Verwandte Artikel zu Secure by Design in the Age of AI™: The Product...

Secure by Design in the Age of AI™: The Product Security Operating Model for the AI Era (The Operating Discipline for AI Library™, Band 7) - Hardcover

Buch 7 von 9: The Operating Discipline for AI Library?

Jordan, Stephen R.

 
9798996940295: Secure by Design in the Age of AI™: The Product Security Operating Model for the AI Era (The Operating Discipline for AI Library™, Band 7)

Inhaltsangabe

Your security lifecycle is running. The queue keeps growing anyway.

That's the paradox behind Secure by Design in the Age of AI: The Product Security Operating Model for the AI Era, Volume VII in The Operating Discipline for AI Library. Product security teams that added an AI addendum to a lifecycle they trusted are watching pull requests pile up while nobody skips a single gate. Stephen R. Jordan names the cause the Dual-Impedance Problem: assisted and agentic development roughly doubles the rate of change while shipping a new kind of risk, models, prompts, retrieval, tools, agents, memory, that a reviewer trained on code was never built to catch. Adding reviewers doesn't fix kind. Adding AI-specific steps doesn't fix rate. And AI-assisted code review, the fix most teams are buying right now, catches a minority of what a trained human flags and slows the queue further when it's used as a gate.

This book installs the five-part operating model that fixes both mismatches at once:

  • An attack surface ledger that gives every model, tool, retrieval source, and agent one owned row, with a validation date
  • A feature tier map that sorts every AI feature by data reach, authority, autonomy, exposure, and consequence, so scarce human judgment goes where the blast radius is
  • A two-lane assurance model: a deterministic machine lane that blocks every change, a human lane reserved for what a machine can't judge, and an advisory band that never gates
  • A ship decision record naming the executive who accepted the risk, with evidence current at the release timestamp
  • A post-release response ladder that runs the product from its first outside vulnerability report through certification, acquisition, and retirement

Ten supporting instruments round it out: a maturity scorecard, a capacity metric that tells you whether your review team can hold, a component admission standard for models and datasets, a protocol for the vulnerability that has no code fix, a one-page agreement that fits security inside a sprint, and an evidence pack that answers your enterprise customer, your auditor, your regulator, and your acquirer from one source.

Written for the CISO and the director or VP of product security at any organization that ships AI-enabled products. Every chapter installs one instrument, states its owner and cadence, and closes with the board question you must be able to answer, the evidence that answers it, the failure pattern to watch for, and a 30-day move you can start this week. No vendor is named. Every claim carries a citation. The closing chapters sequence your first ninety days so your first fully documented release ships in week twelve.

Your customers have already read Volume VI and learned what evidence to demand. This is how you have the answer ready before they ask.

Die Inhaltsangabe kann sich auf eine andere Ausgabe dieses Titels beziehen.