Skip to content
This repository was archived by the owner on Jul 28, 2026. It is now read-only.
This repository was archived by the owner on Jul 28, 2026. It is now read-only.

Propose new control: AI Supply Chain Security #5

Description

@amberb617

Proposed control

Name: AI Supply Chain Security
Tier: 02 (Enforce & Monitor)
ID: AISECA-02-008 (proposed)

Description

Assess and monitor the security posture of the AI supply chain -- model providers, training data sources, fine-tuning pipelines, and plugin/tool ecosystems.

Rationale

Enterprises increasingly depend on third-party models, APIs, and plugins. Compromises in the AI supply chain (model poisoning, backdoored plugins, training data contamination) represent a growing threat vector.

Implementation

  • Model provenance tracking (SBOM for AI)
  • Third-party model security assessments
  • Plugin/tool vetting processes
  • Training data lineage documentation
  • Dependency monitoring for AI libraries

NIST Mapping

  • MAP 5.1 (Third-party risks)
  • GOVERN 5.1 (Policies for third-party AI)
  • MANAGE 3.1 (Pre-deployment risk management)

Metadata

Metadata

Assignees

No one assigned

    Labels

    communityCommunity contribution welcomenew-controlProposal for a new security controltier-02Tier 02 Enforce and Monitor

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions