nerdexam
Isaca

AAISM · Question #72

During the deployment of a generative AI platform, a risk assessment highlighted threats such as data leakage and prompt manipulation. Which of the following is the BEST way to ensure appropriate…

The correct answer is B. Map identified AI threats to enterprise control catalogs and integrate AI-specific safeguards where. AAISM requires that control selection be threat-led and context-specific, aligning AI threats to the organization's existing enterprise control catalogs (security, privacy, resilience) and augmenting them with AI-specific safeguards where coverage is insufficient. This ensures…

AI Security Risk Management

Question

During the deployment of a generative AI platform, a risk assessment highlighted threats such as data leakage and prompt manipulation. Which of the following is the BEST way to ensure appropriate control selection?

Options

  • ARely primarily on vendor-provided security features and seek third-party certifications
  • BMap identified AI threats to enterprise control catalogs and integrate AI-specific safeguards where
  • CApply AI-specific controls from external frameworks without customization and initiate monitoring
  • DPostpone control selection until deployment and address risk through enhanced monitoring

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    73% (16)
  • C
    5% (1)
  • D
    14% (3)

Explanation

AAISM requires that control selection be threat-led and context-specific, aligning AI threats to the organization's existing enterprise control catalogs (security, privacy, resilience) and augmenting them with AI-specific safeguards where coverage is insufficient. This ensures consistency with the risk appetite, removes duplication, and closes AI-unique gaps (e.g., prompt injection, data leakage from context windows, model misuse). Generic reliance on vendors or uncustomized external frameworks does not ensure fit-for-purpose coverage, and deferring control selection to post-deployment contradicts proactive risk treatment.

Topics

#AI risk management#Control selection#Threat mitigation#Generative AI security

Community Discussion

No community discussion yet for this question.

Full AAISM Practice