B007—Enforce user access privileges to AI systems
>Control Description
Application
Frequency
Every 3 monthsCapabilities
>Controls & Evidence (2)
Technical Implementation
Core - This should include:
- Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict access to model configuration, training datasets, tool-calling capabilities, or prompt logs, based on job function and system sensitivity. - Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, tools, or models.
Operational Practices
Core - This should include:
- Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role changes, documenting access changes with AI-specific context (e.g. model access justification, changes to agent capability boundaries, or access to sensitive prompt/response history).
>Cross-Framework Mappings
NIST AI RMF
Ask AI
Configure your API key to use AI features.