You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Assess and monitor the security posture of the AI supply chain -- model providers, training data sources, fine-tuning pipelines, and plugin/tool ecosystems.
Rationale
Enterprises increasingly depend on third-party models, APIs, and plugins. Compromises in the AI supply chain (model poisoning, backdoored plugins, training data contamination) represent a growing threat vector.
Proposed control
Name: AI Supply Chain Security
Tier: 02 (Enforce & Monitor)
ID: AISECA-02-008 (proposed)
Description
Assess and monitor the security posture of the AI supply chain -- model providers, training data sources, fine-tuning pipelines, and plugin/tool ecosystems.
Rationale
Enterprises increasingly depend on third-party models, APIs, and plugins. Compromises in the AI supply chain (model poisoning, backdoored plugins, training data contamination) represent a growing threat vector.
Implementation
NIST Mapping