Prioritized cyber-hygiene safeguards with AI-specific interpretation for large language model (LLM), agent, and Model Context Protocol (MCP) environments. This project maps normalized AI security requirements to relevant CIS safeguards as a research interpretation; it does not present an official CIS mapping, implementation assessment, or certification result.
Scope
All-market research view
This page includes every security requirement connected to CIS Critical Security Controls. Vendor counts, alphabetical examples, and public-support findings come from the current 66-vendor research set; this is not a vendor-specific assessment.
Versionv8.1 with 2026 AI Companion GuidesCurrent source
Connected requirements11security questions in this research
Security requirements17used consistently across vendors
References58identifiers, clauses, safeguards, or categories
How to use this map
Framework connections help structure your evaluation
Each connection shows how a security requirement relates to this framework. Public vendor claims are shown separately, and deployed effectiveness still requires confirmation or testing.
Contributes
9
Related context
1
Closely aligned
1
Official companion guidance
Use the guide for the AI technology being assessed
These guides interpret CIS Controls v8.1 for large language model (LLM), AI agent, and Model Context Protocol (MCP) environments. They are not vendor scorecards.
Maintain an inventory of AI tools, services, models, agents, software as a service (SaaS) AI capabilities, data flows, and provider relationships.
Framework references
2.1Establish and Maintain a Software InventoryIG1+
3.8Document Data FlowsIG2+
15.1Establish and Maintain an Inventory of Service ProvidersIG1+
Lifecycle
Govern · Identify · Monitor
Vendors with public support
66 of 66 vendors reviewed
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS inventories software, data flows, and service providers; the AI-specific asset model comes from the linked large language model (LLM), Agent, and Model Context Protocol (MCP) companion guides.
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Monitor AI usage, user activity, prompts, responses, provider calls, runtime actions, and anomalous behavior.
Framework references
8.2Collect Audit LogsIG1+
8.5Collect Detailed Audit LogsIG2+
8.9Centralize Audit LogsIG2+
8.11Conduct Audit Log ReviewsIG2+
Lifecycle
Monitor · Detect · Operate
Vendors with public support
66 of 66 vendors reviewed
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. These safeguards establish audit-log collection, detail, centralization, and review; AI telemetry scope must still be confirmed.
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Enforce policy against unapproved AI tools or unsafe AI interactions through blocking, coaching, allowlists, or runtime controls.
Framework references
2.5Allowlist Authorized SoftwareIG2+
2.7Allowlist Authorized ScriptsIG3+
9.3Maintain and Enforce Network-Based URL FiltersIG2+
Lifecycle
Protect · Deploy · Operate
Vendors with public support
64 of 66 vendors reviewed
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. Allowlisting and URL filtering support enforcement, but do not by themselves establish prompt-, model-, agent-, or tool-aware policy controls.
Foundational security requirementControls for unapproved AI use
Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
Strong public support
37
Limited public support
14
No supporting claim found
15
Research incomplete
0
Additional security requirementBrowser and business-application controls
Apply session-level controls in browser and software as a service (SaaS) workflows, including uploads, downloads, copy/paste, sharing, and identity-aware access decisions.
Strong public support
19
Limited public support
10
No supporting claim found
37
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Prevent sensitive data exposure through prompts, responses, files, retrieval, memory, embeddings, or AI-connected workflows.
Framework references
3.2Establish and Maintain a Data InventoryIG1+
3.3Configure Data Access Control ListsIG1+
3.8Document Data FlowsIG2+
3.10Encrypt Sensitive Data in TransitIG2+
3.11Encrypt Sensitive Data at RestIG2+
3.13Deploy a Data Loss Prevention SolutionIG3+
3.14Log Sensitive Data AccessIG3+
Lifecycle
Protect · Operate · Monitor
Vendors with public support
65 of 66 vendors reviewed
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS data safeguards provide the operational baseline; AI prompt, response, retrieval, memory, and embedding coverage still requires product-specific evidence.
Foundational security requirementSensitive-data protection for generative AI
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Strong public support
43
Limited public support
15
No supporting claim found
8
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Secure large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, tool calls, application programming interfaces (APIs), model interactions, and runtime behavior.
Framework references
16.1Establish and Maintain a Secure Application Development ProcessIG2+
16.2Establish and Maintain a Process to Accept and Address Software VulnerabilitiesIG2+
16.6Establish and Maintain a Severity Rating System and Process for Application VulnerabilitiesIG2+
16.10Apply Secure Design Principles in Application ArchitecturesIG2+
16.12Implement Code-Level Security ChecksIG3+
16.13Conduct Application Penetration TestingIG3+
Lifecycle
Develop · Test · Release · Deploy · Operate
Vendors with public support
65 of 66 vendors reviewed
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS secure-development safeguards structure application assurance; AI-specific attack classes and runtime controls remain separate test requirements.
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementSensitive-data protection for generative AI
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Strong public support
43
Limited public support
15
No supporting claim found
8
Research incomplete
0
Foundational security requirementControls for unapproved AI use
Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
Strong public support
37
Limited public support
14
No supporting claim found
15
Research incomplete
0
Foundational security requirementAI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Strong public support
42
Limited public support
19
No supporting claim found
5
Research incomplete
0
Related contextSpecific reference · research-team interpretation
AI governance, risk, and compliance operations
Maintain accountable AI inventory, policy, risk assessments, approvals, exceptions, regulatory mappings, third-party oversight, and audit evidence across the AI lifecycle.
Framework references
2.1Establish and Maintain a Software InventoryIG1+
14.1Establish and Maintain a Security Awareness ProgramIG1+
15.2Establish and Maintain a Service Provider Management PolicyIG2+
17.1Designate Personnel to Manage Incident HandlingIG1+
Lifecycle
Govern · Identify · Assess · Approve · Monitor
Vendors with public support
66 of 66 vendors reviewed
Companion-guide relevanceLLMAgentMCP
Project-curated operational baseline only. CIS supports inventory, awareness, provider policy, and incident ownership, but it does not replace an AI management system or regulatory assessment workflow.
Foundational security requirementAI governance, risk, and compliance
Inventory AI systems and owners, translate policy and regulatory obligations into governed workflows, assess risk, manage approvals and exceptions, and retain audit evidence across the AI lifecycle.
Strong public support
36
Limited public support
20
No supporting claim found
10
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
AI assurance, red teaming, and supply-chain security
Test models, applications, retrieval-augmented generation (RAG) systems, agents, coding workflows, and AI artifacts before release and continuously thereafter, with reproducible findings and remediation gates.
Framework references
16.1Establish and Maintain a Secure Application Development ProcessIG2+
16.2Establish and Maintain a Process to Accept and Address Software VulnerabilitiesIG2+
16.4Establish and Manage an Inventory of Third-Party Software ComponentsIG2+
16.6Establish and Maintain a Severity Rating System and Process for Application VulnerabilitiesIG2+
16.10Apply Secure Design Principles in Application ArchitecturesIG2+
16.12Implement Code-Level Security ChecksIG3+
16.13Conduct Application Penetration TestingIG3+
Lifecycle
Develop · Test · Release · Monitor
Vendors with public support
57 of 66 vendors reviewed
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. Secure development, component inventory, code checks, and penetration testing support assurance; AI red-team methods and model artifacts require additional evidence.
Foundational security requirementAI assurance and adversarial testing
Test models, applications, retrieval-augmented generation (RAG) systems, and agents before release and continuously thereafter using adversarial probes, evaluation suites, attack simulation, and security release gates.
Strong public support
24
Limited public support
3
No supporting claim found
39
Research incomplete
0
Foundational security requirementAI model and supply-chain security
Discover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.
Strong public support
13
Limited public support
28
No supporting claim found
25
Research incomplete
0
Additional security requirementAI coding-agent and workstation security
Discover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.
Third-party and software as a service (SaaS) AI risk
Understand and monitor AI risk introduced by external software as a service (SaaS), AI providers, embedded AI features, and supplier services.
Framework references
15.1Establish and Maintain an Inventory of Service ProvidersIG1+
15.2Establish and Maintain a Service Provider Management PolicyIG2+
15.3Classify Service ProvidersIG2+
15.4Ensure Service Provider Contracts Include Security RequirementsIG2+
15.5Assess Service ProvidersIG3+
15.6Monitor Service ProvidersIG3+
15.7Securely Decommission Service ProvidersIG3+
Lifecycle
Govern · Identify · Detect
Vendors with public support
51 of 66 vendors reviewed
Companion-guide relevanceLLMAgentMCP
Project-curated alignment to the full CIS service-provider lifecycle. AI-specific provider scope and evidence expectations come from this project's normalized requirement and the companion guides.
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Platform contextApproved AI platform context
Where a vendor's public claims appear to complement, overlap with, or sit outside native controls in approved enterprise AI deployments.
Observe agent steps, plans, goals, memory, delegation, tool use, and anomalies during runtime.
Framework references
8.2Collect Audit LogsIG1+
8.5Collect Detailed Audit LogsIG2+
8.9Centralize Audit LogsIG2+
8.11Conduct Audit Log ReviewsIG2+
Lifecycle
Operate · Monitor · Detect
Vendors with public support
63 of 66 vendors reviewed
Companion-guide relevanceAgentMCP
Project-curated baseline alignment. Audit-log safeguards support telemetry operations; the Agent and Model Context Protocol (MCP) guides supply the relevant AI runtime interpretation.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Foundational security requirementNon-human identity and service-account security
Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Secure trust, authorization, message flows, tool access, and communication between agents, tools, application programming interfaces (APIs), and external services.
Framework references
5.1Establish and Maintain an Inventory of AccountsIG1+
6.1Establish an Access Granting ProcessIG1+
6.2Establish an Access Revoking ProcessIG1+
6.5Require MFA for Administrative AccessIG1+
6.8Define and Maintain Role-Based Access ControlIG3+
8.2Collect Audit LogsIG1+
Lifecycle
Identify · Protect · Deploy · Monitor
Vendors with public support
66 of 66 vendors reviewed
Companion-guide relevanceAgentMCP
Project-curated baseline alignment. Account, access, administrative MFA, role, and log safeguards support agent-to-tool trust; protocol-specific authorization still requires Model Context Protocol (MCP) and product evidence.
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementAI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
non-human identity (NHI) and AI-agent identity governance
Manage identities, credentials, privileges, secrets, service accounts, and lifecycle for AI agents and other non-human identities.
Framework references
5.1Establish and Maintain an Inventory of AccountsIG1+
5.4Restrict Administrator Privileges to Dedicated Administrator AccountsIG1+
6.1Establish an Access Granting ProcessIG1+
6.2Establish an Access Revoking ProcessIG1+
6.3Require MFA for Externally-Exposed ApplicationsIG1+
6.5Require MFA for Administrative AccessIG1+
6.8Define and Maintain Role-Based Access ControlIG3+
Lifecycle
Govern · Protect · Deploy · Operate
Vendors with public support
60 of 66 vendors reviewed
Companion-guide relevanceAgentMCP
Project-curated baseline alignment. CIS account and access safeguards apply to non-human identities when implemented that way; the Agent and Model Context Protocol (MCP) guides provide the explicit AI context.
Foundational security requirementNon-human identity and service-account security
Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
Foundational security requirementAI agent identity and permissions
Register AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.
Strong public support
15
Limited public support
39
No supporting claim found
12
Research incomplete
0
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
This page organizes research. Audit conclusions, certification assessments, control implementation statements, and vendor endorsements require separate evidence.