 makes AI governance auditable
ISO/IEC 42001 does not prescribe seven named documents; it requires controlled evidence that AI risks, responsibilities, and decisions are managed.
13 ieraksti ar tagu "ai"
Bloga ieraksti tiek publicēti tikai angļu valodā.
ISO/IEC 42001 does not prescribe seven named documents; it requires controlled evidence that AI risks, responsibilities, and decisions are managed.
The Cloud Security Alliance's trait-based approach maps agent behavior and architectural choices to concrete security risks and controls.
AI can read a marketing document against MiFID II requirements faster than any human. It still shouldn't be the one who approves it. That's a design principle, not a limitation.
The OWASP AI Exchange provides a lifecycle map for moving from AI governance and threat analysis to testing, operations, and residual-risk decisions.
NIST's attack taxonomy helps security teams connect adversary goals, access, lifecycle stages, and mitigations across predictive and generative AI.
Microsoft's experience across 100 generative-AI products shows why testing must follow real system risks, not a generic attack checklist.
OWASP's 2025 list shows that securing an LLM application requires architecture, testing, and development controls around the model.
The EU AI Act is not only a legal classification scheme; it requires organizations to connect AI risk, data governance, oversight, and evidence.
NIST's Generative AI Profile extends the AI RMF with concrete actions for governance, data provenance, testing, and incident disclosure.
BaFin's central point is simple: AI security has to cover the whole decision process, not just the model.
Google's SAIF implementation guide turns six security principles into an organizational process for designing, deploying, and operating AI safely.
Google's one-page SAIF summary provides a useful executive test for whether AI security covers architecture, operations, and business risk.
The NIST AI RMF gives organizations a lifecycle structure for connecting AI governance, assets, architecture, measurement, and risk treatment.