rai-standards

โดย microsoft

รวมมาตรฐาน AI ที่มีความรับผิดชอบ: NIST AI RMF 1.0, โครงสร้างการสร้างแบบจำลองภัยคุกคาม AI STRIDE, ระดับความเสี่ยงของ EU AI Act, และแคตตาล็อกมาตรฐานเปิดที่มี...

npx skills add https://github.com/microsoft/hve-core --skill rai-standards

RAI Standards Skill

This skill is the reusable standards package for the RAI Planner. It consolidates the embedded NIST AI RMF content, the AI STRIDE threat-modeling overlay, and a paraphrased EU AI Act reference so the phase playbook can stay focused on workflow and orchestration.

Attribution and licensing posture

  • NIST AI RMF 1.0 is a U.S. Government document and is reproduced here as public-domain reference material with attribution.
  • EU AI Act content in this skill is paraphrased and attributed rather than quoted verbatim, consistent with the open legal-text posture used in the repository.
  • The AI STRIDE overlay is Microsoft-authored reference material for threat-modeling reuse in the RAI workflow.

Framework index

NIST AI RMF trustworthiness characteristics

KeyCharacteristicDescription
validReliableValid and ReliableBase characteristic for correctness, robustness, and stability
safeSafeSafety and harm prevention under normal and adversarial conditions
secureResilientSecure and ResilientResistance to attack, misuse, and failure
accountableTransparentAccountable and TransparentGovernance, auditability, and decision provenance
explainableInterpretableExplainable and InterpretableUnderstandability of model behavior and outputs
privacyEnhancedPrivacy-EnhancedProtection of personal data and confidentiality
fairBiasManagedFair with Harmful Bias ManagedBias detection, mitigation, and equitable outcomes

Phase-to-framework mapping

RAI phasePrimary standards packageNotes
Phase 1 ScopingNIST AI RMF Govern + MapContext, purpose, stakeholders, and policy framing
Phase 2 Risk ClassificationNIST AI RMF GovernGovernance culture, DEI&A, and stakeholder engagement
Phase 3 Standards MappingNIST AI RMF Govern + MeasureCore standards mapping and TEVV alignment
Phase 4 Security Model AnalysisAI STRIDE overlay + MeasureThreat modeling and overlap with security analysis
Phase 5 Impact AssessmentNIST AI RMF ManageRisk prioritization, mitigation, and monitoring
Phase 6 Review and HandoffNIST AI RMF Manage + EU AI ActRegulatory review, incident response, and evidence handoff

Customer extension pattern

The default framework remains NIST AI RMF 1.0. When a customer supplies an additional framework, preserve the default NIST mapping as a baseline and layer the custom framework on top with explicit attribution. This keeps the planner interoperable while allowing organizations to add ISO, sector, or regional references without rewriting the core playbook.

Open-standards catalog

Use the links below as the reference catalog for open standards and governance resources. Do not reproduce normative text verbatim when the license posture does not allow it.

Skills เพิ่มเติมจาก microsoft

oss-growth
microsoft
บุคลิกภาพนักเติบโตโอเอสเอส
official
accessibility-aria-expert
microsoft
ตรวจจับและแก้ไขปัญหาการเข้าถึงใน React/Fluent UI webviews ใช้เมื่อตรวจสอบโค้ดเพื่อความเข้ากันได้กับโปรแกรมอ่านหน้าจอ แก้ไขป้ายกำกับ ARIA ทำให้มั่นใจว่า…
official
generate-canvas-app
microsoft
[เลิกใช้งานแล้ว — ใช้ canvas-app แทน] สร้างแอป Canvas ของ Power Apps ที่สมบูรณ์
official
django
microsoft
แนวทางปฏิบัติที่ดีที่สุดสำหรับการพัฒนาเว็บ Django รวมถึงโมเดล วิว เทมเพลต และการทดสอบ
official
github-issue-creator
microsoft
แปลงบันทึกดิบ บันทึกข้อผิดพลาด การเขียนตามคำบอก หรือภาพหน้าจอ ให้เป็นรายงานปัญหาที่ชัดเจนในรูปแบบ GitHub-flavored markdown ใช้เมื่อผู้ใช้วางข้อมูลบั๊ก ข้อผิดพลาด...
official
python-package-management
microsoft
ใช้ uv สำหรับการจัดการ dependencies และ poethepoet สำหรับการทำงานอัตโนมัติ
official
runtime-validation
microsoft
การตรวจสอบความถูกต้องขณะรันไทม์สำหรับแอปพลิเคชันที่ถูกย้าย — ครอบคลุมกลยุทธ์การทดสอบ (ระยะการวางแผน) และการดำเนินการทดสอบ (ระยะการตรวจสอบความถูกต้อง): การตรวจสอบการเริ่มต้นระบบ,…
official
azure-postgres-ts
microsoft
เชื่อมต่อกับ Azure Database for PostgreSQL Flexible Server โดยใช้แพ็กเกจ pg (node-postgres) ที่รองรับการยืนยันตัวตนด้วยรหัสผ่านและ Microsoft Entra ID (แบบไม่ใช้รหัสผ่าน)
official