Loading…
ChiBrrCon 2027
Friday October 9, 2026 1:15pm - 2:00pm PDT
Limited Capacity filling up
We've all seen the explosion of AI, but the security risks often feel abstract and overwhelming. My talk, 'Bridging the Gap: Unifying AI Risk Management with NIST CSF 2.0,' is about cutting through the noise. (and it can be really loud!)  I'll show you how to stop managing AI risk with a patchwork of solutions and start using a cohesive, practical approach. I'll take two powerful tools—NIST's CSF 2.0 and the AI RMF—and provide a clear, actionable blueprint for unifying them.
You'll leave with a simplified, repeatable process for managing AI risk that you can implement in your organization immediately. Forget the theory; this is about actionable strategy and real-world implementation
The Pain & The Promise: The AI Risk Gap: The explosion of AI has created a critical governance problem: security and risk teams are managing highly abstract AI risks—from algorithmic bias to data poisoning—outside the established controls of the enterprise. This disconnect is chaotic, paralyzing innovation and rendering compliance efforts ineffective. This session provides the solution: a practical, repeatable methodology to finally bridge this gap.
The Bridge-Building Process: Establishing the FoundationIntroduction to the core concept of using the CSF as the enterprise container and the AI RMF as the specialist's tool.
The Bridge-Building Process: We establish a unified framework where the NIST CSF 2.0 provides the overarching Cybersecurity Management System (the Outer Frame), and the NIST AI RMF serves as the Specialized AI Risk Engine (the Inner Core). Our approach focuses on developing a Cyber-AI Profile—a focused set of CSF outcomes tailored specifically to your AI systems and MLOps (a set of practices, tools, and collaborative platforms designed to automate and streamline the entire machine learning lifecycle) environment.

The Blueprint ->   The Integration ->  The Workflow
The What!             The So What!          The How! 
The Foundation    The Bridge              The Application

The Blueprint: Mapping the AI Lifecycle , The Integration and  A Simple Workflow: We will detail a clear, actionable workflow, 4 Steps- showing how AI RMF activities map across the six CSF functions:an example of the first 3
  • GOVERN (The Policy Layer): How AI RMF's Govern function defines the AI Risk Appetite and assigns accountability for the model (GV.RM).
  • IDENTIFY (The Assessment Layer): Using AI RMF's Map and Measure functions to perform Threat Modeling and quantify non-cyber risks (like unacceptable bias) for the CSF risk register (ID.RA)
  • PROTECT (The Control Layer): Implementing MLOps controls for Training Data Integrity and securing the model artifact against tampering (PR.DS, PR.PS).


Speakers
avatar for Jeanine Baisi

Jeanine Baisi

Product Security Consultant, Motorola Solutions Inc.
Jeanine Baisi brings over 20 years of experience in cybersecurity standards, frameworks, and cross-technology practices. A veteran of Motorola Solutions (MSI) for the past decade, Jeanine has navigated pivotal roles ranging from Security Field Services to her current position as a... Read More →
Friday October 9, 2026 1:15pm - 2:00pm PDT
⏪️ 3. Despair (Ballroom)

Attendees (0)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link