Replies: 10 comments 1 reply
-
|
My questions are:
|
Beta Was this translation helpful? Give feedback.
-
|
To my modest understanding security treats AI as any other software, there is no explicit reference to AI in most security standards, and when you conduct Threat Modeling on an AI system you will ask similar questions to a non-AI system (with different answers of course). |
Beta Was this translation helpful? Give feedback.
-
|
from what I see, OWASP is "practice driven" while regulations are "compliance driven". So imo there's a gap here, but I'd like to participate in the research and dig deeper. Additionally, latest OWASP 2025 is still to be released, so maybe AI-related security risks need to be evaluated now. As @oren-reshef fairly notes, EU AI Act only states that AI apps must be secure, which is far from helpful. I wonder, how they will assess security of a certain app if there's literally no stated requirements (or I'm not aware if they are stated somewhere). |
Beta Was this translation helpful? Give feedback.
-
|
curious cases: I generally enjoy reading https://incidentdatabase.ai |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
|
https://www.zerodayinitiative.com/advisories/published/ samt https://attackerkb.com/ |
Beta Was this translation helpful? Give feedback.
-
|
https://medium.com/digitalfrontiers/sast-dast-and-iast-explained-9324572a5d2b - SAST, DAST, IAST explained |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Research goal:
Explore how OWASP guidance and AI security practices compare and complement regulations/standards (NIST, EU AI Act, GDPR, ISO?).
Suggested structure:
• Why AI security is a priority.
• Why OWASP and standards/regulations both matter.
• Background on OWASP.
• Overview of AI-specific risks.
• Overview of regulations & standards (NIST AI RMF, GDPR, EU AI Act).
• How does OWASP Top 10 compare to NIST AI RMF and EU AI Act in addressing AI-related application security risks?
• To what extent can OWASP serve as a bridge between technical security practices and compliance with NIST and EU AI Act requirements?
• What are the gaps between OWASP guidelines and regulatory frameworks regarding AI-driven applications?
• What evidence exists in literature on using OWASP as a complementary tool for regulatory audits or certifications in AI systems?
• How do companies align OWASP practices with ISO certification or EU AI Act compliance in real projects?
• Recap of findings
Beta Was this translation helpful? Give feedback.
All reactions