Get in Touch

Course Outline

Offline Model Deployment Procedures

  • Deploying models in a disconnected environment to eliminate runtime external connectivity.
  • Caching model weights from authorized internal repositories into read-only directories prior to execution.
  • Validating the integrity of model artifacts using SHA-256 checksums and cryptographically signed metadata.
  • Operationalizing EXO in air-gapped networks without reliance on external package registries or cloud services for government systems.

Dashboard and Application Programming Interface (API) Access Control

  • Deploying reverse proxy infrastructure with Transport Layer Security (TLS) termination.
  • Enforcing role-based access control (RBAC) for dashboard interfaces and REST API endpoints.
  • Securing API authentication credentials within operating system native key management systems.
  • Restricting administrative access to authorized network ranges via strict source IP filtering.

Cluster Segmentation and Network Security

  • Isolating EXO clusters through namespace segmentation and virtual local area networks (VLANs).
  • Configuring host-level firewalls to control ingress and egress traffic for designated ports.
  • Mitigating risks associated with unauthorized device discovery and rogue node insertion.
  • Encrypting inter-node communication protocols where remote direct memory access (RDMA) is unavailable.

Model Governance and Provenance

  • Maintaining an internal model registry that tracks approved models, versions, and metadata.
  • Tagging quantized weights alongside original checkpoints to ensure traceability and version control.
  • Enforcing policies that permit the loading of only pre-approved repositories or local artifacts for government use cases.
  • Documenting model lineage, licensing compliance, and acceptable use guidelines.

Audit Logging and Regulatory Compliance

  • Forwarding logs to immutable storage solutions, including Security Information and Event Management (SIEM) systems.
  • Correlating API activity logs with user identity and temporal data for accountability.
  • Capturing events related to model instance lifecycle management and inference requests.
  • Producing periodic compliance reports for internal review and external audit requirements.

Threat Modeling and Incident Response

  • Identifying potential threats, including data exfiltration via model outputs, prompt injection, and side-channel vulnerabilities.
  • Implementing content filtering and monitoring pipelines to detect malicious inputs.
  • Developing incident response procedures for cluster compromise scenarios.
  • Isolating compromised nodes, preserving forensic evidence, and restoring environments from known good states.

Physical Security and Hardware Boundaries

  • Securing physical ports against unauthorized peripheral connections.
  • Leveraging hardware-based secure enclaves and device attestation where supported by government equipment policies.
  • Controlling physical access to computing clusters and shared storage infrastructure.
  • Documenting hardware lifecycle management and secure decommissioning procedures.

Regulatory Alignment

  • Aligning deployment architectures with applicable standards such as GDPR, HIPAA, and SOC 2.
  • Maintaining data sovereignty by processing inference requests within on-premise government facilities.
  • Assessing and documenting supply chain risks associated with open-source components and model weights.
  • Preparing for compliance with emerging artificial intelligence governance frameworks.

Requirements

**Prerequisite Knowledge and Technical Competencies** Candidates are expected to demonstrate proficiency in deploying local Large Language Model (LLM) runtimes, such as EXO. A robust understanding of Unix file system access controls and networking Access Control Lists (ACLs) is required. Additionally, applicants must possess foundational knowledge regarding Transport Layer Security/Secure Sockets Layer (TLS/SSL) certificate lifecycle management and encryption protocols. **Intended Audience** This resource is designed for government personnel, specifically: * Information Security Engineers * Compliance and Regulatory Officers * Administrators responsible for managing AI infrastructure that processes sensitive or classified data
 14 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories