NIST AI Risk Management Framework (AI RMF)
Что такое NIST AI Risk Management Framework (AI RMF)?
NIST AI Risk Management Framework (AI RMF)NIST's voluntary framework for managing AI risks, published January 2023 (AI RMF 1.0) with a Generative AI Profile released in July 2024, organized around four Functions: Govern, Map, Measure, and Manage.
The NIST AI Risk Management Framework (AI RMF 1.0), published 26 January 2023, is a voluntary, sector-agnostic framework for managing risks to individuals, organizations, and society from the design, development, deployment, and use of AI systems. It is structured around four core Functions: Govern (culture, policy, oversight), Map (context, characterization, risk identification), Measure (analysis and assessment of risks), and Manage (prioritization, response, communication). Each Function is broken into Categories and Subcategories with outcome statements rather than prescriptive controls. NIST released the Generative AI Profile (NIST AI 600-1) in July 2024, adding GenAI-specific risk categories (confabulation, dangerous-content generation, data privacy, environmental, human-AI configuration, information integrity, IP, obscene/sexual content, value chain) with mapped actions. AI RMF is increasingly referenced by regulators (it appears in the U.S. Executive Order 14110 and is mapped to ISO/IEC 42001 controls), used by enterprises as the structure for AI policies and red-team programs, and forms the basis of vendor questionnaires.
● Примеры
- 01
An enterprise's AI governance committee adopts the Map/Measure/Manage/Govern structure as the table of contents for its internal AI risk policy.
- 02
A LLM red-team plan uses the NIST GenAI Profile's risk categories (confabulation, dangerous content, value chain) to scope test cases.
● Частые вопросы
Что такое NIST AI Risk Management Framework (AI RMF)?
NIST's voluntary framework for managing AI risks, published January 2023 (AI RMF 1.0) with a Generative AI Profile released in July 2024, organized around four Functions: Govern, Map, Measure, and Manage. Относится к категории Соответствие и стандарты в кибербезопасности.
Что означает NIST AI Risk Management Framework (AI RMF)?
NIST's voluntary framework for managing AI risks, published January 2023 (AI RMF 1.0) with a Generative AI Profile released in July 2024, organized around four Functions: Govern, Map, Measure, and Manage.
Как работает NIST AI Risk Management Framework (AI RMF)?
The NIST AI Risk Management Framework (AI RMF 1.0), published 26 January 2023, is a voluntary, sector-agnostic framework for managing risks to individuals, organizations, and society from the design, development, deployment, and use of AI systems. It is structured around four core Functions: Govern (culture, policy, oversight), Map (context, characterization, risk identification), Measure (analysis and assessment of risks), and Manage (prioritization, response, communication). Each Function is broken into Categories and Subcategories with outcome statements rather than prescriptive controls. NIST released the Generative AI Profile (NIST AI 600-1) in July 2024, adding GenAI-specific risk categories (confabulation, dangerous-content generation, data privacy, environmental, human-AI configuration, information integrity, IP, obscene/sexual content, value chain) with mapped actions. AI RMF is increasingly referenced by regulators (it appears in the U.S. Executive Order 14110 and is mapped to ISO/IEC 42001 controls), used by enterprises as the structure for AI policies and red-team programs, and forms the basis of vendor questionnaires.
Как защититься от NIST AI Risk Management Framework (AI RMF)?
Защита от NIST AI Risk Management Framework (AI RMF) обычно сочетает технические меры и операционные практики, как описано в определении выше.
Какие есть другие названия NIST AI Risk Management Framework (AI RMF)?
Распространённые альтернативные названия: AI RMF 1.0, NIST AI 100-1, NIST AI 600-1.
● Связанные термины
- compliance№ 624
ISO/IEC 42001
The first international management-system standard for AI, published in December 2023, specifying requirements to establish, implement, maintain, and continually improve an AI Management System (AIMS) for organizations that develop or use AI.
- ai-security№ 031
Управление ИИ (AI Governance)
Совокупность политик, процессов, ролей и средств контроля, с помощью которых организации и регуляторы обеспечивают ответственную и законную разработку, развёртывание и эксплуатацию ИИ-систем.
- compliance№ 433
Закон ЕС об ИИ
Регламент ЕС 2024/1689, устанавливающий гармонизированные правила в отношении ИИ на основе риск-ориентированного подхода, с поэтапным применением с 2025 по 2027 год.
- ai-security№ 038
Безопасность ИИ (AI Safety)
Дисциплина, цель которой — не допускать непреднамеренного вреда от ИИ-систем для пользователей, операторов и общества; охватывает технические, операционные и социальные аспекты.
- ai-security№ 036
AI Red Team
Специализированная команда, моделирующая противников против ИИ-систем, чтобы выявить риски безопасности, safety и злоупотреблений раньше реальных атакующих.
- compliance№ 818
NIST Cybersecurity Framework
Добровольная риск-ориентированная методика NIST (США), структурирующая цели кибербезопасности в шесть ключевых функций.
● См. также
- № 037AI Red Teamer