Mapping Principles
The application security requirements on this site have been split into the 13 different principles from the European Telecommunications Standards Institute (ETSI), EN 304 223.
Secure Design
Principle 1: Raise awareness of AI security threats and risks
Primarily applies to: System Operators, Developers, and Data Custodians
Principle 2: Design your AI system for security as well as functionality and performance
Primarily applies to: System Operators and Developers
Principle 3: Evaluate the threats and manage the risks to your AI system
Primarily applies to: Developers and System Operators
Principle 4: Enable human responsibility for AI systems
Primarily applies to: Developers and System Operators
Secure Development
Principle 5: Identify, track and protect your assets
Primarily applies to: Developers, System Operators and Data Custodians
Principle 6: Secure your infrastructure
Primarily applies to: Developers and System Operators
Principle 7: Secure your supply chain
Primarily applies to: Developers, System Operators and Data Custodians
Principle 8: Document your data, models and prompts
Primarily applies to: Developers
Principle 9: Conduct appropriate testing and evaluation
Primarily applies to: Developers and System Operators
Secure Deployment
Principle 10: Communication and processes associated with End-users and Affected Entities
As part of an organisation’s wider deployment practices, they should also consider pre-deployment testing of AI systems
Secure Maintenance
Principle 11: Maintain regular security updates, patches and mitigations
Primarily applies to: Developers and System Operators
Principle 12: Monitor your system’s behaviour
Primarily applies to: Developers and System Operators
Secure End of Life
Principle 13: Ensure proper data and model disposal
Primarily applies to: Developers and System Operators
