An IS auditor is evaluating an organization's incident management program to ensure it is sufficiently prepared to manage AI-related incidents.
Which of the following is MOST important for the auditor to validate?
Show answer and explanation
Correct answer: C
AI-related incidents often differ significantly from traditional IT incidents due to their dependence on data, model behavior, and algorithm performance. According to the AAIATM Study Guide, incident management programs must include capabilities specifically tailored to AI, such as detecting and mitigating model drift and safeguarding against data poisoning or integrity attacks.
"AI incident response frameworks must account for issues unique to machine learning, including model drift, adversarial inputs, and data integrity breaches. An effective program incorporates detection, response, and recovery mechanisms for these AI-specific threats."
While options A and B contribute to improving incident response over time, and option D suggests best-practice alignment, only
option C directly addresses active response capabilities for high-risk, real-time AI vulnerabilities.
References:
ISACA Advanced in AI AuditTM (AAIATM) Study Guide, Section: "AI Governance and Risk
Management," Subsection: "Incident and Risk Management in AI Contexts"