New CREST standard identifies providers who can test AI systems securely

New-CREST-standard-identifies-providers-who-can-test-AI-systems-securely

CREST has announced the launch of its Security Testing of AI standard and accreditation.

According to the company, the new standard for cybersecurity service providers establishes independently assessable requirements for testing Generative AI and Large Language Model (LLM)-enabled systems.

Securing AI systems

AI systems are moving rapidly from experimentation into real-world deployment, with AI becoming embedded within organisations’ applications, workflows, products and business processes.

But up until now, buyers have had no way to know whether the cybersecurity providers testing their AI systems actually have the capability to do so. 

The company highlighted that the CREST Security Testing of AI accreditation was developed to close this gap.

CREST testing

The CREST Security Testing of AI accreditation has been designed to provide independent assurance that cybersecurity service providers have the demonstrable specialist capability to securely and effectively test AI systems.

CREST said that it assesses whether providers have appropriate:

  • Technical expertise and practitioner competence. 
  • Testing methodologies. 
  • Governance and quality controls. 
  • Technical approaches and tooling. 
  • Processes for identifying and evaluating AI-specific security risks. 
  • Evidence to support the conclusions reached during testing. 

Once accredited, providers offer buyers independent assurance of their AI testing capabilities.

This helps guide procurement, streamline supplier due diligence and eliminate reliance on unsupported claims about AI security expertise.

The Security Testing of AI standard has been created under the principle that AI security testing needs to consider the whole system.

To recognise the broader system-level security challenge, the new standard does not just treat the underlying model itself as the entire attack surface.

It recognises that testing needs to also consider applications, prompts and system instructions, retrieval mechanisms, data sources, memory, tools, plugins, APIs, orchestration layers and downstream systems influenced by AI outputs.

The Security Testing of AI standard and accreditation marks the latest stage of CREST’s growing AI assurance programme.

Recent CREST research highlights the magnitude of this evolution across cybersecurity: 69% of penetration testing providers already use AI and 76% have increased their usage over the past year.

Responding to this rapid rate of adoption, CREST announced its AI-Enabled Penetration Testing standard in July.

The company said that this focused on how a penetration testing provider uses AI within the delivery of its services, while this latest standard assures their capability to test AI systems.

“Specifically curated to respond to an emerging market”

Nick Benson, CEO of CREST said: “This latest addition to our new AI range of standards and accreditations was specifically curated to respond to an emerging market need.

“Our membership told us very clearly that as their clients deployed AI-enabled tech, they required more information on their AI testing credentials.

Benson continued: “Offering ‘Security testing of AI systems’ and demonstrating the ability to deliver it effectively are two different things.

“Buyers need to know that the providers assessing their AI have the right expertise and methodologies.

“Providers now have a way to develop their policies in line with our standard, demonstrate their technical capabilities through independent assessment, giving buyers that all-important confidence to proceed,” he concluded.

“Strengthen buyer confidence”

Tim Reed, Technical Director, Sentrium Security Limited, a UK-based CREST member, said: “CREST’s standards turn responsible AI from a promise into something that can be evidenced and assessed.

“We believe this will strengthen buyer confidence, reward credible providers and set a higher bar for the profession, which is why we intend to pursue accreditation.”

“A clear, independently verified framework”

Yann Chalençon, Head of Cyber Security Services, wizlynx group, a Switzerland-based CREST member, said: “CREST’s new standard provides a clear, independently verified framework that will help create consistency, strengthen assurance and build trust in both the testing process and the wider use of AI-enabled cybersecurity services.”

The standards

CREST developed these standards in collaboration with the industry and will continue to refine them through its AI Working Group.

The company said that the new standards follow the launch of it’s AI Charter and AI Principles in June.

A global cohort of more than 100 founding signatory cybersecurity organisations – including more than 10% of CREST’s worldwide membership – publicly committed to supporting the responsible use of AI across industry services.

Existing CREST Members and cybersecurity service providers are now invited to apply for this new accreditation.

The Security Testing of AI accreditation builds on CREST’s Penetration Testing Accreditation, which organisations must hold or apply for alongside this one.

Providers can download the CREST Accreditation Standards here.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox