Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

DASF and AI security operations: what practitioners need to change


(@lalit)
Member Admin
Joined: 1 year ago
Posts: 264
Topic starter  

TL;DR: Databricks AI Security Framework is presented as a way to turn AI risk into operational controls, with Noma Security arguing that 62 risks across the AI lifecycle need continuous discovery, prioritisation, monitoring, and standards mapping, according to Noma Security. The central shift is that AI security now has to treat models, RAG pipelines, and agents as mutable attack surfaces rather than static applications.

NHIMG editorial — based on content published by Noma Security: From Conceptual to Operational for Enterprise Cybersecurity Ten Steps to Secure AI with DASF

Questions worth separating out

Q: How should security teams govern AI systems that use retrieval and internal knowledge bases?

A: They should treat retrieved content as a governed access surface, not just a data source.

Q: Why do sanctioned AI assistants create data exposure risk in collaboration platforms?

A: Sanctioned AI assistants inherit the permissions of the repositories they query, so any over-shared file or loosely governed workspace can become visible through the assistant interface.

Q: What breaks when AI security is handled only at launch time?

A: Controls go stale as the system changes.

Practitioner guidance

  • Define AI deployment boundaries before launch Inventory models, training sources, RAG stores, APIs, and tool integrations so the security scope matches the real system rather than the intended design.
  • Classify and constrain retrievable content Remove confidential material from general retrieval paths unless there is a documented business need and explicit access control.
  • Embed policy checks in AI workflows Place review, validation, and approval gates inside the deployment and orchestration workflow instead of relying on manual sign-off.

What's in the full article

Noma Security's full blog covers the operational detail this post intentionally leaves for the source:

  • A step-by-step walkthrough of the ten DASF implementation phases for AI security teams that need to operationalise controls.
  • Examples of control selection and workflow integration across model serving, orchestration, and monitoring environments.
  • Specific anti-patterns and cautionary examples for AI deployment, drift, prompt abuse, and continuous validation.
  • How the source maps DASF controls to frameworks such as NIST AI RMF, MITRE ATLAS, OWASP, ISO 27001, and the EU AI Act.

👉 Read Noma Security's guide to operationalising DASF for AI security →

DASF and AI security operations: what practitioners need to change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11961
 

AI governance debt is now a material security issue: organisations that deploy AI without lifecycle controls accumulate hidden exposure across training data, retrieval layers, tool access, and output behaviour. The article’s core lesson is that AI systems cannot be secured with launch-time review alone because the attack surface changes after deployment. Practitioners should treat AI governance as an operating discipline, not a project deliverable.

A question worth separating out:

Q: Which frameworks should teams use to evaluate AI security controls and accountability?

A: Use NIST AI RMF for governance, OWASP guidance for common AI attack patterns, MITRE ATLAS for adversarial techniques, and ISO 27001 where enterprise control mapping is needed. The framework should help teams prioritise, test, and evidence controls, not replace validation against the actual model, data, and agent workflows.

👉 Read our full editorial: DASF shows why AI security must move from theory to operations



   
ReplyQuote
Share: