AIF-C01 notes
Security, compliance, and governance

Strategic Guidance for Security, Governance, and Compliance

  • Security protects the confidentiality, integrity, and availability of data, assets, and infrastructure.
  • Governance helps the organization add value and manage risk.
  • Compliance ensures adherence to requirements across the organization.

Defense in depth

Multiple redundant layers of security controls, so that if one fails, others still prevent, detect, respond to, and recover from threats. The layers:

  1. Policies, procedures, and awareness
  2. Identity and access management, with AWS IAM as the foundation
  3. Network and edge protection
  4. Infrastructure protection
  5. Application protection
  6. Data protection
  7. Threat detection and incident response

A high-level governance strategy

  • Create an AI governance board or committee: cross-functional, with legal, compliance, data privacy, and AI experts.
  • Define roles and responsibilities: oversight, policy making, risk assessment, decisions.
  • Implement policies and procedures covering the whole AI lifecycle, from data management to deployment and monitoring.

On this page