share_log

HITRUST Launches New AI Risk Management Assessment

HITRUST Launches New AI Risk Management Assessment

HITRUST推出新的人工智能风险管理评估
PR Newswire ·  08/21 08:00

First-of-its-kind assessment for AI risk management and governance

首创的人工智能风险管理和治理评估

FRISCO, Texas, Aug. 21, 2024 /PRNewswire/ -- HITRUST, the leader in enterprise risk management, information security, and compliance assurances, today announced the launch of its AI Risk Management (AI RM) Assessment, the industry's first comprehensive assessment approach for Artificial Intelligence (AI) risk management processes in an organization. The HITRUST AI Risk Management Assessment ensures that governance associated with implementing AI solutions is in place and can be effectively communicated by companies to management teams, boards of directors and others.

得克萨斯州弗里斯科,2024 年 8 月 21 日 /PRNewswire/ — HITRUST是企业风险管理、信息安全和合规保证领域的领导者,今天宣布推出其人工智能风险管理(AI RM)评估,这是业界首个针对组织人工智能(AI)风险管理流程的综合评估方法。HitRust 人工智能风险管理评估可确保与实施人工智能解决方案相关的治理机制到位,并且公司可以与管理团队、董事会和其他人进行有效的沟通。

The HITRUST approach is based on AI risk management expectations and outcomes through a clearly understandable approach to guide AI adopters and their leaders in their risk management efforts that also aligns with standards issued by both NIST and ISO/IEC. The HITRUST AI RM Assessment is fully supported by a complete assessment approach, SaaS platform, and eco-system that AI adopting companies can use to demonstrate that AI risk management outcomes are met. The offering provides an essential toolkit for benchmarking and reporting on the AI risk management efforts for any organization using or deploying AI-based technologies such as ML and LLMs, and addresses an essential step for organizations seeking to validate and communicate a comprehensive approach and leadership in addressing AI Risk Management.

HiTrust方法基于人工智能风险管理的预期和结果,通过一种清晰易懂的方法来指导人工智能采用者及其领导者的风险管理工作,这些工作也符合NiST和ISO/IEC发布的标准。HitRust AI Rm 评估由完整的评估方法、SaaS 平台和生态系统提供全面支持,采用人工智能的公司可以使用这些方法来证明人工智能风险管理结果已得到满足。该产品为任何使用或部署基于人工智能的技术(例如机器学习和LLM)的组织对人工智能风险管理工作进行基准测试和报告提供了一个必不可少的工具包,并为寻求验证和传达解决人工智能风险管理的全面方法和领导地位的组织提供了一个重要步骤。

HITRUST has leveraged its years of experience to tackle AI risk management

HitRust 利用其多年的经验来解决人工智能风险管理问题

Post this
发布这个

"Standards for AI risk management are evolving rapidly, and it is crucial for companies to address these principles with a thoughtful and comprehensive approach. Governance of this important and powerful capability is vital to unlocking the potential that AI offers, and risk management is critical to implementing AI responsibly." said Robert Booker, Chief Strategy Officer with HITRUST. "HITRUST has applied over 15 years of practical experience and a best in class assurance methodology to AI risk management. The result is an approach that organizations can use to demonstrate that they have established appropriate governance structures and meet essential risk management principles."

“人工智能风险管理的标准正在迅速发展,对于公司来说,以深思熟虑和全面的方法来实现这些原则至关重要。管理这一重要而强大的能力对于释放人工智能的潜力至关重要,风险管理对于负责任地实施人工智能至关重要。” HitRust首席战略官罗伯特·布克说。“HitRust 运用了超过 15 年的实践经验和 一流的保证方法 转到 AI 风险管理。结果是,各组织可以使用这种方法来证明他们已经建立了适当的治理结构并符合基本的风险管理原则。”

The HITRUST AI Risk Management Assessment is the second in a series of AI assurance solutions designed to address AI risk management and security. This comprehensive approach helps companies meet their governance responsibilities at any stage of AI deployment and is strongly recommended as a key starting point. Additionally, HITRUST will release its AI Security Certification Program in Q4 2024, which will include AI-specific control specifications incorporated in the HITRUST CSF and enhancements to the company's assurance methodologies, systems, and ecosystem. The AI security certification will deliver a highly trusted security assurance solution for AI-specific systems. Together, these two offerings are designed to complement each other, with AI RM serving as the ideal starting point, followed by AI security certification for specific AI deployments.

HitRust 人工智能风险管理评估是旨在解决人工智能风险管理和安全问题的一系列人工智能保障解决方案中的第二个。这种全面的方法可以帮助公司在人工智能部署的任何阶段履行其治理责任,强烈建议将其作为关键起点。此外,HiTrust将在2024年第四季度发布其人工智能安全认证计划,其中包括纳入HiTrust CSF的人工智能特定控制规范,以及对公司保障方法、系统和生态系统的增强。人工智能安全认证将为人工智能特定系统提供高度可信的安全保障解决方案。这两个产品组合在一起旨在相互补充,AI Rm 是理想的起点,其次是针对特定 AI 部署的 AI 安全认证。

All adopters of AI, including early adopters, need to demonstrate that they have effectively considered and managed the risks associated with AI. Until now, to address this critical need, governance and risk management teams have had to consider standards and references from numerous sources such as ISO/IEC and NIST to understand the risk management principles needed for AI governance and to then consider how to address and confirm those requirements.

所有人工智能采用者,包括早期采用者,都需要证明他们已有效考虑和管理了与人工智能相关的风险。到目前为止,为了满足这一关键需求,治理和风险管理团队必须考虑来自ISO/IEC和NiST等众多来源的标准和参考资料,以了解人工智能治理所需的风险管理原则,然后考虑如何满足和确认这些要求。

Understanding AI risk management expectations and associated control requirements is foundational to implementing and documenting numerous risk management outcomes. The management lifecycle of these efforts is complex, as companies also often develop multiple and different approaches to socialize the risk management requirements across their organizations; to assemble information from different risk management teams; and to provide meaningful reports that identify the completion and maturity of those requirements. The HITRUST AI Risk Management Assessment leverages the proven HITRUST assessment platform and reporting capabilities to support clear understanding of the risk management requirements and outcomes, and generate reports for internal or external teams to demonstrate the requirements are met.

了解人工智能风险管理预期和相关的控制要求是实施和记录众多风险管理成果的基础。这些工作的管理生命周期很复杂,因为公司还经常开发多种不同的方法来将整个组织的风险管理要求社交化;收集来自不同风险管理团队的信息;并提供有意义的报告来确定这些要求的完成情况和成熟度。HitRust AI 风险管理评估利用久经考验的 HitRust 评估平台和报告功能来支持对风险管理要求和结果的清晰理解,并为内部或外部团队生成报告,以证明要求已得到满足。

"The total effort to address risk management at scale can take weeks or months of labor just to design and maintain an assessment approach, socialize that approach, and to prepare for the assessment work itself," said Bimal Sheth, EVP Standards Development & Assurance Operations at HITRUST. "Even then, there can be questions about completeness and quality and the work can be exhausting where the organization wishes to align to multiple industry standards."

HitRust标准制定与保障运营执行副总裁Bimal Sheth表示:“仅设计和维护评估方法、实现该方法的社会化以及为评估工作本身做准备就可能需要数周或数月的劳动。”“即便如此,仍可能存在关于完整性和质量的问题,如果组织希望与多个行业标准保持一致,工作可能会令人筋疲力尽。”

As an accelerator for AI risk management, HITRUST has created an approach consisting of 51 comprehensive control requirements and a mapping to both NIST and ISO/IEC to illustrate coverage to the different standards and to address the recommendations of both. HITRUST has bundled the AI risk management control requirements with a 1-year subscription to MyCSF, HITRUST's powerful assessment SaaS platform tool, and a report credit for a HITRUST AI Risk Management Insights Report describing the state of AI Risk Management aligned with the language and recommendations of both standards. The HITRUST approach and solution provides an effective, efficient, and no-compromise solution to AI risk management requirement.

作为人工智能风险管理的加速器,HiTrust创建了一种方法,包括51项综合控制要求以及与NiST和ISO/IEC的对照表,以说明不同标准的覆盖范围并解决两者的建议。HitRust已将人工智能风险管理控制要求与Hitrust强大的SaaS评估平台工具myCSF的1年订阅以及HitRust人工智能风险管理洞察报告的报告来源捆绑在一起,该报告描述了人工智能风险管理的状况,该报告符合这两个标准的语言和建议。HiTrust 方法和解决方案为人工智能风险管理要求提供了有效、高效且不折不扣的解决方案。

"HITRUST has leveraged its years of experience in information risk, security and compliance assurances to tackle AI risk management, providing a reliable foundation for organizations at any stage of their AI journey. We believe this should be the essential starting point for any organization engaging with AI and have designed it to be comprehensive and cost-effective for every organization." Added Jeremy Huval, Chief Innovation Officer with HITRUST. "The AI RM solution can be used as a self-assessment and benchmarking tool, or companies can engage one of over 100 HITRUST external assessor firms to validate and verify implementation. Finally, existing HITRUST customers can access the capability with a simple report credit to their existing subscriptions to MyCSF."

“HitRust利用其在信息风险、安全和合规保证方面的多年经验来解决人工智能风险管理问题,为处于人工智能旅程任何阶段的组织提供了可靠的基础。我们认为,这应该是任何参与人工智能的组织的重要起点,并已将其设计为对每个组织都具有全面性和成本效益。”加入了HitRust首席创新官杰里米·胡瓦尔。“AI Rm解决方案可用作自我评估和基准测试工具,或者公司可以聘请100多家HitRust外部评估公司之一来验证和验证实施情况。最后,现有的HitRust客户可以通过一份简单的报告来访问该功能,这要归功于他们现有的myCSF订阅。”

The HITRUST AI Risk Management Assessment and Insights Report are available immediately. For more information about the HITRUST AI Assurance Program and to access the latest resources, visit HITRUST AI Hub or contact [email protected].

HitRust 人工智能风险管理评估和洞察报告立即发布。如需了解有关 HitRust 人工智能保障计划的更多信息并访问最新资源,请访问 HitRust 人工智能中心 或者联系 [电子邮件保护]

About HITRUST

关于 HITRUST

HITRUST, the leader in enterprise risk management, information security, and compliance assurances, offers a certification system for the application and validation of security, privacy, and AI controls, informed by over 50 standards and frameworks. The company's threat-adaptive approach delivers the most relevant and reliable solution, including multiple selectable and traversable control sets, over 100 independent assessment firms, centralized quality reviews and certification, and a powerful SaaS platform enabling its program and ecosystem. For over 17 years, HITRUST has led the assurance industry and today is widely recognized as the most trusted solution to establish, maintain, and demonstrate security capabilities for risks management and compliance.

HitRust是企业风险管理、信息安全和合规保证领域的领导者,为安全、隐私和人工智能控制的应用和验证提供认证体系,该体系以50多个标准和框架为依据。该公司的威胁自适应方法提供了最相关和最可靠的解决方案,包括多个可选择和可遍历的控制集、100多家独立评估公司、集中式质量审查和认证,以及支持其计划和生态系统的强大SaaS平台。在过去的17年中,HitRust一直处于保险行业的领先地位,如今已被广泛认为是建立、维护和展示风险管理和合规安全能力的最值得信赖的解决方案。

For media inquiries, please contact:

媒体垂询,请联系:

Leslie Kesselring
Kesselring Communications for HITRUST
[email protected]
503-358-1012

莱斯利·凯瑟林
HITRUST 的 Kesselring 通讯
[电子邮件保护]
503-358-1012

SOURCE HITRUST Services Corp.

来源 HitRust 服务公司

声明:本内容仅用作提供资讯及教育之目的,不构成对任何特定投资或投资策略的推荐或认可。 更多信息
    抢沙发