What does Secure by Design expect for detect and respond?
Answered
Design for the inevitability of vulnerabilities and incidents. Integrate logging, monitoring, alerting and response capabilities, and continually test and iterate them. NCSC similarly expects incident plans that reflect AI scenarios and monitoring of system behaviour and inputs.
From the guidance
Primary (how) Secure by Design Principles
Section: 5. Build in detect and respond security
Secondary (normative) NCSC: Secure deployment (AI systems)
Section: Develop incident management procedures
Read this in NCSC: Secure deployment (AI systems) (opens in new tab)
Related questions
- How do teams evidence Secure by Design? Delivery, assurance and operations
- Is Secure by Design mandatory for government AI services?
- How should commercial teams apply Secure by Design when buying AI? Buying and building
- What is continuous assurance under Secure by Design? Delivery, assurance and operations
- What does Secure by Design require when buying third-party technology? Buying and building