Create folders, configure AI security policies, associate AIRS best-practice
snippets, and assign AI security profiles to enforce protection on your Managed AIRS for
AWS resources.
| Where Can I Use This? | What Do I Need? |
|
|
- Access to Strata Cloud Manager (SCM)
|
Managed AI Runtime security resource is an instance of the Cloud NGFW
service platform, you can author and enforce network security policies similar to
other Cloud NGFW resources in Strata Cloud Manager.
You can configure, author, and enforce Managed AIRS (AI Access Security) policies for
your Managed AIRS using the Strata Cloud Manager (SCM) console. The workflow begins
by organizing your resources into designated management folders in Strata Cloud
Manager. You can then target a specific folder scope in SCM to set up AI Security
Policies and optionally apply the predefined
AIRS-Best-Practice configuration snippet to quickly baseline
security settings.
To enforce targeted protection, administrators must create custom AI security
profiles and set up model groups mapped to their specific AI environments, such as
AWS Bedrock. These profiles define action policies to alert on or block threats like
prompt injections, data leaks, and toxic content, with an option to enable custom
model support for cloud-based inspection. Finally, an outbound decryption rule with
a trusted certificate must be configured and attached to the policy so the firewall
can inspect encrypted payloads and prompt strings.