
Integrating AI into the ISMS - Safely Managing AI with the Management System You Already Have
AI in the ISMS: Much of it fits into existing processes. More challenging are unclear assets, dynamic models, changes in suppliers, and shadow AI.
Topic
When & Where
Details
Format:
Lecture
Language:
German
Session description
Ronny Frankenstein (HiSolutions), Felix Kuhlenkamp (Bitkom) How can AI be integrated into existing information security management systems, and where does it not fit in? Much of it goes smoothly. AI is simply another asset with risks, and the standard approach works: examine the context, assess the risk, and determine appropriate measures. Much of this is already familiar from service provider management. ISO 42001 can be addressed through risk analyses or as a supplementary catalog of measures; there’s no need for a separate governance framework. Things get trickier when AI doesn’t fit into the usual categories. Even the question of what exactly constitutes the asset doesn’t have a clear-cut answer—is it the model, the training data, API access, or the prompt? It’s difficult to assess ...


