nerdexam
Isaca

AAISM · Question #99

Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?

The correct answer is C. Require opt-out provisions for data usage in service agreements. AAISM directs organizations to manage third-party AI risks through contractual and technical controls that explicitly govern data use, retention, training/fine-tuning, isolation, and deletion. The most effective data-security action when consuming generative AI features is to…

AI Security Risk Management

Question

Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?

Options

  • ARely on the AI provider's independent third-party audit reports for assurance
  • BEstablish policies and awareness training for acceptable use of AI
  • CRequire opt-out provisions for data usage in service agreements
  • DEstablish guidelines and best practices with third parties for intellectual property ownership

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    84% (31)
  • D
    5% (2)

Explanation

AAISM directs organizations to manage third-party AI risks through contractual and technical controls that explicitly govern data use, retention, training/fine-tuning, isolation, and deletion. The most effective data-security action when consuming generative AI features is to require enforceable opt-out provisions that prohibit the provider from using the organization's data for training or secondary purposes and that mandate retention limits and secure deletion.

Topics

#Generative AI security#Data security risk#Third-party risk management#Contractual agreements

Community Discussion

No community discussion yet for this question.

Full AAISM Practice