SlideShare a Scribd company logo
ACCELERATING
BUSINESS AND
RESEARCH
THROUGH
AUTOMATION
AND ARTIFICIAL
INTELLIGENCE IN
THE CMMC
DOMAIN
CMMC Day
Westin Arlington Gateway
Virginia, USA
May 15th, 2023
Patrick Hannah
CTO
CloudHesive
Introduction
Automation, Artificial Intelligence (AI) and Machine Learning (ML) has application in the Cybersecurity
Maturity Model Certification (CMMC) framework in increasing the efficiency and productivity of
organizations participating directly in the Defense Industrial Base (DIB) or research institutions
consuming/producing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI)
Collectively, these “tools” (Automation, AI and ML) can be leveraged to improve an organization’s
implementation and maintenance of an organizational security practice aligned with CMMC, with
improvement measured by labor effort reduction and consistency in application
At the same time, these tools can be leveraged by the workload(s) that fall under the organizational
security practice – e.g. the the technology used in the production of the work product, particularly in
higher education and research institutions
While there is value in the use of these tools, they are not without challenges, and understanding the
multitude of risks, including data security and ethical risks are critical in evaluating the trade-offs
We are at the intersection of 4 domains
CMMC: Organizational alignment, implementation and ongoing maintenance of an information security program aligned to CMMC
Workloads: A broad range of technologies available to organizations and leveraged by organizations who process or produce FCI or CUI
Cloud: Both enabled by Cloud Computing (which NIST 800-145 defines as having the following characteristics):
On Demand Self Service
Broad Network Access
Resource Pooling
Rapid Elasticity
Measured Service
AI/ML: Artificial Intelligence and Machine Learning (also enabled by cloud computing) and loosely described as:
Artificial Intelligence – analogous to SaaS or APIs – an example of this could be Alexa
Machine Learning – analogous to PaaS and Data that you select, implement, operate and maintain – an example of this might be SageMaker
Frameworks – analogous to Software and Data that you select, implement, operate and maintain – an example of this might be Hugging Face NLP
Infrastructure – analogous to IaaS – an example of this might be as simple as a CPU or GPU, physical or cloud-based
Cloud (AWS) Service Categories
Analytics
Application Integration
AWS Cost Management
Blockchain
Business Applications
Compute
Containers
Customer Enablement
Database
Developer Tools
End User Computing
Front-end Web & Mobile
Game Development
Internet of Things
Machine Learning
Management & Governance
Media Services
Migration & Transfer
Networking & Content Delivery
Quantum Technologies
Robotics
Satellite
Security, Identity, & Compliance
Storage
Cloud Workload Types and Origins
Types
Serverless/Native
Service Based
Compute and Container – Orchestrated & Not
Bare Metal, Virtual Machine, ECS, EKS, K8s
Origins
Migrated As-Is
Server Based
Migrated & Optimized
Blends of Server and Service Based
Inherited
Mixed
Hybrid
Mixed
Cloud Workload Lifecycle Management
Workload
Architecture
Monitoring
Automation
Processes
Integration
AI/ML Lifecycle (AWS W-A-F ML Lens)
Themes are forming…
Key Themes from the Q4 2022 AWS Machine Learning
Visionaries Partners Report
Federated Learning Operations
MLOps on Kubernetes
ML Using High Performance Computing (HPC)
Trusted AI
Decision Intelligence
Generative AI
Themes are forming…
The AI Index Report (Stanford)
Industry races ahead of academia
Performance saturation on traditional benchmarks
AI is both helping and harming the environment
The world’s best new scientist … AI?
The number of incidents concerning the misuse of AI is rapidly rising
The remand for AI-related professional skills is increasing across virtually every
American industrial sector
For the first time in the last decade, year-over-year private investment in AI decreased
While the proportion of companies adopting AI has plateaued, the companies that
have adopted AI continue to pull ahead
Policymaker interest in AI is on the rise
Chinese citizens are among those who feel the most positively about AI products and
services. Americans … not so much
…Progress is accelerating
When the abstract was accepted (2/15/2023) until now (5/15/2023) Generative AI has dominated the headlines – GitHub CoPilot,
OpenAI DALL-E, OpenAI ChatGPT are all examples of this. While this has seemingly happened at an accelerated pace, OpenAI’s
projects represent 7 years of work
In three months this has become front and center, but reflects decades of research, investment and refinement and is endemic to our
lives in so many ways – some of those are in front of us: PowerPoint makes suggestions on how to write or format a slide and generates
ALT text for the images, OSX’s image viewer does OCR so well, I’ve had to double-check that I’m looking at an image and not a PDF,
and Chrome can Translate websites for me. All of these contributed to the preparation of this presentation
Generative AI has seemingly gone from a novelty to a technology fit for investment by recognizable technology companies such as
AWS, Microsoft and Google, while also bringing OpenAI into the same conversations. It’s helped these organizations enhance their core
offerings (search, for example) while also providing new revenue streams (subscriptions to personal AI) or the foundation for
organizations to build on top of
With that investment and adoption, options and differentiators have been created in the market with focus on accuracy, application, trust,
amusement and economics
This presentation was not written by Generative AI (but the abstract was)
Abstract
The use of automation and artificial intelligence (AI) in the Cybersecurity Maturity Model
Certification (CMMC) framework has the potential to significantly increase the efficiency and
productivity of businesses and research institutions. This talk will explore the various ways in
which AI and automation can be leveraged to improve various aspects of organizational
operations within the CMMC framework. One key benefit of using AI and automation in the
CMMC framework is the potential to improve compliance with cybersecurity standards. These
technologies can help organizations to more efficiently and effectively implement the
necessary controls and processes to meet CMMC requirements. Additionally, the use of AI
and automation can speed up the time to market for products and services, as it can help to
streamline various internal processes and reduce the need for manual labor. However, the
implementation of AI and automation within the CMMC framework also brings potential ethical
concerns, such as the impact on employment and the potential for biased decision-making.
This talk will examine these concerns and discuss strategies for addressing them. In addition
to the benefits for businesses, the speaker will also discuss the role of AI and automation in
research within the CMMC framework, including the use of these technologies in higher
education and research institutions. Attendees will come away with a greater understanding of
the potential applications of AI and automation in the CMMC framework in their own
organizations, as well as the benefits and challenges associated with implementing these
technologies.
Responsible use of AI and ML
Phase 1: Design and Development
Evaluating Use Cases
ML Capabilities and Limitations
Building and Training Diverse Teams
Be Mindful of Overall Impact
Data Collection
Training and Testing Data
Bias
Explainability of ML Systems
Auditability
Legal Compliance
Phase 2: Deployment
Education, Documentation and Training
Confidence Levels and Human Review
Use Case Evaluation and Testing
Notice and Accessibility
Operational Data
Safety, Security and Robustness
Legal Compliance
Phase 3: Operation
Provide and Use Feedback
Mechanisms
Continuous Improvement and Validation
Ongoing Education
ML Capabilities and Limitations - Personification
Is Personification of AI/ML the same reason that PC’s were originally beige and box-like?
Does it make it relatable and approachable?
Does it create brand recognition?
Does it make it easier to interact/integrate with?
Some examples of Personification
Product Names like Alexa, Siri
Voice/Text Style
Referring to “mistakes as Hallucinations
Personification/humanizing AI/ML has downsides:
It may result in misaligned expectations
It may create ethical concerns
It may create dependence where technical accuracy is required but not delivered
Emily Bender had this to say about Hallucinations “And let's reflect for a moment on how they phrased their disclaimer, shall we? 'Hallucinate' is a terrible word choice
here, suggesting as it does that the language model has *experiences* and *perceives things*. (And on top of that, it's making light of a symptom of serious mental
illness.) Likewise 'LLMs are often Confident'. No, they're not. That would require subjective emotion."
Ultimately, Animals (including People) and AI/ML may demonstrate similar characteristics, but the process in which those characteristics are generated is not the same
Explainability (and Amusement)
Legal Compliance – Considerations
ChatGPT March 20th, 2023 (OpenAI)
Titles and First Messages Leakage
Samsung March 30th, 2023 (The Economist KR)
3 incidents of information leakage using ChatGPT
Understand AI services opt-out policies
”Commercial” services such as AWS offer these
“Consumer” services offer something similar, but not generally an opt-out
Legal Compliance - AI/ML Generated Works and Copyright
Expert opinion on whether Slater (the Photographer)
owns the copyright on the photographs is mixed.
On 21 August 2014 the United States Copyright Office
published an opinion, later included in the third edition of
the office's Compendium of U.S. Copyright Office
Practices, released on 22 December 2014, to clarify that
"only works created by a human can be copyrighted
under United States law, which excludes photographs
and artwork created by animals or by machines without
human intervention" and that "Because copyright law is
limited to 'original intellectual conceptions of the author',
the [copyright] office will refuse to register a claim if it
determines that a human being did not create the work.
The Office will not register works produced by nature,
animals, or plants.”
The compendium specifically highlights "a photograph
taken by a monkey" (right) as an example of something
that cannot be copyrighted.
Safety, Security and Robustness
Be Mindful of Overall Impact – Sustainability
Industry Goals
AWS Goals – Water Positive 2030, 100% Renewable Energy 2025
Partner Impact – 1 of 13 domains in MSP Audit focus on sustainability
Industry Impact – 1 of 6 pillars in Well Architected Framework focus on sustainability
Customer Impact – Proactive (planning) and reactive (actual consumption) visibility into a workload’s Carbon Footprint
Organizational Goals
Your Goals
Our Unique Position
Sphere of Influence Impact
Direct Impact
Sustainability in technology starts with optimization (cost, performance, etc.) – it doesn’t end there
Defining operational parameters – how “fast” does ”it” need to be?
Service selection (which can be influenced by/influences cost optimization objectives) – running 24 hours a day servicing work-day application
If the only tool you have is a hammer, it is tempting to treat everything as if it were a nail - Abraham Maslow
Purpose Built is preferred over Custom Logic, which is preferred over AI, which is preferred over ML
At the ML level, weigh it’s use and its impact on your sustainability goals versus alternatives
Ethical
ChatGPT Disclaimers
Recent Advancements in (US) Government
Aligned to Responsible use of AI/ML
Executive Order on Further Advancing Racial Equity and Support for Underserved Communities
Through The Federal Government
Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems –
CFPB, DOJ, EEOE, FTC
Blueprint for an AI Bill of Rights – Safe and Effective Systems, Algorithmic Discrimination Projections,
Data Privacy, Notice and Explanation, Human Alternatives, Consideration and Fallback
NIST AI Risk Management Framework
Strengthening and Democratizing the U.S. Artificial Intelligence Innovation Ecosystem –
National Artificial Intelligence Research Resource Task Force
Advancing Responsible Artificial Intelligence Innovation, which Introduces:
New investments to power responsible American AI research and development (R&D)
Public assessments of existing generative AI systems
Policies to ensure the U.S. government is leading by example on mitigating AI risks and harnessing AI
opportunities
Sampling of an Organization’s Responsibilities
Organizational Readiness
History
Current state
Maintenance of the current state
Data generation, processing, storage, retrieval
Understand the flow
Scope Reduction
Use an enclave to segment and protect data
Descope where possible – organization, people, domains, access
People Considerations
Employees
Contractors
Vendors
Software/Cloud Considerations
Vary based on COTS versus Custom versus Cloud
Continuous Monitoring
We have all these sources of data we are responsible for – Events and
States
Data derived from the third-party solutions
We need to be able to tell current state and review historically
To support the sample processes
We need to be able to react to the high priority items
Push versus Pull
We need to demonstrate we are doing this
It’s part of the process
Windows and Other Events
Cloud Events
AWS Events
Event Response
The application of AI/ML in the process
How do we address compliance to these “new” tools?
Let’s explore two common use cases where AI/ML services may be used with or
used to create FCI or CUI
Virtual Desktop Enclaves – typical of Organizations in the DIB
Data Enclaves – typical of Higher Education and Research Institutions
How can we use these “new” tools to help us address compliance?
Correlation and “Peopleless” triage of events
Automation of tasks and workflows where consistency, effort and
responsiveness outweigh manual effort
You may already be using it and not know it – many AWS services have
automated reasoning built in
Machine Learning
Amazon Augmented AI - Easily implement human review of machine learning
predictions
Amazon CodeGuru - Intelligent recommendations for building and running
modern applications
Amazon Comprehend - Analyze Unstructured Text
Amazon Comprehend Medical - Amazon Comprehend Medical uses machine
learning to extract insights and relationships from medical text.
AWS DeepComposer - AWS DeepComposer allows developers of all skill levels
to get started with Generative AI.
AWS DeepLens - Deep Learning Enabled Video Camera
AWS DeepRacer - Fully autonomous 1/18th scale race car, driven by machine
learning
Amazon DevOps Guru - ML-powered cloud operations service to improve
application availability.
Amazon Forecast - Amazon Forecast is a fully-managed service for accurate
time-series forecasting
Amazon Fraud Detector - Detect more online fraud faster using machine learning
Amazon HealthLake - Making sense of health data
Amazon Kendra - Highly accurate enterprise search service powered by
machine learning
Amazon Lex - Build Voice and Text Chatbots
Amazon Lookout for Equipment - Detect abnormal equipment behavior by
analyzing sensor data
Amazon Lookout for Metrics - Accurately detect anomalies in your business
metrics and quickly understand why
Amazon Lookout for Vision - Identify defects using computer vision to automate
quality inspection.
Amazon Monitron - End-to-end system for equipment monitoring
Amazon Omics - Transform omics data into insights.
AWS Panorama - Enabling computer vision applications at the edge
Amazon Personalize - Amazon Personalize helps you easily add real-time
recommendations to your apps
Amazon Polly - Turn Text into Lifelike Speech
Amazon Rekognition - Search and Analyze Images
Amazon SageMaker - Build, Train, and Deploy Machine Learning Models
Amazon Textract - Easily extract text and data from virtually any document
Amazon Transcribe - Powerful Speech Recognition
Amazon Translate - Powerful Neural Machine Translation
Security, Identity, & Compliance
AWS Audit Manager - Continuously assess controls for risk and compliance
Detective - Investigate and analyze potential security issues
GuardDuty - Intelligent Threat Detection to Protect Your AWS Accounts and
Workloads
IAM - Manage access to AWS resources
Amazon Macie - Amazon Macie classifies and secures your business-critical content.
Security Hub - AWS Security Hub is AWS’s security and compliance center
Security Lake - Automatically centralize all your security data with a few clicks
Amazon Verified Permissions - Manage, analyze and enforce permissions across
your applications
Conclusion
Work with your organization to develop policy, and evangelize the
acceptable use of AI/ML in achieving your mission objectives
There are no lack of resources to aid in in this effort, and while this is not
conclusive, these might be some areas you might want to prioritize:
Acceptable Accuracy Rates
Supervision Requirements
Risks Introduced by Inaccuracy
Fallback/Failback Positions
Data privacy implications, especially for hosted services
Get Educated! There are many resources throughout this presentation as
well as groups, such as The Good AI (https://thegoodai.org/), that address
the Ethical Implications of AI
Start Small and Iterate!
0800-860-2040
sales-latam@cloudhesive.com
cloudhesive.com
Fort Lauderdale
2419 E. Commercial Blvd, Ste. 300
Ft. Lauderdale, Florida
USA
Buenos Aires
Av. Del Libertador 6680, Piso 6
CABA, Ciudad de Buenos Aires
Argentina
Santiago de Chile
Cerro El Plomo 5420 SB1, Oficina 15
Nueva Las Condes, Santiago de Chile
Chile

More Related Content

Similar to Accelerating Business and Research Through Automation and Artificial Intelligence in the CMMC Domain.pptx

Hybrid use of machine learning and ontology
Hybrid use of machine learning and ontologyHybrid use of machine learning and ontology
Hybrid use of machine learning and ontology
Anthony (Tony) Sarris
 
Cis 519 Week 3 Individual Assignment
Cis 519 Week 3 Individual AssignmentCis 519 Week 3 Individual Assignment
Cis 519 Week 3 Individual Assignment
April Dillard
 
Cloud based Machine Learning Platforms, a review - Sagar Khashu
Cloud based Machine Learning Platforms, a review - Sagar KhashuCloud based Machine Learning Platforms, a review - Sagar Khashu
Cloud based Machine Learning Platforms, a review - Sagar KhashuSagar Khashu
 
The Robos Are Coming - How AI will revolutionize Insurance 0117
The Robos Are Coming - How AI will revolutionize Insurance 0117The Robos Are Coming - How AI will revolutionize Insurance 0117
The Robos Are Coming - How AI will revolutionize Insurance 0117Graham Clark
 
Future of work machine learning and middle level jobs 112618
Future of work machine learning and middle level jobs 112618Future of work machine learning and middle level jobs 112618
Future of work machine learning and middle level jobs 112618
Economic Strategy Institute
 
Top AI & ML tools and frameworks
Top AI & ML tools and frameworksTop AI & ML tools and frameworks
Top AI & ML tools and frameworks
Logic Fruit Technologies
 
aiproject.pptx
aiproject.pptxaiproject.pptx
aiproject.pptx
KamleshParihar12
 
How machine learning will affect software development
How machine learning will affect software development How machine learning will affect software development
How machine learning will affect software development
venkatvajradhar1
 
Understanding GenAI/LLM and What is Google Offering - Felix Goh
Understanding GenAI/LLM and What is Google Offering - Felix GohUnderstanding GenAI/LLM and What is Google Offering - Felix Goh
Understanding GenAI/LLM and What is Google Offering - Felix Goh
NUS-ISS
 
Are You an Accidental or Intentional Architect?
Are You an Accidental or Intentional Architect?Are You an Accidental or Intentional Architect?
Are You an Accidental or Intentional Architect?
iasaglobal
 
The value of cloud computing to ITSM
The value of cloud computing to ITSMThe value of cloud computing to ITSM
The value of cloud computing to ITSM
Patrick Keogh
 
User Experience of AI - How to marry the two for ultimate success?
User Experience of AI - How to marry the two for ultimate success?User Experience of AI - How to marry the two for ultimate success?
User Experience of AI - How to marry the two for ultimate success?
Koru UX Design
 
Improve Customer Experience Management with Text Analytics - MeaningCloud web...
Improve Customer Experience Management with Text Analytics - MeaningCloud web...Improve Customer Experience Management with Text Analytics - MeaningCloud web...
Improve Customer Experience Management with Text Analytics - MeaningCloud web...
MeaningCloud
 
EMERGING ISSUES AND TRENDS IN INFORMATION SYSTEMS (Lecutre 10) .dox-1.docx
EMERGING ISSUES AND TRENDS IN INFORMATION SYSTEMS (Lecutre 10) .dox-1.docxEMERGING ISSUES AND TRENDS IN INFORMATION SYSTEMS (Lecutre 10) .dox-1.docx
EMERGING ISSUES AND TRENDS IN INFORMATION SYSTEMS (Lecutre 10) .dox-1.docx
adhiambodiana412
 
Ai open powermeetupmarch25th
Ai open powermeetupmarch25thAi open powermeetupmarch25th
Ai open powermeetupmarch25th
IBM
 
Real World End to End machine Learning Pipeline
Real World End to End machine Learning PipelineReal World End to End machine Learning Pipeline
Real World End to End machine Learning Pipeline
Srivatsan Srinivasan
 
Ai open powermeetupmarch25th
Ai open powermeetupmarch25thAi open powermeetupmarch25th
Ai open powermeetupmarch25th
IBM
 
Ai open powermeetupmarch25th
Ai open powermeetupmarch25thAi open powermeetupmarch25th
Ai open powermeetupmarch25th
IBM
 
A Practical Guide to AI and Automation
A Practical Guide to AI and AutomationA Practical Guide to AI and Automation
A Practical Guide to AI and Automation
Accelirate Inc.
 

Similar to Accelerating Business and Research Through Automation and Artificial Intelligence in the CMMC Domain.pptx (20)

Hybrid use of machine learning and ontology
Hybrid use of machine learning and ontologyHybrid use of machine learning and ontology
Hybrid use of machine learning and ontology
 
Cis 519 Week 3 Individual Assignment
Cis 519 Week 3 Individual AssignmentCis 519 Week 3 Individual Assignment
Cis 519 Week 3 Individual Assignment
 
Cloud based Machine Learning Platforms, a review - Sagar Khashu
Cloud based Machine Learning Platforms, a review - Sagar KhashuCloud based Machine Learning Platforms, a review - Sagar Khashu
Cloud based Machine Learning Platforms, a review - Sagar Khashu
 
The Robos Are Coming - How AI will revolutionize Insurance 0117
The Robos Are Coming - How AI will revolutionize Insurance 0117The Robos Are Coming - How AI will revolutionize Insurance 0117
The Robos Are Coming - How AI will revolutionize Insurance 0117
 
Future of work machine learning and middle level jobs 112618
Future of work machine learning and middle level jobs 112618Future of work machine learning and middle level jobs 112618
Future of work machine learning and middle level jobs 112618
 
Top AI & ML tools and frameworks
Top AI & ML tools and frameworksTop AI & ML tools and frameworks
Top AI & ML tools and frameworks
 
aiproject.pptx
aiproject.pptxaiproject.pptx
aiproject.pptx
 
How machine learning will affect software development
How machine learning will affect software development How machine learning will affect software development
How machine learning will affect software development
 
Understanding GenAI/LLM and What is Google Offering - Felix Goh
Understanding GenAI/LLM and What is Google Offering - Felix GohUnderstanding GenAI/LLM and What is Google Offering - Felix Goh
Understanding GenAI/LLM and What is Google Offering - Felix Goh
 
Are You an Accidental or Intentional Architect?
Are You an Accidental or Intentional Architect?Are You an Accidental or Intentional Architect?
Are You an Accidental or Intentional Architect?
 
Mann assignment
Mann assignmentMann assignment
Mann assignment
 
The value of cloud computing to ITSM
The value of cloud computing to ITSMThe value of cloud computing to ITSM
The value of cloud computing to ITSM
 
User Experience of AI - How to marry the two for ultimate success?
User Experience of AI - How to marry the two for ultimate success?User Experience of AI - How to marry the two for ultimate success?
User Experience of AI - How to marry the two for ultimate success?
 
Improve Customer Experience Management with Text Analytics - MeaningCloud web...
Improve Customer Experience Management with Text Analytics - MeaningCloud web...Improve Customer Experience Management with Text Analytics - MeaningCloud web...
Improve Customer Experience Management with Text Analytics - MeaningCloud web...
 
EMERGING ISSUES AND TRENDS IN INFORMATION SYSTEMS (Lecutre 10) .dox-1.docx
EMERGING ISSUES AND TRENDS IN INFORMATION SYSTEMS (Lecutre 10) .dox-1.docxEMERGING ISSUES AND TRENDS IN INFORMATION SYSTEMS (Lecutre 10) .dox-1.docx
EMERGING ISSUES AND TRENDS IN INFORMATION SYSTEMS (Lecutre 10) .dox-1.docx
 
Ai open powermeetupmarch25th
Ai open powermeetupmarch25thAi open powermeetupmarch25th
Ai open powermeetupmarch25th
 
Real World End to End machine Learning Pipeline
Real World End to End machine Learning PipelineReal World End to End machine Learning Pipeline
Real World End to End machine Learning Pipeline
 
Ai open powermeetupmarch25th
Ai open powermeetupmarch25thAi open powermeetupmarch25th
Ai open powermeetupmarch25th
 
Ai open powermeetupmarch25th
Ai open powermeetupmarch25thAi open powermeetupmarch25th
Ai open powermeetupmarch25th
 
A Practical Guide to AI and Automation
A Practical Guide to AI and AutomationA Practical Guide to AI and Automation
A Practical Guide to AI and Automation
 

More from CloudHesive

Serverless Generative AI on AWS, AWS User Groups of Florida
Serverless Generative AI on AWS, AWS User Groups of FloridaServerless Generative AI on AWS, AWS User Groups of Florida
Serverless Generative AI on AWS, AWS User Groups of Florida
CloudHesive
 
Amazon Connect & AI - Shaping the Future of Customer Interactions - GenAI and...
Amazon Connect & AI - Shaping the Future of Customer Interactions - GenAI and...Amazon Connect & AI - Shaping the Future of Customer Interactions - GenAI and...
Amazon Connect & AI - Shaping the Future of Customer Interactions - GenAI and...
CloudHesive
 
Amazon Connect Rethink Your Contact Center with CloudHesive.pptx
Amazon Connect Rethink Your Contact Center with CloudHesive.pptxAmazon Connect Rethink Your Contact Center with CloudHesive.pptx
Amazon Connect Rethink Your Contact Center with CloudHesive.pptx
CloudHesive
 
ConnectPath Introduction
ConnectPath IntroductionConnectPath Introduction
ConnectPath Introduction
CloudHesive
 
Modernize your contact center with ConnectPath CX v2.pdf
Modernize your contact center with ConnectPath CX v2.pdfModernize your contact center with ConnectPath CX v2.pdf
Modernize your contact center with ConnectPath CX v2.pdf
CloudHesive
 
Modernize your contact center with ConnectPath CX — Chart.pdf
Modernize your contact center with ConnectPath CX — Chart.pdfModernize your contact center with ConnectPath CX — Chart.pdf
Modernize your contact center with ConnectPath CX — Chart.pdf
CloudHesive
 
End User Computing at CloudHesive.pptx
End User Computing at CloudHesive.pptxEnd User Computing at CloudHesive.pptx
End User Computing at CloudHesive.pptx
CloudHesive
 
Analytics at CloudHesive
Analytics at CloudHesiveAnalytics at CloudHesive
Analytics at CloudHesive
CloudHesive
 
Supporting your CMMC initiatives with Sumo Logic
Supporting your CMMC initiatives with Sumo LogicSupporting your CMMC initiatives with Sumo Logic
Supporting your CMMC initiatives with Sumo Logic
CloudHesive
 
Best Practices and Resources to Effectively Manage and Optimize Your AWS Costs
Best Practices and Resources to Effectively Manage and Optimize Your AWS CostsBest Practices and Resources to Effectively Manage and Optimize Your AWS Costs
Best Practices and Resources to Effectively Manage and Optimize Your AWS Costs
CloudHesive
 
Serverless data and analytics on AWS for operations
Serverless data and analytics on AWS for operations Serverless data and analytics on AWS for operations
Serverless data and analytics on AWS for operations
CloudHesive
 
reInvent reCap 2022
reInvent reCap 2022reInvent reCap 2022
reInvent reCap 2022
CloudHesive
 
Serverless without Code (Lambda)
Serverless without Code (Lambda)Serverless without Code (Lambda)
Serverless without Code (Lambda)
CloudHesive
 
AWS Advanced Analytics Automation Toolkit (AAA)
AWS Advanced Analytics Automation Toolkit (AAA)AWS Advanced Analytics Automation Toolkit (AAA)
AWS Advanced Analytics Automation Toolkit (AAA)
CloudHesive
 
AWS Control Tower
AWS Control TowerAWS Control Tower
AWS Control Tower
CloudHesive
 
Security on AWS, 2021 Edition Meetup
Security on AWS, 2021 Edition MeetupSecurity on AWS, 2021 Edition Meetup
Security on AWS, 2021 Edition Meetup
CloudHesive
 
Security on AWS
Security on AWSSecurity on AWS
Security on AWS
CloudHesive
 
5 minutes on security
5 minutes on security5 minutes on security
5 minutes on security
CloudHesive
 
NIST Cybersecurity Framework (CSF) on the Public Cloud
NIST Cybersecurity Framework (CSF) on the Public CloudNIST Cybersecurity Framework (CSF) on the Public Cloud
NIST Cybersecurity Framework (CSF) on the Public Cloud
CloudHesive
 
Meetup Protect from Ransomware Attacks
Meetup Protect from Ransomware AttacksMeetup Protect from Ransomware Attacks
Meetup Protect from Ransomware Attacks
CloudHesive
 

More from CloudHesive (20)

Serverless Generative AI on AWS, AWS User Groups of Florida
Serverless Generative AI on AWS, AWS User Groups of FloridaServerless Generative AI on AWS, AWS User Groups of Florida
Serverless Generative AI on AWS, AWS User Groups of Florida
 
Amazon Connect & AI - Shaping the Future of Customer Interactions - GenAI and...
Amazon Connect & AI - Shaping the Future of Customer Interactions - GenAI and...Amazon Connect & AI - Shaping the Future of Customer Interactions - GenAI and...
Amazon Connect & AI - Shaping the Future of Customer Interactions - GenAI and...
 
Amazon Connect Rethink Your Contact Center with CloudHesive.pptx
Amazon Connect Rethink Your Contact Center with CloudHesive.pptxAmazon Connect Rethink Your Contact Center with CloudHesive.pptx
Amazon Connect Rethink Your Contact Center with CloudHesive.pptx
 
ConnectPath Introduction
ConnectPath IntroductionConnectPath Introduction
ConnectPath Introduction
 
Modernize your contact center with ConnectPath CX v2.pdf
Modernize your contact center with ConnectPath CX v2.pdfModernize your contact center with ConnectPath CX v2.pdf
Modernize your contact center with ConnectPath CX v2.pdf
 
Modernize your contact center with ConnectPath CX — Chart.pdf
Modernize your contact center with ConnectPath CX — Chart.pdfModernize your contact center with ConnectPath CX — Chart.pdf
Modernize your contact center with ConnectPath CX — Chart.pdf
 
End User Computing at CloudHesive.pptx
End User Computing at CloudHesive.pptxEnd User Computing at CloudHesive.pptx
End User Computing at CloudHesive.pptx
 
Analytics at CloudHesive
Analytics at CloudHesiveAnalytics at CloudHesive
Analytics at CloudHesive
 
Supporting your CMMC initiatives with Sumo Logic
Supporting your CMMC initiatives with Sumo LogicSupporting your CMMC initiatives with Sumo Logic
Supporting your CMMC initiatives with Sumo Logic
 
Best Practices and Resources to Effectively Manage and Optimize Your AWS Costs
Best Practices and Resources to Effectively Manage and Optimize Your AWS CostsBest Practices and Resources to Effectively Manage and Optimize Your AWS Costs
Best Practices and Resources to Effectively Manage and Optimize Your AWS Costs
 
Serverless data and analytics on AWS for operations
Serverless data and analytics on AWS for operations Serverless data and analytics on AWS for operations
Serverless data and analytics on AWS for operations
 
reInvent reCap 2022
reInvent reCap 2022reInvent reCap 2022
reInvent reCap 2022
 
Serverless without Code (Lambda)
Serverless without Code (Lambda)Serverless without Code (Lambda)
Serverless without Code (Lambda)
 
AWS Advanced Analytics Automation Toolkit (AAA)
AWS Advanced Analytics Automation Toolkit (AAA)AWS Advanced Analytics Automation Toolkit (AAA)
AWS Advanced Analytics Automation Toolkit (AAA)
 
AWS Control Tower
AWS Control TowerAWS Control Tower
AWS Control Tower
 
Security on AWS, 2021 Edition Meetup
Security on AWS, 2021 Edition MeetupSecurity on AWS, 2021 Edition Meetup
Security on AWS, 2021 Edition Meetup
 
Security on AWS
Security on AWSSecurity on AWS
Security on AWS
 
5 minutes on security
5 minutes on security5 minutes on security
5 minutes on security
 
NIST Cybersecurity Framework (CSF) on the Public Cloud
NIST Cybersecurity Framework (CSF) on the Public CloudNIST Cybersecurity Framework (CSF) on the Public Cloud
NIST Cybersecurity Framework (CSF) on the Public Cloud
 
Meetup Protect from Ransomware Attacks
Meetup Protect from Ransomware AttacksMeetup Protect from Ransomware Attacks
Meetup Protect from Ransomware Attacks
 

Recently uploaded

BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024
Ortus Solutions, Corp
 
Pro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp BookPro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp Book
abdulrafaychaudhry
 
A Sighting of filterA in Typelevel Rite of Passage
A Sighting of filterA in Typelevel Rite of PassageA Sighting of filterA in Typelevel Rite of Passage
A Sighting of filterA in Typelevel Rite of Passage
Philip Schwarz
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
Drona Infotech
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
Łukasz Chruściel
 
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdf
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdfAutomated software refactoring with OpenRewrite and Generative AI.pptx.pdf
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdf
timtebeek1
 
LORRAINE ANDREI_LEQUIGAN_HOW TO USE ZOOM
LORRAINE ANDREI_LEQUIGAN_HOW TO USE ZOOMLORRAINE ANDREI_LEQUIGAN_HOW TO USE ZOOM
LORRAINE ANDREI_LEQUIGAN_HOW TO USE ZOOM
lorraineandreiamcidl
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
abdulrafaychaudhry
 
Quarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden ExtensionsQuarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden Extensions
Max Andersen
 
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of CodeA Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
Aftab Hussain
 
Introduction to Pygame (Lecture 7 Python Game Development)
Introduction to Pygame (Lecture 7 Python Game Development)Introduction to Pygame (Lecture 7 Python Game Development)
Introduction to Pygame (Lecture 7 Python Game Development)
abdulrafaychaudhry
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus
 
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdfVitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke
 
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptxTop Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
rickgrimesss22
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
Safe Software
 
Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"
Donna Lenk
 
Game Development with Unity3D (Game Development lecture 3)
Game Development  with Unity3D (Game Development lecture 3)Game Development  with Unity3D (Game Development lecture 3)
Game Development with Unity3D (Game Development lecture 3)
abdulrafaychaudhry
 
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data AnalysisProviding Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Globus
 
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Łukasz Chruściel
 

Recently uploaded (20)

BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024
 
Pro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp BookPro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp Book
 
A Sighting of filterA in Typelevel Rite of Passage
A Sighting of filterA in Typelevel Rite of PassageA Sighting of filterA in Typelevel Rite of Passage
A Sighting of filterA in Typelevel Rite of Passage
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
 
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdf
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdfAutomated software refactoring with OpenRewrite and Generative AI.pptx.pdf
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdf
 
LORRAINE ANDREI_LEQUIGAN_HOW TO USE ZOOM
LORRAINE ANDREI_LEQUIGAN_HOW TO USE ZOOMLORRAINE ANDREI_LEQUIGAN_HOW TO USE ZOOM
LORRAINE ANDREI_LEQUIGAN_HOW TO USE ZOOM
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
 
Quarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden ExtensionsQuarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden Extensions
 
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of CodeA Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
 
Introduction to Pygame (Lecture 7 Python Game Development)
Introduction to Pygame (Lecture 7 Python Game Development)Introduction to Pygame (Lecture 7 Python Game Development)
Introduction to Pygame (Lecture 7 Python Game Development)
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
 
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdfVitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdf
 
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptxTop Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
 
Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"
 
Game Development with Unity3D (Game Development lecture 3)
Game Development  with Unity3D (Game Development lecture 3)Game Development  with Unity3D (Game Development lecture 3)
Game Development with Unity3D (Game Development lecture 3)
 
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data AnalysisProviding Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
 
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
 

Accelerating Business and Research Through Automation and Artificial Intelligence in the CMMC Domain.pptx

  • 1. ACCELERATING BUSINESS AND RESEARCH THROUGH AUTOMATION AND ARTIFICIAL INTELLIGENCE IN THE CMMC DOMAIN CMMC Day Westin Arlington Gateway Virginia, USA May 15th, 2023 Patrick Hannah CTO CloudHesive
  • 2. Introduction Automation, Artificial Intelligence (AI) and Machine Learning (ML) has application in the Cybersecurity Maturity Model Certification (CMMC) framework in increasing the efficiency and productivity of organizations participating directly in the Defense Industrial Base (DIB) or research institutions consuming/producing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) Collectively, these “tools” (Automation, AI and ML) can be leveraged to improve an organization’s implementation and maintenance of an organizational security practice aligned with CMMC, with improvement measured by labor effort reduction and consistency in application At the same time, these tools can be leveraged by the workload(s) that fall under the organizational security practice – e.g. the the technology used in the production of the work product, particularly in higher education and research institutions While there is value in the use of these tools, they are not without challenges, and understanding the multitude of risks, including data security and ethical risks are critical in evaluating the trade-offs
  • 3. We are at the intersection of 4 domains CMMC: Organizational alignment, implementation and ongoing maintenance of an information security program aligned to CMMC Workloads: A broad range of technologies available to organizations and leveraged by organizations who process or produce FCI or CUI Cloud: Both enabled by Cloud Computing (which NIST 800-145 defines as having the following characteristics): On Demand Self Service Broad Network Access Resource Pooling Rapid Elasticity Measured Service AI/ML: Artificial Intelligence and Machine Learning (also enabled by cloud computing) and loosely described as: Artificial Intelligence – analogous to SaaS or APIs – an example of this could be Alexa Machine Learning – analogous to PaaS and Data that you select, implement, operate and maintain – an example of this might be SageMaker Frameworks – analogous to Software and Data that you select, implement, operate and maintain – an example of this might be Hugging Face NLP Infrastructure – analogous to IaaS – an example of this might be as simple as a CPU or GPU, physical or cloud-based
  • 4. Cloud (AWS) Service Categories Analytics Application Integration AWS Cost Management Blockchain Business Applications Compute Containers Customer Enablement Database Developer Tools End User Computing Front-end Web & Mobile Game Development Internet of Things Machine Learning Management & Governance Media Services Migration & Transfer Networking & Content Delivery Quantum Technologies Robotics Satellite Security, Identity, & Compliance Storage
  • 5. Cloud Workload Types and Origins Types Serverless/Native Service Based Compute and Container – Orchestrated & Not Bare Metal, Virtual Machine, ECS, EKS, K8s Origins Migrated As-Is Server Based Migrated & Optimized Blends of Server and Service Based Inherited Mixed Hybrid Mixed
  • 6. Cloud Workload Lifecycle Management Workload Architecture Monitoring Automation Processes Integration
  • 7. AI/ML Lifecycle (AWS W-A-F ML Lens)
  • 8. Themes are forming… Key Themes from the Q4 2022 AWS Machine Learning Visionaries Partners Report Federated Learning Operations MLOps on Kubernetes ML Using High Performance Computing (HPC) Trusted AI Decision Intelligence Generative AI
  • 9. Themes are forming… The AI Index Report (Stanford) Industry races ahead of academia Performance saturation on traditional benchmarks AI is both helping and harming the environment The world’s best new scientist … AI? The number of incidents concerning the misuse of AI is rapidly rising The remand for AI-related professional skills is increasing across virtually every American industrial sector For the first time in the last decade, year-over-year private investment in AI decreased While the proportion of companies adopting AI has plateaued, the companies that have adopted AI continue to pull ahead Policymaker interest in AI is on the rise Chinese citizens are among those who feel the most positively about AI products and services. Americans … not so much
  • 10. …Progress is accelerating When the abstract was accepted (2/15/2023) until now (5/15/2023) Generative AI has dominated the headlines – GitHub CoPilot, OpenAI DALL-E, OpenAI ChatGPT are all examples of this. While this has seemingly happened at an accelerated pace, OpenAI’s projects represent 7 years of work In three months this has become front and center, but reflects decades of research, investment and refinement and is endemic to our lives in so many ways – some of those are in front of us: PowerPoint makes suggestions on how to write or format a slide and generates ALT text for the images, OSX’s image viewer does OCR so well, I’ve had to double-check that I’m looking at an image and not a PDF, and Chrome can Translate websites for me. All of these contributed to the preparation of this presentation Generative AI has seemingly gone from a novelty to a technology fit for investment by recognizable technology companies such as AWS, Microsoft and Google, while also bringing OpenAI into the same conversations. It’s helped these organizations enhance their core offerings (search, for example) while also providing new revenue streams (subscriptions to personal AI) or the foundation for organizations to build on top of With that investment and adoption, options and differentiators have been created in the market with focus on accuracy, application, trust, amusement and economics This presentation was not written by Generative AI (but the abstract was)
  • 11. Abstract The use of automation and artificial intelligence (AI) in the Cybersecurity Maturity Model Certification (CMMC) framework has the potential to significantly increase the efficiency and productivity of businesses and research institutions. This talk will explore the various ways in which AI and automation can be leveraged to improve various aspects of organizational operations within the CMMC framework. One key benefit of using AI and automation in the CMMC framework is the potential to improve compliance with cybersecurity standards. These technologies can help organizations to more efficiently and effectively implement the necessary controls and processes to meet CMMC requirements. Additionally, the use of AI and automation can speed up the time to market for products and services, as it can help to streamline various internal processes and reduce the need for manual labor. However, the implementation of AI and automation within the CMMC framework also brings potential ethical concerns, such as the impact on employment and the potential for biased decision-making. This talk will examine these concerns and discuss strategies for addressing them. In addition to the benefits for businesses, the speaker will also discuss the role of AI and automation in research within the CMMC framework, including the use of these technologies in higher education and research institutions. Attendees will come away with a greater understanding of the potential applications of AI and automation in the CMMC framework in their own organizations, as well as the benefits and challenges associated with implementing these technologies.
  • 12. Responsible use of AI and ML Phase 1: Design and Development Evaluating Use Cases ML Capabilities and Limitations Building and Training Diverse Teams Be Mindful of Overall Impact Data Collection Training and Testing Data Bias Explainability of ML Systems Auditability Legal Compliance Phase 2: Deployment Education, Documentation and Training Confidence Levels and Human Review Use Case Evaluation and Testing Notice and Accessibility Operational Data Safety, Security and Robustness Legal Compliance Phase 3: Operation Provide and Use Feedback Mechanisms Continuous Improvement and Validation Ongoing Education
  • 13. ML Capabilities and Limitations - Personification Is Personification of AI/ML the same reason that PC’s were originally beige and box-like? Does it make it relatable and approachable? Does it create brand recognition? Does it make it easier to interact/integrate with? Some examples of Personification Product Names like Alexa, Siri Voice/Text Style Referring to “mistakes as Hallucinations Personification/humanizing AI/ML has downsides: It may result in misaligned expectations It may create ethical concerns It may create dependence where technical accuracy is required but not delivered Emily Bender had this to say about Hallucinations “And let's reflect for a moment on how they phrased their disclaimer, shall we? 'Hallucinate' is a terrible word choice here, suggesting as it does that the language model has *experiences* and *perceives things*. (And on top of that, it's making light of a symptom of serious mental illness.) Likewise 'LLMs are often Confident'. No, they're not. That would require subjective emotion." Ultimately, Animals (including People) and AI/ML may demonstrate similar characteristics, but the process in which those characteristics are generated is not the same
  • 15. Legal Compliance – Considerations ChatGPT March 20th, 2023 (OpenAI) Titles and First Messages Leakage Samsung March 30th, 2023 (The Economist KR) 3 incidents of information leakage using ChatGPT Understand AI services opt-out policies ”Commercial” services such as AWS offer these “Consumer” services offer something similar, but not generally an opt-out
  • 16. Legal Compliance - AI/ML Generated Works and Copyright Expert opinion on whether Slater (the Photographer) owns the copyright on the photographs is mixed. On 21 August 2014 the United States Copyright Office published an opinion, later included in the third edition of the office's Compendium of U.S. Copyright Office Practices, released on 22 December 2014, to clarify that "only works created by a human can be copyrighted under United States law, which excludes photographs and artwork created by animals or by machines without human intervention" and that "Because copyright law is limited to 'original intellectual conceptions of the author', the [copyright] office will refuse to register a claim if it determines that a human being did not create the work. The Office will not register works produced by nature, animals, or plants.” The compendium specifically highlights "a photograph taken by a monkey" (right) as an example of something that cannot be copyrighted.
  • 17. Safety, Security and Robustness
  • 18. Be Mindful of Overall Impact – Sustainability Industry Goals AWS Goals – Water Positive 2030, 100% Renewable Energy 2025 Partner Impact – 1 of 13 domains in MSP Audit focus on sustainability Industry Impact – 1 of 6 pillars in Well Architected Framework focus on sustainability Customer Impact – Proactive (planning) and reactive (actual consumption) visibility into a workload’s Carbon Footprint Organizational Goals Your Goals Our Unique Position Sphere of Influence Impact Direct Impact Sustainability in technology starts with optimization (cost, performance, etc.) – it doesn’t end there Defining operational parameters – how “fast” does ”it” need to be? Service selection (which can be influenced by/influences cost optimization objectives) – running 24 hours a day servicing work-day application If the only tool you have is a hammer, it is tempting to treat everything as if it were a nail - Abraham Maslow Purpose Built is preferred over Custom Logic, which is preferred over AI, which is preferred over ML At the ML level, weigh it’s use and its impact on your sustainability goals versus alternatives
  • 21. Recent Advancements in (US) Government Aligned to Responsible use of AI/ML Executive Order on Further Advancing Racial Equity and Support for Underserved Communities Through The Federal Government Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems – CFPB, DOJ, EEOE, FTC Blueprint for an AI Bill of Rights – Safe and Effective Systems, Algorithmic Discrimination Projections, Data Privacy, Notice and Explanation, Human Alternatives, Consideration and Fallback NIST AI Risk Management Framework Strengthening and Democratizing the U.S. Artificial Intelligence Innovation Ecosystem – National Artificial Intelligence Research Resource Task Force Advancing Responsible Artificial Intelligence Innovation, which Introduces: New investments to power responsible American AI research and development (R&D) Public assessments of existing generative AI systems Policies to ensure the U.S. government is leading by example on mitigating AI risks and harnessing AI opportunities
  • 22. Sampling of an Organization’s Responsibilities Organizational Readiness History Current state Maintenance of the current state Data generation, processing, storage, retrieval Understand the flow Scope Reduction Use an enclave to segment and protect data Descope where possible – organization, people, domains, access People Considerations Employees Contractors Vendors Software/Cloud Considerations Vary based on COTS versus Custom versus Cloud
  • 23. Continuous Monitoring We have all these sources of data we are responsible for – Events and States Data derived from the third-party solutions We need to be able to tell current state and review historically To support the sample processes We need to be able to react to the high priority items Push versus Pull We need to demonstrate we are doing this It’s part of the process
  • 28. The application of AI/ML in the process How do we address compliance to these “new” tools? Let’s explore two common use cases where AI/ML services may be used with or used to create FCI or CUI Virtual Desktop Enclaves – typical of Organizations in the DIB Data Enclaves – typical of Higher Education and Research Institutions How can we use these “new” tools to help us address compliance? Correlation and “Peopleless” triage of events Automation of tasks and workflows where consistency, effort and responsiveness outweigh manual effort You may already be using it and not know it – many AWS services have automated reasoning built in
  • 29. Machine Learning Amazon Augmented AI - Easily implement human review of machine learning predictions Amazon CodeGuru - Intelligent recommendations for building and running modern applications Amazon Comprehend - Analyze Unstructured Text Amazon Comprehend Medical - Amazon Comprehend Medical uses machine learning to extract insights and relationships from medical text. AWS DeepComposer - AWS DeepComposer allows developers of all skill levels to get started with Generative AI. AWS DeepLens - Deep Learning Enabled Video Camera AWS DeepRacer - Fully autonomous 1/18th scale race car, driven by machine learning Amazon DevOps Guru - ML-powered cloud operations service to improve application availability. Amazon Forecast - Amazon Forecast is a fully-managed service for accurate time-series forecasting Amazon Fraud Detector - Detect more online fraud faster using machine learning Amazon HealthLake - Making sense of health data Amazon Kendra - Highly accurate enterprise search service powered by machine learning Amazon Lex - Build Voice and Text Chatbots Amazon Lookout for Equipment - Detect abnormal equipment behavior by analyzing sensor data Amazon Lookout for Metrics - Accurately detect anomalies in your business metrics and quickly understand why Amazon Lookout for Vision - Identify defects using computer vision to automate quality inspection. Amazon Monitron - End-to-end system for equipment monitoring Amazon Omics - Transform omics data into insights. AWS Panorama - Enabling computer vision applications at the edge Amazon Personalize - Amazon Personalize helps you easily add real-time recommendations to your apps Amazon Polly - Turn Text into Lifelike Speech Amazon Rekognition - Search and Analyze Images Amazon SageMaker - Build, Train, and Deploy Machine Learning Models Amazon Textract - Easily extract text and data from virtually any document Amazon Transcribe - Powerful Speech Recognition Amazon Translate - Powerful Neural Machine Translation
  • 30. Security, Identity, & Compliance AWS Audit Manager - Continuously assess controls for risk and compliance Detective - Investigate and analyze potential security issues GuardDuty - Intelligent Threat Detection to Protect Your AWS Accounts and Workloads IAM - Manage access to AWS resources Amazon Macie - Amazon Macie classifies and secures your business-critical content. Security Hub - AWS Security Hub is AWS’s security and compliance center Security Lake - Automatically centralize all your security data with a few clicks Amazon Verified Permissions - Manage, analyze and enforce permissions across your applications
  • 31. Conclusion Work with your organization to develop policy, and evangelize the acceptable use of AI/ML in achieving your mission objectives There are no lack of resources to aid in in this effort, and while this is not conclusive, these might be some areas you might want to prioritize: Acceptable Accuracy Rates Supervision Requirements Risks Introduced by Inaccuracy Fallback/Failback Positions Data privacy implications, especially for hosted services Get Educated! There are many resources throughout this presentation as well as groups, such as The Good AI (https://thegoodai.org/), that address the Ethical Implications of AI Start Small and Iterate!
  • 32. 0800-860-2040 sales-latam@cloudhesive.com cloudhesive.com Fort Lauderdale 2419 E. Commercial Blvd, Ste. 300 Ft. Lauderdale, Florida USA Buenos Aires Av. Del Libertador 6680, Piso 6 CABA, Ciudad de Buenos Aires Argentina Santiago de Chile Cerro El Plomo 5420 SB1, Oficina 15 Nueva Las Condes, Santiago de Chile Chile

Editor's Notes

  1. https://docs.aws.amazon.com/wellarchitected/latest/machine-learning-lens/well-architected-machine-learning-lifecycle.html
  2. https://aws.amazon.com/blogs/apn/explore-key-themes-in-the-aws-machine-learning-visionaries-partners-report/
  3. https://aiindex.stanford.edu/report/
  4. Wolfram Alpha How Target Figured Out A Teen Girl Was Pregnant Before Her Father Did
  5. https://d1.awsstatic.com/responsible-machine-learning/responsible-use-of-machine-learning-guide.pdf
  6. https://en.wikipedia.org/wiki/Hallucination_(artificial_intelligence)
  7. https://en.m.wikipedia.org/wiki/Monkey_selfie_copyright_dispute#Expert_opinions