NIST AI Risk Management Framework (AI RMF)
NIST AI Risk Management Framework (AI RMF) 是什么?
NIST AI Risk Management Framework (AI RMF)NIST's voluntary framework for managing AI risks, published January 2023 (AI RMF 1.0) with a Generative AI Profile released in July 2024, organized around four Functions: Govern, Map, Measure, and Manage.
The NIST AI Risk Management Framework (AI RMF 1.0), published 26 January 2023, is a voluntary, sector-agnostic framework for managing risks to individuals, organizations, and society from the design, development, deployment, and use of AI systems. It is structured around four core Functions: Govern (culture, policy, oversight), Map (context, characterization, risk identification), Measure (analysis and assessment of risks), and Manage (prioritization, response, communication). Each Function is broken into Categories and Subcategories with outcome statements rather than prescriptive controls. NIST released the Generative AI Profile (NIST AI 600-1) in July 2024, adding GenAI-specific risk categories (confabulation, dangerous-content generation, data privacy, environmental, human-AI configuration, information integrity, IP, obscene/sexual content, value chain) with mapped actions. AI RMF is increasingly referenced by regulators (it appears in the U.S. Executive Order 14110 and is mapped to ISO/IEC 42001 controls), used by enterprises as the structure for AI policies and red-team programs, and forms the basis of vendor questionnaires.
● 示例
- 01
An enterprise's AI governance committee adopts the Map/Measure/Manage/Govern structure as the table of contents for its internal AI risk policy.
- 02
A LLM red-team plan uses the NIST GenAI Profile's risk categories (confabulation, dangerous content, value chain) to scope test cases.
● 常见问题
NIST AI Risk Management Framework (AI RMF) 是什么?
NIST's voluntary framework for managing AI risks, published January 2023 (AI RMF 1.0) with a Generative AI Profile released in July 2024, organized around four Functions: Govern, Map, Measure, and Manage. 它属于网络安全的 合规与框架 分类。
NIST AI Risk Management Framework (AI RMF) 是什么意思?
NIST's voluntary framework for managing AI risks, published January 2023 (AI RMF 1.0) with a Generative AI Profile released in July 2024, organized around four Functions: Govern, Map, Measure, and Manage.
NIST AI Risk Management Framework (AI RMF) 是如何工作的?
The NIST AI Risk Management Framework (AI RMF 1.0), published 26 January 2023, is a voluntary, sector-agnostic framework for managing risks to individuals, organizations, and society from the design, development, deployment, and use of AI systems. It is structured around four core Functions: Govern (culture, policy, oversight), Map (context, characterization, risk identification), Measure (analysis and assessment of risks), and Manage (prioritization, response, communication). Each Function is broken into Categories and Subcategories with outcome statements rather than prescriptive controls. NIST released the Generative AI Profile (NIST AI 600-1) in July 2024, adding GenAI-specific risk categories (confabulation, dangerous-content generation, data privacy, environmental, human-AI configuration, information integrity, IP, obscene/sexual content, value chain) with mapped actions. AI RMF is increasingly referenced by regulators (it appears in the U.S. Executive Order 14110 and is mapped to ISO/IEC 42001 controls), used by enterprises as the structure for AI policies and red-team programs, and forms the basis of vendor questionnaires.
如何防御 NIST AI Risk Management Framework (AI RMF)?
针对 NIST AI Risk Management Framework (AI RMF) 的防御通常结合技术控制与运营实践,详见上方完整定义。
NIST AI Risk Management Framework (AI RMF) 还有哪些其他名称?
常见的别称包括: AI RMF 1.0, NIST AI 100-1, NIST AI 600-1。
● 相关术语
- compliance№ 624
ISO/IEC 42001
The first international management-system standard for AI, published in December 2023, specifying requirements to establish, implement, maintain, and continually improve an AI Management System (AIMS) for organizations that develop or use AI.
- ai-security№ 031
AI 治理
组织和监管机构用于确保 AI 系统以负责任、合法方式开发、部署与运营的政策、流程、角色与控制的总和。
- compliance№ 433
欧盟人工智能法案
欧盟第 2024/1689 号条例,确立基于风险方法的人工智能统一规则,于 2025 至 2027 年分阶段适用。
- ai-security№ 038
AI 安全(Safety)
致力于防止 AI 系统对用户、运营者及社会造成非预期危害的学科,涵盖技术、运营与社会三个维度。
- ai-security№ 036
AI 红队
针对 AI 系统模拟对抗者的专门团队,在真实攻击者之前发现安全、Safety 与滥用风险。
- compliance№ 818
NIST 网络安全框架
由美国国家标准与技术研究院发布的自愿性、基于风险的框架,将网络安全目标分为六大核心功能。
● 参见
- № 037AI Red Teamer