What is ISO/IEC 27090?
ISO/IEC 27090 provides guidance on understanding, detecting and mitigating security threats specific to artificial intelligence (AI) systems throughout their life cycle. It explains how vulnerabilities can be exploited, what the consequences can be and which measures can help address them.
For organizations developing or using AI, the standard helps identify what needs protecting, from training data to AI models. It addresses threats such as data poisoning and model theft, while recognizing that established cybersecurity practices remain essential.
Why is ISO/IEC 27090 important?
AI introduces security challenges that conventional cybersecurity measures alone may not fully address. Manipulated training data can affect a system’s behaviour, while apparently legitimate queries can be used to steal a model. These attacks can be difficult to detect and can compromise systems even when conventional protections are in place.
As organizations use AI more widely, security failures can have consequences for both businesses and individuals, particularly in safety-critical applications. ISO/IEC 27090 helps organizations connect these threats to their potential impact and make informed decisions about detection and protection. This supports more secure AI development and use as systems and threats evolve.
Benefits
- Identify AI-specific vulnerabilities and their potential consequences
- Make informed choices about threat detection and mitigation
- Strengthen protection for training data, models and intellectual property
- Address security risks across AI development, operation and model updates
- Complement established cybersecurity practices with AI-specific measures
FAQ
ISO/IEC 27090 complements the established security practices in ISO/IEC 27001 and ISO/IEC 27002 by addressing threats specific to AI systems. Its guidance helps organizations understand where conventional measures remain useful and where additional protection is needed for AI data, models and workflows.
Data collected during operation may later be used to update or retrain a model. If that data has been corrupted, it can introduce vulnerabilities into future versions of the system. In systems that learn continuously or iteratively, operational inputs can also become training data, creating opportunities for data poisoning beyond initial development.
Informaciones generales
-
Estado: En desarrolloEtapa: Norma Internacional en proceso de publicación [60.00]
-
Edición: 1
-
Comité Técnico :ISO/IEC JTC 1/SC 27ICS :35.030
- RSS actualizaciones
