Articoli correlati a The AI IT Security Implementation & Strategy™:...

The AI IT Security Implementation & Strategy™: Running the Program the Audit Proved You Needed (The Operating Discipline for AI Library™) - Rilegato

Libro 6 di 6: The Operating Discipline for AI Library?

Jordan, Stephen R.

 
9798996940271: The AI IT Security Implementation & Strategy™: Running the Program the Audit Proved You Needed (The Operating Discipline for AI Library™)

Sinossi

You ran the AI security audit. You have the model inventory, the non-human identity count, the vendor map, and the data flows. The audit committee accepted it. Then you walked back to your desk and realized the environment it describes changes every week. Someone deployed an agent on Tuesday. A vendor activated an AI feature inside a product you already own on Wednesday and did not tell you.

Nothing in the audit was wrong. An audit is an instrument for describing a state, and what a security leader is accountable for is a rate of change.

An audit produces a photograph. What you are accountable for is a moving object.

This is the book about what happens next.

The AI IT Security Implementation & Strategy is Volume VI of The Operating Discipline for AI Library and the second volume of its security pillar. It converts the audit's evidence base into a running program across the four domains a security leader owns: security governance and risk management, security operations, third-party and supply chain risk, and data protection and privacy.

Each domain receives three chapters that ask the same three questions in the same order. What has AI broken here, working from the artifacts the audit produced rather than from theory. How does the same technology rebuild the capability, because nothing operating at human speed can supervise decisions made at machine speed. And what does the endgame look like, closing with a one-year target operating model that names an owner, a cadence, a quarterly milestone, and a budget line.

Inside, you will build:

  • The Human Supervision Matrix, which defines machine autonomy per action class rather than per tool, so the policy survives the next product release instead of being reopened by it.
  • The Red-Button Protocol, which converts suspension from a paragraph in a policy document into a rehearsed capability with a named executor, a dependency map, and a measured time to confirmed stop.
  • The Agent Authority Chain, tracing delegation through six elements from human principal to agent to sub-agent to tool call, so that "who authorized this" has an answer that survives an inquiry.
  • Adaptive AI Trust Scores, replacing the annual vendor questionnaire with a continuously maintained measure that carries a direction, so a degrading vendor is visible before the renewal conversation rather than during it.
  • The AI Decision Provenance Chain, reconstructing what data went in, what processed it, what the decision was, and what could have altered it.
  • AI Security Debt, a countable register of accepted risk that carries an age dimension, because a three-year-old exception and a three-month-old exception are not the same governance failure.
  • The AI Security Scorecard, the quarterly board instrument, with the metric definitions and trend fields already structured.

A closing chapter sequences the first ninety days, because four domains launched at once with one team and one budget become zero programs by month four. The appendix supplies twenty-two working instruments as populatable worksheets, and a framework alignment section maps the guidance to the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, the OWASP top ten lists, MITRE ATLAS, and Google SAIF.

Written for chief information security officers, security directors, and security managers. No vendor is named anywhere in the book.

Somewhere ahead of you, on a date you do not control, someone will ask you to prove your AI exposure is governed. A regulator. An enterprise customer's security team. An insurance carrier at renewal. Or your own audit committee.

The audit tells you what is true today. The program keeps it true.

Le informazioni nella sezione "Riassunto" possono far riferimento a edizioni diverse di questo titolo.