Guidance
Machine learning principles
These principles help developers, engineers, decision makers and risk owners make informed decisions about the design, development, deployment and operation of their machine learning (ML) systems.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 20 of 22
Your model's expected lifespan is captured in its metadata as laid out in principle 2.3.
You understand that your model is a representation of the data on which it was trained and should be decommissioned through an appropriate process.
Data associated with the use of the model (such as logs) is retained in an appropriate location and for an appropriate length of time for your system or organisational auditing requirements.
An ML system is uniquely reliant on the data on which it was trained. Assets generated in this way can be used to extrapolate information about the original data on which they were trained, whether through traditional cyber attacks or ML specific attacks such as membership inference or model inversion.
Review how your asset's metadata states to decommission data and the underlying model. Evaluate if this is still appropriate and compliant.
Where it's appropriate to dispose of material, ensure this is done securely and an appropriate method is used for the nature of the asset's sensitivity. This is especially important when models are deployed at the edge of a network, outside of controlled environments. The NCSC has guidance on secure of sanitisation storage media.
Retention, via archiving, should also be considered. If you have taken actions based on the output of an ML system, consider how long after those actions you reasonably need to be able to explain or defend them. If you will need to explain something, consider whether you will need access to security logs, model weights or training data. The National Archives have guidance on archiving personal data.


