Cloud Wars
  • Home
  • Top 10
  • CW Minute
  • CW Podcast
  • Categories
    • AI and Copilots
    • Innovation & Leadership
    • Cybersecurity
    • Data
  • Member Resources
    • Cloud Wars AI Agent
    • Digital Summits
    • Guidebooks
    • Reports
  • About Us
    • Our Story
    • Tech Analysts
    • Marketing Services
  • Summit NA
  • Dynamics Communities
  • Ask Copilot
Twitter Instagram
  • Summit NA
  • Dynamics Communities
  • AI Copilot Summit NA
  • Ask Cloud Wars
Twitter LinkedIn
Cloud Wars
  • Home
  • Top 10
  • CW Minute
  • CW Podcast
  • Categories
    • AI and CopilotsWelcome to the Acceleration Economy AI Index, a weekly segment where we cover the most important recent news in AI innovation, funding, and solutions in under 10 minutes. Our goal is to get you up to speed – the same speed AI innovation is taking place nowadays – and prepare you for that upcoming customer call, board meeting, or conversation with your colleague.
    • Innovation & Leadership
    • CybersecurityThe practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.
    • Data
  • Member Resources
    • Cloud Wars AI Agent
    • Digital Summits
    • Guidebooks
    • Reports
  • About Us
    • Our Story
    • Tech Analysts
    • Marketing Services
    • Login / Register
Cloud Wars
    • Login / Register
Home » NIST Provides Comprehensive Resources for AI Risk Management, GenAI Use Cases
AI and Copilots

NIST Provides Comprehensive Resources for AI Risk Management, GenAI Use Cases

Chris HughesBy Chris HughesAugust 21, 2024Updated:August 21, 20244 Mins Read
Facebook Twitter LinkedIn Email
Share
Facebook Twitter LinkedIn Email

The U.S. National Institute of Standards and Technology (NIST) has long been an industry leader in providing guidance, frameworks, and best practices for securing the use of technologies. Its role in the AI ecosystem is proving no different.

In October 2023, the White House issued an executive order (EO) titled “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence” or in short, the AI EO. The EO laid out robust visions for ensuring AI safety and security, including tasking NIST with “Developing Guides, Standards, and Best Practices for AI Safety and Security.”

NIST has done just that, publishing a series of resources aimed at this requirement, among them the AI Risk Management Framework (AI RMF), building on its Secure Software Development Framework (SSDF) and the AI RMF GenAI Profile. These resources are aimed at helping organizations govern and manage AI risks and provide vendor-agnostic comprehensive guidance for organizations to aid the business in secure AI adoption and usage.

Let’s briefly examine each and how they may be used below.

AI Risk Management Framework (RMF)

The AI RMF is “intended to address risks in the design, development, use, and evaluation of AI products, services, and systems.” This makes it a great resource to help organizations securely adopt AI as businesses rush in to explore AI use cases, utilize external AI services, and build on top of AI foundation models.

AI RMF is oriented around mapping risks, measuring their potential impacts, and then managing those risks appropriately.

Source: NIST

It examines the potential harms of AI use, including harm to people, organizations, systems, and the overall ecosystem. It also emphasizes the need for AI trustworthiness: being valid, reliable, safe, and fair while also ensuring characteristics such as privacy are considered as well.

Source: NIST

The NIST AI RMF “Core” includes four functions: map, measure, manage, and govern. Each involves categories and subcategories with their own associated risks, considerations, and potential actions organizations can take to mitigate risk.

There are also “Profiles” that align with specific use cases or scenarios.

AI RMF GenAI Profile

As part of the AI RMF, NIST has begun producing “profiles” for specific use cases. It took a similar approach to the widely popular NIST Cybersecurity Framework (CSF), which has profiles for specific industries and organizational use cases.

GenAI and large language models (LLMs) represent some of the fastest-growing areas of adoption within the broader domain of AI. As organizations rapidly adopt GenAI capabilities and services, it is crucial that they build on a sound foundation, and the AI RMF GenAI Profile represents an opportunity to do that.

The AI RMF GenAI Profile covers risks that are either unique to, or exacerbated by, GenAI. These include, but are not limited to, dangerous recommendations, data privacy, human AI configuration, information integrity, and intellectual property (IP) concerns. The profile lays out these key risks, their potential impact to organizations, as well as recommendations for mitigating them. It also lays out a comprehensive table that includes the unique identifier, actions organizations can take to manage the risks, what risks it is tied to, and the relevant AI actors involved.

For example, risks associated with information integrity under the govern sub-category may call for actions such as having long-term documentation retention policies for auditing, investigation, and content provenance. Another example, but under the mapping sub-category, involves data privacy. It calls for the organization to conduct periodic audits and monitor AI-generated content for privacy risks or sensitive data exposure.

Below is an example excerpt from the tables, demonstrating one of the risks discussed above:

Source: NIST

The AI RMF GenAI Profile includes a comprehensive appendix with key considerations for any organization designing, developing, and using GenAI and looking to manage GenAI risks. It specifically calls out considerations around governance, pre-deployment testing, content provenance, and incident disclosure. The appendix provides fundamental controls, recommendations, and additional resources for addressing these considerations and risks.

Closing Thoughts

The NIST AI RMF and GenAI Profile represent powerful, comprehensive resources for organizations to effect secure AI adoption and usage. It is often said security is “bolted on” rather than “built in,” but for savvy security leaders thinking ahead, leveraging these resources as well as others from organizations such as Open Web Application Security Project (OWASP) and Cloud Security Alliance, leaders can help enable the business with secure AI outcomes.


ai Cloud Wars Archive Cybersecurity data privacy featured framework governance risk
Share. Facebook Twitter LinkedIn Email
Analystuser

Chris Hughes

CEO and Co-Founder
Aquia

Areas of Expertise
  • Cloud
  • Cybersecurity
  • LinkedIn

Chris Hughes is a Cloud Wars Analyst focusing on the critical intersection of cloud technology and cybersecurity. As co-founder and CEO of Aquia, Chris draws on nearly 20 years of IT and cybersecurity experience across both public and private sectors, including service with the U.S. Air Force and leadership roles within FedRAMP. In addition to his work in the field, Chris is an adjunct professor in cybersecurity and actively contributes to industry groups like the Cloud Security Alliance. His expertise and certifications in cloud security for AWS and Azure help organizations navigate secure cloud migrations and transformations.

  Contact Chris Hughes ...

Related Posts

Workday Empowers Digital Workforce with Agent System of Record and Global Partnerships

June 13, 2025

AWS Launches MCP Servers to Supercharge AI-Assisted App Development

June 13, 2025

Oracle Surges on AI Boom as FY26 Cloud Growth to Blow Past 40%

June 12, 2025

Cognizant and ServiceNow Unite to Centralize IT, HR, and Customer Service with AI

June 12, 2025
Add A Comment

Comments are closed.

Recent Posts
  • Workday Empowers Digital Workforce with Agent System of Record and Global Partnerships
  • AWS Launches MCP Servers to Supercharge AI-Assisted App Development
  • Oracle Surges on AI Boom as FY26 Cloud Growth to Blow Past 40%
  • Cognizant and ServiceNow Unite to Centralize IT, HR, and Customer Service with AI
  • AI Agent Security: Red Teaming Emerges as Solution to Broad Range of Threat Categories

  • Ask Cloud Wars AI Agent
  • Tech Guidebooks
  • Industry Reports
  • Newsletters

Join Today

Most Popular Guidebooks

Accelerating GenAI Impact: From POC to Production Success

November 1, 2024

ExFlow from SignUp Software: Streamlining Dynamics 365 Finance & Operations and Business Central with AP Automation

September 10, 2024

Delivering on the Promise of Multicloud | How to Realize Multicloud’s Full Potential While Addressing Challenges

July 19, 2024

Zero Trust Network Access | A CISO Guidebook

February 1, 2024

Advertisement
Cloud Wars
Twitter LinkedIn
  • Home
  • About Us
  • Privacy Policy
  • Get In Touch
  • Marketing Services
  • Do not sell my information
© 2025 Cloud Wars.

Type above and press Enter to search. Press Esc to cancel.

  • Login
Forgot Password?
Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.