CISOOnline

Securing AI agents: Key controls and best practices

“We spent twenty years building identity management for people: usernames, passwords, role-based access,” says Justin Beals, CEO of governance, risk, and compliance company Strike Graph. “None of that was designed for agents that don’t get tired, don’t go home, and act on probabilities instead of rules.”

“We’re so behind on building secure infrastructure, secure architectures, and containing against a potential rogue employee,” Chris Wysopal, chief security evangelist at Veracode, tells CSO. “Now you just have something doing that at machine speed, so I think it’s very dangerous. We really have to get a handle on containing and controlling these agents. We need some standards around what’s acceptable, what is due diligence, what are best practices.”

In network and application telemetry, agent actions often show up as authenticated with legitimate employee credentials, originating from trusted IP addresses or using approved application programming interfaces. To build effective security policies for them, organizations need to distinguish agents from the employees whose authority they inherit.

According to security experts, when an agent crosses an unauthorized boundary, security teams must be able to detect it and immediately revoke every credential, session, and process that agent launched. They also need to be able to roll back everything the rogue agent might have done.



Source link