Statement 21: Establish the training environment
Agencies must
Criterion 76: Establish compute resources and infrastructure for the training environment.
This allows for infrastructure and computational constraints to be considered in relation to business needs and supports configuration of learning strategies best optimised for the infrastructure environment.
Criterion 77: Secure the infrastructure.
Implement required security and access controls for infrastructure used for training, validating, and testing the AI model which are dependent on the security classification of the data. For details, see the Information security manual (ISM), Essential Eight maturity model, Protective Security Policy Framework and Strategies to mitigate cyber security incidents.
Agencies should
- Criterion 78: Reuse approved AI modelling frameworks, libraries, and tools.