SEC536: Adversarial AI - Penetration Testing AI Systems

The paper identifies expected, unexpected, emergency, and unapproved change, with unapproved change being the most difficult to detect and recover from without active monitoring and offline backups.
Eight standards are referenced, including the ISA/IEC 62443 Series, NIST Special Publication 800-82, ANSI/ISA-84.00.01-2004, API RP 1173, OSHA 1910.119, ISA-18.2, API RP 754, and IEC 61511-1.
Building an accurate inventory is difficult because assets can operate on isolated networks, move between environments (as with contractor laptops), and lack consistent labeling or fingerprinting once discovered.
It supports four areas: vulnerability management, monitoring, incident response, and improvement/recovery, by ensuring changes to cyber assets are documented, tracked, and reversible.
Change volume is highest during Field Acceptance Testing (FAT) and Site Acceptance Testing (SAT), then declines significantly once the system enters operational service.