CISOOnline

CISOs are struggling to threat-model AI. Can 15-minute sessions help?

Shostack says a short session is not supposed to be exhaustive. It should, however, identify enough meaningful risks to guide the next decision: Is the risk acceptable, does the system need to change, or is a deeper review required?

“One of the things that we’ve learned from the agile world is that when you make the period of work small, you iterate more and faster,” he says. If the first session misses the mark, the team can erase the whiteboard and try again without losing days or weeks of work. “You make the experiments cheap, and when the experiment is cheap, you can run it repeatedly.”

The result should be a set of concrete stories about how the system could fail. Those scenarios can help CISOs understand the risks they are accepting and help technical teams choose appropriate controls, which can mean limiting data access, narrowing tool permissions, adding human approval points, or even reconsidering whether an LLM is needed at all.



Source link