Recognizing the urgent need to defend this expanding landscape, India's national cybersecurity agency (CERT-In) has stepped forward with definitive guidance. This blog post explores the guidelines issued by CERT-In regarding Artificial Intelligence Bills of Materials (AI-BOMs) and outlines how organizations can seamlessly operationalize these requirements to protect their AI ecosystems.
What is CERT-In?
The Indian Computer Emergency Response Team (CERT-In), under the Ministry of Electronics and Information Technology (MeitY), Government of India, plays a key role in securing the Indian cyberspace through Incident Prevention, Response, and Security Quality Management Services. Its mission focuses on enhancing infrastructure security through proactive action and effective collaboration.
CERT-In aims to prevent cyber-attacks, minimize operational damage, reduce recovery time, and lower national vulnerability. Additionally, the organization continuously fosters public resilience by actively enhancing cybersecurity awareness among citizens.
What is AI-BOM?
An AI Bill of Materials (AI-BOM) is a machine-readable inventory documenting all components of an AI system, including models, datasets, dependencies, and configurations. Similar to a software bill of materials (SBOM), it ensures end-to-end security by mapping the complete AI supply chain.
This inventory tracks critical structural elements like training data, software libraries (e.g., PyTorch), and inference APIs. Implementing AI-BOMs allows enterprises to mitigate threat vectors like model poisoning, maintain regulatory compliance, and audit system governance effectively.
Key Guidelines from CERT-In for Securing AI Systems
To safeguard modern production environments against cascading supply-chain compromises, CERT-In has officially issued explicit guidelines focusing on the adoption of AI-BOMs. Designed for AI developers, system integrators, and consumer enterprise organizations, the guidelines emphasize five core architectural practices.
- Adopt AI-BOM using industry-recognized formats (SPDX or CycloneDX) to enable interoperability, automation, and seamless sharing across ecosystems.
- Leverage VEX (Vulnerability Exploitability eXchange) for contextual vulnerability prioritization to communicate whether vulnerabilities are exploitable, not exploitable, under investigation, or mitigated.
- Foster AI model reproducibility and auditability by documenting scripts, model weights, and configuration settings within the AI-BOM to support validation and regulatory audits.
- Embed continuous monitoring and supply chain assurance by mandating AI-BOMs for third-party AI and implement ongoing monitoring for drift, anomalies, and emerging threats.
- Track complete model lineage and lifecycle changes by maintaining clear records of model versions, retraining activities, and enhancements to ensure traceability, accountability, and compliance over time.
Operationalizing Compliance: Protectt.ai's AI Security Platform
Translating CERT-In's rigorous compliance guidelines into daily security workflows requires enterprise-grade tooling. To meet this operational challenge, Protectt.ai offers its advanced AI Security Platform, a specialized suite built to automate, monitor, and defend enterprise AI investments.
- AI Model Scanner which generates AI-BOMs in SPDX and CycloneDX formats while providing visibility into model components, dependencies, and potential vulnerabilities. This enables security teams to strengthen AI supply-chain transparency, vulnerability management, and regulatory readiness as AI governance expectations continue to evolve.
- AI Model Scanner detects AI supply-chain threats such as model backdoors, unsafe pickle serialisation, and embedded malicious payloads in third-party AI components.
- Based on the package used, AI Model Scanner scans for CVEs from authoritative databases such as NIST NVD, Github Security Advisory and OSV.
- The identified vulnerabilities are also mapped to standards and frameworks such as, OWASP Top10 for ML/LLM and MITRE ATLAS.
Other components in our AI Security Platform providing comprehensive end to end protection for AI Systems in Production:
- AI Red Teaming capabilities to simulate adversarial attacks such as prompt injection and model manipulation.
- AI Runtime Security to detect malicious prompts, jailbreak attempts, and abnormal AI behavior in production environments.
Ready to Align with CERT-In Guidelines? Let's Connect
Navigating the technical and governance demands of AI-BOM tracking, continuous AI auditing, and active runtime protection can be demanding. Our digital security experts will walk you through CERT-In’s AI security guidance and demonstrate how our AI Security Platform can seamlessly operationalize these requirements for your organization. Please Schedule a Demo here.