nerdexam
Isaca

AAISM · Question #196

Cybersecurity teams should FIRST be embedded in the:

The correct answer is D. Model design phase. This reflects the 'security by design' or 'shift-left' principle: embedding cybersecurity at the model design phase allows threat modeling, security requirements, privacy-by-design considerations, and architectural risk decisions to be incorporated from the very beginning of…

AI Security Design and Implementation

Question

Cybersecurity teams should FIRST be embedded in the:

Options

  • AModel testing phase
  • BModel deployment phase
  • CModel training phase
  • DModel design phase

How the community answered

(18 responses)
  • C
    6% (1)
  • D
    94% (17)

Explanation

This reflects the 'security by design' or 'shift-left' principle: embedding cybersecurity at the model design phase allows threat modeling, security requirements, privacy-by-design considerations, and architectural risk decisions to be incorporated from the very beginning of the AI lifecycle. Identifying and addressing security issues at design is exponentially less costly than retrofitting controls later. Embedding security only at model training (C), testing (A), or deployment (B) means that fundamental architectural flaws and design-level vulnerabilities have already been baked in, making them far harder and more expensive to remediate.

Topics

#Secure by Design#AI Development Security#Early Security Integration

Community Discussion

No community discussion yet for this question.

Full AAISM Practice