AI and Third-Party Risk: Solutions for Assessing and Managing Your AI Vendors and Systems
暫譯: 人工智慧與第三方風險:評估與管理您的人工智慧供應商及系統的解決方案

Rasner, Gregory C., Rasner, Maria C.

  • 出版商: Apress
  • 出版日期: 2026-04-02
  • 售價: $1,440
  • 貴賓價: 9.5$1,368
  • 語言: 英文
  • 頁數: 193
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 9798868824647
  • ISBN-13: 9798868824647
  • 相關分類: AI Coding
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Artificial Intelligence is no longer a future concern--it's a present-day disruptor. As vendors and partners increasingly adopt AI-enabled products and services, third-party and supply-chain risk professionals face a new challenge: managing a rapidly evolving risk landscape with limited guidance. This book delivers the clarity and structure needed to navigate that complexity.

Designed for business professionals--not just technologists--this practical guide walks readers through the full lifecycle of AI-related vendor risk, from intake to offboarding. With hands-on examples, actionable templates, and real-world use cases, it equips readers to assess and manage AI risk confidently, even in environments without dedicated IT security teams. It also explores how AI can be used within TPRM programs to enhance efficiency and accuracy.

As regulatory frameworks around AI continue to emerge and evolve, this book provides timely insight into compliance expectations and how they impact risk programs and leadership. Whether you're a seasoned risk manager or new to the field, you'll find concise, jargon-free guidance that respects your time and delivers immediate value.

AI may be complex, but managing its risk doesn't have to be. This book transforms confusion into clarity, helping you turn disruption into opportunity--and build a resilient, future-ready risk management program.

What You Will Learn:

How to measure risk and risk-based approaches.

Third-party risk frameworks.

How to assess the risk of AI with vendors.

Major AI risk management frameworks.

Regulatory guidance for AI--a country-by-country analysis.


Who This Book Is for:

- C-level suite: this is not designed to be overly technical but covers material enough to allow this level to be conversant in strategy and leadership needs to success.

- Director-level in Cyber and IT: this level of personnel are above the individual contributors (IC) and require the information in this book to translate the strategy goals set by C-suite and the tactics required for the ICs to implement and govern.

- GRC leaders and staff: the focus on governance in this book will assist these teams to better understand the strategy and technologies to determine the governance models needed.

- Individual Contributors: although not designed to be a technical manual for engineering staff, it does provide a Rosetta Stone for them to understand how important strategy and governance are to

商品描述(中文翻譯)

人工智慧不再是未來的關注點——它已成為當前的顛覆者。隨著供應商和合作夥伴越來越多地採用人工智慧驅動的產品和服務,第三方及供應鏈風險專業人士面臨著一個新的挑戰:在有限的指導下管理快速變化的風險環境。本書提供了所需的清晰度和結構,以便在這種複雜性中導航。

本書專為商業專業人士設計——不僅僅是技術專家——這本實用指南引導讀者了解與人工智慧相關的供應商風險的完整生命周期,從風險評估到終止合作。通過實用的範例、可行的模板和真實的案例,它使讀者能夠自信地評估和管理人工智慧風險,即使在沒有專門IT安全團隊的環境中。它還探討了如何在第三方風險管理(TPRM)計劃中使用人工智慧,以提高效率和準確性。

隨著圍繞人工智慧的監管框架不斷出現和演變,本書提供了及時的見解,幫助讀者了解合規期望及其對風險計劃和領導的影響。無論您是經驗豐富的風險管理者還是新手,您都會發現簡明、無行話的指導,尊重您的時間並提供即時價值。

人工智慧可能很複雜,但管理其風險不必如此。本書將困惑轉化為清晰,幫助您將顛覆轉變為機會——並建立一個具有韌性、未來準備的風險管理計劃。

您將學到的內容:
- 如何衡量風險和基於風險的方法。
- 第三方風險框架。
- 如何評估與供應商的人工智慧風險。
- 主要的人工智慧風險管理框架。
- 有關人工智慧的監管指導——逐國分析。

本書的讀者對象:
- C級高管:本書不旨在過於技術化,但涵蓋的內容足以讓這一層級能夠參與策略和領導所需的成功需求。
- 網路安全和IT領域的主管:這一層級的工作人員高於個別貢獻者(IC),需要本書中的資訊來轉化C級高管設定的策略目標以及IC實施和治理所需的戰術。
- GRC領導者和員工:本書對治理的重點將幫助這些團隊更好地理解策略和技術,以確定所需的治理模型。
- 個別貢獻者:雖然本書並非為工程人員設計的技術手冊,但它提供了一個羅塞塔石,幫助他們理解策略和治理對於成功的重要性。

作者簡介

Gregory Rasner (CISSP, CIPM, ITIL, CCNA) is the founder and CEO of Third Party Threat Hunting LLC, bringing his extensive expertise in third-party, supply chain, and cybersecurity risk to the market. He authored the books "Cybersecurity & Third-Party Risk: Threat Hunting" (Wiley, 2021) and "Zero Trust and Third-Party Risk" (Wiley, 2023), "Privileged Access Management: Strategies for Zero Trust in the Enterprise" (Apress, 2025), developed the internationally recognized training and certification program "Third-Party Cyber Risk Assessor" TPRCA (Third Party Risk Association, 2023) and other training programs. He is a regular keynote speaker and panelist on cybersecurity and risk management topics, also contributing to blogs, podcasts, and online articles. Greg has held leadership roles across the finance, healthcare, biotech, high-tech, and manufacturing sectors and earned his B.A. from Claremont McKenna College.

Maria Rasner (CISM, CCZK, CCSK, TAISE) - has years of extensive Identity and Access Management and Privileged Access Management experience. Maria is the co-author of the book "Privileged Access Management: Strategies for Zero Trust in the Enterprise" (Apress, 2025). She has run governance, remediation, implementation of small and large IAM and PAM programs, both on-premises and in the cloud. Her experience and certifications include cloud IAM and PAM experience in AWS and Azure cloud environments. Maria has several articles on the topic of Cloud PAM Security published in ISSA Online Journal and IDSA website. Maria has strong enthusiasm for continuous learning, always exploring new developments in AI. She has taken the Google AI Essentials training as well as Stanford University's Deep Learning Specialization course. Maria is a member of Cloud Security Alliance's AI Controls Framework Working Group responsible for the publication of AI Controls Matrix (AICM). She's also certified in TAISE (Trusted AI Safery Expert).

作者簡介(中文翻譯)

Gregory Rasner(CISSP、CIPM、ITIL、CCNA)是第三方威脅獵捕有限責任公司的創始人兼首席執行官,將他在第三方、供應鏈和網絡安全風險方面的豐富專業知識帶入市場。他著有《網絡安全與第三方風險:威脅獵捕》(Wiley,2021)和《零信任與第三方風險》(Wiley,2023)、《特權訪問管理:企業中的零信任策略》(Apress,2025),並開發了國際認可的培訓和認證計劃「第三方網絡風險評估師」TPRCA(第三方風險協會,2023)及其他培訓計劃。他是網絡安全和風險管理主題的定期主題演講者和小組成員,並為博客、播客和在線文章做出貢獻。Greg在金融、醫療保健、生物技術、高科技和製造業等領域擔任過領導職位,並獲得了克萊蒙特·麥肯納學院的文學士學位。

Maria Rasner(CISM、CCZK、CCSK、TAISE)擁有多年豐富的身份和訪問管理及特權訪問管理經驗。Maria是《特權訪問管理:企業中的零信任策略》(Apress,2025)一書的共同作者。她負責小型和大型身份和訪問管理(IAM)及特權訪問管理(PAM)計劃的治理、修復和實施,無論是在本地還是雲端。她的經驗和認證包括在AWS和Azure雲環境中的雲IAM和PAM經驗。Maria在ISSA在線期刊和IDSA網站上發表了多篇有關雲PAM安全的文章。Maria對持續學習充滿熱情,始終探索人工智慧的新發展。她參加了Google AI Essentials培訓以及斯坦福大學的深度學習專業課程。Maria是雲安全聯盟AI控制框架工作組的成員,負責發布AI控制矩陣(AICM)。她還獲得了TAISE(受信任的AI安全專家)認證。