{
  "node_id": "cisa-ncsc-guidelines-secure-ai-system-development-2023",
  "title": "CISA-NCSC Joint Guidelines for Secure AI System Development (November 26, 2023)",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2026-06-13",
  "bluf": "On November 26, 2023 the UK National Cyber Security Centre (NCSC) and the US Cybersecurity and Infrastructure Security Agency (CISA), with co-sealing from 21 additional international cyber agencies including ACSC (Australia), CCCS (Canada), CCB (Belgium), CSEC (Canada), BSI (Germany), ANSSI (France), JPCERT/CC (Japan), NCSC-NL (Netherlands), NSM-NCSC (Norway), NCSC-NZ (New Zealand), SingCERT (Singapore), and others, jointly published the Guidelines for Secure AI System Development. The Guidelines apply to providers of AI systems - whether developing models from scratch or building on top of third-party tools - and structure secure-by-design AI development across four life cycle areas: (1) Secure Design - threat modelling, security considerations during requirements and design, AI-specific risks; (2) Secure Development - supply chain security, documentation, technical debt management; (3) Secure Deployment - infrastructure protection, model and asset protection, incident management procedures, responsible release; (4) Secure Operation and Maintenance - monitoring system behaviour and input, updates and patching, sharing lessons. Within each area the document enumerates specific recommended practices with rationale. The Guidelines are voluntary but represent the consensus position of the major Western cyber agencies on AI security baseline expectations and are referenced in subsequent national AI policy across the signatory jurisdictions.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "industry_mapping",
      "iso_standard",
      "international_alignment"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-ai-rmf-1-0",
    "nist-sp-800-218-ssdf",
    "nist-ai-100-2-adversarial-ml-taxonomy-2024",
    "cisa-secure-by-design-guidance-2024"
  ],
  "primary_citations_count": 7
}