ISO/IEC 42001 makes AI governance auditable
ISO/IEC 42001 does not prescribe seven named documents; it requires controlled evidence that AI risks, responsibilities, and decisions are managed.
Practical AI security: protecting systems, data, and people as AI becomes part of everyday operations.
Записи блога публикуются только на английском языке.
ISO/IEC 42001 does not prescribe seven named documents; it requires controlled evidence that AI risks, responsibilities, and decisions are managed.
Europe didn't ban AI. It ranked the harm — and the high-risk band is where most real systems actually live.
The Cloud Security Alliance's trait-based approach maps agent behavior and architectural choices to concrete security risks and controls.
The OWASP AI Exchange provides a lifecycle map for moving from AI governance and threat analysis to testing, operations, and residual-risk decisions.
NIST's attack taxonomy helps security teams connect adversary goals, access, lifecycle stages, and mitigations across predictive and generative AI.
Microsoft's experience across 100 generative-AI products shows why testing must follow real system risks, not a generic attack checklist.
OWASP's 2025 list shows that securing an LLM application requires architecture, testing, and development controls around the model.
NIST's Generative AI Profile extends the AI RMF with concrete actions for governance, data provenance, testing, and incident disclosure.
BaFin's central point is simple: AI security has to cover the whole decision process, not just the model.
Google's SAIF implementation guide turns six security principles into an organizational process for designing, deploying, and operating AI safely.
Google's one-page SAIF summary provides a useful executive test for whether AI security covers architecture, operations, and business risk.
The NIST AI RMF gives organizations a lifecycle structure for connecting AI governance, assets, architecture, measurement, and risk treatment.