From the course: Threat Modeling for AI/ML Systems

Unlock the full course today

Join today to access over 24,700 courses taught by industry experts.

Specific frameworks

Specific frameworks

- [Instructor] Each of the frameworks I've given you helps you find problems and address them. Security frameworks like OWASP Top 10 and the Berryville lists each point to how to solve each problem they identify. The AI Act and NIST's framework provide durable guidance around governance for AI programs. You can think of them as a foundation for the security work you do on products and services that contain machine learning, and especially in the case of the AI Act, act as a backstop that can help you get threats addressed. As I said earlier, if your organization isn't at least engaged in mapping, measuring, and managing AI risks, those are important to start on now, so the work you do in the future has consistency. The more technical frameworks, like those from OWASP and Berryville, are useful for figuring out how to address a threat. Once you know that you're at risk of prompt injection, you can use these frameworks to quickly find additional information. For example, each of the top…

Contents