AAISM · Question #99
Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?
The correct answer is C. Require opt-out provisions for data usage in service agreements. AAISM directs organizations to manage third-party AI risks through contractual and technical controls that explicitly govern data use, retention, training/fine-tuning, isolation, and deletion. The most effective data-security action when consuming generative AI features is to…
Question
Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?
Options
- ARely on the AI provider's independent third-party audit reports for assurance
- BEstablish policies and awareness training for acceptable use of AI
- CRequire opt-out provisions for data usage in service agreements
- DEstablish guidelines and best practices with third parties for intellectual property ownership
How the community answered
(37 responses)- A3% (1)
- B8% (3)
- C84% (31)
- D5% (2)
Explanation
AAISM directs organizations to manage third-party AI risks through contractual and technical controls that explicitly govern data use, retention, training/fine-tuning, isolation, and deletion. The most effective data-security action when consuming generative AI features is to require enforceable opt-out provisions that prohibit the provider from using the organization's data for training or secondary purposes and that mandate retention limits and secure deletion.
Topics
Community Discussion
No community discussion yet for this question.