QuestionQ81

AI Risk Management

When using pre-trained AI models from third parties for customer due diligence in a highly regulated financial industry, which of the following is the PRIMARY security concern?

Explanation

The primary security concern is software supply-chain compromise: an unvalidated dependency or typosquatted package may introduce malicious code, vulnerabilities, or unauthorized access into a system that processes sensitive customer-due-diligence data. NIST supply-chain guidance treats third-party and open-source components as cybersecurity risks requiring verification and vulnerability management.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!