Audit AI inputs, outputs, permissions, and model changes.
Detect later tampering by an operator.
Choose two controls.
Use separated centralized logs with retention, encryption, and tamper detection, and record consistent identity, model, time, and policy fields while minimizing secrets.
Detailed explanation
The runtime operator cannot freely rewrite the audit trail.
The runtime operator cannot freely rewrite the audit trail.
Events can be correlated during investigation.
Events can be correlated during investigation.
Audit evidence and diagnosis are lost.
Audit evidence and diagnosis are lost.
Logs can become a sensitive data source.
Logs can become a sensitive data source.
Try it yourself
An example you can run in a temporary verification environment.
AWS CloudTrail・CloudWatch Logs公式とAIF-C01 Domain 5.2の監査・ログ保護を確認する。Expected result
ログの完全性、検索性、機密性を同時に設計できる。Key points
- Separation
- Tamper detection
- Minimization
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.