A generative application receives customer free text.
Protect personal and confidential information in input, logs, and output.
Choose two controls.
Classify, mask, reject, or allow-list input data and apply retention, access, detection, and deletion controls to logs and output.
Detailed explanation
Unneeded sensitive data is kept out of the model request.
Unneeded sensitive data is kept out of the model request.
Non-input paths are included in data protection.
Non-input paths are included in data protection.
Models can reproduce sensitive input unintentionally.
Models can reproduce sensitive input unintentionally.
Exposure and purpose limitation grow.
Exposure and purpose limitation grow.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式Amazon Bedrock Guardrails、ログ保護、AIF-C01 Domain 5.1を確認する。Expected result
入力、ログ、出力を一つのデータライフサイクルとして保護できる。Key points
- Data classification
- Masking
- Log protection
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.