ai-security-verification
AI Security Verification Standard (AISVS)
Conduct comprehensive security verification of AI-driven applications using the OWASP AI Security Verification Standard (AISVS) framework's 13-category structured checklist.
Steps
-
Training Data Governance & Bias Management — Assess data quality, provenance, bias detection, and governance controls throughout the data lifecycle.
-
User Input Validation — Evaluate input sanitization, prompt injection defenses, adversarial input detection, and boundary validation mechanisms.
-
Model Lifecycle Management & Change Control — Review model versioning, deployment controls, rollback capabilities, and change management processes.
-
Infrastructure, Configuration & Deployment Security — Examine deployment security, container hardening, network controls, and infrastructure configuration.
-
Access Control & Identity — Verify authentication mechanisms, authorization controls, privilege management, and identity governance.
-
Supply Chain Security for Models, Frameworks & Data — Assess third-party model security, dependency management, and supply chain integrity.
-
Model Behavior, Output Control & Safety Assurance — Evaluate output validation, safety guardrails, behavior monitoring, and harmful content prevention.