What is the GREATEST benefit of performing AI security risk assessments?
AAISM emphasizes that the primary value of AI security risk assessments is prioritizing risks based on likelihood, impact, and business relevance.
Updating the register (A) is administrative. Privacy controls (B) are one category of mitigation. Funding (D) is possible but not the primary purpose.
============================================
A viral video shows a blurry person making claims about a product safety issue. The video has random low-quality sections. This MOST likely represents what threat?
AAISM defines deepfakes as manipulated media where individuals appear in synthetic or altered video/audio. Indicators include:
* blurred or inconsistent facial rendering
* mismatched frames
* low-quality or distorted transitions
These characteristics match the scenario provided.
Hallucinations (A) relate to model outputs, not video manipulation. Drift (B) affects model performance. Poisoning (C) affects training data, not video content.
An organization deploying an LLM is concerned input manipulations could compromise security. What is the MOST effective way to determine an acceptable risk threshold?
AAISM instructs that acceptable risk thresholds must be determined using business impact analysis. This aligns with the broader enterprise risk management principle of defining tolerances based on:
* potential harm
* regulatory exposure
* financial impact
* operational disruption
Monitoring (A) detects attacks but does not set thresholds. Blocking special characters (B) is unrealistic and overly restrictive. Static thresholds (D) ignore business context and practicality.
============================================
Which of the following is MOST important to ensure security throughout the AI data life cycle?
AAISM emphasizes data lineage, provenance tracking, and inventory completeness as essential controls to ensure data security and accountability across all AI data life-cycle phases. This enables detection of unauthorized modifications, improper use, and compliance violations.
Periodic reviews (B) are necessary but insufficient without lineage. Restricting third-party use (C) is one control but not comprehensive. Open-source model choice (A) does not secure data.
=============================================
The PRIMARY ethical concern of generative AI is that it may:
AAISM materials emphasize that the primary ethical concern with generative AI is the risk to information integrity. Generative models can create content that appears authentic but is fabricated, misleading, or manipulated. This undermines trust in information ecosystems and can have wide-reaching social, legal, and organizational impacts. While confidentiality breaches and bias are concerns, they are not the central ethical issue inherent to generative models. Availability is less relevant in this context. The most pressing concern is that generative AI may compromise the integrity of information.
AAISM Study Guide -- AI Risk Management (Ethical Risks of Generative AI)
ISACA AI Security Management -- Integrity Concerns in Generative Systems
Betty Stewart
11 days agoJeffrey Bell
24 days agoMatthew Carter
1 month agoBarbara Martin
2 months agoAndrew Anderson
2 months agoAmanda Thomas
3 months agoMichelle Bailey
2 months agoDennis Ramirez
2 months agoChristopher Flores
2 months agoChristopher Jones
2 months agoViola
3 months agoFranklyn
4 months agoThad
4 months agoRosio
4 months agoRebbeca
4 months agoJulie
5 months agoCarrol
5 months agoGiovanna
5 months agoKing
5 months agoRebeca
6 months agoDolores
6 months agoNovella
6 months agoRebecka
6 months agoYolando
7 months agoOlene
7 months agoLayla
7 months agoMarylyn
7 months agoElin
8 months agoMaddie
8 months agoDaniel
8 months agoTien
8 months agoLavonna
9 months agoMaynard
9 months agoTerry
9 months agoVirgina
9 months agoCarry
10 months agoStephaine
10 months agoJesus
10 months agoAbraham
10 months agoValene
10 months agoGracie
10 months agoJanine
10 months ago