Mappings
How the rules cross to the frameworks you already use.
This page is a navigational crosswalk from the pack's mapped rules to security and AI-governance frameworks. It is not a claim of endorsement or compliance: no framework publisher endorses, sponsors, or is affiliated with this pack, and a mapping asserts a relationship of ideas, not certification against a standard.
The crosswalk carries 957 mappings from 105 of the pack's rules to 514 identifiers across 17 frameworks. Every mapped identifier is validated against a pinned-edition manifest before it can ship; the counts here are generated from that live state, never hand-entered.
Methodology and limits
How the crosswalk is built, and what it does not claim
The mappings are part of the rules themselves. Each mapped rule records, in its own source, the framework identifiers it maps to, and every one is checked in continuous integration against a pinned-edition manifest of that framework's identifiers. An identifier that is not in the pinned edition cannot ship, so a fabricated or mistyped mapping is caught before publication rather than after.
- Five relation kinds. The wording of each mapping follows the framework's type: a rule supports a control, aligns with guidance, addresses a risk, mitigates a technique, or mitigates a weakness.
- Each mapping carries its fit. A tight mapping is a direct, one-to-one correspondence; a broad mapping is a looser, thematic relation. The fit is shown next to every identifier and in both exports.
- Identifiers and published titles only. Only control, guidance, risk, technique, and weakness identifiers and the frameworks' own published titles are reproduced, as navigational pointers; some frameworks (NIST AI RMF, for example) label an item with a full sentence, reproduced verbatim as that item's published title. No further specification prose, requirement text, control or clause bodies, figures, or tables from any framework are reproduced.
- What absence means. This is a first-cut, curated set that will grow. The absence of a mapping does not mean a rule is irrelevant to a framework; it means no mapping has been asserted yet. A pinned edition may also lag a framework's most recent release.
- ISO/IEC entries. The two ISO/IEC entries reproduce clause and control numbers with their short headings only, as pointers to a licensed copy of the standard, never any clause or Annex body text.
Framework registry
The frameworks in the crosswalk
Each framework is pinned to a single edition. The edition-stability badge reads stable for a settled published edition, beta for a pre-release edition, and snapshot for a point-in-time capture of a moving source. For a full-edition manifest the last column states how many of that edition's identifiers the current rules reference; for a curated subset it states the count referenced, with no edition total.
| Framework | Publisher | Edition | Relation | Edition stability | Identifiers referenced |
|---|---|---|---|---|---|
| CSA AI Controls Matrix | Cloud Security Alliance | 1.1.0 | supports control | stable | 79 referenced (curated subset) |
| CSA Cloud Controls Matrix | Cloud Security Alliance | 4.1.0 | supports control | stable | 57 referenced (curated subset) |
| ISO/IEC 23894:2023 AI guidance on risk management | ISO/IEC | 2023 | aligns with guidance | stable | 14 referenced (curated subset) |
| ISO/IEC 42001:2023 AI management system | ISO/IEC | 2023 | supports control | stable | 18 referenced (curated subset) |
| MITRE ATLAS | MITRE | 2026.06 | mitigates technique | snapshot | 67 referenced (curated subset) |
| MITRE CWE | MITRE | 4.20 | mitigates weakness | snapshot | 72 referenced (curated subset) |
| NIST SP 800-53 Security and Privacy Controls | NIST | Rev 5 (catalog 5.2.0) | supports control | stable | 67 referenced (curated subset) |
| NIST AI Risk Management Framework | NIST | 1.0 (NIST AI 100-1) | aligns with guidance | stable | 24 referenced (curated subset) |
| NIST Secure Software Development Framework | NIST | 1.1 (SP 800-218) | supports control | stable | 20 referenced (curated subset) |
| OWASP API Security Top 10 | OWASP Foundation | 2023 | addresses risk | stable | 8 referenced (curated subset) |
| OWASP Top 10 for Agentic Applications | OWASP Foundation | 2026 | addresses risk | stable | 9 referenced (curated subset) |
| OWASP Application Security Verification Standard | OWASP Foundation | 5.0.0 | supports control | stable | 13 referenced (curated subset) |
| OWASP Cheat Sheet Series | OWASP Foundation | commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04) | aligns with guidance | snapshot | 27 referenced (curated subset) |
| OWASP Top 10 for LLM Applications | OWASP Foundation | 2026 | addresses risk | stable | 10 of 10 |
| OWASP MCP Top 10 | OWASP Foundation | 2025 | addresses risk | beta | 10 of 10 |
| OWASP Top 10 Proactive Controls | OWASP Foundation | 4.0.0 | supports control | stable | 9 referenced (curated subset) |
| OWASP Top 10 (Web Application Security Risks) | OWASP Foundation | 2025 | addresses risk | stable | 10 of 10 |
Forward view
By rule
Every rule that carries at least one mapping, in AIQT priority order. Open a rule to see the frameworks it maps to and the identifiers under each, with the fit noted in parentheses.
Claims about the work rest on observation
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.12: Transparency and explainability (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
A completeness claim enumerates its set
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.12: Transparency and explainability (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
Corroborate external claims
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0067.000: Citations (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
- MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context. (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM07: Misinformation (tight)
Evidence-grounded completion
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.12: Transparency and explainability (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
A guard is only as good as its input
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MEASURE 2.13: Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. (broad)
- MAP 2.3: Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection, and construct validation. (tight)
Measured and estimated figures stay separate
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.12: Transparency and explainability (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MEASURE 1.1: Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation. (broad)
No fabrication
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.12: Transparency and explainability (broad)
- B.5: Risk sources related to machine learning (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
- MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context. (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM07: Misinformation (tight)
Read before characterizing
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
- MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context. (broad)
Capture the reference when the claim is made
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.7.5: Data provenance (tight)
Reproduce a defect before fixing it
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-2: Flaw Remediation (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- RV.1.2: Test code to confirm new vulnerabilities (broad)
A current timestamp is read from the clock
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AU-8: Time Stamps (broad)
Validate an inferred premise before acting
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
Anything wrong is fixed first
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-2: Flaw Remediation (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (broad)
Branch and merge only on green
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.7: Maintainability (broad)
- B.7: System life cycle issues (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.1.3: Processes for responsible design and development of AI systems (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-10: Developer Configuration Management (broad)
- CM-3: Configuration Change Control (tight)
- CM-3(2): Testing, Validation, and Documentation of Changes (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PS.1.1: Protect stored code with least privilege (broad)
- PW.7.1: Decide on code review and analysis (broad)
Cut branches from the live protected line and re-home after a rewrite
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.1.3: Processes for responsible design and development of AI systems (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-10: Developer Configuration Management (broad)
- CM-3: Configuration Change Control (tight)
- CM-3(2): Testing, Validation, and Documentation of Changes (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.7.1: Decide on code review and analysis (broad)
A check fails closed on input it cannot read
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-17: Fail-safe Procedures (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- error-handling: Error Handling Cheat Sheet (broad)
Commit identity
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.3.2: AI roles and responsibilities (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 2.1: Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PS.1.1: Protect stored code with least privilege (broad)
Gate discipline
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-3(2): Testing, Validation, and Documentation of Changes (broad)
- SA-11: Developer Testing and Evaluation (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PO.4.1: Define software security check criteria (broad)
- PW.8.2: Perform and document code testing (tight)
Verify licence compatibility before introducing third-party material
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented. (broad)
No concealed failure
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.12: Transparency and explainability (broad)
- 6.7: Recording and reporting (tight)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-11: Developer Testing and Evaluation (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. (tight)
- MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (tight)
Protected-branch integrity
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.7: Maintainability (broad)
- B.7: System life cycle issues (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.1.3: Processes for responsible design and development of AI systems (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-3: Configuration Change Control (tight)
- CM-5: Access Restrictions for Change (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.7.1: Decide on code review and analysis (broad)
- PS.1.1: Protect stored code with least privilege (tight)
A required step remains required under friction
- ISO/IEC 42001:2023 AI management system (2023): supports control
- 10.2: Nonconformity and corrective action (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (broad)
A rerun pass does not erase an earlier failure
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-2: Flaw Remediation (broad)
Separate task changes from pre-existing work
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-3: Configuration Change Control (broad)
A launched task stays observable
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- 6.7: Recording and reporting (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.6: AI system operation and monitoring (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (broad)
Validation is a gate on apply
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-11: Developer Testing and Evaluation (broad)
- CM-3(2): Testing, Validation, and Documentation of Changes (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.7.1: Decide on code review and analysis (broad)
- PW.8.1: Decide on executable code testing (broad)
Workers produce inert data
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- B.4: Level of automation (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.1.3: Processes for responsible design and development of AI systems (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0053: AI Agent Tool Invocation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AC-6: Least Privilege (tight)
- CM-5: Access Restrictions for Change (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.7.2: Perform code review and analysis (broad)
- PS.1.1: Protect stored code with least privilege (tight)
A behavioural change carries a check that fails without it
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-3(2): Testing, Validation, and Documentation of Changes (broad)
- SA-11: Developer Testing and Evaluation (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.8.2: Perform and document code testing (broad)
Defence in depth by default
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-8: Security and Privacy Engineering Principles (broad)
A verification finding is fixed, not argued away
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-11: Developer Testing and Evaluation (broad)
- SI-2: Flaw Remediation (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
- MANAGE 2.3: Procedures are followed to respond to and recover from a previously unknown risk when it is identified. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PO.4.1: Define software security check criteria (broad)
- PW.7.2: Perform code review and analysis (broad)
High-assurance verification
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-3(2): Testing, Validation, and Documentation of Changes (broad)
- SA-11(3): Independent Verification of Assessment Plans and Evidence (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.2.1: Review software design against security requirements (broad)
- PW.7.2: Perform code review and analysis (broad)
Isolate verifiers and judge by their result signal
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-11(3): Independent Verification of Assessment Plans and Evidence (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. (broad)
- MEASURE 2.13: Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. (broad)
Match the surrounding code
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.7: Maintainability (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
Minimize external dependencies in favour of standard libraries
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-8: Security and Privacy Engineering Principles (broad)
Propose a guardrail when an error reveals a gap
- ISO/IEC 42001:2023 AI management system (2023): supports control
- 10.2: Nonconformity and corrective action (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 2.3: Procedures are followed to respond to and recover from a previously unknown risk when it is identified. (tight)
Prefer the smallest correct change
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.7: Maintainability (broad)
Surface a counterproductive instruction before executing it
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- 6.2: Communication and consultation (broad)
- A.2: Accountability (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.3.3: Reporting of concerns (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (broad)
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (tight)
A test's verdict comes from the code, not its surroundings
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-8(29): Repeatable and Documented Procedures (broad)
- SA-11: Developer Testing and Evaluation (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.8.2: Perform and document code testing (broad)
Verifier diversity
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.4: AI system verification and validation (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-11(3): Independent Verification of Assessment Plans and Evidence (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. (broad)
- MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.7.1: Decide on code review and analysis (broad)
Maintain an AI toolchain register
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.4.4: Tooling resources (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-8: System Component Inventory (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 1.6: Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. (tight)
Assess and advise are discussion only
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- B.4: Level of automation (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.9.2: Processes for responsible use of AI systems (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (broad)
- MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (broad)
Change record
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- 6.7: Recording and reporting (tight)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- 7.5.2: Creating and updating documented information (broad)
- 7.5.3: Control of documented information (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-3: Configuration Change Control (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PO.3.3: Generate artifacts from security tools (broad)
Change record has a curated public face
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.8.5: Information for interested parties (broad)
Clarify before acting
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- 6.2: Communication and consultation (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
- MAP 1.6: System requirements (e.g., "the system shall respect the privacy of its users") are elicited from and understood by relevant AI actors. (broad)
Continue by default
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- B.4: Level of automation (broad)
Express authorization before execution
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- B.4: Level of automation (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.9.2: Processes for responsible use of AI systems (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (broad)
- MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (broad)
Human oversight and the autonomy threshold
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- A.10: Safety (broad)
- B.4: Level of automation (tight)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.3.2: AI roles and responsibilities (broad)
- A.9.2: Processes for responsible use of AI systems (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0053: AI Agent Tool Invocation (broad)
- AML.T0086: Exfiltration via AI Agent Tool Invocation (broad)
- AML.T0101: Data Destruction via AI Agent Tool Invocation (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (tight)
- MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (tight)
Reconcile the record against reality
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CA-7: Continuous Monitoring (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 1.5: Ongoing monitoring and periodic review of the risk management process and its outcomes are planned. (broad)
Records first
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- 6.7: Recording and reporting (tight)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- 7.5.2: Creating and updating documented information (broad)
- 7.5.3: Control of documented information (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 1.4: The risk management process and its outcomes are established through transparent policies, procedures, and other controls. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.1.2: Track security requirements and design decisions (tight)
Close each session on green
- ISO/IEC 42001:2023 AI management system (2023): supports control
- 8.1: Operational planning and control (broad)
Resume from the durable handoff
- ISO/IEC 42001:2023 AI management system (2023): supports control
- 8.1: Operational planning and control (broad)
Trust recovery and escalation
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- A.12: Transparency and explainability (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (tight)
Autonomy steps down after a confirmed trust loss
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (broad)
- MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (tight)
Decision classification before enacting
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (tight)
- B.4: Level of automation (tight)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.9.2: Processes for responsible use of AI systems (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (tight)
- MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (tight)
Background work during CI waits
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-3(2): Testing, Validation, and Documentation of Changes (broad)
Cost tier
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities. (broad)
- MAP 1.5: Organizational risk tolerances are determined and documented. (broad)
Classify content by sensitivity tier
- CSA AI Controls Matrix (1.1.0): supports control
- DSP-10: Sensitive Data Transfer (broad)
- DSP-17: Sensitive Data Protection (broad)
- DSP-24: Data Differentiation and Relevance (broad)
- IAM-16: Knowledge Access Control - Need to Know (broad)
- DSP-04: Data Classification (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- DSP-10: Sensitive Data Transfer (broad)
- DSP-17: Sensitive Data Protection (broad)
- DSP-04: Data Classification (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- MP-3: Media Marking (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V14: Data Protection (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM02: Sensitive Information Disclosure (broad)
Egress goes only to expected destinations
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0025: Exfiltration via Cyber Means (broad)
- AML.T0086: Exfiltration via AI Agent Tool Invocation (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-610: Externally Controlled Reference to a Resource in Another Sphere (broad)
- CWE-923: Improper Restriction of Communication Channel to Intended Endpoints (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SC-7: Boundary Protection (broad)
- AC-4: Information Flow Enforcement (tight)
- SC-7(5): Deny by Default - Allow by Exception (tight)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI02: Tool Misuse and Exploitation (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM02: Sensitive Information Disclosure (broad)
Keep secrets out
- CSA AI Controls Matrix (1.1.0): supports control
- DSP-17: Sensitive Data Protection (broad)
- LOG-08: Audit Logs Sanitization (broad)
- AIS-12: Source Code Management (tight)
- IAM-14: Credentials Management (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- DSP-17: Sensitive Data Protection (broad)
- LOG-08: Audit Logs Sanitization (broad)
- IAM-14: Credentials Management (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0082: RAG Credential Harvesting (broad)
- AML.T0083: Credentials from AI Agent Configuration (broad)
- AML.T0098: AI Agent Tool Credential Harvesting (broad)
- AML.T0055: Unsecured Credentials (tight)
- AML.T0095.000: Code Repositories (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-798: Use of Hard-coded Credentials (broad)
- CWE-532: Insertion of Sensitive Information into Log File (tight)
- CWE-540: Inclusion of Sensitive Information in Source Code (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- IA-5(7): No Embedded Unencrypted Static Authenticators (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V14: Data Protection (broad)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- secrets-management: Secrets Management Cheat Sheet (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM02: Sensitive Information Disclosure (broad)
- OWASP MCP Top 10 (2025): addresses risk
- MCP01: Token Mismanagement & Secret Exposure (tight)
Retrieval enforces the requester's authorization
- CSA AI Controls Matrix (1.1.0): supports control
- IAM-18: Agent Access Restriction (broad)
- IAM-05: Least Privilege (tight)
- IAM-15: Authorization Mechanisms (tight)
- IAM-16: Knowledge Access Control - Need to Know (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- IAM-05: Least Privilege (tight)
- IAM-15: Authorization Mechanisms (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.8: Privacy (broad)
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0053: AI Agent Tool Invocation (broad)
- AML.T0082: RAG Credential Harvesting (broad)
- AML.T0085: Data from AI Services (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-285: Improper Authorization (broad)
- CWE-441: Unintended Proxy or Intermediary ('Confused Deputy') (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AC-3: Access Enforcement (tight)
- AC-6: Least Privilege (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI03: Identity and Privilege Abuse (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP07: Insufficient Authentication & Authorization (tight)
No cross-context bleed
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-14: AI Cache Protection (broad)
- IAM-16: Knowledge Access Control - Need to Know (broad)
- AIS-11: Agents Security Boundaries (tight)
- I&S-06: Segmentation and Segregation (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- I&S-06: Segmentation and Segregation (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.8: Privacy (broad)
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0057: LLM Data Leakage (broad)
- AML.T0080: AI Agent Context Poisoning (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (broad)
- CWE-653: Improper Isolation or Compartmentalization (broad)
- CWE-488: Exposure of Data Element to Wrong Session (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AC-4: Information Flow Enforcement (tight)
- SC-4: Information in Shared System Resources (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP MCP Top 10 (2025): addresses risk
- MCP10: Context Injection & Over-Sharing (tight)
No disclosure of secrets or hidden context
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-15: Prompt Differentiation (broad)
- DSP-17: Sensitive Data Protection (broad)
- IAM-16: Knowledge Access Control - Need to Know (broad)
- TVM-13: Guardrails (broad)
- CSA Cloud Controls Matrix (4.1.0): supports control
- DSP-17: Sensitive Data Protection (broad)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.8: Privacy (broad)
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0082: RAG Credential Harvesting (broad)
- AML.T0098: AI Agent Tool Credential Harvesting (broad)
- AML.T0056: Extract LLM System Prompt (tight)
- AML.T0057: LLM Data Leakage (tight)
- AML.T0069: Discover LLM System Information (tight)
- AML.T0084: Discover AI Agent Configuration (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere (broad)
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AC-4: Information Flow Enforcement (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM02: Sensitive Information Disclosure (tight)
- LLM08: Hidden Context Exposure (tight)
Rotate a leaked secret
- CSA AI Controls Matrix (1.1.0): supports control
- SEF-07: Incident Management and Response (broad)
- CEK-12: Key Rotation (tight)
- CEK-19: Key Compromise (tight)
- IAM-14: Credentials Management (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- SEF-07: Incident Management and Response (broad)
- CEK-12: Key Rotation (tight)
- CEK-19: Key Compromise (tight)
- IAM-14: Credentials Management (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0012: Valid Accounts (broad)
- AML.T0091.000: Application Access Token (broad)
- AML.T0091.001: Web Session Cookie (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- IR-4: Incident Handling (broad)
- IA-5: Authenticator Management (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 2.3: Procedures are followed to respond to and recover from a previously unknown risk when it is identified. (broad)
- MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (broad)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- secrets-management: Secrets Management Cheat Sheet (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP01: Token Mismanagement & Secret Exposure (tight)
Strong authentication
- CSA AI Controls Matrix (1.1.0): supports control
- IAM-13: Strong Authentication (tight)
- IAM-14: Credentials Management (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- IAM-13: Strong Authentication (tight)
- IAM-14: Credentials Management (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0012: Valid Accounts (broad)
- AML.T0055: Unsecured Credentials (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-306: Missing Authentication for Critical Function (broad)
- CWE-798: Use of Hard-coded Credentials (broad)
- CWE-287: Improper Authentication (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- IA-5(5): Change Authenticators Prior to Delivery (broad)
- IA-5(7): No Embedded Unencrypted Static Authenticators (broad)
- IA-2: Identification and Authentication (Organizational Users) (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.1.3: Use standardized security features and services (broad)
- PW.5.1: Follow secure coding practices (broad)
- OWASP API Security Top 10 (2023): addresses risk
- API2: Broken Authentication (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V6: Authentication (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- authentication: Authentication Cheat Sheet (tight)
- multifactor-authentication: Multifactor Authentication Cheat Sheet (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A07: Authentication Failures (tight)
Least-privilege authorization
- CSA AI Controls Matrix (1.1.0): supports control
- IAM-16: Knowledge Access Control - Need to Know (broad)
- IAM-17: Output Modification and Special Authorization (broad)
- IAM-18: Agent Access Restriction (broad)
- IAM-05: Least Privilege (tight)
- IAM-15: Authorization Mechanisms (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- IAM-05: Least Privilege (tight)
- IAM-15: Authorization Mechanisms (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0053: AI Agent Tool Invocation (broad)
- AML.T0082: RAG Credential Harvesting (broad)
- AML.T0085: Data from AI Services (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-284: Improper Access Control (broad)
- CWE-862: Missing Authorization (tight)
- CWE-863: Incorrect Authorization (tight)
- CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AC-3: Access Enforcement (tight)
- AC-6: Least Privilege (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP API Security Top 10 (2023): addresses risk
- API1: Broken Object Level Authorization (tight)
- API3: Broken Object Property Level Authorization (tight)
- API5: Broken Function Level Authorization (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V8: Authorization (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- mass-assignment: Mass Assignment Cheat Sheet (broad)
- authorization: Authorization Cheat Sheet (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C1: Implement Access Control (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A01: Broken Access Control (tight)
Configuration that executes on load is treated as code
- MITRE CWE (4.20): mitigates weakness
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-7: Software, Firmware, and Information Integrity (broad)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI05: Unexpected Code Execution (RCE) (tight)
Sound cryptography
- CSA AI Controls Matrix (1.1.0): supports control
- CEK-03: Data Protection (broad)
- CEK-04: Encryption Algorithm (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- CEK-03: Data Protection (broad)
- CEK-04: Encryption Algorithm (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.8: Privacy (broad)
- A.11: Security (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-311: Missing Encryption of Sensitive Data (broad)
- CWE-295: Improper Certificate Validation (tight)
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SC-8: Transmission Confidentiality and Integrity (broad)
- SC-28: Protection of Information at Rest (broad)
- SC-13: Cryptographic Protection (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V12: Secure Communication (broad)
- V11: Cryptography (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- cryptographic-storage: Cryptographic Storage Cheat Sheet (tight)
- transport-layer-security: Transport Layer Security Cheat Sheet (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C2: Use Cryptography to Protect Data (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A04: Cryptographic Failures (tight)
Trusted, pinned dependency provenance
- CSA AI Controls Matrix (1.1.0): supports control
- MDS-12: Open Model Risk Assessment (broad)
- TVM-06: External Library Vulnerabilities (broad)
- UEM-02: Application and Service Approval (broad)
- MDS-02: Model Artifact Scanning (tight)
- MDS-09: Model Signing/Ownership Verification (tight)
- STA-01: Supply Chain Risk Management Policies and Procedures (tight)
- STA-08: Supply Chain Inventory (tight)
- STA-09: Service Bill of Material (BOM) (tight)
- STA-10: Supply Chain Risk Management (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- TVM-06: External Library Vulnerabilities (broad)
- UEM-02: Application and Service Approval (broad)
- STA-01: Supply Chain Risk Management Policies and Procedures (tight)
- STA-08: Supply Chain Inventory (tight)
- STA-09: Service Bill of Material (BOM) (tight)
- STA-10: Supply Chain Risk Management (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- B.5: Risk sources related to machine learning (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.4.4: Tooling resources (broad)
- A.10.3: Suppliers (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0018.002: Embed Malware (broad)
- AML.T0111: AI Supply Chain Reputation Inflation (broad)
- AML.T0112.001: AI Artifacts (broad)
- AML.T0010.001: AI Software (tight)
- AML.T0010.003: Model (tight)
- AML.T0010.005: AI Agent Tool (tight)
- AML.T0011.000: Unsafe AI Artifacts (tight)
- AML.T0011.001: Malicious Package (tight)
- AML.T0011.002: Poisoned AI Agent Tool (tight)
- AML.T0104: Publish Poisoned AI Agent Tool (tight)
- AML.T0109: AI Supply Chain Rug Pull (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-1357: Reliance on Insufficiently Trustworthy Component (broad)
- CWE-494: Download of Code Without Integrity Check (tight)
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SR-3: Supply Chain Controls and Processes (tight)
- SR-4: Provenance (tight)
- SR-11: Component Authenticity (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 6.1: Policies and procedures are in place that address AI risks associated with third-party entities. (broad)
- MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PO.3.2: Securely deploy and maintain toolchains (broad)
- PW.4.1: Acquire well-secured third-party components (tight)
- PW.4.4: Verify third-party components meet requirements (tight)
- OWASP API Security Top 10 (2023): addresses risk
- API9: Improper Inventory Management (broad)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI04: Agentic Supply Chain Vulnerabilities (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- software-supply-chain-security: Software Supply Chain Security Cheat Sheet (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM04: Supply Chain (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP04: Software Supply Chain Attacks & Dependency Tampering (tight)
- MCP09: Shadow MCP Servers (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A03: Software Supply Chain Failures (tight)
- A08: Software or Data Integrity Failures (tight)
Fail closed in security-relevant paths
- MITRE CWE (4.20): mitigates weakness
- CWE-636: Not Failing Securely ('Failing Open') (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- error-handling: Error Handling Cheat Sheet (broad)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A10: Mishandling of Exceptional Conditions (tight)
Validate federated identity and token flows
- CSA AI Controls Matrix (1.1.0): supports control
- IAM-13: Strong Authentication (broad)
- IAM-14: Credentials Management (broad)
- IAM-15: Authorization Mechanisms (broad)
- CSA Cloud Controls Matrix (4.1.0): supports control
- IAM-13: Strong Authentication (broad)
- IAM-14: Credentials Management (broad)
- IAM-15: Authorization Mechanisms (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-287: Improper Authentication (broad)
- CWE-304: Missing Critical Step in Authentication (tight)
- CWE-347: Improper Verification of Cryptographic Signature (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V9: Self-contained Tokens (tight)
- V10: OAuth and OIDC (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- json-web-token: JSON Web Token Cheat Sheet (tight)
- oauth2: OAuth2 Cheat Sheet (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C7: Secure Digital Identities (broad)
Validate and contain uploaded files
- MITRE CWE (4.20): mitigates weakness
- CWE-434: Unrestricted Upload of File with Dangerous Type (tight)
- CWE-646: Reliance on File Name or Extension of Externally-Supplied File (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V5: File Handling (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- file-upload: File Upload Cheat Sheet (tight)
Guardrail configuration is integrity-protected
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AC-6(1): Authorize Access to Security Functions (broad)
- SI-7: Software, Firmware, and Information Integrity (broad)
- CM-3: Configuration Change Control (tight)
- CM-5: Access Restrictions for Change (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP02: Privilege Escalation via Scope Creep (tight)
Human authorization for consequential actions
- CSA AI Controls Matrix (1.1.0): supports control
- CCC-05: Change Agreements (broad)
- CCC-04: Unauthorized Change Protection (tight)
- GRC-15: Human supervision (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- CCC-05: Change Agreements (broad)
- CCC-04: Unauthorized Change Protection (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- A.10: Safety (broad)
- B.4: Level of automation (tight)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.9.2: Processes for responsible use of AI systems (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0053: AI Agent Tool Invocation (broad)
- AML.T0086: Exfiltration via AI Agent Tool Invocation (broad)
- AML.T0081: Modify AI Agent Configuration (tight)
- AML.T0101: Data Destruction via AI Agent Tool Invocation (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-862: Missing Authorization (broad)
- CWE-451: User Interface (UI) Misrepresentation of Critical Information (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-3: Configuration Change Control (tight)
- CM-5: Access Restrictions for Change (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (tight)
- MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM03: Excessive Agency (tight)
Validate external input at the boundary
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-08: API Security (broad)
- AIS-09: Input Validation (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- AIS-04: Secure Application Development Lifecycle (broad)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.9: Robustness (broad)
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0049: Exploit Public-Facing Application (broad)
- AML.T0050: Command and Scripting Interpreter (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (broad)
- CWE-20: Improper Input Validation (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-10: Information Input Validation (tight)
- SI-10(5): Restrict Inputs to Trusted Sources and Approved Formats (tight)
- SI-10(6): Injection Prevention (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V2: Validation and Business Logic (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- input-validation: Input Validation Cheat Sheet (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C3: Validate all Input & Handle Exceptions (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A05: Injection (tight)
Trust between agents is earned, not inherited
- CSA AI Controls Matrix (1.1.0): supports control
- IAM-05: Least Privilege (broad)
- IAM-13: Strong Authentication (broad)
- IAM-15: Authorization Mechanisms (broad)
- AIS-11: Agents Security Boundaries (tight)
- IAM-18: Agent Access Restriction (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- IAM-05: Least Privilege (broad)
- IAM-12: Unique Identities (broad)
- IAM-13: Strong Authentication (broad)
- IAM-15: Authorization Mechanisms (broad)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0051.001: Indirect (broad)
- AML.T0053: AI Agent Tool Invocation (broad)
- AML.T0073: Impersonation (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-501: Trust Boundary Violation (broad)
- CWE-272: Least Privilege Violation (tight)
- CWE-290: Authentication Bypass by Spoofing (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AC-3: Access Enforcement (broad)
- AC-6: Least Privilege (broad)
- IA-9: Service Identification and Authentication (tight)
- SI-10: Information Input Validation (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI10: Rogue Agents (broad)
- ASI03: Identity and Privilege Abuse (tight)
- ASI07: Insecure Inter-Agent Communication (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- ai-agent-security: AI Agent Security Cheat Sheet (broad)
- mcp-security: MCP Security Cheat Sheet (broad)
- OWASP MCP Top 10 (2025): addresses risk
- MCP07: Insufficient Authentication & Authorization (tight)
Key management
- CSA AI Controls Matrix (1.1.0): supports control
- CEK-01: Encryption and Key Management Policy and Procedures (broad)
- CEK-10: Key Generation (tight)
- CEK-11: Key Purpose (tight)
- CEK-12: Key Rotation (tight)
- CEK-13: Key Revocation (tight)
- CEK-14: Key Destruction (tight)
- CEK-21: Key Inventory Management (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- CEK-01: Encryption and Key Management Policy and Procedures (broad)
- CEK-10: Key Generation (tight)
- CEK-11: Key Purpose (tight)
- CEK-12: Key Rotation (tight)
- CEK-13: Key Revocation (tight)
- CEK-14: Key Destruction (tight)
- CEK-21: Key Inventory Management (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0012: Valid Accounts (broad)
- AML.T0055: Unsecured Credentials (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-323: Reusing a Nonce, Key Pair in Encryption (broad)
- CWE-321: Use of Hard-coded Cryptographic Key (tight)
- CWE-324: Use of a Key Past its Expiration Date (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- IA-5(7): No Embedded Unencrypted Static Authenticators (tight)
- SC-12: Cryptographic Key Establishment and Management (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V11: Cryptography (broad)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- key-management: Key Management Cheat Sheet (tight)
Least-privilege tool and file access
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-13: AI Sandboxing (broad)
- IAM-10: Management of Privileged Access Roles (broad)
- UEM-02: Application and Service Approval (broad)
- IAM-05: Least Privilege (tight)
- IAM-18: Agent Access Restriction (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- IAM-10: Management of Privileged Access Roles (broad)
- UEM-02: Application and Service Approval (broad)
- IAM-05: Least Privilege (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0053: AI Agent Tool Invocation (broad)
- AML.T0086: Exfiltration via AI Agent Tool Invocation (broad)
- AML.T0098: AI Agent Tool Credential Harvesting (broad)
- AML.T0101: Data Destruction via AI Agent Tool Invocation (broad)
- AML.T0112.000: Local AI Agent (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-269: Improper Privilege Management (broad)
- CWE-250: Execution with Unnecessary Privileges (tight)
- CWE-272: Least Privilege Violation (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SC-39: Process Isolation (broad)
- AC-6: Least Privilege (tight)
- CM-7: Least Functionality (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI02: Tool Misuse and Exploitation (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM03: Excessive Agency (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP02: Privilege Escalation via Scope Creep (tight)
Redact sensitive content from logs
- CSA AI Controls Matrix (1.1.0): supports control
- DSP-17: Sensitive Data Protection (broad)
- LOG-08: Audit Logs Sanitization (tight)
- LOG-09: Log Records (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- DSP-08: Data Privacy by Design and Default (broad)
- DSP-17: Sensitive Data Protection (broad)
- LOG-08: Audit Logs Sanitization (tight)
- LOG-09: Log Records (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.8: Privacy (broad)
- A.11: Security (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.8: AI system recording of event logs (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0055: Unsecured Credentials (broad)
- AML.T0063: Discover AI Model Outputs (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (broad)
- CWE-532: Insertion of Sensitive Information into Log File (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AU-3(3): Limit Personally Identifiable Information Elements (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V16: Security Logging and Error Handling (broad)
Social pressure is not authorization
- MITRE CWE (4.20): mitigates weakness
- CWE-807: Reliance on Untrusted Inputs in a Security Decision (tight)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI09: Human-Agent Trust Exploitation (tight)
Encode output for its sink
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-10: Output Validation (broad)
- CSA Cloud Controls Matrix (4.1.0): supports control
- AIS-04: Secure Application Development Lifecycle (broad)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0050: Command and Scripting Interpreter (broad)
- AML.T0113: Steal Web Session Cookie (broad)
- AML.T0077: LLM Response Rendering (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-116: Improper Encoding or Escaping of Output (broad)
- CWE-838: Inappropriate Encoding for Output Context (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-10(6): Injection Prevention (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V1: Encoding and Sanitization (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- cross-site-scripting-prevention: Cross Site Scripting Prevention Cheat Sheet (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A05: Injection (broad)
Generated output is untrusted input
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-05: Application Security Testing (broad)
- AIS-09: Input Validation (broad)
- AIS-13: AI Sandboxing (broad)
- TVM-13: Guardrails (broad)
- AIS-10: Output Validation (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- AIS-04: Secure Application Development Lifecycle (broad)
- AIS-05: Application Security Testing (broad)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.9: Robustness (broad)
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0050: Command and Scripting Interpreter (broad)
- AML.T0077: LLM Response Rendering (tight)
- AML.T0102: Generate Malicious Commands (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-20: Improper Input Validation (broad)
- CWE-1426: Improper Validation of Generative AI Output (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-11: Developer Testing and Evaluation (broad)
- SI-10(6): Injection Prevention (tight)
- SI-15: Information Output Filtering (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- PW.7.1: Decide on code review and analysis (broad)
- PW.8.1: Decide on executable code testing (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V1: Encoding and Sanitization (tight)
- V2: Validation and Business Logic (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- cross-site-scripting-prevention: Cross Site Scripting Prevention Cheat Sheet (tight)
- injection-prevention: Injection Prevention Cheat Sheet (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM10: Improper Output Handling (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C3: Validate all Input & Handle Exceptions (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A05: Injection (broad)
Referenced instructions are pinned and re-verified
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0010: AI Supply Chain Compromise (broad)
- AML.T0051: LLM Prompt Injection (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-353: Missing Support for Integrity Check (broad)
- CWE-494: Download of Code Without Integrity Check (broad)
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM03: Excessive Agency (broad)
Resist data, model, and memory poisoning
- CSA AI Controls Matrix (1.1.0): supports control
- MDS-06: Adversarial Attack Analysis (broad)
- MDS-07: Robustness against Adversarial Attack / Model Hardening (broad)
- DSP-21: Data Poisoning Prevention & Detection (tight)
- DSP-23: Data Integrity Check (tight)
- MDS-01: Training Pipeline Security (tight)
- MDS-08: Model Integrity Checks (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- B.5: Risk sources related to machine learning (broad)
- A.4: Availability and quality of training and test data (tight)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.7.3: Acquisition of data (broad)
- A.7.4: Quality of data for AI systems (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0010.002: Data (broad)
- AML.T0066: Retrieval Content Crafting (broad)
- AML.T0018.000: Poison AI Model (tight)
- AML.T0020: Poison Training Data (tight)
- AML.T0059: Erode Dataset Integrity (tight)
- AML.T0070: RAG Poisoning (tight)
- AML.T0071: False RAG Entry Injection (tight)
- AML.T0080: AI Agent Context Poisoning (tight)
- AML.T0099: AI Agent Tool Data Poisoning (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-348: Use of Less Trusted Source (broad)
- CWE-345: Insufficient Verification of Data Authenticity (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-7: Software, Firmware, and Information Integrity (tight)
- SI-10(5): Restrict Inputs to Trusted Sources and Approved Formats (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI06: Memory & Context Poisoning (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM05: Data and Model Poisoning (tight)
- LLM09: Vector and Embedding Weaknesses (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP03: Tool Poisoning (tight)
Prefer removing a path over constraining or monitoring it
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AC-6: Least Privilege (broad)
- SC-7: Boundary Protection (broad)
- CM-7: Least Functionality (tight)
A preview makes no change
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI09: Human-Agent Trust Exploitation (tight)
Higher-trust instructions outrank lower-trust ones
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0051: LLM Prompt Injection (broad)
- AML.T0054: LLM Jailbreak (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-1427: Improper Neutralization of Input Used for LLM Prompting (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM01: Prompt Injection (broad)
Protect audit records from the actors they record
- CSA AI Controls Matrix (1.1.0): supports control
- LOG-04: Audit Logs Access and Accountability (broad)
- LOG-02: Audit Logs Protection (tight)
- LOG-10: Audit Records Protection (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- LOG-04: Audit Logs Access and Accountability (broad)
- LOG-02: Audit Logs Protection (tight)
- LOG-10: Audit Records Protection (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-732: Incorrect Permission Assignment for Critical Resource (broad)
- CWE-471: Modification of Assumed-Immutable Data (MAID) (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AU-9: Protection of Audit Information (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V16: Security Logging and Error Handling (broad)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- logging: Logging Cheat Sheet (broad)
- OWASP MCP Top 10 (2025): addresses risk
- MCP08: Lack of Audit and Telemetry (broad)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A09: Security Logging & Alerting Failures (broad)
Reject known-vulnerable dependency versions
- CSA AI Controls Matrix (1.1.0): supports control
- TVM-03: Vulnerability Identification (broad)
- TVM-06: External Library Vulnerabilities (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- TVM-03: Vulnerability Identification (broad)
- TVM-06: External Library Vulnerabilities (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-1395: Dependency on Vulnerable Third-Party Component (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- RA-5: Vulnerability Monitoring and Scanning (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.4.4: Verify third-party components meet requirements (tight)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI04: Agentic Supply Chain Vulnerabilities (broad)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- vulnerable-dependency-management: Vulnerable Dependency Management Cheat Sheet (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM04: Supply Chain (broad)
- OWASP MCP Top 10 (2025): addresses risk
- MCP04: Software Supply Chain Attacks & Dependency Tampering (broad)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C6: Keep your Components Secure (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A03: Software Supply Chain Failures (tight)
Publish artefacts with verifiable integrity
- CSA AI Controls Matrix (1.1.0): supports control
- MDS-09: Model Signing/Ownership Verification (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-345: Insufficient Verification of Data Authenticity (broad)
- CWE-353: Missing Support for Integrity Check (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-7: Software, Firmware, and Information Integrity (broad)
- SR-4: Provenance (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PS.3.2: Maintain provenance data (SBOM) per release (broad)
- PS.2.1: Provide software integrity verification information (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- software-supply-chain-security: Software Supply Chain Security Cheat Sheet (broad)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A08: Software or Data Integrity Failures (broad)
Deserialize untrusted data only as data
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-09: Input Validation (broad)
- MDS-02: Model Artifact Scanning (broad)
- MDS-13: Secure Model Format (broad)
- CSA Cloud Controls Matrix (4.1.0): supports control
- AIS-04: Secure Application Development Lifecycle (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-20: Improper Input Validation (broad)
- CWE-502: Deserialization of Untrusted Data (tight)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI05: Unexpected Code Execution (RCE) (broad)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- deserialization: Deserialization Cheat Sheet (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A08: Software or Data Integrity Failures (broad)
Secure by default configuration
- CSA AI Controls Matrix (1.1.0): supports control
- CCC-06: Change Management Baseline (broad)
- CCC-07: Detection of Baseline Deviation (broad)
- AIS-02: Application Security Baseline Requirements (tight)
- I&S-04: OS Hardening and Base Controls (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- CCC-06: Change Management Baseline (broad)
- CCC-07: Detection of Baseline Deviation (broad)
- AIS-02: Application Security Baseline Requirements (tight)
- I&S-04: OS Hardening and Base Controls (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0049: Exploit Public-Facing Application (broad)
- AML.T0063: Discover AI Model Outputs (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-1188: Initialization of a Resource with an Insecure Default (tight)
- CWE-1269: Product Released in Non-Release Configuration (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CM-6: Configuration Settings (tight)
- CM-7: Least Functionality (tight)
- SI-11: Error Handling (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.9.1: Define a secure default configuration baseline (tight)
- PW.9.2: Implement and document secure default settings (tight)
- OWASP API Security Top 10 (2023): addresses risk
- API8: Security Misconfiguration (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V13: Configuration (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C5: Secure By Default Configurations (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A02: Security Misconfiguration (tight)
Security logging with traceable context
- CSA AI Controls Matrix (1.1.0): supports control
- LOG-01: Logging and Monitoring Policy and Procedures (broad)
- LOG-07: Logging Scope (tight)
- LOG-09: Log Records (tight)
- LOG-12: Transaction/Activity Logging (tight)
- LOG-13: Access Control Logs (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- LOG-01: Logging and Monitoring Policy and Procedures (broad)
- LOG-07: Logging Scope (tight)
- LOG-09: Log Records (tight)
- LOG-12: Transaction/Activity Logging (tight)
- LOG-13: Access Control Logs (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.2: Accountability (broad)
- A.11: Security (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.8: AI system recording of event logs (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-778: Insufficient Logging (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- AU-2: Event Logging (tight)
- AU-3: Content of Audit Records (tight)
- AU-12: Audit Record Generation (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. (broad)
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V16: Security Logging and Error Handling (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- logging: Logging Cheat Sheet (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP08: Lack of Audit and Telemetry (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C9: Implement Security Logging and Monitoring (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A09: Security Logging & Alerting Failures (tight)
Secure session and token handling
- CSA AI Controls Matrix (1.1.0): supports control
- CEK-03: Data Protection (broad)
- IAM-13: Strong Authentication (broad)
- IAM-14: Credentials Management (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- CEK-03: Data Protection (broad)
- IAM-13: Strong Authentication (broad)
- IAM-14: Credentials Management (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0055: Unsecured Credentials (broad)
- AML.T0091.000: Application Access Token (broad)
- AML.T0091.001: Web Session Cookie (broad)
- AML.T0113: Steal Web Session Cookie (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-522: Insufficiently Protected Credentials (broad)
- CWE-331: Insufficient Entropy (tight)
- CWE-352: Cross-Site Request Forgery (CSRF) (tight)
- CWE-613: Insufficient Session Expiration (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- IA-5: Authenticator Management (broad)
- SC-23: Session Authenticity (tight)
- SC-23(1): Invalidate Session Identifiers at Logout (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.5.1: Follow secure coding practices (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V7: Session Management (tight)
- V9: Self-contained Tokens (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- cross-site-request-forgery-prevention: Cross-Site Request Forgery Prevention Cheat Sheet (broad)
- session-management: Session Management Cheat Sheet (tight)
Validate server-initiated requests
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-09: Input Validation (broad)
- I&S-09: Network Defense (broad)
- CSA Cloud Controls Matrix (4.1.0): supports control
- AIS-04: Secure Application Development Lifecycle (broad)
- I&S-09: Network Defense (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-918: Server-Side Request Forgery (SSRF) (tight)
- OWASP API Security Top 10 (2023): addresses risk
- API7: Server Side Request Forgery (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- server-side-request-forgery-prevention: Server Side Request Forgery Prevention Cheat Sheet (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C10: Stop Server Side Request Forgery (tight)
Resolve privileged filesystem paths against symlink races
- MITRE CWE (4.20): mitigates weakness
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition (broad)
- CWE-59: Improper Link Resolution Before File Access ('Link Following') (tight)
- CWE-363: Race Condition Enabling Link Following (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V5: File Handling (broad)
Threat-model new trust boundaries before implementation
- CSA AI Controls Matrix (1.1.0): supports control
- TVM-04: Threat Analysis and Modelling (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- TVM-04: Threat Analysis and Modelling (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- 6.4.2: Risk identification (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-8: Security and Privacy Engineering Principles (broad)
- SA-11(2): Threat Modeling and Vulnerability Analyses (tight)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.1.1: Use risk modeling to assess software risk (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- threat-modeling: Threat Modeling Cheat Sheet (tight)
- OWASP Top 10 Proactive Controls (4.0.0): supports control
- C4: Address Security from the Start (tight)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A06: Insecure Design (broad)
Validate tool arguments before use
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-09: Input Validation (tight)
- AIS-11: Agents Security Boundaries (tight)
- AIS-13: AI Sandboxing (tight)
- IAM-18: Agent Access Restriction (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- AIS-04: Secure Application Development Lifecycle (broad)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0050: Command and Scripting Interpreter (broad)
- AML.T0102: Generate Malicious Commands (broad)
- MITRE CWE (4.20): mitigates weakness
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (broad)
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') (broad)
- CWE-20: Improper Input Validation (tight)
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-10: Information Input Validation (tight)
- SI-10(6): Injection Prevention (tight)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI05: Unexpected Code Execution (RCE) (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V2: Validation and Business Logic (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP05: Command Injection & Execution (broad)
- OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
- A05: Injection (broad)
Untrusted content is data, not instructions
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-09: Input Validation (broad)
- AIS-11: Agents Security Boundaries (broad)
- DSP-24: Data Differentiation and Relevance (broad)
- TVM-02: Malware and Malicious Instructions Protection Policy and Procedures (broad)
- TVM-13: Guardrails (broad)
- AIS-15: Prompt Differentiation (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- AIS-04: Secure Application Development Lifecycle (broad)
- TVM-02: Malware and Malicious Instructions Protection Policy and Procedures (broad)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.9: Robustness (broad)
- A.11: Security (broad)
- B.5: Risk sources related to machine learning (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0068: LLM Prompt Obfuscation (broad)
- AML.T0070: RAG Poisoning (broad)
- AML.T0078: Drive-by Compromise (broad)
- AML.T0080: AI Agent Context Poisoning (broad)
- AML.T0092: Manipulate User LLM Chat History (broad)
- AML.T0094: Delay Execution of LLM Instructions (broad)
- AML.T0099: AI Agent Tool Data Poisoning (broad)
- AML.T0051.000: Direct (tight)
- AML.T0051.001: Indirect (tight)
- AML.T0051.002: Triggered (tight)
- AML.T0054: LLM Jailbreak (tight)
- AML.T0093: Prompt Infiltration via Public-Facing Application (tight)
- AML.T0100: AI Agent Clickbait (tight)
- AML.T0110: AI Agent Tool Poisoning (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-1427: Improper Neutralization of Input Used for LLM Prompting (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-10(6): Injection Prevention (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- llm-prompt-injection-prevention: LLM Prompt Injection Prevention Cheat Sheet (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM01: Prompt Injection (tight)
- OWASP MCP Top 10 (2025): addresses risk
- MCP06: Intent Flow Subversion (tight)
- MCP10: Context Injection & Over-Sharing (tight)
Verify a dependency exists before adding it
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-12: Source Code Management (broad)
- MDS-02: Model Artifact Scanning (broad)
- MDS-12: Open Model Risk Assessment (broad)
- STA-09: Service Bill of Material (BOM) (broad)
- TVM-06: External Library Vulnerabilities (broad)
- UEM-02: Application and Service Approval (broad)
- STA-08: Supply Chain Inventory (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- STA-01: Supply Chain Risk Management Policies and Procedures (broad)
- STA-03: SSRM Supply Chain (broad)
- STA-09: Service Bill of Material (BOM) (broad)
- TVM-06: External Library Vulnerabilities (broad)
- UEM-02: Application and Service Approval (broad)
- STA-08: Supply Chain Inventory (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.11: Security (broad)
- B.5: Risk sources related to machine learning (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0011.001: Malicious Package (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-1357: Reliance on Insufficiently Trustworthy Component (broad)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 6.1: Policies and procedures are in place that address AI risks associated with third-party entities. (broad)
- MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
- NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
- PW.4.1: Acquire well-secured third-party components (tight)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM04: Supply Chain (tight)
Bounded consumption and safe failure
- CSA AI Controls Matrix (1.1.0): supports control
- AIS-13: AI Sandboxing (broad)
- MDS-11: Model Failure (broad)
- CSA Cloud Controls Matrix (4.1.0): supports control
- I&S-02: Capacity and Resource Planning (broad)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.9: Robustness (broad)
- A.11: Security (broad)
- B.4: Level of automation (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.6.2.6: AI system operation and monitoring (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0046: Spamming AI System with Chaff Data (broad)
- AML.T0029: Denial of AI Service (tight)
- AML.T0034.000: Excessive Queries (tight)
- AML.T0034.001: Resource-Intensive Queries (tight)
- AML.T0034.002: Agentic Resource Consumption (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-674: Uncontrolled Recursion (broad)
- CWE-834: Excessive Iteration (broad)
- CWE-400: Uncontrolled Resource Consumption (tight)
- CWE-770: Allocation of Resources Without Limits or Throttling (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SC-5: Denial-of-service Protection (tight)
- SC-6: Resource Availability (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP API Security Top 10 (2023): addresses risk
- API4: Unrestricted Resource Consumption (tight)
- OWASP Top 10 for Agentic Applications (2026): addresses risk
- ASI08: Cascading Failures (tight)
- OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
- denial-of-service: Denial of Service Cheat Sheet (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM06: Unbounded Consumption (tight)
A destructive operation requires a verified restore path
- CSA AI Controls Matrix (1.1.0): supports control
- BCR-08: Backup (broad)
- CSA Cloud Controls Matrix (4.1.0): supports control
- BCR-08: Backup (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- CP-9: System Backup (broad)
- CP-9(1): Testing for Reliability and Integrity (broad)
- CP-10: System Recovery and Reconstitution (broad)
- CP-9(2): Test Restoration Using Sampling (tight)
Minimize personal data sent to AI services
- CSA AI Controls Matrix (1.1.0): supports control
- DSP-17: Sensitive Data Protection (broad)
- DSP-08: Data Privacy by Design and Default (tight)
- DSP-12: Limitation of Purpose in Personal Data Processing (tight)
- DSP-22: Privacy Enhancing Technologies (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- DSP-17: Sensitive Data Protection (broad)
- DSP-08: Data Privacy by Design and Default (tight)
- DSP-12: Limitation of Purpose in Personal Data Processing (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.8: Privacy (broad)
- ISO/IEC 42001:2023 AI management system (2023): supports control
- A.7.6: Data preparation (broad)
- MITRE ATLAS (2026.06): mitigates technique
- AML.T0024.000: Infer Training Data Membership (broad)
- AML.T0024.001: Invert AI Model (broad)
- AML.T0057: LLM Data Leakage (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-359: Exposure of Private Personal Information to an Unauthorized Actor (broad)
- CWE-201: Insertion of Sensitive Information Into Sent Data (tight)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SI-19: De-identification (broad)
- SI-12(1): Limit Personally Identifiable Information Elements (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V14: Data Protection (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM02: Sensitive Information Disclosure (tight)
Honour residency, retention, and deletion
- CSA AI Controls Matrix (1.1.0): supports control
- DSP-11: Personal Data Access, Reversal, Rectification and Deletion (tight)
- DSP-16: Data Retention and Deletion (tight)
- DSP-19: Data Location (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- DSP-11: Personal Data Access, Reversal, Rectification and Deletion (tight)
- DSP-16: Data Retention and Deletion (tight)
- DSP-19: Data Location (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.8: Privacy (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-9(5): Processing, Storage, and Service Location (tight)
- SI-12: Information Management and Retention (tight)
- SI-12(3): Information Disposal (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented. (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V14: Data Protection (broad)
Bind personal-data use to its authorized purpose
- CSA AI Controls Matrix (1.1.0): supports control
- DSP-12: Limitation of Purpose in Personal Data Processing (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- DSP-12: Limitation of Purpose in Personal Data Processing (tight)
- ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
- A.8: Privacy (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- PT-2: Authority to Process Personally Identifiable Information (tight)
- PT-3: Personally Identifiable Information Processing Purposes (tight)
- NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
- GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented. (broad)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V14: Data Protection (broad)
Fixtures and examples use synthetic data
- CSA AI Controls Matrix (1.1.0): supports control
- DSP-15: Limitation of Production Data Use (tight)
- CSA Cloud Controls Matrix (4.1.0): supports control
- DSP-15: Limitation of Production Data Use (tight)
- MITRE CWE (4.20): mitigates weakness
- CWE-359: Exposure of Private Personal Information to an Unauthorized Actor (broad)
- CWE-531: Inclusion of Sensitive Information in Test Code (broad)
- NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
- SA-3(2): Use of Live or Operational Data (tight)
- SA-15(9): Use of Live Data (tight)
- OWASP Application Security Verification Standard (5.0.0): supports control
- V14: Data Protection (broad)
- OWASP Top 10 for LLM Applications (2026): addresses risk
- LLM02: Sensitive Information Disclosure (broad)
Reverse view
By framework
The same mappings read the other way. Open a framework to see each of its identifiers that a rule references, and the rules that reference it. Identifiers that no rule references are not listed; the registry above states the coverage honestly instead.
CSA AI Controls Matrix (1.1.0)
supports control. 79 identifiers referenced from a curated subset of the edition.
- AIS-02: Application Security Baseline Requirements
- Secure by default configuration (tight)
- AIS-05: Application Security Testing
- AIS-08: API Security
- AIS-09: Input Validation
- AIS-10: Output Validation
- Encode output for its sink (broad)
- Generated output is untrusted input (tight)
- AIS-11: Agents Security Boundaries
- AIS-12: Source Code Management
- Keep secrets out (tight)
- Verify a dependency exists before adding it (broad)
- AIS-13: AI Sandboxing
- AIS-14: AI Cache Protection
- No cross-context bleed (broad)
- AIS-15: Prompt Differentiation
- BCR-08: Backup
- CCC-04: Unauthorized Change Protection
- CCC-05: Change Agreements
- CCC-06: Change Management Baseline
- Secure by default configuration (broad)
- CCC-07: Detection of Baseline Deviation
- Secure by default configuration (broad)
- CEK-01: Encryption and Key Management Policy and Procedures
- Key management (broad)
- CEK-03: Data Protection
- Sound cryptography (broad)
- Secure session and token handling (broad)
- CEK-04: Encryption Algorithm
- Sound cryptography (tight)
- CEK-10: Key Generation
- Key management (tight)
- CEK-11: Key Purpose
- Key management (tight)
- CEK-12: Key Rotation
- Rotate a leaked secret (tight)
- Key management (tight)
- CEK-13: Key Revocation
- Key management (tight)
- CEK-14: Key Destruction
- Key management (tight)
- CEK-19: Key Compromise
- Rotate a leaked secret (tight)
- CEK-21: Key Inventory Management
- Key management (tight)
- DSP-04: Data Classification
- DSP-08: Data Privacy by Design and Default
- DSP-10: Sensitive Data Transfer
- DSP-11: Personal Data Access, Reversal, Rectification and Deletion
- DSP-12: Limitation of Purpose in Personal Data Processing
- DSP-15: Limitation of Production Data Use
- DSP-16: Data Retention and Deletion
- DSP-17: Sensitive Data Protection
- Classify content by sensitivity tier (broad)
- Keep secrets out (broad)
- No disclosure of secrets or hidden context (broad)
- Redact sensitive content from logs (broad)
- Minimize personal data sent to AI services (broad)
- DSP-19: Data Location
- DSP-21: Data Poisoning Prevention & Detection
- DSP-22: Privacy Enhancing Technologies
- DSP-23: Data Integrity Check
- DSP-24: Data Differentiation and Relevance
- GRC-15: Human supervision
- I&S-04: OS Hardening and Base Controls
- Secure by default configuration (tight)
- I&S-06: Segmentation and Segregation
- No cross-context bleed (tight)
- I&S-09: Network Defense
- IAM-05: Least Privilege
- IAM-10: Management of Privileged Access Roles
- IAM-13: Strong Authentication
- IAM-14: Credentials Management
- Keep secrets out (tight)
- Rotate a leaked secret (tight)
- Strong authentication (tight)
- Validate federated identity and token flows (broad)
- Secure session and token handling (tight)
- IAM-15: Authorization Mechanisms
- IAM-16: Knowledge Access Control - Need to Know
- IAM-17: Output Modification and Special Authorization
- Least-privilege authorization (broad)
- IAM-18: Agent Access Restriction
- LOG-01: Logging and Monitoring Policy and Procedures
- LOG-02: Audit Logs Protection
- LOG-04: Audit Logs Access and Accountability
- LOG-07: Logging Scope
- LOG-08: Audit Logs Sanitization
- Keep secrets out (broad)
- Redact sensitive content from logs (tight)
- LOG-09: Log Records
- LOG-10: Audit Records Protection
- LOG-12: Transaction/Activity Logging
- LOG-13: Access Control Logs
- MDS-01: Training Pipeline Security
- MDS-02: Model Artifact Scanning
- MDS-06: Adversarial Attack Analysis
- MDS-07: Robustness against Adversarial Attack / Model Hardening
- MDS-08: Model Integrity Checks
- MDS-09: Model Signing/Ownership Verification
- MDS-11: Model Failure
- MDS-12: Open Model Risk Assessment
- MDS-13: Secure Model Format
- SEF-07: Incident Management and Response
- Rotate a leaked secret (broad)
- STA-01: Supply Chain Risk Management Policies and Procedures
- STA-08: Supply Chain Inventory
- STA-09: Service Bill of Material (BOM)
- STA-10: Supply Chain Risk Management
- TVM-02: Malware and Malicious Instructions Protection Policy and Procedures
- TVM-03: Vulnerability Identification
- TVM-04: Threat Analysis and Modelling
- TVM-06: External Library Vulnerabilities
- TVM-13: Guardrails
- UEM-02: Application and Service Approval
CSA Cloud Controls Matrix (4.1.0)
supports control. 57 identifiers referenced from a curated subset of the edition.
- AIS-02: Application Security Baseline Requirements
- Secure by default configuration (tight)
- AIS-04: Secure Application Development Lifecycle
- Validate external input at the boundary (broad)
- Encode output for its sink (broad)
- Generated output is untrusted input (broad)
- Deserialize untrusted data only as data (broad)
- Validate server-initiated requests (broad)
- Validate tool arguments before use (broad)
- Untrusted content is data, not instructions (broad)
- AIS-05: Application Security Testing
- BCR-08: Backup
- CCC-04: Unauthorized Change Protection
- CCC-05: Change Agreements
- CCC-06: Change Management Baseline
- Secure by default configuration (broad)
- CCC-07: Detection of Baseline Deviation
- Secure by default configuration (broad)
- CEK-01: Encryption and Key Management Policy and Procedures
- Key management (broad)
- CEK-03: Data Protection
- Sound cryptography (broad)
- Secure session and token handling (broad)
- CEK-04: Encryption Algorithm
- Sound cryptography (tight)
- CEK-10: Key Generation
- Key management (tight)
- CEK-11: Key Purpose
- Key management (tight)
- CEK-12: Key Rotation
- Rotate a leaked secret (tight)
- Key management (tight)
- CEK-13: Key Revocation
- Key management (tight)
- CEK-14: Key Destruction
- Key management (tight)
- CEK-19: Key Compromise
- Rotate a leaked secret (tight)
- CEK-21: Key Inventory Management
- Key management (tight)
- DSP-04: Data Classification
- DSP-08: Data Privacy by Design and Default
- DSP-10: Sensitive Data Transfer
- DSP-11: Personal Data Access, Reversal, Rectification and Deletion
- DSP-12: Limitation of Purpose in Personal Data Processing
- DSP-15: Limitation of Production Data Use
- DSP-16: Data Retention and Deletion
- DSP-17: Sensitive Data Protection
- Classify content by sensitivity tier (broad)
- Keep secrets out (broad)
- No disclosure of secrets or hidden context (broad)
- Redact sensitive content from logs (broad)
- Minimize personal data sent to AI services (broad)
- DSP-19: Data Location
- I&S-02: Capacity and Resource Planning
- I&S-04: OS Hardening and Base Controls
- Secure by default configuration (tight)
- I&S-06: Segmentation and Segregation
- No cross-context bleed (tight)
- I&S-09: Network Defense
- IAM-05: Least Privilege
- IAM-10: Management of Privileged Access Roles
- IAM-12: Unique Identities
- IAM-13: Strong Authentication
- IAM-14: Credentials Management
- Keep secrets out (tight)
- Rotate a leaked secret (tight)
- Strong authentication (tight)
- Validate federated identity and token flows (broad)
- Secure session and token handling (tight)
- IAM-15: Authorization Mechanisms
- LOG-01: Logging and Monitoring Policy and Procedures
- LOG-02: Audit Logs Protection
- LOG-04: Audit Logs Access and Accountability
- LOG-07: Logging Scope
- LOG-08: Audit Logs Sanitization
- Keep secrets out (broad)
- Redact sensitive content from logs (tight)
- LOG-09: Log Records
- LOG-10: Audit Records Protection
- LOG-12: Transaction/Activity Logging
- LOG-13: Access Control Logs
- SEF-07: Incident Management and Response
- Rotate a leaked secret (broad)
- STA-01: Supply Chain Risk Management Policies and Procedures
- STA-03: SSRM Supply Chain
- STA-08: Supply Chain Inventory
- STA-09: Service Bill of Material (BOM)
- STA-10: Supply Chain Risk Management
- TVM-02: Malware and Malicious Instructions Protection Policy and Procedures
- TVM-03: Vulnerability Identification
- TVM-04: Threat Analysis and Modelling
- TVM-06: External Library Vulnerabilities
- UEM-02: Application and Service Approval
ISO/IEC 23894:2023 AI guidance on risk management (2023)
aligns with guidance. 14 identifiers referenced from a curated subset of the edition.
- 6.2: Communication and consultation
- 6.4.2: Risk identification
- 6.7: Recording and reporting
- No concealed failure (tight)
- A launched task stays observable (broad)
- Change record (tight)
- Records first (tight)
- A.2: Accountability
- Commit identity (broad)
- Workers produce inert data (broad)
- Surface a counterproductive instruction before executing it (broad)
- Assess and advise are discussion only (broad)
- Express authorization before execution (broad)
- Human oversight and the autonomy threshold (broad)
- Trust recovery and escalation (broad)
- Autonomy steps down after a confirmed trust loss (broad)
- Decision classification before enacting (tight)
- Human authorization for consequential actions (broad)
- Security logging with traceable context (broad)
- A.4: Availability and quality of training and test data
- A.7: Maintainability
- Branch and merge only on green (broad)
- Protected-branch integrity (broad)
- Match the surrounding code (broad)
- Prefer the smallest correct change (broad)
- A.8: Privacy
- Retrieval enforces the requester's authorization (broad)
- No cross-context bleed (broad)
- No disclosure of secrets or hidden context (broad)
- Sound cryptography (broad)
- Redact sensitive content from logs (broad)
- Minimize personal data sent to AI services (broad)
- Honour residency, retention, and deletion (broad)
- Bind personal-data use to its authorized purpose (broad)
- A.9: Robustness
- A.10: Safety
- A.11: Security
- Defence in depth by default (broad)
- Keep secrets out (broad)
- Retrieval enforces the requester's authorization (broad)
- No cross-context bleed (broad)
- No disclosure of secrets or hidden context (broad)
- Rotate a leaked secret (broad)
- Strong authentication (broad)
- Least-privilege authorization (broad)
- Sound cryptography (broad)
- Trusted, pinned dependency provenance (broad)
- Validate external input at the boundary (broad)
- Trust between agents is earned, not inherited (broad)
- Key management (broad)
- Least-privilege tool and file access (broad)
- Redact sensitive content from logs (broad)
- Encode output for its sink (broad)
- Generated output is untrusted input (broad)
- Resist data, model, and memory poisoning (broad)
- Secure by default configuration (broad)
- Security logging with traceable context (broad)
- Secure session and token handling (broad)
- Validate tool arguments before use (broad)
- Untrusted content is data, not instructions (broad)
- Verify a dependency exists before adding it (broad)
- Bounded consumption and safe failure (broad)
- A.12: Transparency and explainability
- Claims about the work rest on observation (broad)
- A completeness claim enumerates its set (broad)
- Evidence-grounded completion (broad)
- Measured and estimated figures stay separate (broad)
- No fabrication (broad)
- No concealed failure (broad)
- Trust recovery and escalation (broad)
- B.4: Level of automation
- Workers produce inert data (broad)
- Assess and advise are discussion only (broad)
- Continue by default (broad)
- Express authorization before execution (broad)
- Human oversight and the autonomy threshold (tight)
- Decision classification before enacting (tight)
- Human authorization for consequential actions (tight)
- Bounded consumption and safe failure (broad)
- B.5: Risk sources related to machine learning
- B.7: System life cycle issues
- Branch and merge only on green (broad)
- Protected-branch integrity (broad)
ISO/IEC 42001:2023 AI management system (2023)
supports control. 18 identifiers referenced from a curated subset of the edition.
- 7.5.2: Creating and updating documented information
- Change record (broad)
- Records first (broad)
- 7.5.3: Control of documented information
- Change record (broad)
- Records first (broad)
- 8.1: Operational planning and control
- Close each session on green (broad)
- Resume from the durable handoff (broad)
- 10.2: Nonconformity and corrective action
- A.3.2: AI roles and responsibilities
- Commit identity (broad)
- Human oversight and the autonomy threshold (broad)
- A.3.3: Reporting of concerns
- A.4.4: Tooling resources
- A.6.1.3: Processes for responsible design and development of AI systems
- A.6.2.4: AI system verification and validation
- Gate discipline (broad)
- No concealed failure (broad)
- A rerun pass does not erase an earlier failure (broad)
- Validation is a gate on apply (broad)
- A behavioural change carries a check that fails without it (broad)
- A verification finding is fixed, not argued away (broad)
- High-assurance verification (broad)
- Isolate verifiers and judge by their result signal (broad)
- A test's verdict comes from the code, not its surroundings (broad)
- Verifier diversity (broad)
- A.6.2.6: AI system operation and monitoring
- A launched task stays observable (broad)
- Bounded consumption and safe failure (broad)
- A.6.2.8: AI system recording of event logs
- A.7.3: Acquisition of data
- A.7.4: Quality of data for AI systems
- A.7.5: Data provenance
- A.7.6: Data preparation
- A.8.5: Information for interested parties
- A.9.2: Processes for responsible use of AI systems
- A.10.3: Suppliers
MITRE ATLAS (2026.06)
mitigates technique. 67 identifiers referenced from a curated subset of the edition.
- AML.T0010: AI Supply Chain Compromise
- AML.T0010.001: AI Software
- AML.T0010.002: Data
- AML.T0010.003: Model
- AML.T0010.005: AI Agent Tool
- AML.T0011.000: Unsafe AI Artifacts
- AML.T0011.001: Malicious Package
- AML.T0011.002: Poisoned AI Agent Tool
- AML.T0012: Valid Accounts
- Rotate a leaked secret (broad)
- Strong authentication (broad)
- Key management (broad)
- AML.T0018.000: Poison AI Model
- AML.T0018.002: Embed Malware
- AML.T0020: Poison Training Data
- AML.T0024.000: Infer Training Data Membership
- AML.T0024.001: Invert AI Model
- AML.T0025: Exfiltration via Cyber Means
- AML.T0029: Denial of AI Service
- AML.T0034.000: Excessive Queries
- AML.T0034.001: Resource-Intensive Queries
- AML.T0034.002: Agentic Resource Consumption
- AML.T0046: Spamming AI System with Chaff Data
- AML.T0049: Exploit Public-Facing Application
- AML.T0050: Command and Scripting Interpreter
- Validate external input at the boundary (broad)
- Encode output for its sink (broad)
- Generated output is untrusted input (broad)
- Validate tool arguments before use (broad)
- AML.T0051: LLM Prompt Injection
- AML.T0051.000: Direct
- AML.T0051.001: Indirect
- AML.T0051.002: Triggered
- AML.T0053: AI Agent Tool Invocation
- Workers produce inert data (broad)
- Human oversight and the autonomy threshold (broad)
- Retrieval enforces the requester's authorization (broad)
- Least-privilege authorization (broad)
- Human authorization for consequential actions (broad)
- Trust between agents is earned, not inherited (broad)
- Least-privilege tool and file access (broad)
- AML.T0054: LLM Jailbreak
- AML.T0055: Unsecured Credentials
- Keep secrets out (tight)
- Strong authentication (broad)
- Key management (tight)
- Redact sensitive content from logs (broad)
- Secure session and token handling (broad)
- AML.T0056: Extract LLM System Prompt
- AML.T0057: LLM Data Leakage
- AML.T0059: Erode Dataset Integrity
- AML.T0063: Discover AI Model Outputs
- Redact sensitive content from logs (broad)
- Secure by default configuration (broad)
- AML.T0066: Retrieval Content Crafting
- AML.T0067.000: Citations
- Corroborate external claims (tight)
- AML.T0068: LLM Prompt Obfuscation
- AML.T0069: Discover LLM System Information
- AML.T0070: RAG Poisoning
- AML.T0071: False RAG Entry Injection
- AML.T0073: Impersonation
- AML.T0077: LLM Response Rendering
- Encode output for its sink (tight)
- Generated output is untrusted input (tight)
- AML.T0078: Drive-by Compromise
- AML.T0080: AI Agent Context Poisoning
- AML.T0081: Modify AI Agent Configuration
- AML.T0082: RAG Credential Harvesting
- Keep secrets out (broad)
- Retrieval enforces the requester's authorization (broad)
- No disclosure of secrets or hidden context (broad)
- Least-privilege authorization (broad)
- AML.T0083: Credentials from AI Agent Configuration
- Keep secrets out (broad)
- AML.T0084: Discover AI Agent Configuration
- AML.T0085: Data from AI Services
- AML.T0086: Exfiltration via AI Agent Tool Invocation
- AML.T0091.000: Application Access Token
- Rotate a leaked secret (broad)
- Secure session and token handling (broad)
- AML.T0091.001: Web Session Cookie
- Rotate a leaked secret (broad)
- Secure session and token handling (broad)
- AML.T0092: Manipulate User LLM Chat History
- AML.T0093: Prompt Infiltration via Public-Facing Application
- AML.T0094: Delay Execution of LLM Instructions
- AML.T0095.000: Code Repositories
- Keep secrets out (tight)
- AML.T0098: AI Agent Tool Credential Harvesting
- Keep secrets out (broad)
- No disclosure of secrets or hidden context (broad)
- Least-privilege tool and file access (broad)
- AML.T0099: AI Agent Tool Data Poisoning
- AML.T0100: AI Agent Clickbait
- AML.T0101: Data Destruction via AI Agent Tool Invocation
- AML.T0102: Generate Malicious Commands
- AML.T0104: Publish Poisoned AI Agent Tool
- AML.T0109: AI Supply Chain Rug Pull
- AML.T0110: AI Agent Tool Poisoning
- AML.T0111: AI Supply Chain Reputation Inflation
- AML.T0112.000: Local AI Agent
- AML.T0112.001: AI Artifacts
- AML.T0113: Steal Web Session Cookie
- Encode output for its sink (broad)
- Secure session and token handling (broad)
MITRE CWE (4.20)
mitigates weakness. 72 identifiers referenced from a curated subset of the edition.
- CWE-20: Improper Input Validation
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- CWE-116: Improper Encoding or Escaping of Output
- Encode output for its sink (broad)
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- Classify content by sensitivity tier (broad)
- No cross-context bleed (broad)
- No disclosure of secrets or hidden context (tight)
- Redact sensitive content from logs (broad)
- CWE-201: Insertion of Sensitive Information Into Sent Data
- CWE-250: Execution with Unnecessary Privileges
- CWE-269: Improper Privilege Management
- CWE-272: Least Privilege Violation
- CWE-284: Improper Access Control
- Least-privilege authorization (broad)
- CWE-285: Improper Authorization
- CWE-287: Improper Authentication
- Strong authentication (tight)
- Validate federated identity and token flows (broad)
- CWE-290: Authentication Bypass by Spoofing
- CWE-295: Improper Certificate Validation
- Sound cryptography (tight)
- CWE-304: Missing Critical Step in Authentication
- CWE-306: Missing Authentication for Critical Function
- Strong authentication (broad)
- CWE-311: Missing Encryption of Sensitive Data
- Sound cryptography (broad)
- CWE-321: Use of Hard-coded Cryptographic Key
- Key management (tight)
- CWE-323: Reusing a Nonce, Key Pair in Encryption
- Key management (broad)
- CWE-324: Use of a Key Past its Expiration Date
- Key management (tight)
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
- Sound cryptography (tight)
- CWE-331: Insufficient Entropy
- CWE-345: Insufficient Verification of Data Authenticity
- CWE-347: Improper Verification of Cryptographic Signature
- CWE-348: Use of Less Trusted Source
- CWE-352: Cross-Site Request Forgery (CSRF)
- CWE-353: Missing Support for Integrity Check
- CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
- CWE-363: Race Condition Enabling Link Following
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
- CWE-400: Uncontrolled Resource Consumption
- CWE-434: Unrestricted Upload of File with Dangerous Type
- CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')
- CWE-451: User Interface (UI) Misrepresentation of Critical Information
- CWE-471: Modification of Assumed-Immutable Data (MAID)
- CWE-488: Exposure of Data Element to Wrong Session
- No cross-context bleed (tight)
- CWE-494: Download of Code Without Integrity Check
- CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
- CWE-501: Trust Boundary Violation
- CWE-502: Deserialization of Untrusted Data
- CWE-522: Insufficiently Protected Credentials
- CWE-531: Inclusion of Sensitive Information in Test Code
- CWE-532: Insertion of Sensitive Information into Log File
- Keep secrets out (tight)
- Redact sensitive content from logs (tight)
- CWE-540: Inclusion of Sensitive Information in Source Code
- Keep secrets out (tight)
- CWE-610: Externally Controlled Reference to a Resource in Another Sphere
- CWE-613: Insufficient Session Expiration
- CWE-636: Not Failing Securely ('Failing Open')
- CWE-646: Reliance on File Name or Extension of Externally-Supplied File
- CWE-653: Improper Isolation or Compartmentalization
- No cross-context bleed (broad)
- CWE-674: Uncontrolled Recursion
- CWE-732: Incorrect Permission Assignment for Critical Resource
- CWE-770: Allocation of Resources Without Limits or Throttling
- CWE-778: Insufficient Logging
- CWE-798: Use of Hard-coded Credentials
- Keep secrets out (broad)
- Strong authentication (broad)
- CWE-807: Reliance on Untrusted Inputs in a Security Decision
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
- CWE-834: Excessive Iteration
- CWE-838: Inappropriate Encoding for Output Context
- Encode output for its sink (tight)
- CWE-862: Missing Authorization
- CWE-863: Incorrect Authorization
- Least-privilege authorization (tight)
- CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes
- Least-privilege authorization (tight)
- CWE-918: Server-Side Request Forgery (SSRF)
- CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
- CWE-1188: Initialization of a Resource with an Insecure Default
- Secure by default configuration (tight)
- CWE-1269: Product Released in Non-Release Configuration
- Secure by default configuration (tight)
- CWE-1357: Reliance on Insufficiently Trustworthy Component
- CWE-1395: Dependency on Vulnerable Third-Party Component
- CWE-1426: Improper Validation of Generative AI Output
- CWE-1427: Improper Neutralization of Input Used for LLM Prompting
NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0))
supports control. 67 identifiers referenced from a curated subset of the edition.
- AC-3: Access Enforcement
- AC-4: Information Flow Enforcement
- AC-6: Least Privilege
- AC-6(1): Authorize Access to Security Functions
- AU-2: Event Logging
- AU-3: Content of Audit Records
- AU-3(3): Limit Personally Identifiable Information Elements
- AU-8: Time Stamps
- AU-9: Protection of Audit Information
- AU-12: Audit Record Generation
- CA-7: Continuous Monitoring
- CM-3: Configuration Change Control
- Branch and merge only on green (tight)
- Cut branches from the live protected line and re-home after a rewrite (tight)
- Protected-branch integrity (tight)
- Separate task changes from pre-existing work (broad)
- Change record (tight)
- Guardrail configuration is integrity-protected (tight)
- Human authorization for consequential actions (tight)
- CM-3(2): Testing, Validation, and Documentation of Changes
- Branch and merge only on green (tight)
- Cut branches from the live protected line and re-home after a rewrite (tight)
- Gate discipline (broad)
- Validation is a gate on apply (tight)
- A behavioural change carries a check that fails without it (broad)
- High-assurance verification (broad)
- Background work during CI waits (broad)
- CM-5: Access Restrictions for Change
- CM-6: Configuration Settings
- Secure by default configuration (tight)
- CM-7: Least Functionality
- CM-8: System Component Inventory
- CP-9: System Backup
- CP-9(1): Testing for Reliability and Integrity
- CP-9(2): Test Restoration Using Sampling
- CP-10: System Recovery and Reconstitution
- IA-2: Identification and Authentication (Organizational Users)
- Strong authentication (tight)
- IA-5: Authenticator Management
- Rotate a leaked secret (tight)
- Secure session and token handling (broad)
- IA-5(5): Change Authenticators Prior to Delivery
- Strong authentication (broad)
- IA-5(7): No Embedded Unencrypted Static Authenticators
- Keep secrets out (tight)
- Strong authentication (broad)
- Key management (tight)
- IA-9: Service Identification and Authentication
- IR-4: Incident Handling
- Rotate a leaked secret (broad)
- MP-3: Media Marking
- PT-2: Authority to Process Personally Identifiable Information
- PT-3: Personally Identifiable Information Processing Purposes
- RA-5: Vulnerability Monitoring and Scanning
- SA-3(2): Use of Live or Operational Data
- SA-8: Security and Privacy Engineering Principles
- SA-8(29): Repeatable and Documented Procedures
- SA-9(5): Processing, Storage, and Service Location
- SA-10: Developer Configuration Management
- SA-11: Developer Testing and Evaluation
- Gate discipline (broad)
- No concealed failure (broad)
- Validation is a gate on apply (broad)
- A behavioural change carries a check that fails without it (broad)
- A verification finding is fixed, not argued away (broad)
- A test's verdict comes from the code, not its surroundings (tight)
- Generated output is untrusted input (broad)
- SA-11(2): Threat Modeling and Vulnerability Analyses
- SA-11(3): Independent Verification of Assessment Plans and Evidence
- High-assurance verification (tight)
- Isolate verifiers and judge by their result signal (broad)
- Verifier diversity (broad)
- SA-15(9): Use of Live Data
- SC-4: Information in Shared System Resources
- No cross-context bleed (tight)
- SC-5: Denial-of-service Protection
- SC-6: Resource Availability
- SC-7: Boundary Protection
- SC-7(5): Deny by Default - Allow by Exception
- SC-8: Transmission Confidentiality and Integrity
- Sound cryptography (broad)
- SC-12: Cryptographic Key Establishment and Management
- Key management (tight)
- SC-13: Cryptographic Protection
- Sound cryptography (tight)
- SC-23: Session Authenticity
- SC-23(1): Invalidate Session Identifiers at Logout
- SC-28: Protection of Information at Rest
- Sound cryptography (broad)
- SC-39: Process Isolation
- SI-2: Flaw Remediation
- SI-7: Software, Firmware, and Information Integrity
- SI-10: Information Input Validation
- SI-10(5): Restrict Inputs to Trusted Sources and Approved Formats
- SI-10(6): Injection Prevention
- SI-11: Error Handling
- Secure by default configuration (tight)
- SI-12: Information Management and Retention
- SI-12(1): Limit Personally Identifiable Information Elements
- SI-12(3): Information Disposal
- SI-15: Information Output Filtering
- SI-17: Fail-safe Procedures
- SI-19: De-identification
- SR-3: Supply Chain Controls and Processes
- SR-4: Provenance
- SR-11: Component Authenticity
NIST AI Risk Management Framework (1.0 (NIST AI 100-1))
aligns with guidance. 24 identifiers referenced from a curated subset of the edition.
- GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented.
- GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities.
- Cost tier (broad)
- GOVERN 1.4: The risk management process and its outcomes are established through transparent policies, procedures, and other controls.
- Records first (broad)
- GOVERN 1.5: Ongoing monitoring and periodic review of the risk management process and its outcomes are planned.
- GOVERN 1.6: Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.
- GOVERN 2.1: Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented.
- Commit identity (broad)
- GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight.
- Surface a counterproductive instruction before executing it (broad)
- Assess and advise are discussion only (broad)
- Express authorization before execution (broad)
- Human oversight and the autonomy threshold (tight)
- Autonomy steps down after a confirmed trust loss (broad)
- Decision classification before enacting (tight)
- Human authorization for consequential actions (tight)
- GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset.
- Claims about the work rest on observation (broad)
- A completeness claim enumerates its set (broad)
- Corroborate external claims (broad)
- Evidence-grounded completion (broad)
- No fabrication (broad)
- Read before characterizing (broad)
- Validate an inferred premise before acting (broad)
- Gate discipline (broad)
- A verification finding is fixed, not argued away (broad)
- Surface a counterproductive instruction before executing it (tight)
- Clarify before acting (broad)
- Generated output is untrusted input (broad)
- GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing.
- No concealed failure (tight)
- Security logging with traceable context (broad)
- GOVERN 6.1: Policies and procedures are in place that address AI risks associated with third-party entities.
- MANAGE 2.3: Procedures are followed to respond to and recover from a previously unknown risk when it is identified.
- MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.
- MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.
- Branch and merge only on green (broad)
- Cut branches from the live protected line and re-home after a rewrite (broad)
- Protected-branch integrity (broad)
- Change record (broad)
- MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented.
- Anything wrong is fixed first (broad)
- No concealed failure (tight)
- A required step remains required under friction (broad)
- A launched task stays observable (broad)
- Trust recovery and escalation (tight)
- Autonomy steps down after a confirmed trust loss (tight)
- Rotate a leaked secret (broad)
- MAP 1.5: Organizational risk tolerances are determined and documented.
- Cost tier (broad)
- MAP 1.6: System requirements (e.g., "the system shall respect the privacy of its users") are elicited from and understood by relevant AI actors.
- Clarify before acting (broad)
- MAP 2.3: Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection, and construct validation.
- MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies.
- MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented.
- Validation is a gate on apply (broad)
- Workers produce inert data (broad)
- Keep secrets out (broad)
- Retrieval enforces the requester's authorization (broad)
- No cross-context bleed (broad)
- No disclosure of secrets or hidden context (broad)
- Trusted, pinned dependency provenance (broad)
- Trust between agents is earned, not inherited (broad)
- Least-privilege tool and file access (broad)
- Redact sensitive content from logs (broad)
- Generated output is untrusted input (broad)
- Referenced instructions are pinned and re-verified (broad)
- Resist data, model, and memory poisoning (broad)
- Higher-trust instructions outrank lower-trust ones (broad)
- Security logging with traceable context (broad)
- Untrusted content is data, not instructions (broad)
- Bounded consumption and safe failure (broad)
- Minimize personal data sent to AI services (broad)
- MEASURE 1.1: Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation.
- MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates.
- High-assurance verification (tight)
- Isolate verifiers and judge by their result signal (broad)
- Verifier diversity (broad)
- MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented.
- Verifier diversity (broad)
- MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context.
- Corroborate external claims (broad)
- No fabrication (broad)
- Read before characterizing (broad)
- Generated output is untrusted input (broad)
- MEASURE 2.13: Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented.
NIST Secure Software Development Framework (1.1 (SP 800-218))
supports control. 20 identifiers referenced from a curated subset of the edition.
- PO.3.2: Securely deploy and maintain toolchains
- PO.3.3: Generate artifacts from security tools
- Change record (broad)
- PO.4.1: Define software security check criteria
- Gate discipline (broad)
- A verification finding is fixed, not argued away (broad)
- PS.1.1: Protect stored code with least privilege
- Branch and merge only on green (broad)
- Commit identity (broad)
- Protected-branch integrity (tight)
- Workers produce inert data (tight)
- PS.2.1: Provide software integrity verification information
- PS.3.2: Maintain provenance data (SBOM) per release
- PW.1.1: Use risk modeling to assess software risk
- PW.1.2: Track security requirements and design decisions
- Records first (tight)
- PW.1.3: Use standardized security features and services
- Strong authentication (broad)
- PW.2.1: Review software design against security requirements
- High-assurance verification (broad)
- PW.4.1: Acquire well-secured third-party components
- PW.4.4: Verify third-party components meet requirements
- PW.5.1: Follow secure coding practices
- Match the surrounding code (broad)
- Keep secrets out (broad)
- Strong authentication (broad)
- Least-privilege authorization (broad)
- Sound cryptography (broad)
- Validate external input at the boundary (broad)
- Key management (broad)
- Redact sensitive content from logs (broad)
- Encode output for its sink (broad)
- Generated output is untrusted input (broad)
- Security logging with traceable context (broad)
- Secure session and token handling (broad)
- PW.7.1: Decide on code review and analysis
- Branch and merge only on green (broad)
- Cut branches from the live protected line and re-home after a rewrite (broad)
- Protected-branch integrity (broad)
- Validation is a gate on apply (broad)
- Verifier diversity (broad)
- Generated output is untrusted input (broad)
- PW.7.2: Perform code review and analysis
- Workers produce inert data (broad)
- A verification finding is fixed, not argued away (broad)
- High-assurance verification (broad)
- PW.8.1: Decide on executable code testing
- Validation is a gate on apply (broad)
- Generated output is untrusted input (broad)
- PW.8.2: Perform and document code testing
- PW.9.1: Define a secure default configuration baseline
- Secure by default configuration (tight)
- PW.9.2: Implement and document secure default settings
- Secure by default configuration (tight)
- RV.1.2: Test code to confirm new vulnerabilities
OWASP API Security Top 10 (2023)
addresses risk. 8 identifiers referenced from a curated subset of the edition.
- API1: Broken Object Level Authorization
- Least-privilege authorization (tight)
- API2: Broken Authentication
- Strong authentication (tight)
- API3: Broken Object Property Level Authorization
- Least-privilege authorization (tight)
- API4: Unrestricted Resource Consumption
- API5: Broken Function Level Authorization
- Least-privilege authorization (tight)
- API7: Server Side Request Forgery
- API8: Security Misconfiguration
- Secure by default configuration (tight)
- API9: Improper Inventory Management
OWASP Top 10 for Agentic Applications (2026)
addresses risk. 9 identifiers referenced from a curated subset of the edition.
- ASI02: Tool Misuse and Exploitation
- ASI03: Identity and Privilege Abuse
- ASI04: Agentic Supply Chain Vulnerabilities
- ASI05: Unexpected Code Execution (RCE)
- ASI06: Memory & Context Poisoning
- ASI07: Insecure Inter-Agent Communication
- ASI08: Cascading Failures
- ASI09: Human-Agent Trust Exploitation
- Social pressure is not authorization (tight)
- A preview makes no change (tight)
- ASI10: Rogue Agents
OWASP Application Security Verification Standard (5.0.0)
supports control. 13 identifiers referenced from a curated subset of the edition.
- V1: Encoding and Sanitization
- Encode output for its sink (tight)
- Generated output is untrusted input (tight)
- V2: Validation and Business Logic
- V5: File Handling
- V6: Authentication
- Strong authentication (tight)
- V7: Session Management
- V8: Authorization
- Least-privilege authorization (tight)
- V9: Self-contained Tokens
- V10: OAuth and OIDC
- V11: Cryptography
- Sound cryptography (tight)
- Key management (broad)
- V12: Secure Communication
- Sound cryptography (broad)
- V13: Configuration
- Secure by default configuration (tight)
- V14: Data Protection
- V16: Security Logging and Error Handling
OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04))
aligns with guidance. 27 identifiers referenced from a curated subset of the edition.
- ai-agent-security: AI Agent Security Cheat Sheet
- authentication: Authentication Cheat Sheet
- Strong authentication (tight)
- authorization: Authorization Cheat Sheet
- Least-privilege authorization (tight)
- cross-site-request-forgery-prevention: Cross-Site Request Forgery Prevention Cheat Sheet
- cross-site-scripting-prevention: Cross Site Scripting Prevention Cheat Sheet
- Encode output for its sink (tight)
- Generated output is untrusted input (tight)
- cryptographic-storage: Cryptographic Storage Cheat Sheet
- Sound cryptography (tight)
- denial-of-service: Denial of Service Cheat Sheet
- deserialization: Deserialization Cheat Sheet
- error-handling: Error Handling Cheat Sheet
- file-upload: File Upload Cheat Sheet
- injection-prevention: Injection Prevention Cheat Sheet
- input-validation: Input Validation Cheat Sheet
- json-web-token: JSON Web Token Cheat Sheet
- key-management: Key Management Cheat Sheet
- Key management (tight)
- llm-prompt-injection-prevention: LLM Prompt Injection Prevention Cheat Sheet
- logging: Logging Cheat Sheet
- mass-assignment: Mass Assignment Cheat Sheet
- Least-privilege authorization (broad)
- mcp-security: MCP Security Cheat Sheet
- multifactor-authentication: Multifactor Authentication Cheat Sheet
- Strong authentication (tight)
- oauth2: OAuth2 Cheat Sheet
- secrets-management: Secrets Management Cheat Sheet
- Keep secrets out (tight)
- Rotate a leaked secret (tight)
- server-side-request-forgery-prevention: Server Side Request Forgery Prevention Cheat Sheet
- session-management: Session Management Cheat Sheet
- software-supply-chain-security: Software Supply Chain Security Cheat Sheet
- threat-modeling: Threat Modeling Cheat Sheet
- transport-layer-security: Transport Layer Security Cheat Sheet
- Sound cryptography (tight)
- vulnerable-dependency-management: Vulnerable Dependency Management Cheat Sheet
OWASP Top 10 for LLM Applications (2026)
addresses risk. 10 of 10 identifiers referenced.
- LLM01: Prompt Injection
- LLM02: Sensitive Information Disclosure
- LLM03: Excessive Agency
- LLM04: Supply Chain
- LLM05: Data and Model Poisoning
- LLM06: Unbounded Consumption
- LLM07: Misinformation
- Corroborate external claims (tight)
- No fabrication (tight)
- LLM08: Hidden Context Exposure
- LLM09: Vector and Embedding Weaknesses
- LLM10: Improper Output Handling
OWASP MCP Top 10 (2025)
addresses risk. 10 of 10 identifiers referenced.
- MCP01: Token Mismanagement & Secret Exposure
- Keep secrets out (tight)
- Rotate a leaked secret (tight)
- MCP02: Privilege Escalation via Scope Creep
- MCP03: Tool Poisoning
- MCP04: Software Supply Chain Attacks & Dependency Tampering
- MCP05: Command Injection & Execution
- MCP06: Intent Flow Subversion
- MCP07: Insufficient Authentication & Authorization
- MCP08: Lack of Audit and Telemetry
- MCP09: Shadow MCP Servers
- MCP10: Context Injection & Over-Sharing
- No cross-context bleed (tight)
- Untrusted content is data, not instructions (tight)
OWASP Top 10 Proactive Controls (4.0.0)
supports control. 9 identifiers referenced from a curated subset of the edition.
- C1: Implement Access Control
- Least-privilege authorization (tight)
- C2: Use Cryptography to Protect Data
- Sound cryptography (tight)
- C3: Validate all Input & Handle Exceptions
- C4: Address Security from the Start
- C5: Secure By Default Configurations
- Secure by default configuration (tight)
- C6: Keep your Components Secure
- C7: Secure Digital Identities
- C9: Implement Security Logging and Monitoring
- C10: Stop Server Side Request Forgery
OWASP Top 10 (Web Application Security Risks) (2025)
addresses risk. 10 of 10 identifiers referenced.
- A01: Broken Access Control
- Least-privilege authorization (tight)
- A02: Security Misconfiguration
- Secure by default configuration (tight)
- A03: Software Supply Chain Failures
- A04: Cryptographic Failures
- Sound cryptography (tight)
- A05: Injection
- Validate external input at the boundary (tight)
- Encode output for its sink (broad)
- Generated output is untrusted input (broad)
- Validate tool arguments before use (broad)
- A06: Insecure Design
- A07: Authentication Failures
- Strong authentication (tight)
- A08: Software or Data Integrity Failures
- A09: Security Logging & Alerting Failures
- A10: Mishandling of Exceptional Conditions
Sources, exports, and attribution
Take the data, and where it comes from
The full crosswalk is available as data for governance tooling:
- mappings.csv: flat, one row per rule-and-identifier pair, the join key most GRC tools expect.
- mappings.json: the framework registry once, plus a flat array of every mapping.
Attribution and licensing for every framework referenced here are recorded in the project NOTICE. Framework identifiers and titles remain the property of their respective publishers where applicable (some, such as NIST material, are US-government public-domain works). No framework publisher endorses, sponsors, or is affiliated with this pack, and no publisher's name or marks are used to imply endorsement.