AWS wellarchitected medium security documentation change
Summary
Added AI-specific incident reporting requirements (model manipulation, poisoning attacks) and expanded incident response procedures to include AI playbooks and reporting
Security assessment
Changes address emerging AI security threats by explicitly adding model manipulation and poisoning attacks to incident reporting. The new playbooks and procedures directly respond to security vulnerabilities in AI systems, showing concrete expansion of incident response to cover AI-specific attack vectors.
Diff
diff --git a/wellarchitected/latest/financial-services-industry-lens/fsisec12.md b/wellarchitected/latest/financial-services-industry-lens/fsisec12.md index 1441981fd..e7317d961 100644 --- a//wellarchitected/latest/financial-services-industry-lens/fsisec12.md +++ b//wellarchitected/latest/financial-services-industry-lens/fsisec12.md @@ -9 +9 @@ FSISEC12-BP01 Regularly review your incident response plan for regulatory compli -Various regulations require that the banking organizations and managed service providers notify the regulators as soon as a cyber security incident has been discovered, such as the [Final Issuances](https://www.occ.treas.gov/topics/laws-and-regulations/occ-regulations/final-issuances/index-final-issuances.html) published by the Office of the Comptroller of the Currency (OCC), Security and Exchanges Commision (SEC) [Cybersecurity Disclosure](https://www.sec.gov/news/statement/gerding-cybersecurity-disclosure-20231214) or the Network and Information Systems (NIS) regulation. +Various regulations require that the banking organizations and managed service providers notify the regulators as soon as a cyber security incident has been discovered, such as the [Final Issuances](https://www.occ.treas.gov/topics/laws-and-regulations/occ-regulations/final-issuances/index-final-issuances.html) published by the Office of the Comptroller of the Currency (OCC), Security and Exchanges Commision (SEC) [Cybersecurity Disclosure](https://www.sec.gov/news/statement/gerding-cybersecurity-disclosure-20231214) or the Network and Information Systems (NIS) regulation. Incident reporting now includes AI-specific events such as harmful model responses or unauthorized model access, model manipulation and poisoning attacks. @@ -22,0 +23,10 @@ As mentioned before, as part of your incident response plan, you should [develop + * For AI systems: + + * Include AI-specific incidents in response procedures. + + * Develop playbooks for model misuse. + + * Establish reporting procedures for AI incidents. + + * Include AI events in regulatory reporting requirements. + @@ -50 +60 @@ Incident response -Key AWS services +Generative AI security and governance