nerdexam
Isaca

AAISM · Question #195

A regulator warns of increased risk of AI re-identification attacks on anonymized datasets. What should the information security manager do FIRST?

The correct answer is C. Implement a monitoring program including privacy audits and adversarial testing. AAISM states that anonymization is not permanent and may be reversible through re- identification attacks. The first action should be to evaluate and measure the actual privacy risk - adversarial re-identification testing - privacy audits - monitoring for misuse This provides…

AI Security Risk Management

Question

A regulator warns of increased risk of AI re-identification attacks on anonymized datasets. What should the information security manager do FIRST?

Options

  • AAssume anonymization is permanent and continue operations
  • BImmediately delete anonymized datasets and suspend AI services
  • CImplement a monitoring program including privacy audits and adversarial testing
  • DEstablish strong access controls for services using anonymized data

How the community answered

(57 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    84% (48)
  • D
    9% (5)

Explanation

AAISM states that anonymization is not permanent and may be reversible through re- identification attacks. The first action should be to evaluate and measure the actual privacy risk - adversarial re-identification testing - privacy audits - monitoring for misuse This provides the factual basis needed before making destructive or operational decisions.

Topics

#AI privacy#Data re-identification#Risk management#Adversarial testing

Community Discussion

No community discussion yet for this question.

Full AAISM Practice