Summary is AI-generated, newsdesk-reviewed
  • CREST launches AI Security Testing Accreditation for Generative AI and LLM-enabled systems standards.
  • Accreditation provides independent assurance of providers' capabilities in AI security testing.
  • New standard addresses entire AI system, enhancing security expertise and buyer confidence.

CREST, a global non-profit representing the cybersecurity sector, has introduced a new standard for Security Testing of AI, along with corresponding accreditation. This initiative is intended for cybersecurity service providers, setting criteria for assessing Generative AI and Large Language Model (LLM)-enabled systems.

As AI technologies increasingly integrate into organisational applications and business processes, the necessity for reliable cybersecurity testing becomes vital. Previously, buyers were unsure whether cybersecurity firms genuinely possessed the competence to test AI systems effectively.

Independent assurance for service providers

To address these concerns, CREST developed its Security Testing of AI accreditation. This provides an assurance that cybersecurity service providers can competently and securely test AI systems. The accreditation evaluates several aspects, including:

  • Technical expertise and practitioner competence
  • Testing methodologies
  • Governance and quality controls
  • Technical approaches and tooling
  • Processes for assessing AI-specific security risks
  • Evidence backing the conclusions derived from testing

By ensuring these capabilities, accredited providers offer buyers a reliable independent assurance of their AI testing competencies. This streamlines procurement and due diligence, reducing dependency on unsupported claims.

Expert input and validation

Nick Benson, CEO of CREST, remarked, "This latest addition to our new AI range of standards and accreditations was specifically curated to respond to an emerging market need. Our membership told us very clearly that as their clients deployed AI-enabled tech, they required more information on their AI testing credentials. Offering 'Security testing of AI systems' and demonstrating the ability to deliver it effectively are two different things. Buyers need to know that the providers assessing their AI have the right expertise and methodologies. Providers now have a way to develop their policies in line with our standard, demonstrate their technical capabilities through independent assessment, giving buyers that all-important confidence to proceed."

Comprehensive system approach

CREST previously unveiled an AI-Enabled Penetration Testing standard earlier this year

CREST's Security Testing of AI standard recognises that AI security testing must encompass the entire system, beyond simply the model itself. This involves considering applications, prompts, retrieval mechanisms, data sources, and more. The initiative aims at providing a holistic approach to AI security, addressing the entire attack surface influenced by AI outputs.

This standard forms part of CREST’s wider AI assurance programme. Corresponding research by CREST has shown that 69% of penetration testing providers are using AI, with 76% increasing their usage in the past year. In response to such growth, CREST previously unveiled an AI-Enabled Penetration Testing standard earlier this year.

Tim Reed, Technical Director at Sentrium Security Limited, a UK-based CREST member, stated: "CREST’s standards turn responsible AI from a promise into something that can be evidenced and assessed. We believe this will strengthen buyer confidence, reward credible providers and set a higher bar for the profession, which is why we intend to pursue accreditation."

Future developments and membership involvement

Yann Chalençon, Head of Cyber Security Services at wizlynx group in Switzerland, highlighted that "CREST’s new standard provides a clear, independently verified framework that will help create consistency, strengthen assurance and build trust in both the testing process and the wider use of AI-enabled cybersecurity services."

The new standards are part of CREST's ongoing efforts, which also saw the launch of an AI Charter and AI Principles earlier this year. The initiative has been backed by over 100 signatory cybersecurity organisations worldwide. Existing CREST members and other cybersecurity service providers are now encouraged to seek this new accreditation, which complements the existing Penetration Testing Accreditation.

In case you missed it

What are the unique aspects of the critical infrastructure market?
What are the unique aspects of the critical infrastructure market?

Critical national infrastructure encompasses sectors such as energy, utilities, healthcare, and data centers – environments that underpin economic stability and public safety...

Milestone Systems boosts Columbia safety with VMS
Milestone Systems boosts Columbia safety with VMS

Milestone Systems, a provider of open platform video management software (VMS), is helping Columbia Borough, Pennsylvania, strengthen public safety through a community-wide video s...

AI and regulation are reshaping the future of building security
AI and regulation are reshaping the future of building security

There was a time when physical security and cybersecurity occupied two very different worlds. One was concerned with the nuts and bolts of locks, doors and perimeter protection. Th...