Description
Secure data handling practices including access control, encryption, sanitization, and protection of training data and model artifacts.
Implementation Guidance
Data Classification
Classify AI data assets by sensitivity: public (open datasets), internal (proprietary training data), confidential (PII, financial data), and restricted (regulated data, trade secrets). Apply security controls proportionate to classification.
Security Controls
Implement layered data security: encryption at rest and in transit, role-based access control to training data and model artifacts, audit logging of all data access, secure deletion procedures, and network segmentation for AI training environments.
Model Artifact Protection
Protect trained models as sensitive intellectual property: secure model registries with access control, integrity verification (checksums) for model files, secure serving infrastructure, and protection against model extraction attacks.
Evidence Requirements
- Data classification records for AI assets
- Access control configurations and audit logs
- Encryption implementation records
- Model registry access controls and integrity logs