From the course: Advanced AI Threat Modeling and Risk Assessment

Unlock this course with a free trial

Join today to access over 26,000 courses taught by industry experts.

Key takeaways and next steps

Key takeaways and next steps

So we have this collection of frameworks. How do they all fit together? I want you to think of them more as your foundation, and they can be used a bit interchangeably. You might start off with STRIDE AI for your initial brainstorming after looking at the architecture diagrams. You'd use OWASP LLM Top 10 as your industry standard for LLM application vulnerabilities. These are the things you should try to make sure that your AI systems are not vulnerable to, what mitigating controls you have to prevent that. MITRE Atlas gives you a good idea of the real-world adversary tactics, especially when combined with MITRE ATT&CK. The NIST AI RMF is for risk prioritization and governance. When you think about the regulatory impacts that you might have, EU AI Act is a huge one. It's a good one to review and understand because I think a lot of other AI acts and regulatory compliance things are going to be very similar to the EU AI Act. No single framework is enough, you need to combine them all…

Contents