版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
OpportunitiesforAIincyberdefenceUseofAIbycybersecurityteams
AustralianGovernment
AustraliansignalsDirectorate
AUSTRALIAN
DIRECTRATE
ASDGNA
cybrrty
centre
CscAutrs"·
communicationssecurityEstablishmentcanada
canadiancentre
forcybersecurity
centredelascuritdes
tcommunicationscanadacentrecanadien
pourlacyberscurit
Nationalcybersecuritycentre
NEWZEALAND
Nationalcybersecuritycentre
apartofGCHQ
Tableofcontents
Introduction· 4
Audience· 4
Thecybersecuritylandscapeisevolving· 5
IntegratingAIforcybersecurity· 7
SecurelyadoptingAI· 13
Conclusion· 17
Furtherinformation· 17
AppendixA:CybersecurityquestionsforAIvendors· 18
AppendixB:AIcapabilityquestionsforcybersecurityvendors· 21
.au
Introduction
Artificialintelligence(AI)israpidlyreshapingthecybersecuritylandscape.AshighlycapableAI
becomesmorewidelyavailable,maliciousactorsareusingittodelivercyberthreatsatgreaterscaleandspeed.Organisationsthatdon’tre-evaluateandimprovetheirdefenceswillremainvulnerabletotheseAI-enabledcyberthreats.
Cybersecurityhastraditionallyreliedonspecialisedteamsandreactiveworkflowstomanagerisk.Theseapproachesremainimportant,butthescaleandcomplexityofthemoderncybersecurity
landscapeincreasinglystrainthem.Heavydependenceonmanualprocessescanmakeitdifficulttoprioritiserisks,investigatepotentialthreatsandmaintainconsistentdefensivecoverage.
AIpresentsasignificantopportunityforcyberdefenders.Whenusedsafely,securelyandresponsiblyAIcan:
•strengthenprioritisationofcyberrisks
•improvedetectionofthreatsandvulnerabilities
•supportfasterresponseandrecovery
•reducerelianceonrepetitivemanualtasks.
Thisguidancewasco-sealbytheCanadianCentreforCyberSecurity(CyberCentre),theNew
ZealandNationalCyberSecurityCentre(NCSC-NZ)andtheUnitedKingdomNationalCyberSecurityCentre(NCSC-UK),andaddresseshoworganisationscanuseAItostrengthenorganisationalcybersecuritywhilemanagingtherisksofusingAI.ItoutlineshowthecybersecuritylandscapeisevolvinganddescribeshoworganisationscanuseAIalignedwiththe
Informationsecuritymanual
(ISM)
cybersecurityfunctionsofGovern,Identify,Protect,Detect,RespondandRecover.Italsosetsout
principlesforsecurelyadoptingAI,alongwithkeyquestionsforcyberdefenderstoaskAIvendorstosupportsecureuse.
Humanoversight,governanceand
SecurebyDesign
practicesremainessential.AIcansignificantlyenhancecybersecurity,butitisnotareplacementforstrongcybersecurityfundamentals.Poorly
designedorpoorlygovernedAIsystemscanintroducenewattackpaths.Thiscanoccurthrough
excessivesystemaccess,relianceonuntrustedinputs,orautomatedactionswithoutadequate
safeguards.Organisationsthatlackrobustidentityandaccessmanagement,secureconfiguration,patchmanagement,networksegmentation,monitoringandincidentresponseprocessesare
unlikelytoachievebettersecurityoutcomessimplybydeployingAI.
Audience
Thisguidancesupportscyberdefenders,suchasChiefInformationSecurityOfficersandseniorsecurityleaderswhoareresponsibleforcybersecuritystrategy,operationsandriskoutcomes.
Thepublicationassumesafoundationalunderstandingofcybersecurityconceptsandsupportsinformeddecision-makingaboutsafe,secureandresponsibleuseofAIwithincybersecurity.
4OpportunitiesforAIincyberdefence
OpportunitiesforAIincyberdefence5
Thecybersecurity
landscapeisevolving
ThecybersecuritylandscapeisrapidlyevolvingasmaliciousactorsincreasinglyuseAItoimprovethespeed,scaleandsophisticationofattacks.Toadapt,cyberdefenderscanuseAItostrengthenanalysis,prioritisationanddefensivedecisionmaking.
SpectrumofAIuseincybersecurity
OrganisationsareincreasinglyexploringhowAIcanbeusedtoenhancecybersecurityoutcomes.
Thefocusshouldremainonimprovingsecuritywithintheorganisation,notingthatsimplyidentifyingvulnerabilitiesdoesnot,onitsown,strengthensecurity.Withoutappropriatecontext,prioritisation
andremediation,poorlyimplementedAIusecouldintroduceadditionalriskratherthanreduceit.
OrganisationsshoulddrawonaspectrumofAIcapabilitiesdependingontheirobjectives,risk
appetiteandavailabletechnology.ThisspectrumrangesfromadvancedfrontierAImodels,throughtogeneralpurposelargelanguagemodels(LLM),toembeddedAIfeatureswithinexistingsecurity
tools.Foralistofquestionstosupportvendorassessment,refertoAppendicesAandB.
Attheleadingedge,frontierAImodelscanperformawidevarietyoftasksandreflectthe
capabilitiespresentintoday’smostadvancedmodels.ComparedtomorecommongenerativeAI
systems,frontierAIenablemorecomplexreasoning,broadertaskcoverage,andtighterintegrationwithtools,dataandoperationalworkflows.FrontierAIusealsocarriescostandsustainability
considerations,includingtokenconsumption,computedemandsandongoingoperational
expenditure.OrganisationsshouldconsiderthesefactorswhenselectingAImodels,ensuringthe
levelofmodelcapabilityiscommensuratewiththerequirementsandvalueoftheintendedusecase.
Inacybersecuritycontext,frontierAIshouldbeintegratedtoaugmentexistingtoolsandprocesses,ratherthandeployingitasastandalonesolution.Withincybersecurityoperations,organisations
achievesaferandmoreeffectiveAIusebydeployingmodernandfit-for-purposesecuritysoftware
thatconstrains,testsandgovernsAIcapabilitiestosupportspecificISMfunctions.
ThejointFiveEyes
statementurgesorganisationsleaderstouseAItostrengthendefence
.
Theapproachanorganisationtakeswilldependonwhatitistryingtoachieveandwhatithas
accessto.Alayeredstrategyallowsorganisationstocombinethesecapabilities,usingmore
advancedAIwhereappropriatewhileleveragingexistingtoolstoenhanceoperationalefficiency.
ThisensuresAIisusedtostrengthenexistingcybersecuritypracticesratherthanreplacethem,supportingsafe,secureandresponsibleadoptionacrosstheorganisation.
NoteveryorganisationcanadoptfrontierAIatthesamepace,especiallywhereresourcesand
skillsarelimited,creatinggapsbetweencyberdefenders.The
WorldEconomicForum
highlightsthatsmallerandpublic-sectororganisationsfacelowercyberresilience,withcriticalinfrastructureshowingparticularlylowconfidenceinrespondingtomajorincidents.
Thesechallengespointtotheneedforstrongerlocalreadiness,trustedpartnerships,andpracticalsupport.
6OpportunitiesforAIincyberdefence
AgenticAI
AgenticAIreferstoAIsystemsthatcanindependentlyplan,decideandtakeactionstoachievea
goal,ratherthansimplyrespondingtoindividualprompts.ThesesystemsuseadvancedAImodels,suchasLLMs,tounderstandtheirenvironmentandreasonaboutoptions.Theyarecombinedwithaccesstotools,data,memoryandworkflows,enablingthemtoactandoperatewithadegreeofautonomy.
UnliketraditionalAIorchatsystems,agenticAIactivelyworkstowardoutcomesevenwhen
objectivesarelooselydefined.Itcanoperatewithlimitedongoinghumanoversight,adaptits
behaviourbasedonresults,andinsomecasescreatesubtasksorsubagentstocompletecomplexwork.Whilehumanssetgoals,constraintsandpermissions,agenticAIsystemsexecutegoal
directedactionsovertimeratherthansimplyprovidingadviceoroutputs.
Formoreinformation,refertoourco-authoredpublicationbyCybersecurityandInfrastructure
SecurityAgency(CISA),NationalSecurityAgency(NSA),CanadianCentreforCyberSecurity(CCCS),NationalCyberSecurityCentreNewZealand(NCSC-NZ),NationalCyberSecurityCentre(NCSC-UK)on
CarefuladoptionofagenticAIservices
.
MaliciousactorsareleveragingAI
MaliciousactorsareincreasinglyleveragingAItoacceleratedevelopmentofcyberattacksand
deploythematscale.TheyembedAImodelsdirectlyintomaliciousworkflowstoautomate
reconnaissance,developattacktooling,analysecompromiseddataandgeneratetailoredmaliciousoutputs.Thisacceleratesvulnerabilitydiscovery,andshortensthetimebetweenvulnerability
discoveryandexploitation,leavingdefenderswithlesswarningandresponsetime.
AIalsolowersthetechnicalbarrierstoentry.LessskilledmaliciousactorscanuseAItoperformactivitiesthatpreviouslyrequiredspecialistexpertise,suchasproducingevasivemalware,
conductinglarge-scaledataanalysisorexecutingconvincingsocialengineeringcampaigns.
AsAIcapabilitiesbecomemoreaccessible,maliciousactorswillcontinuetoincreasethespeed,
scaleandimpactofmaliciouscyberoperations.Tostayahead,organisationsshouldstrengthendefensivecapabilitybyreinforcingcybersecurityfundamentals.Theseincludeminimisingattacksurface,promptlypatchingsystems,implementinglayereddefence-in-deptharchitectures,
increasingautomationandimprovingthreatdetection.Withoutcorrespondingadvancesin
defence,AI-enabledthreatsarelikelytoerodetheeffectivenessoftraditionalsecurityapproaches.
Forfurtherinformation,refertotheUnitedKingdom’sNationalCyberSecurityCentre’s(UK’sNCSC)
ImpactofAIoncyberthreatfromnowto2027
assessment.
OpportunitiesforAIincyberdefence7
IntegratingAIforcybersecurity
TheuseofAIforcybersecurityshouldalignwiththeISManditsassociatedcontrols.TheISMgroupscybersecurityprinciplesinto6functions:Govern,Identify,Protect,Detect,RespondandRecover.ThissectionoutlineshoworganisationscanapplyAIwithineachfunctiontosupportcybersecurity,as
illustratedinFigure1.
ManyAIusecasesinvolveprocessingsensitiveoperationalinformation.OrganisationsshouldapplyAIwhilemaintainingappropriatecontrolsandprotectinginformation,inlinewiththeirsecurityanddatahandlingobligations.Thisincludesenforcingleastprivilegeaccess,restrictingdataexposuretoAIsystems,validatingoutputsbeforeuseandmaintainingauditabilityofAI-assistedactions.
Organisationsshouldalsoundertakeongoingassessmentofcosts,benefitsandrisks,recognisingthatbothAIcapabilitiesandmaliciousactoruseofAIwillcontinuetoevolve.
GovernIdentifyProtectDetectRespondRecover
FrontierAImodels
Createlearningenvironments
Generatedynamicattackscenarios
Support activitiesSummarise&interpretinformation
Analyse&informrestorationactivities
AdvancevisibilityIdentifypatterns
SupportteamsIdentify issues
Analyse
data
Identify
gaps
Automate&enrichdiscovery
Figure1.ApplyingAIacrossthesixcybersecurityfunctions
8OpportunitiesforAIincyberdefence
Govern
Developandmaintainastrongandresilientcybersecurityculture
TheGovernfunctionfocusesonhowcybersecurityandcyberriskaredirected,understoodand
managedacrosstheorganisation.Itestablishesclearaccountability,decisionmakingstructureandoversightmechanismsthatconnectexecutiveleadershipwithtechnicalteams.Asthreatsevolve,
effectivegovernancesupportstimelyreviewandadaptationofpolicies,controlsandassurancearrangementstomaintainorganisationalresilience.
AI-specificthreatintelligencesharingshouldalsobestrengthened,leveragingASD’sACSC(includingitsPartnershipProgram:
.au/partnershipprogram
),theNationalCyberThreatNotificationSystem(NCTNS),andCISA’sAICybersecurityCollaborationPlaybooktosupporttimely,trustedcollaborationacrosspartners.
AsorganisationsadoptAIincybersecurity,governanceshoulddefineclearexpectationsforitsuse,oversight,andhumanaccountability.ThisincludesapplyingboundedautonomytokeepAIwithindefinedlimits,especiallyincriticalsystemsandsecurityoperations.ItalsorequiresrecoverabilitysoAIfunctionscanbesafelyrestrictedorrestored,ensuringoperationscontinueifsystemsfailorarecompromised.
AImaysupportorganisationsto:
•identifyinconsistenciesinriskevaluationacrossbusinessunits,systemsorprojects
•analysesupplychainrisks,includingsoftwaredependencies,vulnerabilityexposureandvendorsecuritypractices
•supportthecreationanduseofinventories,suchassoftwarebillofmaterials(SBOM)andcryptographicbillofmaterials(CBOM)
•strengthenpolicyinterpretationandcompliance,suchasusinganinternalAIassistantto
providecontextawareguidancebasedonorganisationalpoliciesandregulatoryrequirements
•prioritisecybersecuritydecisionsbasedonriskassessment.
OpportunitiesforAIincyberdefence9
Identify
Identifyassetsandassociatedsecurityrisks
TheIdentifyfunctionfocusesonunderstandingwhatassetsexistwithintheenvironmentandthesecurityrisksassociatedwiththem.Itestablishesvisibilityofsystems,software,dataandconfigurationstoenableinformedrisk-baseddecisions.
AImaysupportorganisationsto:
•enhanceassetdiscoverybyusingnetworktelemetrytoidentifyunmonitoredorhiddenassetsacrosstheenvironment
•prioritisepatchingdecisionsbyusingmultiplefactorsincludingseverityratings,exploitavailability,threatintelligenceandoperationalimpactofexploitation
•identifyandassessvulnerabilitychainingbylinkingmultiplelowerseverityvulnerabilitiesintoattackpaths
•identifyinsecureconfigurationsandrecommendremediationactions
•reviewlogsamplestoidentifyactionsanadversarycouldtakewithouttriggeringalerts,andassistwithrefiningdetectionlogic
•analyseSBOMsandCBOMstomapallsoftwarecomponentstoidentifyoutdatedlibraries,hiddenrisks,andsupplychainexposures
•mapAItrainingandfine-tuningdatasourcestoassessprovenance,retentionandpoisoningexposure.
Redteamscenario:AI-drivenattackpathanalysis
Anorganisation’sredteamusesasuitableAImodeltoanalyseitsenterpriseenvironment,
ingestingsystemarchitecture,identityrelationships,andvulnerabilitydataatscale.The
modelisconfiguredwithrelativelybroadpermissions,allowingittocorrelatefindingsacrossnetwork,applicationandaccesscontrollayers.
Overtime,theAIidentifieshowmultiplelow-andmedium-severityweaknessescancombineintomeaningfulattackpathsthatwouldbedifficultandtime-consumingforhumansto
detectmanually.Forexample,itlinksabenignmisconfiguration,excessivepermissionsandaminorsoftwareflawintoasequencethatcouldenableprivilegeescalationandlateral
movement.
Bycontinuouslygeneratingandrefiningthesescenarios,theredteamusesAItouncover
high-impactchainsthatarenotobviouswhenissuesareconsideredinisolation.This
improvestestingcoverageandhelpsorganisationprioritiseremediationbasedonreal-worldattackfeasibilityratherthanindividualvulnerabilityseverity.
FormoreinformationonSBOMs,refertotheUnitedStates’CybersecurityandInfrastructureSecurityAgency’s
ASharedVisionofSoftwareBillofMaterials(SBOM)forCybersecurity
.
10OpportunitiesforAIincyberdefence
Protect
Implementandmaintaincontrolstomanagesecurityrisks
TheProtectfunctionfocusesonimplementingandmaintainingsafeguardsthatreducethelikelihoodandimpactofcybersecurityincidents.Thisincludesmaintainingsecureconfigurations,managingidentitiesandaccess,reducingattacksurface,andensuringcontrolsremaineffectiveassystems
andthreatschange.
AImaysupportorganisationsto:
•prioritisehardeningactionsbasedonexploitabilityandenvironmentalcontexttoreducetheattacksurface
•enhancesecurityarchitecturebyevaluatingcomplexenvironments,trustboundariesanddataflowstosimulaterealisticattackpathsanddetectweaknesses
•analyseidentities,rolesandbehavioursofusersandagentstoidentifybreachesofleastprivilegeaccess,detectexcessiveorunintendedpermissions,andidentifyprivilegecreepororphanedaccounts
•analysereal-timetrafficpatternstoidentifypotentialsecuritythreats,includinganomalousorautonomousAIdrivenactivity,andrecommendimprovementstonetworksegmentationrules
•scansourcecode,infrastructureascode,andpipelinedefinitionstodiscovervulnerabilitiesandbusinesslogicflawsthatpattern-basedscannersmiss
•zero-trustandmoderndefensiblearchitecturesshouldextendtoAIagentsaswellashumanusers.Thisinvolvesreplacingstaticcredentialswithdynamictokensandenforcingclear
privilegeboundariesonwhatagentscanaccessandexecute.
Codereviewscenario:AIidentifyinghiddenvulnerabilities
AnorganisationdeploysanAItooltoreviewsourcecodethatautomaticallyanalyses
sourcecodewheneveradevelopersubmitschanges.Duringaroutineupdate,adeveloperintroducesafeaturethatprocessesuserinputandstoresitinadatabase.Whilethecode
functionsasintended,theAIidentifiesthattheinputisnotproperlyvalidatedbeforestorage.
Althoughthisissueappearsminorandwouldlikelypasstraditionalchecks,sincethesyntaxiscorrectandnoobviousruleisviolated,theAIrecognisesthebroadersecurityimplication.Ithighlightsthatamaliciousactorcouldexploitthisgaptoinsertmaliciousdata,potentiallyleadingtocompromise.
Byflaggingtheissueearly,theorganisationisabletocorrectthevalidationlogicbeforerelease.Thisreducestheriskofintroducingexploitablevulnerabilitiesintoproductionandstrengthensoverallsecuritywithoutslowingdevelopmenttime.
ForfurtherinformationonsecurityevaluationsofAI,refertotheFrontierModelForum’s
Technical
Report:ManagingAdvancedCyberRisksinFrontierAIFrameworks
,whichoutlinesemergingindustryviewsonhowfrontierAImodelscansupportcyberriskmanagement,includingtheidentificationofvulnerabilitiesandinsecuredefaults.
OpportunitiesforAIincyberdefence11
Detect
Detectandanalysecybersecurityeventstoidentifycybersecurityincidents
TheDetectfunctionfocussesonidentificationandanalysisofcybersecurityeventstoenablethe
timelydetectionofpotentialincidents.Itsupportscontinuousmonitoringacrosssystems,networksandidentitiestosurfaceanomalousactivityandemergingthreats.
AImaysupportorganisationsto:
•detectcybersecurityeventsandincidents,withanalystjudgementtovalidatefindings
•leverageframeworkssuchas
MITREATLAS
™,OWASPTop10forLLMApplications,OWASPTop10forAgenticApplication,NISTAIRMFGenerativeAIProfileandMAESTROthreatmodelto
informAIsupporteddetectionofmaliciousbehaviourstargetingAIenabledsystems
•analysenetworktelemetry(forexample,flows,logs,DomainNameSystem,andapplicationprogramminginterfacecalls)todetectanomalousbehaviour,suchasunexpected
communicationbetweenservicesorconnectionstoknownmaliciousendpoints
•detectAImisusethroughAI-specifictelemetry,suchasmodelinputs(includingpromptmanipulation),decisiontraces,policychecksandconfidencesignals,whileprotectingtheintegrityofdetectionlogsfromtampering
•analysebehaviourandconfigurationcontexttodistinguishlegitimateactivityfromsuspiciousactivitytominimisefalsepositivesandfalsenegatives
•baselinehigh-riskactivitiessuchasidentity,privilegedaccessandremoteaccesstoassistinanomalydetection.
Securityoperationscentreplatformscenario:AI-driventhreatdetectionandtriage
Anorganisationhasasecurityoperationscentre(SOC)platformthatusesAI-assisted
detectiontotriagealertsacrossidentity,endpoint,networkandcloudtelemetry.Tohelp
analystsmanagehighalertvolumes,theplatformcorrelatesdataacrosstheDomainNameSystem,applicationprogramminginterface(API)transactions,andnetworkflows.Italso
trackspatternsinprivilegedaccessandsurfacesprioritisedincidentsforanalystreview.
Overtime,theorganisationbuildsconfidenceintheplatform’sabilitytosuppressfalse
positivesandhighlightthealertsthatmattermost.TheAIcontinuouslyrefinesits
understandingofnormalandabnormalbehaviour,improvingdetectionaccuracyacrosstheenvironment.
Inthisscenario,theSOCplatformenablesanalyststoidentifyandrespondtothemostcriticalthreatsmorequickly,reducingresponsetimesandalleviatingoperationaloverloadwhile
maintainingstrongsecurityvisibility.
12OpportunitiesforAIincyberdefence
Respond
Respondtocybersecurityincidents
TheRespondfunctionfocusesoneffective,timelyandcoordinatedactionduringcybersecurityincidents.Itensuresorganisationscancontainandmitigateincidentswhilemaintainingcriticaloperations.
AImaysupportorganisationsto:
•assistanalystsbycorrelatingalerts,logsandforensicartefactsintoacoherentexplanationoftheincident
•interpretalertsandobservedsystemoruserbehavioursinthecontextoftheorganisation’sspecificsystems,architectureandriskenvironment
•reducerelianceonmanualsearchesduringinvestigations
•sequenceresponseactionsacrossidentity,endpointandnetworkcontrols
•draftincidentupdatesthatbridgerespondersandexecutivesbyaligningwithdefinedcommunicationexpectations,withrespondersvalidatingaccuracybeforedistribution
•augmentsurgecapacitybyautomatingtriageandpreparingorinitiatingpre-approvedandreversibleresponseactionsinparallelacrossconcurrentincidents,withhumanapproval
requiredforhigh-impactcontainment,disruption,recoveryorcommunicationdecisions,whichisespeciallycriticalinAI-drivenattackscenarios
•proposecontainmentandremediationactionsforuncertaincases,alignedwithorganisationalincidentresponseplaybooks,forreviewbyhumanincidentresponders.
Recover
Resumenormalbusinessoperationsfollowingcybersecurityincidents
TheRecoverfunctionfocusesonrestoringsystemsandservicesfollowingacybersecurityincidentsonormalbusinessoperationscansafelyresume.Itprioritisesandcontrolsrecoveryactivitiesbasedonverifiedsystemintegrityandacceptedresidualrisk.
AImaysupportorganisationsto:
•analyserebuildandrestorationpathwaystosupportrecoveryplanning,sequencingandassuranceactivities
•triggerautomatedrecoveryactionsandplaybookstoremediateimpactedassetsandreturnthemtoasecure,trustedstate,withhumanapprovalfordestructiveorirreversiblechangessuchassystemrestorationordatarollback
•validatesystemandservicerestorationsagainstknownbaselinestoconfirmintegritybeforeresumingoperations
•rollbackAImodelstopreviousversionswherecompromise,poisoningorunintendedmodeldriftissuspected
•verifytheintegrityandexpectedbehaviourofAImodelsandassociateddatathroughAI-specificvalidationchecksbeforere-enablingAI-augmentedorautonomousfunctions
•enablerapidandsaferesumptionofcriticalbusinessservicesbyidentifyingpotentialcascadingfailuresacrossinterconnectedsystemsandreducingtheriskofoccurrence
•generateandevaluaterecoverysequencesfornovelorcomplexincidenttypesthatfalloutsidepredefinedautomationorsecurityorchestration,automationandresponseplaybooks
•identifyweaknessesinrecoveryarrangements,dependenciesorassumptionsproactively,beforetheyareencounteredduringarealincident.
OpportunitiesforAIincyberdefence13
SecurelyadoptingAI
WhenadoptingAI,organisationsshouldprioritisestrongsecuritypractices.Whilenomitigation
strategycanprovidecompleteprotection,organisationsshouldimplementastrongcybersecuritybaselinealignedwithASD’s
ISM
andthe
EssentialEight
,tomateriallyreducecybersecurityrisk.
AsAIcapabilitiesandthecyberthreatenvironmentevolves,organisationsshouldregularlyreviewandupdatetheircontrolstoensureAIcontinuestobeusedsafely,securely,responsiblyandin
accordancewithorganisationalrisktolerance.Criticalinfrastructure(CI)shouldplaceparticularfocusonmaintainingresilient,continuouslyassuredcontrolsgivenitsheightenedriskandimpact.
DatareadinessisacoreprerequisiteforAIadoption.AIsupportedcyberdefencewillonlybeas
reliableastheunderlyingdataitdrawson,includingassetinventories,loggingcoverage,identity
andprivilegedata,vulnerabilityrecordsandconfigurationdata.Organisationsshouldassessand
upliftthequality,coverageandcurrencyofthisdatabeforeandduringAIadoption,recognisingthatgapsorinconsistencieswilldirectlylimittheaccuracyandvalueofAIgeneratedinsights.
AdoptingAIincyberdefencedependsonworkforcecapabilityasmuchastechnology.CyberdefendersshouldunderstandhowtouseAItoolseffectively,includinghowtovalidateoutputs,recogniselimitationsandavoidoverreliance.Organisationsshouldincorporatetheseskillsintoongoingworkforcedevelopmenttosupporteffectivehuman-AIteaming.
OrganisationsshouldalsoensureAIsystemsusedforcybersecurity,andAIsystemsused
operationally,areprotectedfromadversarialtechniquessuchaspromptinjection,modelevasionandmodelextraction,inlinewith
GuidelinesforsecureAIsystemdevelopment,
NationalInstituteofStandardsandTechnology’s(NIST)
AdversarialMachineLearning:ATaxonomyandTerminologyof
AttacksandMitigations(NISTAI100-2E2025)
and
MITREATLAS™
.
Humanoversight
AIshouldsupportcyberdefenders,notreplacehumanjudgment,particularlywheredecisionscouldaffecthighconsequencecyberorsafetyenvironments.AsAIsystemsbecomemorecapableand
beginrecommendingortakingactions,stronghumanoversightisessential.
AIuseintroducesrisksthatcandegradereliabilityifnotproperlymanaged.Theserisksinclude
hallucinatedormisleadingoutputs,adversarialmanipulation(suchaspromptinjectionormodel
evasion),overrelianceonAI,oversightfatigueandoperationalpressuresrelatedtoscale,availabilityorcost.
WhileAIcansignificantlyincreasespeedandscale,organisationsshouldverifyitsoutputsagainstevidenceandcontext.OngoingmonitoringandhumanoversighthelpensurethatAI-enabled
accelerationimprovesaccuracyandreliability,ratherthanintroducingnewerrors.
Organisationsshould:
•ensureAIsupports,rathe
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 临床执业医师(女性生殖系统)模拟试卷70
- 事业单位水利岗笔试模拟练习习题集含答案
- 幼儿教师模拟试题及答案
- 河北省涉县鹿头中学2027届数学八上期末达标检测试题含解析
- 2027届浙江湖州德清县数学七年级第一学期期末复习检测试题含解析
- 幼小衔接家长课:入园分离焦虑
- 四年级分水岭:给家长的7条建议
- 河南省郑中学国际学校2027届九上数学期末监测模拟试题含解析
- 中国银行业从业人员资格认证考试题库(含答案)
- 2026年危险货物水路运输从业资格考试题库(含答案)
- 公路工程交工验收施工总结报告
- 2026年上海市中考语文试卷(含答案)
- 2026年事业单位工勤技能岗位技术等级考试(汽车驾驶员·技师)题库附答案
- 【案例】某集团IT运维智能体(AIOps Agent)自主故障诊断与自愈平台详细设计方案
- 2026年浮选工(技师)技能鉴定精练考试题(附答案)
- 2026中国细胞培养基国产化替代进程与质量评价报告
- 太平保险在线测评题
- 人防地下室验收监理评估报告范例
- 积雪草保湿研究报告
- 科学护眼:眼保健操标准教程与实践指南
- 2025年北银金科技术笔试及答案
评论
0/150
提交评论