Building an AI Risk Management Program: A 安全 & 审核团队视角

大卫Kliemann
作者: 大卫Kliemann, Cloud Risk & 控制领导者,IBM云
发表日期: 2024年6月25日
阅读时间: 2 分钟

Generative AI is all the rage as organizations rush to figure out how they can “做人工智能.” 研究显示 that AI could add near US$16 trillion in economic value by 2030. But in order for organizations to fully take advantage, they need to implement trustworthy AI at the enterprise level.

365买球网站下载级的人工智能, 包括生成式人工智能, 需要高度的可持续性, compute-and-data intensive distributed infrastructure. Because AI workloads will likely form the backbone of mission-critical workloads and ultimately house and manage the most trusted data, the systems infrastructure must be trustworthy and resilient by design.

安全, risk and audit leaders need to understand there are a whole new set of risks that we need to do our part to ensure are mitigated; risks in addition to the security and privacy risks that we already are dealing with. It’s fundamental for organizations to develop a comprehensive AI risk management program that augments their current cyber, 风险和隐私程序.

在八月,期间 Building an AI Risk Management Program 会议 2024年GRC大会 在奥斯汀, 德州, I will review some of those key AI risks and leverage lessons from numerous cases across regulated industries of organizations that are trying to both solve the security, risk and compliance challenges while enabling their organizations to still move at the “speed of business.”

除了, while there have been numerous publications designed to provide guidance around understanding some of those AI-related risks (Nist ai RMF, 斜接阿特拉斯, IBM AI Adversarial Robustness 360). It’s key for organizations to have both an overall governance structure and a comprehensive framework of controls that are designed to actually mitigate those risks as part of that AI risk management program. 

In this session, one such framework, co-developed with the IBM Financial Services Cloud Council (a group of over 90 financial institutions), that is adapted specifically with Generative AI in mind will be highlighted. A framework such as this one can help organizations align with evolving industry standards and best practices, across the entire AI technology stack, agnostic of the specific solutions that they use, as they take that next step in their journey to leverage trustworthy AI. 

人工智能技术栈

和我一起来 2024年GRC大会 as we discuss how security and audit teams can help their organizations move down their AI path in a secure and trustworthy manner.

额外的资源