
Securing AI as its developed and deployed: the NIST AI RMF
About this event
In recent years, with the arrival of AI, it seems many orgs and groups have focused on securing AI at a technical level. Mitre, OWASP, CSA, and others have developed various security frameworks for AI apps and models, but most of these focus on when they are deployed. But what about how we address the larger issues of creating and managing AI security? Thankfully this hasn’t been ignored, and thankfully we haven’t yet been overwhelmed with a large number of frameworks for this. NIST, maybe better known for things such as the cybersecurity and privacy frameworks and the like, has in recent years involved itself in AI, in part due to several executive orders. This has included the creation of the AI Risk Management Framework (AI RMF), which was rolled out in Jan 2023. This framework is intended to help incorporate “trustworthiness” considerations into the design, development, use, and evaluation of AI products, services, and systems. With this presentation, we will focus on the NIST AI RMF, how it is structured and how it may be used, as well as reviewing the many AI-related resources at NIST. We will touch on some of the other frameworks, many of which are already tied with the AI RMF, such as the ISO/IEC 42001. As NIST has announced they will start work on updating the AI RMF, most likely to version 1.1 as they have done with the CSF and Privacy frameworks, we will touch on what we know about this. Presenter Michael Brown, CISSP, HCISPP, CISA, CISM, CGEIT, CRISC, CDPSE, GSLC, GSTRT, GLEG, GSNA, Associate CCISO is an information security professional and leader with years of experience in IT and information security/cybersecurity. While a security consultant advisor, he worked with clients in the healthcare, financial, manufacturing, and other sectors to assess their security programs and work with them to improve and mature their security posture. He is now Security and Compliance Director for FRG Systems, ensuring their HITRUST and SOC compliance. He is experienced with a variety of security regulations, frameworks, and standards. A seasoned speaker and presenter, he has presented at SFISSA, BSides Tampa, St Pete, and Orlando, HackMiamiCon, and ISSA International. He is an ISSA Fellow and Secretary and past president of the South Florida Chapter of ISSA and is a member of ISACA, ISC2, Infragard, IAPP, and the CISO Society. He is currently working to implement an AI Security program at his company based on ISO/IEC 42001 and NIST AI RMF. He hopes to report on this progress at conferences in 2027.
Questions & comments
Ask the host anything — replies are visible to everyone.
—