share_log

HITRUST Launches New AI Risk Management Assessment

HITRUST Launches New AI Risk Management Assessment

HITRUST推出新的人工智能風險管理評估
PR Newswire ·  08/21 08:00

First-of-its-kind assessment for AI risk management and governance

首次針對人工智能風險管理和治理的評估

FRISCO, Texas, Aug. 21, 2024 /PRNewswire/ -- HITRUST, the leader in enterprise risk management, information security, and compliance assurances, today announced the launch of its AI Risk Management (AI RM) Assessment, the industry's first comprehensive assessment approach for Artificial Intelligence (AI) risk management processes in an organization. The HITRUST AI Risk Management Assessment ensures that governance associated with implementing AI solutions is in place and can be effectively communicated by companies to management teams, boards of directors and others.

德克薩斯州弗里斯科,2024年8月21日/PRNewswire/ - HITRUST作爲企業風險管理、信息安全和合規保證領域的領導者,HITRUST今天宣佈推出其人工智能風險管理(AI RM)評估,這是業內首個針對組織中人工智能(AI)風險管理流程的綜合評估方法。HITRUST的AI風險管理評估確保在實施AI解決方案時與之相關的治理得到落地,並能夠有效地傳達給公司的管理團隊、董事會和其他相關人員。

The HITRUST approach is based on AI risk management expectations and outcomes through a clearly understandable approach to guide AI adopters and their leaders in their risk management efforts that also aligns with standards issued by both NIST and ISO/IEC. The HITRUST AI RM Assessment is fully supported by a complete assessment approach, SaaS platform, and eco-system that AI adopting companies can use to demonstrate that AI risk management outcomes are met. The offering provides an essential toolkit for benchmarking and reporting on the AI risk management efforts for any organization using or deploying AI-based technologies such as ML and LLMs, and addresses an essential step for organizations seeking to validate and communicate a comprehensive approach and leadership in addressing AI Risk Management.

HITRUST的方法基於人工智能風險管理的期望和結果,通過一種清晰易懂的方法來指導AI採用者及其領導者在風險管理方面的努力,同時也符合NISt和ISO/IEC發佈的標準。HITRUST AI RM評估得到完整評估方法、SaaS平台和生態系統的全面支持,採用人工智能的公司可以利用這些工具來證明達到了人工智能風險管理的預期結果。該產品提供了一個必不可少的工具包,用於對任何使用或部署基於人工智能技術(如機器學習和LLMs)的組織的人工智能風險管理工作進行基準測試和報告,併爲尋求驗證和傳達綜合方法和領導力以應對人工智能風險管理的組織提供了一個重要的步驟。

HITRUST has leveraged its years of experience to tackle AI risk management

HITRUST利用多年的經驗應對人工智能風險管理

Post this
發佈此貼

"Standards for AI risk management are evolving rapidly, and it is crucial for companies to address these principles with a thoughtful and comprehensive approach. Governance of this important and powerful capability is vital to unlocking the potential that AI offers, and risk management is critical to implementing AI responsibly." said Robert Booker, Chief Strategy Officer with HITRUST. "HITRUST has applied over 15 years of practical experience and a best in class assurance methodology to AI risk management. The result is an approach that organizations can use to demonstrate that they have established appropriate governance structures and meet essential risk management principles."

「人工智能風險管理的標準正在迅速發展,企業必須以一種深思熟慮和全面的方式解決這些原則。對於解鎖AI所提供潛力的重要和強大的能力,治理至關重要,而風險管理對於負責任地實施AI至關重要。」HITRUST首席戰略官Robert Booker表示,“HITRUST運用了超過15年的實際經驗和一種 最佳的分類保證方法論 針對人工智能風險管理。其結果是一種組織機構可以使用的方法,以證明他們建立了適當的治理結構並滿足基本的風險管理原則。

The HITRUST AI Risk Management Assessment is the second in a series of AI assurance solutions designed to address AI risk management and security. This comprehensive approach helps companies meet their governance responsibilities at any stage of AI deployment and is strongly recommended as a key starting point. Additionally, HITRUST will release its AI Security Certification Program in Q4 2024, which will include AI-specific control specifications incorporated in the HITRUST CSF and enhancements to the company's assurance methodologies, systems, and ecosystem. The AI security certification will deliver a highly trusted security assurance solution for AI-specific systems. Together, these two offerings are designed to complement each other, with AI RM serving as the ideal starting point, followed by AI security certification for specific AI deployments.

HITRUSt人工智能風險管理評估是一系列旨在解決人工智能風險管理和安全性的人工智能保證解決方案中的第二項。這種綜合方法可以幫助公司滿足在任何人工智能部署階段都需要履行的治理責任,並且強烈建議作爲關鍵的起點。此外,HITRUSt將在2024年第4季度發佈其人工智能安全認證計劃,該計劃將包括HITRUSt CSF中納入的人工智能特定控制規範以及公司的保證方法、系統和生態系統的改進。人工智能安全認證將爲人工智能特定系統提供高度可信的安全保證解決方案。這兩個產品共同設計,通過人工智能風險管理評估作爲理想的起點,然後是特定人工智能部署的人工智能安全認證。

All adopters of AI, including early adopters, need to demonstrate that they have effectively considered and managed the risks associated with AI. Until now, to address this critical need, governance and risk management teams have had to consider standards and references from numerous sources such as ISO/IEC and NIST to understand the risk management principles needed for AI governance and to then consider how to address and confirm those requirements.

人工智能的所有采用者,包括早期採用者,都需要證明他們已有效地考慮和管理與人工智能相關的風險。直到現在,爲了滿足這一關鍵需求,治理和風險管理團隊不得不考慮來自ISO/IEC和NISt等多個來源的標準和參考文獻,以了解人工智能治理所需的風險管理原則,然後考慮如何解決和確認這些要求。

Understanding AI risk management expectations and associated control requirements is foundational to implementing and documenting numerous risk management outcomes. The management lifecycle of these efforts is complex, as companies also often develop multiple and different approaches to socialize the risk management requirements across their organizations; to assemble information from different risk management teams; and to provide meaningful reports that identify the completion and maturity of those requirements. The HITRUST AI Risk Management Assessment leverages the proven HITRUST assessment platform and reporting capabilities to support clear understanding of the risk management requirements and outcomes, and generate reports for internal or external teams to demonstrate the requirements are met.

了解人工智能風險管理的期望和相關的控制要求是實施和記錄許多風險管理結果的基礎。這些工作的管理生命週期很複雜,因爲公司通常還會開發多種不同的方法來推廣風險管理要求,從不同的風險管理團隊收集信息,並提供有意義的報告,以確定這些要求的完成情況和成熟度。HITRUSt人工智能風險管理評估藉助經過驗證的HITRUSt評估平台和報告能力,支持清晰理解風險管理要求和結果,並生成報告以向內部或外部團隊證明已滿足這些要求。

"The total effort to address risk management at scale can take weeks or months of labor just to design and maintain an assessment approach, socialize that approach, and to prepare for the assessment work itself," said Bimal Sheth, EVP Standards Development & Assurance Operations at HITRUST. "Even then, there can be questions about completeness and quality and the work can be exhausting where the organization wishes to align to multiple industry standards."

「在面對大規模風險管理時,總的工作量可能需要數週或數月的工作時間才能設計和維護評估方法、社交化該方法,以及準備評估工作本身,」HITRUSt的標準開發與保障運營執行副總裁比馬爾·謝特表示。「即便如此,人們仍可能對完整性和質量提出質疑,如果組織希望與多個行業標準保持一致,工作可能會令人精疲力盡。」

As an accelerator for AI risk management, HITRUST has created an approach consisting of 51 comprehensive control requirements and a mapping to both NIST and ISO/IEC to illustrate coverage to the different standards and to address the recommendations of both. HITRUST has bundled the AI risk management control requirements with a 1-year subscription to MyCSF, HITRUST's powerful assessment SaaS platform tool, and a report credit for a HITRUST AI Risk Management Insights Report describing the state of AI Risk Management aligned with the language and recommendations of both standards. The HITRUST approach and solution provides an effective, efficient, and no-compromise solution to AI risk management requirement.

作爲AI風險管理的推動者,HITRUSt開發了一種方法,包括51個全面的控制要求,並與NISt和ISO/IEC進行了映射,以說明對不同標準的覆蓋範圍,並滿足兩者的建議。HITRUSt將AI風險管理控制要求與一年的MyCSF訂閱,HITRUST強大的評估SaaS平台工具和一份HITRUSt AI風險管理洞察報告捆綁在一起,該報告描述了與兩個標準的語言和建議保持一致的AI風險管理現狀。HITRUSt的方法和解決方案爲AI風險管理需求提供了一種有效、高效、不折衷的解決方案。

"HITRUST has leveraged its years of experience in information risk, security and compliance assurances to tackle AI risk management, providing a reliable foundation for organizations at any stage of their AI journey. We believe this should be the essential starting point for any organization engaging with AI and have designed it to be comprehensive and cost-effective for every organization." Added Jeremy Huval, Chief Innovation Officer with HITRUST. "The AI RM solution can be used as a self-assessment and benchmarking tool, or companies can engage one of over 100 HITRUST external assessor firms to validate and verify implementation. Finally, existing HITRUST customers can access the capability with a simple report credit to their existing subscriptions to MyCSF."

「HITRUSt在信息風險、安全和合規保障方面的多年經驗,幫助解決了AI風險管理問題,爲組織在其AI之旅的任何階段提供了可靠的基礎。我們認爲這應該成爲與AI交互的任何組織的必要起點,並設計成對每個組織來說都是全面且具有成本效益的。」HITRUSt的首席創新官傑里米·胡瓦爾補充道。「AI風險管理解決方案可以用作自我評估和基準測試工具,或者企業可以與100多家HITRUSt外部評估公司之一合作,驗證和核實其實施情況。最後,現有的HITRUSt客戶可以通過將簡要報告信用添加到其現有的MyCSF訂閱中來訪問該功能。」

The HITRUST AI Risk Management Assessment and Insights Report are available immediately. For more information about the HITRUST AI Assurance Program and to access the latest resources, visit HITRUST AI Hub or contact [email protected].

HITRUSt AI風險管理評估和洞察報告立即可用。欲了解有關HITRUSt AI保證計劃以及訪問最新資源的更多信息,請訪問 HITRUSt 人工智能中心或聯繫[email protected].

About HITRUST

關於HITRUST

HITRUST, the leader in enterprise risk management, information security, and compliance assurances, offers a certification system for the application and validation of security, privacy, and AI controls, informed by over 50 standards and frameworks. The company's threat-adaptive approach delivers the most relevant and reliable solution, including multiple selectable and traversable control sets, over 100 independent assessment firms, centralized quality reviews and certification, and a powerful SaaS platform enabling its program and ecosystem. For over 17 years, HITRUST has led the assurance industry and today is widely recognized as the most trusted solution to establish, maintain, and demonstrate security capabilities for risks management and compliance.

HITRUSt,在企業風險管理、信息安全和合規性保證方面是領先者,提供了一個認證系統,用於安全、隱私和人工智能控制的申請和驗證,參考了50多個標準和框架。公司的威脅適應性方法提供了最相關和可靠的解決方案,包括多個可選擇和可遍歷的控制集,超過100家獨立評估公司,中央質量審查和認證,以及一個強大的SaaS平台,實現其項目和生態系統。17年來,HITRUSt一直領導保證行業,如今被廣泛認爲是建立、維護並展示安全能力以管理風險和合規性的最可信賴方案。

For media inquiries, please contact:

媒體垂詢,請聯繫:

Leslie Kesselring
Kesselring Communications for HITRUST
[email protected]
503-358-1012

Leslie Kesselring
Kesselring Communications代表HITRUST
[email protected]
503-358-1012

SOURCE HITRUST Services Corp.

HITRUST服務公司的信息來源

声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論