ISO 27090

ISO 27090 fills a key gap by introducing detailed guidance for identifying, assessing, and mitigating security risks that are specific to AI technologies. ISO/IEC 27001 does not fully account for the unique threat landscape that applies to artificial intelligence systems.

The threats covered in ISO/IEC (DIS) 27090 include data poisoning, model inversion, evasion attacks, membership inference, model exfiltration, prompt injection, and many others. These are not addressed explicitly in ISO/IEC 27001 which is why 27090 is necessary for any organization deploying AI within its ISMS or AIMS.