QuestionQ107

AI Technologies and Controls

When generative AI output data is created by a third party, which of the following MUST be established to protect against code-level vulnerabilities?

Explanation

Robust third-party contracts establish enforceable security requirements for suppliers, such as secure-development practices, vulnerability testing, disclosure, and remediation obligations. NIST supply-chain guidance recommends including secure development, delivery, operational support, and maintenance requirements in supplier agreements.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!