QuestionQ141

AI Risk Management

After an organization has deployed an AI-based system, a regulator cautions that anonymized data sets face an increased risk of AI re-identification attacks. What should the information security manager do FIRST?

Explanation

De-identification reduces privacy risk but does not permanently eliminate the possibility of re-identification. A monitoring program with privacy audits and adversarial testing evaluates whether evolving AI capabilities can re-identify individuals and provides evidence for risk treatment. NIST recommends evaluating the risks created by de-identification and performing re-identification studies to gauge that risk.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!