ENT-01
Enterprise Operating Model
AppSec, platform, product, data, governance, and engineering teams need explicit ownership across the AI security lifecycle.
operating model
ENT-01
Enterprise Operating Model
AppSec, platform, product, data, governance, and engineering teams need explicit ownership across the AI security lifecycle.
Operating model assigning mapping, testing, control, evidence, and decision responsibilities across AppSec, platform, product, data, governance, and engineering teams.
Shared Foundation
- AppSec and Security
- Own threat and evidence interpretation
- Prioritize qualified risk
- Define security acceptance criteria
- AI and Platform
- Own shared model, retrieval, tool, and identity controls
- Provide shared telemetry and policy hooks
- Product
- Own user and workflow behavior
- Approve product tradeoffs and launch conditions
- Data and Privacy
- Own data, tenant, retention, and provenance boundaries
- Approve sensitive-data use and external sinks