S0093RS3-T14-S0093-Z · Full risk code

Inference Interface Without Access Control

推論介面缺乏存取控制

Deployment
Risk Description

When an organization's test endpoint runs for an extended period without authentication, and its address is inadvertently disclosed; due to unmitigated control gaps, heavy external calls cause computing costs to spike, and the organization cannot determine whether sensitive content was processed through the endpoint during that time, triggering compliance exposure and operational reputational costs.

Framework Mappings

NIST CSF 2.0PR.AA
ISO/IEC 27001Annex A 5.15、8.16
MITRE ATLASAML.T0024
NIST AI 600-1Information Security
ISO/IEC 5338部署

Risk Treatment & Implementation Guidance

Require authentication and authorization on all inference endpoints including test environments, prohibiting long-running anonymous endpoints; Set rate limits and usage alerts reporting anomalous calls; Periodically inventory exposed endpoints, taking unregistered ones offline