Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Offline Model Deployment Procedures
- Deploying models in a disconnected environment to eliminate runtime external connectivity.
- Caching model weights from authorized internal repositories into read-only directories prior to execution.
- Validating the integrity of model artifacts using SHA-256 checksums and cryptographically signed metadata.
- Operationalizing EXO in air-gapped networks without reliance on external package registries or cloud services for government systems.
Dashboard and Application Programming Interface (API) Access Control
- Deploying reverse proxy infrastructure with Transport Layer Security (TLS) termination.
- Enforcing role-based access control (RBAC) for dashboard interfaces and REST API endpoints.
- Securing API authentication credentials within operating system native key management systems.
- Restricting administrative access to authorized network ranges via strict source IP filtering.
Cluster Segmentation and Network Security
- Isolating EXO clusters through namespace segmentation and virtual local area networks (VLANs).
- Configuring host-level firewalls to control ingress and egress traffic for designated ports.
- Mitigating risks associated with unauthorized device discovery and rogue node insertion.
- Encrypting inter-node communication protocols where remote direct memory access (RDMA) is unavailable.
Model Governance and Provenance
- Maintaining an internal model registry that tracks approved models, versions, and metadata.
- Tagging quantized weights alongside original checkpoints to ensure traceability and version control.
- Enforcing policies that permit the loading of only pre-approved repositories or local artifacts for government use cases.
- Documenting model lineage, licensing compliance, and acceptable use guidelines.
Audit Logging and Regulatory Compliance
- Forwarding logs to immutable storage solutions, including Security Information and Event Management (SIEM) systems.
- Correlating API activity logs with user identity and temporal data for accountability.
- Capturing events related to model instance lifecycle management and inference requests.
- Producing periodic compliance reports for internal review and external audit requirements.
Threat Modeling and Incident Response
- Identifying potential threats, including data exfiltration via model outputs, prompt injection, and side-channel vulnerabilities.
- Implementing content filtering and monitoring pipelines to detect malicious inputs.
- Developing incident response procedures for cluster compromise scenarios.
- Isolating compromised nodes, preserving forensic evidence, and restoring environments from known good states.
Physical Security and Hardware Boundaries
- Securing physical ports against unauthorized peripheral connections.
- Leveraging hardware-based secure enclaves and device attestation where supported by government equipment policies.
- Controlling physical access to computing clusters and shared storage infrastructure.
- Documenting hardware lifecycle management and secure decommissioning procedures.
Regulatory Alignment
- Aligning deployment architectures with applicable standards such as GDPR, HIPAA, and SOC 2.
- Maintaining data sovereignty by processing inference requests within on-premise government facilities.
- Assessing and documenting supply chain risks associated with open-source components and model weights.
- Preparing for compliance with emerging artificial intelligence governance frameworks.
Requirements
**Prerequisite Knowledge and Technical Competencies**
Candidates are expected to demonstrate proficiency in deploying local Large Language Model (LLM) runtimes, such as EXO. A robust understanding of Unix file system access controls and networking Access Control Lists (ACLs) is required. Additionally, applicants must possess foundational knowledge regarding Transport Layer Security/Secure Sockets Layer (TLS/SSL) certificate lifecycle management and encryption protocols.
**Intended Audience**
This resource is designed for government personnel, specifically:
* Information Security Engineers
* Compliance and Regulatory Officers
* Administrators responsible for managing AI infrastructure that processes sensitive or classified data
14 Hours
Testimonials (1)
The trainer had an excellent knowledge of fortigate and delivered the content very well. Thanks a lot to Soroush.