ある組織がAIモデルを外部パートナーと共有しています。あるパートナーから、モデルの出力によって機密データが誤って公開されたとの報告がありました。情報システム監査人が推奨する最良の推奨事項は次のうちどれですか?
正解:C
In the case of a potential data exposure through AI model outputs, the first and most responsible action from an auditing and risk standpoint is to halt further risk propagation. According to the AAIA™ Study Guide, immediate containment is vital, especially when regulatory and reputational risks are high.
"Upon detection of a data breach risk, AI models should be immediately disabled from public or partner use, and all relevant parties should be notified as part of a responsible disclosure and containment strategy." While options A and D are longer-term remediation steps and B is investigative, none of them provide the urgent containment that is best practice in such a breach context.
Reference: ISACA Advanced in AI Audit™ (AAIA™) Study Guide, Section: "Ethical and Legal Considerations in AI," Subsection: "AI Data Breach and Disclosure Management"