Law / Frameworks / FINOS AIGF / Preventative
FINOS AIGF AIR-PREV-008Quality of Service (QoS) and DDoS Prevention for AI Systems
The increasing integration of Artificial Intelligence (AI) into financial applications, particularly through Generative AI, Retrieval Augmented Generation (RAG), and Agentic workflows, introduces significant operational risks. These include potential disruptions in service availability, degradation of performance, and inequities in service delivery. This control addresses the critical need to ensure Quality of Service (QoS) and implement robust Distributed Denial of Service (DDoS) prevention measures for AI systems.FINOS AI Governance Framework, version 2, as maintained on , AIR-PREV-008
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: security.
- 154
- laws
- 116
- places
- 0
- with court rulings behind them
- 14
- not yet in force
- 4
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
- CIS Controls3.10 Encryption of sensitive data as it crosses networks.
- CIS Controls3.11 Encryption of sensitive data where it is stored on servers and applications.
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
78 laws, 76 placesShow the other 68 laws
Security baseline statutes
33 laws, 31 placesShow the other 23 laws
Sector security regimes
16 laws, 16 placesShow the other 6 laws
| FSM Telecommunications Act of 2014, Security Safeguards for Customer Information |
Through its security duty. What it requires |
|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Through its security duty. What it requires |
|
| Telecommunications Act 2009, Security Safeguards for Consumer Information |
Through its security duty. What it requires |
|
| Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit |
Through its security duty. What it requires |
|
| Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set |
Through its security duty. What it requires |
|
| Law on Communications, network and subscriber-information protection duties |
Through its security duty. What it requires |
Product security requirements
8 laws, 8 placesVulnerability and incident reporting
8 laws, 8 placesSensitive categories
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Law on the Protection of Personal Data, sensitive data categories |
Through its security duty. What it requires |
|
| Law No. 133/V/2001 on the Protection of Personal Data, sensitive data categories |
Through its security duty. What it requires |
|
| Law No. 09-08, sensitive personal data and offense records |
Through its security duty. What it requires |
|
| Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data |
Through its security duty. What it requires |
|
| Lei n.º 03/2016, sensitive categories and suspect records |
Through its security duty. What it requires |
Cross border transfer
3 laws, 3 places| Place | Law | How it reaches this control |
|---|---|---|
| Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form |
Through its security duty. What it requires |
|
| Loi n° 2022-59, transfert transfrontalier des données |
Through its security duty. What it requires |
|
| DOJ Data Security Program (Bulk Sensitive Personal Data Rule) |
Through its security duty. What it requires |
AI risk obligations
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
Through its security duty. What it requires |
Breach notification
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| National Digital Identification Act 2024, personal data breach notification |
Through its security duty. What it requires |
Enforcement supervision
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 |
Through its security duty. What it requires |
Full text of the FINOS AI Governance Framework, CC BY 4.0. FINOS AI Governance Framework, https://air-governance-framework.finos.org/, copyright 2025 FINOS, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Titles and purpose text are quoted; markdown emphasis and links were removed. Every control of the framework.
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.