ConceptioArchiveNIST
NISTpublic full text

NIST SP 800-218A: Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile

Harold Booth (NIST); Murugiah Souppaya (NIST); Apostol Vassilev (NIST); Michael Ogata (NIST); Martin Stanley (CISA); Karen Scarfone (Scarfone Cybersecurity) · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
accesscontrolcomputersecurityidentityincidentresponsenistriskmanagement
cybersecurity, computer security, cryptography, access control, incident response, privacy, identity, risk management, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 800-218A Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: July 2024 Author(s) Harold Booth (NIST) , Murugiah Souppaya (NIST) , Apostol Vassilev (NIST) , Michael Ogata (NIST) , Martin Stanley (CISA) , Karen Scarfone (Scarfone Cybersecurity) Abstract This document augments the secure software development practices and tasks defined in Secure Software Development Framework (SSDF) version 1.1 by adding practices, tasks, recommendations, considerations, notes, and informative references that are specific to AI model development throughout the software development life cycle. These additions are documented in the form of an SSDF Community Profile to support Executive Order (EO) 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence , which tasked NIST with “developing a companion resource to the [SSDF] to incorporate secure development practices for generative AI and for dual-use foundation models.” This Community Profile is intended to be useful to the producers of AI models, the producers of AI systems that use those models, and the acquirers of those AI systems. This Profile should be used in conjunction with NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities. This document augments the secure software development practices and tasks defined in Secure Software Development Framework (SSDF) version 1.1 by adding practices, tasks, recommendations, considerations, notes, and informative references that are specific to AI model development throughout the... See full abstract This document augments the secure software development practices and tasks defined in Secure Software Development Framework (SSDF) version 1.1 by adding practices, tasks, recommendations, considerations, notes, and informative references that are specific to AI model development throughout the software development life cycle. These additions are documented in the form of an SSDF Community Profile to support Executive Order (EO) 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence , which tasked NIST with “developing a companion resource to the [SSDF] to incorporate secure development practices for generative AI and for dual-use foundation models.” This Community Profile is intended to be useful to the producers of AI models, the producers of AI systems that use those models, and the acquirers of those AI systems. This Profile should be used in conjunction with NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities. Hide full abstract Keywords artificial intelligence ; artificial intelligence model ; cybersecurity risk management ; generative artificial intelligence ; secure software development ; Secure Software Development Framework (SSDF) ; software acquisition ; software development ; software security Control Families None selected Documentation Publication: https://doi.org/10.6028/NIST.SP.800-218A Download URL Supplemental Material: Secure Software Development Framework NIST news article White House fact sheet NIST AI publications Publication Parts: SP 800-218 Document History: 04/29/24: SP 800-218A (Draft) 07/26/24: SP 800-218A (Final) Topics Security and Privacy acquisition , risk management Technologies artificial intelligence , software & firmware HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 2969 · SHA-256 1f2121e993c0e975
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.