A CISO is rolling out the NIST AI RMF at a healthcare analytics company. Her first step is drafting an AI risk governance policy, assigning an AI Risk Officer role, creating an AI risk committee with representatives from legal, compliance, and engineering, and defining escalation paths for AI-related incidents. She presents this work to the board as the foundation of the AI risk management program.
A CISO is implementing the NIST AI RMF in her organization. She starts by establishing AI risk policies, roles, responsibilities, and accountability structures across all departments. Which NIST AI RMF core function does this activity belong to?
- A.C. GOVERN
- B.B. MEASURE
- C.A. MAP
- D.D. MANAGE
Why A is correct
The GOVERN function of NIST AI RMF focuses on establishing organizational structures for AI risk management: policies, accountability, roles, responsibilities, culture, and oversight mechanisms. MAP categorizes risks in context. MEASURE analyzes and quantifies risks. MANAGE addresses and treats identified risks. Governance infrastructure must be in place before the other functions can operate effectively.
Know someone studying for AI Security Fundamentals? Send them this one.