AI (V1) Principle 3

Iniziamo. È gratuito!
o registrati con il tuo indirizzo email
AI (V1) Principle 3 da Mind Map: AI (V1) Principle 3

1. ETSI

1.1. EN 304 223 - Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems

1.1.1. Provision 5.1.3-1

1.1.2. Provision 5.1.3-1.1

1.1.3. Provision 5.1.3-1.2

1.1.4. Provision 5.1.3-1.3

1.1.5. Provision 5.1.3-2

1.1.6. Provision 5.1.3-3

1.1.7. Provision 5.1.3-4

1.2. TR 104 128 - Securing Artificial Intelligence (SAI); Guide to Cyber Security for AI Models and Systems

1.2.1. Provision 5.1.3-1

1.2.2. Provision 5.1.3-1.1

1.2.3. Provision 5.1.3-1.2

1.2.4. Provision 5.1.3-1.3

1.2.5. Provision 5.1.3-2

1.2.6. Provision 5.1.3-3

1.2.7. Provision 5.1.3-4

1.3. TR 104 048 - Securing Artificial Intelligence (SAI); Data Supply Chain Security

1.3.1. 6.5 Analysis - Hash checks

1.4. SAI 002 - Securing Artificial Intelligence (SAI); Data Supply Chain Security

1.4.1. 6.1.3 Supply chain security - 1

1.4.2. 6.5 - Following standard cybersecurity supply chain guidance

2. NIST

2.1. AI RMF 1.0

2.1.1. GOVERN 1.3

2.1.2. GOVERN 1.4

2.1.3. GOVERN 1.5

2.1.4. GOVERN 2.1

2.1.5. GOVERN 3.1

2.1.6. GOVERN 4.2

2.1.7. MAP 1.5

2.1.8. MAP 3.2

2.1.9. MAP 4.2

2.1.10. MAP 5.1

2.1.11. MEASURE 1.1

2.1.12. MEASURE 2.8

2.1.13. MEASURE 2.10

2.1.14. MEASURE 3.1

2.1.15. MEASURE 3.2

2.1.16. MANAGE 1.2

2.1.17. MANAGE 1.3

2.1.18. MANAGE 1.4

2.1.19. MANAGE 2.3

2.2. SP 800-218A

2.2.1. PW.1.1

2.2.2. RV.2.2

2.3. AI 800-1

2.3.1. Practice 1.1: Anticipate model capabilities - 5

2.3.2. Practice 1.1: Anticipate model capabilities - 7

2.3.3. Practice 1.2 Create threat profiles - 3

2.3.4. Practice 1.2 Create threat profiles - 4

2.3.5. Practice 1.3: Conduct risk assessments - 1

2.3.6. Practice 1.3: Conduct risk assessments - 2

2.3.7. Practice 1.3: Conduct risk assessments - 3

2.3.8. Practice 1.3: Conduct risk assessments - 4

2.3.9. Practice 1.3: Conduct risk assessments - 5

2.3.10. Practice 1.3: Conduct risk assessments - 6

2.3.11. Practice 1.3: Conduct risk assessments - 7

2.3.12. Practice 1.3: Conduct risk assessments - 8

2.3.13. Practice 2.1. Map anticipated model capabilities to appropriate risk mitigations to manage misuse risk - 1

2.3.14. Practice 2.1. Map anticipated model capabilities to appropriate risk mitigations to manage misuse risk - 2

2.3.15. Practice 2.1. Map anticipated model capabilities to appropriate risk mitigations to manage misuse risk - 3

2.3.16. Practice 2.1. Map anticipated model capabilities to appropriate risk mitigations to manage misuse risk - 4

2.3.17. Practice 2.1. Map anticipated model capabilities to appropriate risk mitigations to manage misuse risk - 5

2.3.18. Practice 2.2 Establish an organizational plan to manage misuse risk - 4

2.3.19. Practice 3.1: Assess misuse risk from threat actors gaining unauthorized access to the model - 1

2.3.20. Practice 3.1: Assess misuse risk from threat actors gaining unauthorized access to the model - 3

2.3.21. Practice 3.2: Maintain security practices sufficient to prevent unauthorized access - 4

2.3.22. Practice 5.2: Assess misuse risk based on implemented safeguards - 2

2.3.23. Practice 5.3: Adopt appropriate deployment strategies based on misuse risk assessments - 1

2.3.24. Practice 5.3: Adopt appropriate deployment strategies based on misuse risk assessments - 3

2.3.25. Practice 5.3: Adopt appropriate deployment strategies based on misuse risk assessments - 4

2.4. IR 8596: Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile): NIST Community Profile

2.4.1. GV.RM-01

2.4.2. GV.RM-02

2.4.3. GV.RM-03

2.4.4. GV.RM-04

2.4.5. GV.RM-05

2.4.6. GV.RM-06

2.4.7. GV.RM-07

2.4.8. GV.PO-01

2.4.9. GV.PO-02

2.4.10. GV.OV-01

2.4.11. GV.OV-02

2.4.12. GV.OV-03

2.4.13. GV.SC-01

2.4.14. ID.RA-02

2.4.15. ID.RA-03

2.4.16. ID.RA-04

2.4.17. ID.RA-05

2.4.18. ID.RA-06

2.4.19. ID.RA-07

2.4.20. RC.RP-04

3. MITRE

3.1. SAFE-AI

3.1.1. Vulnerability exploit

4. Multi Agency

4.1. Guidelines for secure AI system development

4.1.1. Model the threats to your system

5. European Commission

5.1. Ethics guidelines for trustworthy AI

5.1.1. 1.2.1 Resilience to attack and security

5.1.2. 1.7.2 Minimisation and Reporting of Negative Impacts

5.1.3. 2.1.2 Ethics and Rule of Law by Design

6. Personal Data Protection Commission Singapore (PDPC)

6.1. Model Artificial Intelligence Governance Framework Second Edition

6.1.1. 2. Risk management and internal controls - a)

6.1.2. 2. Risk management and internal controls - b) (i)

6.1.3. 2. Risk management and internal controls - b) (iv)

6.1.4. 2. Risk management and internal controls - b) (v)

7. Google

7.1. Secure AI Framework

7.1.1. Risk Governance

8. CoSAI

8.1. AI Incident Response Framework

8.1.1. 3.3.1. Preparation Phase - Risk Assessment & Threat Modeling

9. Microsoft

9.1. Cloud Adoption Framework - Secure AI

9.1.1. Discover AI security risks 4 - Conduct periodic risk assessments

9.2. Responsible AI Standard

9.2.1. A2.1

9.2.2. A2.2

9.2.3. A2.3

9.2.4. A5.7

9.2.5. T3.1

9.2.6. F3.7

9.2.7. RS2.1

9.2.8. RS2.2

9.2.9. RS3.3

9.2.10. RS3.4

9.2.11. RS3.6

10. Cloud Security Alliance (CSA)

10.1. AI Controls Matrix

10.1.1. A&A-06

10.1.2. AIS-01

10.1.3. BCR-01

10.1.4. BCR-02

10.1.5. CEK-06

10.1.6. CEK-07

10.1.7. CEK-20

10.1.8. DCS-05

10.1.9. DSP-09

10.1.10. DSP-21

10.1.11. GRC-02

10.1.12. GRC-03

10.1.13. GRC-09

10.1.14. GRC-10

10.1.15. IAM-08

10.1.16. I&S-08

10.1.17. MDS-01

10.1.18. MDS-06

10.1.19. MDS-11

10.1.20. MDS-12

10.1.21. STA-15

10.1.22. TVM-08

10.1.23. TVM-11

10.1.24. TVM-12

10.1.25. TVM-13

11. CISA

11.1. Principles for the Secure Integration of Artificial Intelligence in Operational Technology

11.1.1. 2.2.3 - Exposure of Sensitive Information

11.1.2. 4.1.2 - Understand the correctness of AI system results to support continued safe operation of systems in an OT environment.

11.1.3. 4.2.1 - Establish failsafe mechanisms that enable AI systems to fail gracefully without disrupting critical operations.

11.1.4. 4.2.3 - Incorporate AI considerations into the cybersecurity incident response plan.

12. NCSC/NSA/CISA etc

12.1. AI Data Security

12.1.1. 1.10 Conduct ongoing data security risk assessments

13. SANS

13.1. Critical AI Security Guidelines

13.1.1. 4.5 Modality

13.1.2. 4.6 Languages and Character Sets

14. OECD

14.1. Due Diligence Guidance for Responsible AI

14.1.1. Step 2.1 – Initial scoping of risks

14.1.2. Step 2.2 – In-depth assessment of most significant risks

14.1.3. Step 2.3 – Assess involvement with the actual or potential impact (cause, contribute, directly linked)

14.1.4. Step 2.4 – Prioritise the most significant (i.e., most salient) risks

14.1.5. Step 3.1 – Addressing risks that the enterprise causes or contributes to

15. IMDA

15.1. Model AI Governance Framework for Agentic AI

15.1.1. 2.1.1 Determine suitable use cases for agent deployment

16. SDAIA (Saudi Arabia)

16.1. AI Ethics Principles

16.1.1. Principle 5 – Reliability & Safety - Plan and Design - 2

16.1.2. Principle 7 – Accountability & Responsibility - Plan and Design - 2

16.2. Generative AI Guidelines

16.2.1. 4.5 Privacy & Security - 3

16.2.2. 4.5 Privacy & Security - 5

17. Cyber Security Council (UAE)

17.1. National Cyber Security Policy for Artificial Intelligence

17.1.1. 2.1.2

17.1.2. 2.2.4

17.1.3. 2.3.3

17.1.4. 3.1.2 Cyber Risk Management for AI/ML - 1

17.1.5. 3.1.2 Cyber Risk Management for AI/ML - 2

17.1.6. 3.1.2 Cyber Risk Management for AI/ML - 3

17.1.7. 3.1.2 Cyber Risk Management for AI/ML - 4

17.1.8. 3.1.2 Cyber Risk Management for AI/ML - 5

17.1.9. 3.1.4 Change Management and Reporting - 2

17.1.10. 3.2.2 Security Configuration Management - 2

17.1.11. 3.3.1 Security by Design for AI/ML Models - 2

17.1.12. 3.6.2 Incident Reporting and Management for AI/ML - 6

17.1.13. 3.6.3 Digital Forensics for AI/ML Security Incidents - 3

18. Smart Dubai (UAE)

18.1. AI Ethics Principles & Guidelines

18.1.1. 1.2.2.2

18.1.2. 1.2.2.3

19. Central Bank of the UAE

19.1. Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E

19.1.1. 2. Governance and Accountability - c

19.1.2. 2. Governance and Accountability - d

19.1.3. 2. Governance and Accountability - e

19.1.4. 8. Integration with Existing Frameworks - a

19.1.5. 8. Integration with Existing Frameworks - d

20. Qatar Central Bank

20.1. Artificial Intelligence Guidelines

20.1.1. 6.1

20.1.2. 6.2

20.1.3. 7.2

20.1.4. 7.6

20.1.5. 8.2.1

20.1.6. 9.1

20.1.7. 9.3

20.1.8. 9.4

20.1.9. 9.5

20.1.10. 9.5.1

20.1.11. 9.5.2

20.1.12. 9.6

20.1.13. 9.7

20.1.14. 9.8

20.1.15. 10.4

20.1.16. 12.3

20.1.17. 20.3

20.1.18. 20.9

20.1.19. 23.3

20.1.20. 23.5

21. MIC/METI (Japan)

21.1. AI Guidelines for Business

21.1.1. Human-Centric - 2 (b)

21.1.2. Safety - 1 (d)

21.1.3. Safety - 1 (e)

21.1.4. Ensuring security - 1 (c)

21.1.5. Ensuring security - 2

21.1.6. Accountability - 2

21.1.7. Accountability - 5 (a)

22. METI (Japan)

22.1. Governance Guidelines for Implementation of AI Principles

22.1.1. Action Target 1-3

22.1.2. Action Target 3-1

22.1.3. Action Target 3-1-1

22.1.4. Action Target 3-4-2

23. EU

23.1. EU AI Act

23.1.1. 9.1 Risk Management System

23.1.2. 9.2 Risk Management System

23.1.3. 9.3 Risk Management System

23.1.4. 9.4 Risk Management System

23.1.5. 9.5 Risk Management System

23.1.6. 9.6 Risk Management System

23.1.7. 9.9 Risk Management System

23.1.8. 9.10 Risk Management System

23.1.9. 55.8 Obligations of Providors of General-Purpose AI models with Systemic Risk

23.1.10. 55.9 Obligations of Providors of General-Purpose AI models with Systemic Risk

24. ISO/IEC

24.1. DIS 27090

24.1.1. 7.4

24.2. TR 27563:2023

24.2.1. 7.3

24.2.2. 7.4

24.2.3. 7.5

24.2.4. 7.6

24.2.5. 7.7

24.3. TR 27091

24.3.1. 6.3

24.4. TS 42119-2:2025

24.4.1. 6

25. CEN/CENELEC

25.1. prEN 40000-1-1

25.1.1. acceptable risk

25.1.2. residual cybersecurity risk

25.2. prEN 40000-1-2: Cybersecurity requirements for products with digital elements - Part 1-2: Principles for cyber resilience

25.2.1. 5.2

25.2.2. 6.3

25.2.3. 6.4

25.2.4. 6.6

25.2.5. 6.7

26. ENISA

26.1. Multilayer Framework for Good Cybersecurity Practices for AI

26.1.1. Networking 8

27. U.S. Department of Health & Human Services

27.1. Trustworthy AI (TAI) Playbook: Executive Summary

27.1.1. Safe / Secure

28. ICO

28.1. Guidance on the AI Auditing Framework - Draft guidance for consultation

28.1.1. How should we set a meaningful risk appetite?

28.1.2. What do we need to consider when undertaking data protection impact assessments for AI?

28.1.3. How do we identify and assess risks?

28.1.4. How do we identify mitigating measures?

28.1.5. How do we conclude our DPIA?

28.1.6. What’s different about security in AI compared to ‘traditional’ technologies?

28.1.7. Preventative Controls - 13

29. ISO

29.1. 42001:2023 - Information technology — Artificial intelligence — Management system

29.1.1. 6.1

29.1.2. 8.1

29.1.3. 8.2

29.1.4. 8.3

29.1.5. 8.4