> ## Content Index
> Fetch the complete content index at: https://www.aigl.blog/llms.txt
> Use this file to discover other available public pages before exploring further.

# A multilayer framework for good cybersecurity practices for AI
- URL: https://www.aigl.blog/a-multilayer-framework-for-good-cybersecurity-practices-for-ai/
- Published: 2026-09-19T07:58:31.000Z
- Updated: 2026-09-19T07:58:31.000Z
- Description: This ENISA report presents a three-layer framework for securing AI systems through ICT cybersecurity foundations, AI-specific measures and sectoral practices. It also reports findings from a survey of EU national competent authorities.
- Author: Jakub Szarmach
- Tags: Report, AI Security, Risk Management, Technical Controls, EU AI Act, Compliance & Audit, #aigl-library

## ⚡ Quick Summary

Published by the European Union Agency for Cybersecurity (ENISA), this report presents the Framework for AI Good Cybersecurity Practices (FAICP), a scalable approach for national competent authorities (NCAs), AI stakeholders and the research community. Its purpose is to help secure AI systems, operations and processes across the full AI life cycle, their supporting ICT infrastructure, and supply-chain elements. It treats AI systems as cyber assets within an ICT infrastructure rather than as isolated models.

FAICP has three layers: cybersecurity foundations for the ICT environment; AI-specific cybersecurity addressing AI assets, life-cycle threats and controls; and sector-specific practices for AI used in areas including energy, health, automotive and telecommunications. The report argues that ordinary ICT security practices must be complemented by dynamic AI risk management that accounts for technical and social threats, including data poisoning, bias, fairness, transparency and accountability. It also analyses a 30-question survey of EU NCAs. Of the 10 responses received, the report finds limited AI-specific preparedness and recommends further guidance, tools, skills development, monitoring and research.

## 🧩 What’s Covered

The report proceeds from general ICT security to AI-specific and sectoral applications, then examines national preparedness.

- **Aims, beneficiaries and method:** Defines the study’s objectives: developing FAICP, collecting information on national cybersecurity requirements and enforcement, and identifying gaps. It identifies AI stakeholders and national authorities as beneficiaries, and describes a literature review spanning standards, legislation, tools, sectoral practices and national strategies.
- **Layer I — cybersecurity foundations:** Positions AI within six ICT building blocks: infrastructure, telecom, IT applications and technologies, domain or sectoral e-services, data and data processes, and users or procedures. It covers the confidentiality, integrity/authenticity and availability/non-repudiation dimensions, risk analysis and treatment, attacker characterisation, certification, and EU instruments including NIS 2, the Cybersecurity Act and GDPR.
- **Layer II — AI fundamentals:** Catalogues AI subfields and assets, including data, models, artefacts, actors, processes and environments/tools. It sets out AI-specific assessment needs, covering technical, social, policy and legal threats, and explains ML threats such as evasion, poisoning, model or data disclosure, component compromise, and failure or malfunction.
- **Trustworthiness, controls and testing:** Defines trustworthiness through characteristics including accountability, accuracy, explainability, fairness, privacy, reliability, resiliency, robustness, safety, security and transparency. It links threats to measures such as adversarial training, data cleaning, access control and federated learning, and discusses the difficulties of security testing for evolving, data-driven systems.
- **Standards, tools and initiatives:** Summarises work by ISO/IEC, ETSI and IEEE, and identifies tools and resources such as the Assessment List for Trustworthy Artificial Intelligence, MITRE ATLAS, Counterfit and GuardAI. Annex II lists security- and design-related standards and maps selected standards to life-cycle stages.
- **Layer III — sectoral practices:** Reviews available guidance and examples for energy, health, automotive and telecommunications. It describes sectoral attack surfaces, such as connected medical devices and autonomous-vehicle perception, planning and control pipelines, and calls for collaboration and shared lessons on horizontal threats.
- **NCA survey and recommendations:** Structures the questionnaire around human capital, moving from lab to market, networking, infrastructure and regulation. It reports that many Member States expect existing cybersecurity mechanisms or the proposed AI Act to guide their approach, and recommends longitudinal risk assessment, data-life-cycle monitoring, interdisciplinary work and periodic surveys.

## 💡 Why it matters?

The report gives governance, security and technical teams a way to avoid treating an AI model as the full security boundary. Its layered approach links organisation-wide ICT controls with model, data and life-cycle risks, then adds operational context for critical sectors. This is directly useful where responsibility is split across developers, operators, suppliers and oversight bodies.

It also frames AI security as more than attack resistance. The proposed risk work includes properties such as robustness, fairness, explainability, privacy and accountability, while the survey shows why authorities may need more AI-specific capabilities for monitoring, incident handling, metrics and assessment.

## ❓ What’s Missing

The report is a framework and catalogue of practices rather than an implementation manual with a single control baseline, scoring method or certification scheme for AI systems. It explicitly states that evaluation methodologies for defining security requirements for AI certification schemes are not yet available. It identifies a need for widely accepted scales to measure AI threats and risks, dynamic tools for data-life-cycle security, and approaches that assess evolving systems throughout their life cycle. Its survey evidence is also limited: it received 10 responses, and many reported measures are described at a high level without identifying the Member State or providing comparable national implementation detail. The discussion is framed around the proposed AI Act and contemporaneous policy landscape of June 2023.

## 👥 Best For

National competent authorities planning AI-security monitoring and enforcement; security and risk teams integrating AI systems into enterprise ICT controls; and AI developers, operators, auditors and supply-chain partners designing life-cycle risk assessments. It is particularly relevant to teams working in energy, health, automotive or telecommunications contexts.

## 📄 Source Details

*A multilayer framework for good cybersecurity practices for AI* was published in June 2023 by the European Union Agency for Cybersecurity (ENISA). Authors: Nineta Polemi and Isabel Praça. The complete supplied PDF comprises 46 pages, with numbered report pages 1–44; ISBN 978-92-9204-619-4, doi:10.2824/588830, reference TP-04-23-025-EN-N.