Which AI assets should I protect, including logs?
Answered
Protect models, data (including user feedback), prompts, software, documentation, logs and assessments — including information about unsafe capabilities and failure modes. Treat logs as sensitive data and control confidentiality, integrity and availability. Know where assets live and how to restore a known-good state.
From the guidance
Primary (how) NCSC: Secure development (AI systems)
Section: Identify, track and protect your assets
Read this in NCSC: Secure development (AI systems) (opens in new tab)
Related questions
- What AI assets should I document and inventory? Delivery, assurance and operations
- How do I stop an AI system from leaking personal or sensitive data?
- What is adversarial machine learning and why does it matter?
- Can attackers steal my model or training data through the API?
- What is data poisoning in an AI system?