Which AI assets should I protect, including logs?

Answered

Protect models, data (including user feedback), prompts, software, documentation, logs and assessments — including information about unsafe capabilities and failure modes. Treat logs as sensitive data and control confidentiality, integrity and availability. Know where assets live and how to restore a known-good state.

From the guidance

Primary (how) NCSC: Secure development (AI systems)

You understand the value to your organisation of your AI-related assets, including models, data (including user feedback), prompts, software, documentation, logs and assessments (including information about potentially unsafe capabilities and failure modes), recognising where they represent significant investment and where access to them enables an attacker. You treat logs as sensitive data and implement controls to protect their confidentiality, integrity and availability.

Section: Identify, track and protect your assets

Read this in NCSC: Secure development (AI systems) (opens in new tab)

Related questions