The AWS Customer Incident Response Team (CIRT) has developed a methodology that you can use to investigate security incidents involving generative AI-based applications.
Generative AI applications include five components.
You should prepare for a security event across three domains: people, process, and technology.
The Methodology for incident response on generative AI workloads consists of seven elements.
For each element, a list of specific questions you can use to guide the response is provided.
An example incident is given to illustrate the application of the methodology.
To respond to security events related to a generative AI workload, you should still follow the guidance and principles outlined in the AWS Security Incident Response Guide.
The methodology equips you with a structured approach to prepare for and respond to security incidents involving generative AI workloads.
For more information about best practices for designing your generative AI application, see Generative AI for the AWS Security Reference Architecture.
If you have feedback about this post, submit comments in the Comments section below.