当前位置:首页 >英文主页 >中英对照 > 报告详情

云安全联盟(CSA):2024年AI组织责任研究报告:AI治理、风险管理、合规管理与文化构建 (英文版)(93页).pdf

上传人: Y**** 编号:182120 2024-11-21 93页 2.90MB

下载:

1、AI OrganizationalResponsibilities:Governance,Risk Management,Compliance and Cultural AspectsThe permanent and official location for the AI Organizational Responsibilities Working Group ishttps:/cloudsecurityalliance.org/research/working-groups/ai-organizational-responsibilities 2024 Cloud Security A

2、lliance All Rights Reserved.You may download,store,display on yourcomputer,view,print,and link to the Cloud Security Alliance at https:/cloudsecurityalliance.org subject tothe following:(a)the draft may be used solely for your personal,informational,noncommercial use;(b)the draft may not be modified

3、 or altered in any way;(c)the draft may not be redistributed;and(d)thetrademark,copyright or other notices may not be removed.You may quote portions of the draft aspermitted by the Fair Use provisions of the United States Copyright Act,provided that you attribute theportions to the Cloud Security Al

4、liance.Copyright 2024,Cloud Security Alliance.All rights reserved.2AcknowledgmentsLead AuthorsNick HamiltonKen HuangMichael RozaContributorsCandy AlexanderRomeo Ayalin IISaurav BhattacharyaPurnima BihariMarina BregkouSergei ChaschinHong ChenJosh ChristieRocelli CoracheaSatchit DokrasSemih GeliliJan

5、GerstRajiv GunjaJerry HuangOnyeka IllohKrystal JacksonAashita JainVamsi KaipaGian KapoorBen Kereopa-YorkeChris KirschkeHadir LabibMadhavi NajanaIkechukwu OkoliGovindaraj PalanisamyParesh PatelLars RuddigkeitBhuvaneswari SelvaduraiAlex SharpeEric TierlingCatalin TiganilaAshish VashishthaPeter Ventura

6、Sean WrightSounil YuReviewersIlango AllikuzhiDaniele CattedduAnton ChuvakinJoseph EmerickOdun FadahunsiSharat GaneshDebrup GhoshArpitha KaushikVaibhav MalikTaresh MehraMayur PahwaMaria Schwenger MjAkram SheriffYuanji SunMark SzalkiewiczRakesh VenugopalWickey WangRajashekar YasaniCSA Global StaffMari

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要讨论了人工智能(AI)组织责任中的治理、风险管理和合规性以及文化方面。文章首先介绍了六个跨领域关注点,包括评估标准、RACI模型、高阶实施策略、持续监控和报告、访问控制以及适用框架和法规。然后,文章详细讨论了风险管理、治理和合规性、安全文化和培训以及防止影子AI等关键领域。在风险管理部分,文章讨论了威胁建模、风险评估、攻击模拟、事件响应计划、运营弹性、审计日志和活动监控、风险缓解以及数据漂移监控。在治理和合规性部分,文章讨论了AI安全政策、流程和程序、审计、董事会报告、法律监管要求、可衡量/可审核的控制措施、欧盟AI法案、美国关于开发安全、可靠、可信赖AI的行政命令等。在安全文化和培训部分,文章讨论了基于角色的教育、意识建设、负责任的AI培训和沟通与报告。在防止影子AI部分,文章讨论了AI清单、差距分析、未授权系统识别、访问控制、活动监控和变更控制流程。
如何在AI中实施有效的风险管理? 如何确保AI系统的合规性和治理? 如何培养安全文化和AI培训?
客服
商务合作
小程序
服务号
折叠