NIST AI RMF: govern, map, measure, and manage
The NIST AI RMF gives organizations a lifecycle structure for connecting AI governance, assets, architecture, measurement, and risk treatment.
Автор: Tim Crouch
Больше из серии AI SecurityThe NIST AI Risk Management Framework gives organizations a structure for managing AI without prescribing one technology or regulatory regime. Its four functions - Govern, Map, Measure, and Manage - are designed to operate continuously across the AI lifecycle. Evidence from measurement and operations should change governance, context, and control decisions.
CISSP Domain 1, Security and Risk Management, is the clearest connection. Govern establishes policy, accountability, risk tolerance, culture, and oversight. Map defines the use case, affected people, dependencies, assumptions, and potential impacts. Measure turns those concerns into analysis and evidence. Manage prioritizes risk, selects responses, allocates resources, and monitors whether decisions remain valid. This is recognizable security governance adapted to AI's uncertainty and social reach.
Domain 2, Asset Security, appears whenever the framework asks who owns data, models, systems, documentation, and outputs across the lifecycle. Teams need inventories, provenance, classification, handling rules, and awareness of third-party components. An AI system cannot be evaluated responsibly when its underlying assets and dependencies are unknown.
Domain 3, Security Architecture and Engineering, connects trustworthy characteristics to design. Validity, reliability, safety, security, resilience, transparency, explainability, privacy, and fairness involve trade-offs. Architects must decide which characteristics matter in context, select controls, document assumptions, and design for monitoring and change.
The framework's strength is also its limitation: it tells organizations how to structure risk work, not which answer to choose. That is intentional. A hiring model, fraud detector, medical assistant, and internal writing tool should not receive identical controls.
My takeaway is that the AI RMF supplies a governance spine. Use it to make context explicit, connect assets and architecture to measurable risks, assign decisions to accountable people, and keep the process alive after deployment. Without that cycle, AI risk management becomes either a policy document nobody operates or a technical test nobody can place in business context.