2023欧盟AI网络安全与标准化报告_第1页
2023欧盟AI网络安全与标准化报告_第2页
2023欧盟AI网络安全与标准化报告_第3页
2023欧盟AI网络安全与标准化报告_第4页
2023欧盟AI网络安全与标准化报告_第5页
已阅读5页,还剩32页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

CYBERSECURITYOFAIANDSTANDARDISATION

0

MARCH2023

CYBERSECURITYOFAIANDSTANDARDISATION

PAGE

10

ABBREVIATIONS

Abbreviation

Definition

AI

ArtificialIntelligence

CEN-CENELEC

EuropeanCommitteeforStandardisation–EuropeanCommitteeforElectrotechnicalStandardisation

CIA

Confidentiality,IntegrityandAvailability

EN

EuropeanStandard

ESO

EuropeanStandardisationOrganisation

ETSI

EuropeanTelecommunicationsStandardsInstitute

GR

GroupReport

ICT

InformationAndCommunicationsTechnology

ISG

IndustrySpecificationGroup

ISO

InternationalOrganizationforStandardization

IT

InformationTechnology

JTC

JointTechnicalCommittee

ML

MachineLearning

NIST

NationalInstituteofStandardsandTechnology

R&D

ResearchAndDevelopment

SAI

SecurityofArtificialIntelligence

SC

Subcommittee

SDO

Standards-DevelopingOrganisation

TR

TechnicalReport

TS

TechnicalSpecifications

WI

WorkItem

ABOUTENISA

TheEuropeanUnionAgencyforCybersecurity,ENISA,istheUnion’sagencydedicatedtoachievingahighcommonlevelofcybersecurityacrossEurope.Establishedin2004andstrengthenedbytheEUCybersecurityAct,theEuropeanUnionAgencyforCybersecuritycontributestoEUcyberpolicy,enhancesthetrustworthinessofICTproducts,servicesandprocesseswithcybersecuritycertificationschemes,cooperateswithMemberStatesandEUbodies,andhelpsEuropeprepareforthecyberchallengesoftomorrow.Throughknowledgesharing,capacitybuildingandawarenessraising,theAgencyworkstogetherwithitskeystakeholderstostrengthentrustintheconnectedeconomy,toboostresilienceoftheUnion’sinfrastructure,and,ultimately,tokeepEurope’ssocietyandcitizensdigitallysecure.MoreinformationaboutENISAanditsworkcanbefoundhere:

www.enisa.europa.eu.

CONTACT

Forcontactingtheauthorspleaseuse

team@enisa.europa.eu

Formediaenquiriesaboutthispaper,pleaseuse

press@enisa.europa.eu.

AUTHORS

P.Bezombes,S.Brunessaux,S.Cadzow

EDITOR(S)

ENISA:

E.Magonara

S.Gorniak

P.Magnabosco

E.Tsekmezoglou

ACKNOWLEDGEMENTS

WewouldliketothanktheJointResearchCentreandtheEuropeanCommissionfortheiractivecontributionandcommentsduringthedraftingstage.Also,wewouldliketothanktheENISAAdHocExpertGrouponArtificialIntelligence(AI)cybersecurityforthevaluablefeed-backandcommentsinvalidatingthisreport.

LEGALNOTICE

ThispublicationrepresentstheviewsandinterpretationsofENISA,unlessstatedotherwise.ItdoesnotendorsearegulatoryobligationofENISAorofENISAbodiespursuanttotheRegulation(EU)No2019/881.

ENISAhastherighttoalter,updateorremovethepublicationoranyofitscontents.Itisintendedforinformationpurposesonlyanditmustbeaccessiblefreeofcharge.AllreferencestoitoritsuseasawholeorpartiallymustcontainENISAasitssource.

Third-partysourcesarequotedasappropriate.ENISAisnotresponsibleorliableforthecontentoftheexternalsourcesincludingexternalwebsitesreferencedinthispublication.

NeitherENISAnoranypersonactingonitsbehalfisresponsiblefortheusethatmightbemadeoftheinformationcontainedinthispublication.

ENISAmaintainsitsintellectualpropertyrightsinrelationtothispublication.

COPYRIGHTNOTICE

©EuropeanUnionAgencyforCybersecurity(ENISA),2023

ThispublicationislicencedunderCC-BY4.0“Unlessotherwisenoted,thereuseofthisdocumentisauthorisedundertheCreativeCommonsAttribution4.0International(CCBY4.0)licence/licenses/by/4.0/).Thismeansthatreuseisallowed,providedthatappropriatecreditisgivenandanychangesareindicated”.

Coverimage©.

ForanyuseorreproductionofphotosorothermaterialthatisnotundertheENISAcopyright,permissionmustbesoughtdirectlyfromthecopyrightholders.

ISBN978-92-9204-616-3,DOI10.2824/277479,TP-03-23-011-EN-C

TABLEOFCONTENTS

TOC\o"1-2"\h\z\u

INTRODUCTION 8

DOCUMENTPURPOSEANDOBJECTIVES 8

TARGETAUDIENCEANDPREREQUISITES 8

STRUCTUREOFTHESTUDY 8

2.SCOPEOFTHEREPORT:DEFINITIONOFAIANDCYBERSECURITY

OFAI

9

2.1ARTIFICIALINTELLIGENCE

9

2.2CYBERSECURITYOFAI

10

3.STANDARDISATIONINSUPPORTOFCYBERSECURITYOFAI

12

3.1RELEVANTACTIVITIESBYTHEMAINSTANDARDS-DEVELOPINGORGANISATIONS

12

3.1.1CEN-CENELEC

12

3.1.2ETSI

13

3.1.3ISO-IEC

14

3.1.4Others

14

4.ANALYSISOFCOVERAGE

16

4.1STANDARDISATIONINSUPPORTOFCYBERSECURITYOFAI–NARROWSENSE

16

4.2STANDARDISATIONINSUPPORTOFTHECYBERSECURITYOFAI–TRUSTWORTHINESS

19

4.3CYBERSECURITYANDSTANDARDISATIONINTHECONTEXTOFTHEDRAFTAIACT

21

5.CONCLUSIONS

24

5.1WRAP-UP

24

5.2RECOMMENDATIONS

25

5.2.1Recommendationstoallorganisations

25

5.2.2Recommendationstostandards-developingorganisations

25

5.2.3RecommendationsinpreparationfortheimplementationofthedraftAIAct

25

5.3FINALOBSERVATIONS

26

AANNEX:

27

A.1SELECTIONOFISO27000SERIESSTANDARDSRELEVANTTOTHECYBERSECURITYOFAI

27

RELEVANTISO/IECSTANDARDSPUBLISHEDORPLANNED/UNDERDEVELOPMENT 29

CEN-CENELECJOINTTECHNICALCOMMITTEE21ANDDRAFTAIACTREQUIREMENTS 31

ETSIACTIVITIESANDDRAFTAIACTREQUIREMENTS 33

EXECUTIVESUMMARY

Theoverallobjectiveofthepresentdocumentistoprovideanoverviewofstandards(existing,beingdrafted,underconsiderationandplanned)relatedtothecybersecurityofartificialintelligence(AI),assesstheircoverageandidentifygapsinstandardisation.ItdoessobyconsideringthespecificitiesofAI,andinparticularmachinelearning,andbyadoptingabroadviewofcybersecurity,encompassingboththe‘traditional’confidentiality–integrity–availabilityparadigmandthebroaderconceptofAItrustworthiness.Finally,thereportexamineshowstandardisationcansupporttheimplementationofthecybersecurityaspectsembeddedintheproposedEUregulationlayingdownharmonisedrulesonartificialintelligence(COM(2021)206final)(draftAIAct).

ThereportdescribesthestandardisationlandscapecoveringAI,bydepictingtheactivitiesofthemainStandards-DevelopingOrganisations(SDOs)thatseemtobeguidedbyconcernaboutinsufficientknowledgeoftheapplicationofexistingtechniquestocounterthreatsandvulnerabilitiesarisingfromAI.Thisresultsintheongoingdevelopmentofadhocreportsandguidance,andofadhocstandards.

Thereportarguesthatexistinggeneralpurposetechnicalandorganisationalstandards(suchasISO-IEC27001andISO-IEC9001)cancontributetomitigatingsomeoftherisksfacedbyAIwiththehelpofspecificguidanceonhowtheycanbeappliedinanAIcontext.Thisconsiderationstemsfromthefactthat,inessence,AIissoftwareandthereforesoftwaresecuritymeasurescanbetransposedtotheAIdomain.

Thereportalsospecifiesthatthisapproachisnotexhaustiveandthatithassomelimitations.Forexample,whilethereportfocusesonsoftwareaspects,thenotionofAIcanincludebothtechnicalandorganisationalelementsbeyondsoftware,suchashardwareorinfrastructure.Otherexamplesincludethefactthatdeterminingappropriatesecuritymeasuresreliesonasystem-specificanalysis,andthefactthatsomeaspectsofcybersecurityarestillthesubjectofresearchanddevelopment,andthereforemightbenotmatureenoughtobeexhaustivelystandardised.Inaddition,existingstandardsseemnottoaddressspecificaspectssuchasthetraceabilityandlineageofbothdataandAIcomponents,ormetricson,forexample,robustness.

Thereportalsolooksbeyondthemereprotectionofassets,ascybersecuritycanbeconsideredasinstrumentaltothecorrectimplementationoftrustworthinessfeaturesofAIand–conversely

–thecorrectimplementationoftrustworthinessfeaturesiskeytoensuringcybersecurity.Inthiscontext,itisnotedthatthereisariskthattrustworthinessishandledseparatelywithinAI-specificandcybersecurity-specificstandardisationinitiatives.Oneexampleofanareawherethismighthappenisconformityassessment.

Lastbutnotleast,thereportcomplementstheobservationsabovebyextendingtheanalysistothedraftAIAct.Firstly,thereportstressestheimportanceoftheinclusionofcybersecurityaspectsintheriskassessmentofhigh-risksystemsinordertodeterminethecybersecurityrisksthatarespecifictotheintendeduseofeachsystem.Secondly,thereporthighlightsthelackofstandardscoveringthecompetencesandtoolsoftheactorsperformingconformityassessments.Thirdly,itnotesthatthegovernancesystemsdrawnupbythedraftAIActandthe

CybersecurityAct(CSA)1shouldworkinharmonytoavoidduplicationofeffortsatnationallevel.

Finally,thereportconcludesthatsomestandardisationgapsmightbecomeapparentonlyastheAItechnologiesadvanceandwithfurtherstudyofhowstandardisationcansupportcybersecurity.

1Regulation(EU)2019/881oftheEuropeanParliamentandoftheCouncilof17April2019onENISA(theEuropeanUnionAgencyforCybersecurity)andoninformationandcommunicationstechnologycybersecuritycertificationandrepealingRegulation(EU)No526/2013(CybersecurityAct)(https://eur-lex.europa.eu/eli/reg/2019/881/oj).

INTRODUCTION

DOCUMENTPURPOSEANDOBJECTIVES

Theoverallobjectiveofthepresentdocumentistoprovideanoverviewofstandards(existing,beingdrafted,underconsiderationandplanned)relatedtothecybersecurityofartificialintelligence(AI),assesstheircoverageandidentifygapsinstandardisation.ThereportisintendedtocontributetotheactivitiespreparatorytotheimplementationoftheproposedEUregulationlayingdownharmonisedrulesonartificialintelligence(COM(2021)206final)(thedraftAIAct)onaspectsrelevanttocybersecurity.

TARGETAUDIENCEANDPREREQUISITES

ThetargetaudienceofthisreportincludesanumberofdifferentstakeholdersthatareconcernedbythecybersecurityofAIandstandardisation.

Theprimaryaddresseesofthisreportarestandards-developingorganisations(SDOs)andpublicsector/governmentbodiesdealingwiththeregulationofAItechnologies.

Theambitionofthereportistobeausefultoolthatcaninformabroadersetofstakeholdersoftheroleofstandardsinhelpingtoaddresscybersecurityissues,inparticular:

academiaandtheresearchcommunity;

theAItechnicalcommunity,AIcybersecurityexpertsandAIexperts(designers,developers,machinelearning(ML)experts,datascientists,etc.)withaninterestindevelopingsecuresolutionsandinintegratingsecurityandprivacybydesignintheirsolutions;

businesses(includingsmallandmedium-sizedenterprises)thatmakeuseofAIsolutionsand/orareengagedincybersecurity,includingoperatorsofessentialservices.

Thereaderisexpectedtohaveadegreeoffamiliaritywithsoftwaredevelopmentandwiththeconfidentiality,integrityandavailability(CIA)securitymodel,andwiththetechniquesofbothvulnerabilityanalysisandriskanalysis.

STRUCTUREOFTHESTUDY

Thereportisstructuredasfollows:

definitionoftheperimeteroftheanalysis(Chapter

2

):introductiontotheconceptsofAIandcybersecurityofAI;

inventoryofstandardisationactivitiesrelevanttothecybersecurityofAI(Chapter

3

):overviewofstandardisationactivities(bothAI-specificandnon-AIspecific)supportingthecybersecurityofAI;

analysisofcoverage(Chapter

4

):analysisofthecoverageofthemostrelevantstandardsidentifiedinChapter3withrespecttotheCIAsecuritymodelandtotrustworthinesscharacteristicssupportingcybersecurity;

wrap-upandconclusions(Chapter

5

):buildingontheprevioussections,recommendationsonactionstoensurestandardisationsupporttothecybersecurityofAI,andonpreparationfortheimplementationofthedraftAIAct.

SCOPEOFTHEREPORT:DEFINITIONOFAIANDCYBERSECURITYOFAI

ARTIFICIALINTELLIGENCE

UnderstandingAIanditsscopeseemstobetheveryfirststeptowardsdefiningcybersecurityofAI.Still,acleardefinitionandscopeofAIhaveproventobeelusive.TheconceptofAIisevolvingandthedebateoverwhatitis,andwhatitisnot,isstilllargelyunresolved–partlyduetotheinfluenceofmarketingbehindtheterm‘AI’.Evenatthescientificlevel,theexactscopeofAIremainsverycontroversial.Inthiscontext,numerousforumshaveadopted/proposeddefinitionsofAI.2

Initsdraftversion,theAIActproposesadefinitioninArticle3(1):

‘artificialintelligencesystem’(AIsystem)meanssoftwarethatisdevelopedwithoneormoreofthetechniquesandapproacheslistedinAnnexIandcan,foragivensetofhuman-definedobjectives,generateoutputssuchascontent,predictions,recommendations,ordecisionsinfluencingtheenvironmentstheyinteractwith.ThetechniquesandapproachesreferredtoinAnnexIare:

Machinelearningapproaches,includingsupervised,unsupervisedandreinforcementlearning,usingawidevarietyofmethodsincludingdeeplearning;

logic-andknowledge-basedapproaches,includingknowledgerepresentation,inductive(logic)programming,knowledgebases,inferenceanddeductiveengines,(symbolic)reasoningandexpertsystems;

statisticalapproaches,Bayesianestimation,searchandoptimisationmethods

Box1:Example–DefinitionofAI,asincludedinthedraftAIAct

InlinewithpreviousENISAwork,whichconsidersitthedrivingforceintermsofAItechnologies,thereportmainlyfocusesonML.ThischoiceisfurthersupportedbythefactthatthereseemtobeageneralconsensusonthefactthatMLtechniquesarepredominantincurrentAIapplications.Lastbutnotleast,itisconsideredthatthespecificitiesofMLresultinvulnerabilitiesthataffectthecybersecurityofAIinadistinctivemanner.ItistobenotedthatthereportconsidersAIfromalifecycleperspective3.ConsiderationsconcerningMLonlyhavebeenflagged.

2Forexample,theUnitedNationsEducational,ScientificandCulturalOrganization(UNESCO)inthe‘Firstdraftoftherecommendationontheethicsofartificialintelligence’,andtheEuropeanCommission’sHigh-LevelExpertGrouponArtificialIntelligence.

3SeethelifecycleapproachportrayedintheENISAreportSecuringMachineLearningAlgorithms

(https:/

/www

.

enisa.europa.eu/publications/securing-machine-learning-algorithms).

Box2:Specificitiesofmachinelearning–examplesfromasupervisedlearningmodel4

MLsystemscannotachieve100%inbothprecisionandrecall.Dependingonthesituation,MLneedstotradeoffprecisionforrecallandviceversa.ItmeansthatAIsystemswill,onceinawhile,makewrongpredictions.ThisisallthemoreimportantbecauseitisstilldifficulttounderstandwhentheAIsystemwillfail,butitwilleventually.

ThisisoneofthereasonsfortheneedforexplainabilityofAIsystems.Inessence,algorithmsaredeemedtobeexplainableifthedecisionstheymakecanbeunderstoodbyahuman(e.g.,adeveloperoranauditor)andthenexplainedtoanenduser(ENISA,SecuringMachineLearningAlgorithms).

AmajorspecificcharacteristicofMListhatitreliesontheuseoflargeamountsofdatatodevelopMLmodels.Manuallycontrollingthequalityofthedatacanthenbecomeimpossible.Specifictraceabilityordataqualityproceduresneedtobeputinplacetoensurethat,tothegreatestextentpossible,thedatabeinguseddonotcontainbiases(e.g.forgettingtoincludefacesofpeoplewithspecifictraits),havenotbeendeliberatelypoisoned(e.g.addingdatatomodifytheoutcomeofthemodel)andhavenotbeendeliberatelyorunintentionallymislabelled(e.g.apictureofadoglabelledasawolf).

CYBERSECURITYOFAI

AIandcybersecurityhavebeenwidelyaddressedbytheliteraturebothseparatelyandincombination.TheENISAreportSecuringMachineLearningAlgorithms5describesthemultidimensionalrelationshipbetweenAIandcybersecurity,andidentifiesthreedimensions:

cybersecurityofAI:lackofrobustnessandthevulnerabilitiesofAImodelsandalgorithms,

AItosupportcybersecurity:AIusedasatool/meanstocreateadvancedcybersecurity(e.g.,bydevelopingmoreeffectivesecuritycontrols)andtofacilitatetheeffortsoflawenforcementandotherpublicauthoritiestobetterrespondtocybercrime,

malicioususeofAI:malicious/adversarialuseofAItocreatemoresophisticatedtypesofattacks.

Thecurrentreportfocusesonthefirstofthesedimensions,namelythecybersecurityofAI.Still,therearedifferentinterpretationsofthecybersecurityofAIthatcouldbeenvisaged:

anarrowandtraditionalscope,intendedasprotectionagainstattacksontheconfidentiality,integrityandavailabilityofassets(AIcomponents,andassociateddataandprocesses)acrossthelifecycleofanAIsystem,

abroadandextendedscope,supportingandcomplementingthenarrowscopewithtrustworthinessfeaturessuchasdataquality,oversight,robustness,accuracy,explainability,transparencyandtraceability.

Thereportadoptsanarrowinterpretationofcybersecurity,butitalsoincludesconsiderationsaboutthecybersecurityofAIfromabroaderandextendedperspective.Thereasonisthatlinksbetweencybersecurityandtrustworthinessarecomplexandcannotbeignored:therequirementsoftrustworthinesscomplementandsometimesoverlapwiththoseofAIcybersecurityinensuringproperfunctioning.Asanexample,oversightisnecessarynotonlyforthegeneralmonitoringofanAIsysteminacomplexenvironment,butalsotodetectabnormalbehavioursduetocyberattacks.Inthesameway,adataqualityprocess(includingdatatraceability)isanaddedvaluealongsidepuredataprotectionfromcyberattack.Hence,

4Besidestheonesmentionedinthebox,the‘FalseNegativeRate”andthe‘FalsePositiveRate”andthe‘Fmeasure”areexamplesofotherrelevantmetrics.

5https:/

/www.e

n

isa.europa.eu/publications/securing-machine-learning-algorithms

trustworthinessfeaturessuchasrobustness,oversight,accuracy,traceability,explainabilityandtransparencyinherentlysupportandcomplementcybersecurity.

STANDARDISATIONINSUPPORTOFCYBERSECURITYOFAI

RELEVANTACTIVITIESBYTHEMAINSTANDARDS-DEVELOPINGORGANISATIONS

ItisrecognisedthatmanySDOsarelookingatAIandpreparingguidesandstandardisationdeliverablestoaddressAI.Therationaleformuchofthisworkisthatwheneversomethingnew(inthisinstanceAI)isdevelopedthereisabroadrequirementtoidentifyifexistingprovisionsapplytothenewdomainandhow.Suchstudiesmayhelptounderstandthenatureofthenewandtodetermineifthenewissufficientlydivergentfromwhathasgonebeforetojustify,orrequire,thedevelopmentandapplicationofnewtechniques.Theycouldalsogivedetailedguidanceontheapplicationofexistingtechniquestothenew,ordefineadditionaltechniquestofillthegaps.

Still,inthescopeofthisreport,thefocusismainlyonstandardsthatcanbeharmonised.ThislimitsthescopeofanalysistothoseoftheInternationalOrganizationforStandardization(ISO)andInternationalElectrotechnicalCommission(IEC),theEuropeanCommitteeforStandardization(CEN)andEuropeanCommitteeforElectrotechnicalStandardization(CENELEC),andtheEuropeanTelecommunicationsStandardsInstitute(ETSI).CENandCENELECmaytransposestandardsfromISOandIEC,respectively,toEUstandardsundertheauspicesof,respectively,theViennaandFrankfurtagreements.

CEN-CENELEC

CEN-CENELECaddressesAIandCybersecuritymainlywithintwojointtechnicalcommittees(JTCs).

JTC13‘Cybersecurityanddataprotection’hasasitsprimaryobjectivetotransposerelevantinternationalstandards(especiallyfromISO/IECJTC1subcommittee(SC)27)asEuropeanstandards(ENs)intheinformationtechnology(IT)domain.Italsodevelops‘homegrown’ENs,wheregapsexist,insupportofEUdirectivesandregulations.

JTC21‘Artificialintelligence’isresponsibleforthedevelopmentandadoptionofstandardsforAIandrelateddata(especiallyfromISO/IECJTC1SC42),andprovidingguidancetoothertechnicalcommitteesconcernedwithAI.

JTC13addresseswhatisdescribedasthenarrowscopeofcybersecurity(seeSection2.2).ThecommitteehasidentifiedalistofstandardsfromISO-IECthatareofinterestforAIcybersecurityandmightbeadopted/adaptedbyCEN-CENELECbasedontheirtechnicalcooperationagreement.ThemostprominentidentifiedstandardsbelongtotheISO27000seriesoninformationsecuritymanagementsystems,whichmaybecomplementedbytheISO15408seriesforthedevelopment,evaluationand/orprocurementofITproductswithsecurityfunctionality,aswellassector-specificguidance,e.g.ISO/IEC27019:2017Informationtechnology–Securitytechniques–Informationsecuritycontrolsfortheenergyutilityindustry(seetheannex

A.1,

forthefulllistofrelevantISO27000seriesstandardsthathavebeenidentifiedbyCEN-CENELEC).

Inaddition,thefollowingguidanceandusecasedocumentsaredraftsunderdevelopment(someataveryearlystage)andexploreAImorespecifically.Itisprematuretoevaluatetheimpactsofthesestandards.

ISO/IECAWI27090,Cybersecurity–Artificialintelligence–Guidanceforaddressingsecuritythreatsandfailuresinartificialintelligencesystems:ThedocumentaimstoprovideinformationtoorganisationstohelpthembetterunderstandtheconsequencesofsecuritythreatstoAIsystems,throughouttheirlifecycles,anddescribeshowtodetectandmitigatesuchthreats.Thedocumentisatthepreparatorystage.

ISO/IECCDTR27563,Cybersecurity–ArtificialIntelligence–Impactofsecurityandprivacyinartificialintelligenceusecases:Thedocumentisatthecommitteestage.

Bydesign,JTC21isaddressingtheextendedscopeofcybersecurity(seeSection

4.2

),whichincludestrustworthinesscharacteristics,dataquality,AIgovernance,AImanagementsystems,etc.Giventhis,afirstlistofISO-IEC/SC42standardshasbeenidentifiedashavingdirectapplicabilitytothedraftAIActandisbeingconsideredforadoption/adaptionbyJTC21:

ISO/IEC22989:2022,Artificialintelligenceconceptsandterminology(published),

ISO/IEC23053:2022,Frameworkforartificialintelligence(AI)systemsusingmachinelearning(ML)(published),

ISO/IECDIS42001,AImanagementsystem(underdevelopment),

ISO/IEC23894,GuidanceonAIriskmanagement(publicationpending),

ISO/IECTS4213,Assessmentofmachinelearningclassificationperformance(published),

ISO/IECFDIS24029-2,Methodologyfortheuseofformalmethods(underdevelopment),

ISO/IECCD5259series:DataqualityforanalyticsandML(underdevelopment).

Inaddition,JTC21hasidentifiedtwogapsandhaslaunchedaccordinglytwoadhocgroupswiththeambitionofpreparingnewworkitemproposals(NWIPs)supportingthedraftAIAct.Thepotentialfuturestandardsare:

AIsystemsriskcatalogueandriskmanagement,

AItrustworthinesscharacterisation(e.g.,robustness,accuracy,safety,explainability,transparencyandtraceability).

Finally,ithasbeendeterminedthatISO-IEC42001onAImanagementsystemsandISO-IEC27001oncybersecuritymanagementsystemsmaybecomplementedbyISO9001onqualitymanagementsystemsinordertohavepropercoverageofAIanddataqualitymanagement.

ETSI

ETSIhassetupadedicatedOperationalCo-ordinationGrouponArtificialIntelligence,whichcoordinatesthestandardisationactivitiesrelatedtoAIthatarehandledinthetechnicalbodies,committeesandindustryspecificationgroups(ISGs)ofETSI.Inaddition,ETSIhasaspecificgrouponthesecurityofAI(SAI)thathasbeenactivesince2019indevelopingreportsthatgiveamoredetailedunderstandingoftheproblemsthatAIbringstosystems.Inaddition,alargenumberofETSI’stechnicalbodieshavebeenaddressingtheroleofAIindifferentareas,e.g.,zerotouchnetworkandservicemanagement(ISGZSM),healthTCeHEALTH)andtransport(TCITS).

ISGSAIisapre-standardisationgroupidentifyingpathstoprotectsystemsfromAI,andAIfromattack.Thisgroupisworkingonatechnicallevel,addressingspecificcharacteristicsofAI.Ithaspublishedanumberofreportsandiscontinuingtodevelopreportstopromoteawiderunderstandingandtogiveasetofrequirementsformoredetailednormativestandardsifsuchareproventoberequired.

Thefollowingarepublishedgroupreports(GRs)fromISGSAIthatapplytounderstandinganddevelopingprotectionstoandfromAI:

ETSIGRSAI-001:AIThreatOntology,

ETSIGRSAI-002:DataSupplyChainSecurity,

ETSIGRSAI-004:ProblemStatement,

ETSIGRSAI-005:MitigationStrategyReport,

ETSIGRSAI-006:TheRoleofHardwareinSecurityofAI.

ThefollowingworkitemsofISGSAIareindevelopment/pendingpublicationatthetimeofwriting:

ETSIDGRSAI-007:ExplicabilityandTransparencyofAIProcessing(pendingpublication),

ETSIDGRSAI-008:PrivacyAspectsofAI/MLSystems(finaldraft),

ETSIDGRSAI-009:ArtificialIntelligenceComputingPlatformSecurityFramework(pendingpublication),

ETSIDGRSAI-010:TraceabilityofAIModels(underdevelopment–earlydraft),

ETSIDGR/SAI-0011:Automatedmanipulationofmultimediaidentityrepresentations(earlydraft),

ETSIDGR/SAI-003:SecuritytestingofAI(stabledraft),

ETSIDGR/SAI-0012:CollaborativeAI(earlydraft).

Inadditiontotheworkalreadypublishedandbeingdeveloped,thegroupmaintainsa‘roadmap’thatidentifiesthelonger-termplanningofworkandhowvariousstakeholdersinteract.

Inaddition,asadirectconsequenceofthedraftAIActandtheCybersecurityAct,thefollowingpotentialfutureWIsarebeingdiscussed:AIreadinessandtransition,testing,andcertification.

TheworkinETSIISGSAIiswithinthewidercontextofETSI’sworkinAI,whichincludescontributionsfromtheotherETSIbodies,includingitscybersecuritytechnicalcommittee(TCCyber).Amongotherprojects,thecommitteeisspecificallyextendingTS102165-1,Methodsandprotocols;Part1:Methodandproformaforthreat,vulnerability,riskanalysis(TVRA).

ISO-IEC

ISO-IECcarriesoutitsworkonAIinJTC1SC42.Thelistintheannex

A.2

presentsthestandardspublishedorunderdevelopmentwiththeirpublicationtargetdates(unlessalreadymentionedintheprevioussections).

Others

AlmostallhorizontalandsectorialstandardisationorganisationshavelaunchedAI-relatedstandardisationactivitieswithverylittleconsistencyamongthem.ThereportLandscapeofAIstandardsAIstandardisat

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论