{"id":3814,"date":"2024-05-30T07:40:01","date_gmt":"2024-05-30T12:40:01","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/four-security-questions-to-ask-your-enterprise-generative-ai-provider"},"modified":"2024-05-30T07:40:01","modified_gmt":"2024-05-30T12:40:01","slug":"4-security-questions-to-ask-your-enterprise-generative-ai-provider","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/30\/4-security-questions-to-ask-your-enterprise-generative-ai-provider\/","title":{"rendered":"4 Security Questions to Ask Your Enterprise Generative AI Provider"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt5c68ce2cd5715df5\/66552a4009eeb9bc2bffa3a4\/meeting-Prostock-studio-AlamyStockPhoto.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Generative artificial intelligence (GenAI) is a transformative technology that is quickly becoming the focal point of many enterprise IT strategies. As part of that effort, security teams are working to identify, develop, and implement best practices for securing GenAI use in the enterprise. This requires not only a review of internal IT security practices that account for GenAI, but also a strong understanding of what&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/aka.ms\/SecuringAIWhitepaper\" rel=\"noopener\">role GenAI providers play<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;in supporting secure enterprise use. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/looking-to-leverage-generative-ai-prep-for-success-with-these-4-tips\" rel=\"noopener\">Best practices<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in this area are constantly evolving, but there are four foundational questions enterprise security teams should be asking to get the conversation started.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Will My Data Remain Private?\">Will My Data Remain Private?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">GenAI providers should have clearly documented privacy policies. Ideally, customers should be able to retain control of their information and not have it used to train foundational models or shared with other customers without their explicit permission.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Can I Trust the Content Created by GenAI?\">Can I Trust the Content Created by GenAI?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like humans, GenAI will sometimes get things wrong. But while perfection cannot be expected, transparency and accountability should. This can be accomplished in three ways: Use authoritative data sources to foster accuracy, provide visibility into reasoning and sources to maintain transparency, and provide a mechanism for user feedback to support continuous improvement. In this way, providers can help maintain the credibility of the content the tools create.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Will You Help Us Maintain a Safe, Responsible Usage Environment?\">Will You Help Us Maintain a Safe, Responsible Usage Environment?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Enterprise security teams have an obligation to ensure safe and responsible GenAI use within their organizations. AI providers should be able to support their efforts in a number of ways.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, one area of concern is user overreliance on the technology. GenAI is meant to assist workers in their daily tasks, not to replace the actual workers. As such, users should be encouraged to think critically about the information they are being served by AI. Providers can help promote the right amount of user scrutiny by visibly citing sources and using carefully considered language that reinforces thoughtful usage.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another risk, perhaps less common, is hostile misuse by insiders. This would include attempts to engage GenAI in harmful actions, such as generating dangerous code. AI providers can help mitigate this type of risk by including safety protocols in their system design and setting clear boundaries on what GenAI can and cannot do.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Was This GenAI Technology Designed With Security in Mind?\">Was This GenAI Technology Designed With Security in Mind?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like other types of enterprise software, GenAI technology should be designed and developed with security in mind, and technology providers should document and share their security development practices. Further, security development life cycles should be adapted to account for new threat vectors introduced by GenAI. This includes actions like updating threat-modeling requirements to address AI and machine learning-specific threats and implementing strict input validation and sanitization of user-provided prompts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/how-to-red-team-genai-challenges-best-practices-and-learnings\" rel=\"noopener\">AI-aware red teaming<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;can also be a powerful security enhancement, allowing providers to look for exploitable vulnerabilities, the generation of potentially harmful content and other such issues. Red teaming has the advantage of being highly adaptive and can be used both before and after product release \u2014 an essential benefit in maintaining the security of a rapidly evolving technology like GenAI.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Shared Responsibility\">Shared Responsibility<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These questions can help enterprise security teams gain a vital understanding of their GenAI providers&#8217; efforts across four foundational areas of protection: data privacy and ownership, transparency and accountability, user guidance and policy, and secure design and development.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And while these are an excellent starting point, a number of promising industry-level initiatives also are poised to help ensure the safe and responsible development and usage of GenAI that should further expand our understanding of secure AI considerations. However, one thing is clear: Leading providers of GenAI technology understand their role in this shared responsibility and are willing to provide <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2023\/07\/21\/commitment-safe-secure-ai\/\" rel=\"noopener\">information on their efforts<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;to advance safe, secure, and trustworthy AI. So go ahead and get that conversation started today.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u2014 Read more <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/program\/partner-perspectives-microsoft\" rel=\"noopener\">Partner Perspectives from Microsoft Security<\/a><\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/four-security-questions-to-ask-your-enterprise-generative-ai-provider\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Generative artificial intelligence (GenAI) is a transformative technology that is<\/p>\n","protected":false},"author":12,"featured_media":3815,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3814","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?fit=1200%2C800&ssl=1",1200,800,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?fit=1200%2C800&ssl=1",1200,800,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?fit=1200%2C800&ssl=1",1200,800,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/4-security-questions-to-ask-your-enterprise-generative-ai-provider.jpg?fit=1200%2C800&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3814","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3814"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3814\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3815"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3814"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3814"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}