OECD AI Principles OECDAI-3: Robustness, Security, Safety, and Adversarial Attack Protection
Adhere to OECD AI Principles Section 1.4 (Robustness + security + safety). AI systems should be robust + secure + and safe throughout their entire lifecycle so that in conditions of normal use + foreseeable use or misuse + or other adverse conditions they function appropriately and do not pose unreasonable safety risk. To this end AI actors should ensure traceability + auditability + ability to log + and apply a systematic risk management approach to each phase of the AI system lifecycle on a continuous basis to address risks related to AI systems + including privacy + digital security + safety + and bias. Implement (a) AI risk identification and assessment aligned with NIST AI RMF + ISO/IEC 23894 + ISO/IEC 42001, (b) AI system categorisation by risk level + (c) AI model validation and testing covering performance + robustness + fairness + safety + security + (d) ongoing AI risk monitoring including drift + adversarial attack + emergent capability + (e) AI model security and integrity including model signing + provenance + access control + (f) adversarial attack protection (evasion + poisoning + extraction + inference + prompt injection + jailbreak + agentic misuse + similar) + (g) safe AI deployment procedures + (h) AI system lifecycle management + (i) AI system robustness and resilience.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 228 controls across 91 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33