AI-IRF / D06 / D06-CTL-02

User and stakeholder scope

Objective

Establish a repeatable and accountable capability for user and stakeholder scope during AI security incident handling.

Control / requirement

The organization should define ownership, decision criteria, technical procedures, dependencies, and escalation conditions for user and stakeholder scope.

Business impact

Failure may increase incident duration, uncertainty, evidence loss, propagation, or regulatory exposure.

Validation approach

Inspect approved procedure; test through scenario or technical exercise; verify retained evidence and action records.

Expected evidence

Policy or playbook; exercise or incident record; technical logs; decision and approval evidence.

Mapping and source

Prototype website catalogue — replace with the authoritative approved AI-IRF control record.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.