Create an AI rule - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-16
Category
Administrator Guide

AI rules identify misconfigurations and security flaws across your organization's AI ecosystem. These rules detect risks associated with AI infrastructure, supply chains, and data models for services such as AWS Bedrock, Amazon SageMaker, Azure OpenAI, and GCP Vertex AI.

Perform these steps to create a custom AI rule:

  1. Navigate to Posture ManagementRules & PoliciesRulesCloud Security.

  2. Click on Create RuleAI.

  3. In the Overview step, provide the following:

    1. Enter a Rule Name and Description.

    2. Select a Severity. Findings generated by this rule will inherit this severity.

    3. (Optional) Add Labels.

    4. (Optional) Enable Remediation using the toggle. In a later step, you'll enter the remediation instructions.

    5. (Optional) Associate this rule with a Compliance Control. Click Add, select one or more custom compliance controls from the list, and then click Assign. Custom configuration rules can only be associated with custom compliance controls.

    6. Click Next.

  4. In the Rule Logic step, use the query builder to define the detection criteria.

    1. Use the "Select" dropdown to choose AI services, such as Dataset, AI Model, Model Endpoint.

    2. Click WHERE to choose from the attributes of an asset. The list of attributes displayed varies, depending on the asset category you selected.

    3. Set conditions, building logical statements that use attributes specific to AI assets. For example, you can create a rule that flags AI models trained on sensitive data buckets or AI models that have public exposures.

    4. Click Search to see real-time results from your environment.

  5. Click Next to define Remediation instructions (if you had turned on Enable Remediation in the Overview step) or click Done.

  6. (Optional) In the text field, define remediation actions or provide other information that will be included on issues created by this rule.

  7. Click Done to save your rule.