nerdexam
Isaca

AAISM · Question #213

Which of the following should be done FIRST when developing an acceptable use policy for generative AI?

The correct answer is A. Determine the scope and intended use of AI. Defining the scope and intended use of AI is the foundational first step because it establishes what the policy must govern. Without knowing what AI tools are in scope, which use cases are permitted, and which business functions are affected, you cannot meaningfully review…

AI Security Strategy and Governance

Question

Which of the following should be done FIRST when developing an acceptable use policy for generative AI?

Options

  • ADetermine the scope and intended use of AI
  • BReview AI regulatory requirements
  • CConsult with risk management and legal
  • DReview existing company policies

How the community answered

(57 responses)
  • A
    93% (53)
  • B
    2% (1)
  • C
    2% (1)
  • D
    4% (2)

Explanation

Defining the scope and intended use of AI is the foundational first step because it establishes what the policy must govern. Without knowing what AI tools are in scope, which use cases are permitted, and which business functions are affected, you cannot meaningfully review regulations, consult legal/risk teams, or align existing policies. Scope determines context, and context drives all subsequent policy development activities. The other steps (B, C, D) are all downstream dependencies of this initial scoping decision.

Topics

#Acceptable Use Policy#Generative AI governance#Policy development#AI scope definition

Community Discussion

No community discussion yet for this question.

Full AAISM Practice