FDE01Forward deployment
Handbook 11

Assign responsibility for data and risk

Assign an owner for risks that remain after controls.

On this pageChapter guideDiscussion questionRelated exerciseReferences

Chapter guide

Inventory purpose and access for source data, copies, retrieval indexes, logs and evaluation datasets. Trace how permission revocation, deletion and withdrawn material reach every copy; checking the login screen is not enough.

For each risk scenario, describe the conditions, event, affected people, existing controls, gaps and next owner action. Link asset inventories, risk assessments, impact records, lifecycle checks and supplier responsibilities so owners can review them.

Contain an incident first, then separate facts from unknowns, notify, investigate and assign restoration to an authorized owner. Community guidance helps identify gaps; legal conclusions still require the applicable jurisdiction and qualified judgment.

Controls before and after an action
Controls before and after an actionAfter failure or a timeout, inspect the business record before retrying. Prevent repeated requests from creating extra actions, and reconcile the actual result.Check authorityIdentity / scope / purposeCheck the actionInputs / impact / approvalControlled executionLog / limit / stopVerify the outcomeExternal final stateUnknown outcome ≠ failed action
After failure or a timeout, inspect the business record before retrying. Prevent repeated requests from creating extra actions, and reconcile the actual result.Swipe to view the full diagram.

Discussion question

Who can stop the system when you are unavailable, and have they tested that ability?

Related exercise

Follow the related lesson below and try its exercise. Use the linked template to record your judgment, evidence and open questions, then revise with the checklist. With a partner, check which parts of each other’s work need clarification.

References

OWASP / Agent Control Standard (ACS) NIST / AI Risk Management Framework