AIF-C01 notes
Security, compliance, and governance

Strategic Guidance for Security, Governance, and Compliance

Concepts of security, governance, and compliance in organizations

Security, governance, and compliance might seem like the same function. The following are examples of the primary goals of each:

  • Security: Ensure that confidentiality, integrity, and availability are maintained for organizational data and information assets and infrastructure. This function is often called information security or cybersecurity in an organization.
  • Governance: Ensure that an organization can add value and manage risk in the operation of business.
  • Compliance: Ensure normative adherence to requirements across the functions of an organization.

Organizations implement security, governance, and compliance functions to assure that they can deliver on their primary business. Sometimes the requirements for these functions are referred to as the most important requirements, or the things that must not be sacrificed in product development or delivery.

Defense in depth

Defense in depth for AI on AWS

This course focuses on one of the most common paradigms, known as defense in depth, that organizations follow to integrate their security, governance, and compliance functions while building on AWS. Here are some features of a defense in depth security strategy:

  • A defense in depth security strategy uses multiple redundant defenses to protect your AWS accounts, workloads, data, and assets. It helps make sure that if any one security control is compromised or fails, additional layers exist to help isolate threats and prevent, detect, respond, and recover from security events.
  • Applying a defense in depth security strategy to generative AI workloads, data, and information can help create the best conditions to achieve business objectives. Defense-in-depth security mitigates many of the common risks that any workload faces by layering controls, helping teams govern generative AI workloads using familiar tools.
  • You can use a combination of strategies, including AWS and AWS Partner services and solutions, at each layer to improve the security and resiliency of your generative AI workloads.

Seven layers are shown from the innermost to the outermost. Each layer is explained in the interactive information markers.

2: Identity and access management

2: Identity and access management

Identity and access management ensures that only authorized users, applications, or services can access and interact with the cloud infrastructure and its services.

AWS offers several services that can be used for identity and access management. The fundamental service is AWS Identity and Access Management (IAM).

You will learn more about security later in the course.

Developing a high-level strategy for governance and compliance

High-level strategy for governance and compliance

Developing a high-level governance and compliance strategy for an organization producing AI solutions is important for ensuring the responsible deployment of these technologies. To begin, you might consider the following:

  • Establish an AI governance framework
  • Address AI compliance considerations

Governance framework

The following is an example approach for establishing a governance framework.

  • Establish an AI governance board or committee: This cross-functional team should include representatives from various departments, such as legal, compliance, data privacy, and subject matter experts in AI development.
  • Define roles and responsibilities: Clearly outline the roles and responsibilities of the governance board, including oversight, policy-making, risk assessment, and decision-making processes.
  • Implement policies and procedures: Develop comprehensive policies and procedures that address the entire AI lifecycle, from data management to model deployment and monitoring.

You will learn more about governance and compliance later in the course.

Additional resources

Architect defense-in-depth security for generative AI applications

For a detailed discussion about the defense-in-depth security architecture, choose the following link.

AWS Blog

Governance Perspective: Managing an AI-Driven Organization

To learn more about the AWS AI governance perspective, choose the following link.

AWS Whitepaper

AWS Compliance

To learn about the AWS compliance offerings, choose the following link.

AWS Webpage

Next, you will learn about applying governance and compliance for AI systems.

On this page