Network Security (10 points)
TLS 1.3 for all AI traffic, VPN/private link for on-prem, network segmentation, DDoS protection, egress filtering, DNS security, certificate management, network monitoring, firewall rules, and intrusion detection.
Application Security (10 points)
Input validation, output screening, rate limiting, session management, API authentication, error handling, dependency scanning, code signing, CSRF protection, and content security policy.
Data Security (15 points)
PII redaction, zero-history architecture, encryption at rest, encryption in transit, DLP policies, data classification, access controls, audit logging, backup procedures, retention policies, data sovereignty, anonymization, consent management, breach notification, and privacy impact assessment.
Identity Security (15 points)
SSO integration, MFA enforcement, RBAC implementation, least privilege access, API key management, service account governance, session timeouts, access reviews, provisioning automation, deprovisioning automation, password policies, privileged access management, directory integration, conditional access, and identity monitoring.
.png)