CIS Critical Security Controls for Akamai API Security
See how Akamai API Security's public claims connect to security requirements and CIS Critical Security Controls references.
What this page shows
Requirements connected to Akamai API Security's public claims
Only requirements with strong or limited public support appear. The framework references identify what to investigate; they do not establish implementation, conformance, certification, or product effectiveness.
Versionv8.1 with 2026 AI Companion GuidesCurrent source
Related requirements7security questions in this research
Security requirements with public support4strong or limited public support
References33identifiers, clauses, safeguards, or categories
How to use this map
Framework connections help structure your evaluation
Each connection shows how a security requirement relates to this framework. Public vendor claims are shown separately, and deployed effectiveness still requires confirmation or testing.
Contributes
6
Related context
1
Official companion guidance
Use the guide for the AI technology being assessed
These guides interpret CIS Controls v8.1 for large language model (LLM), AI agent, and Model Context Protocol (MCP) environments. They are not vendor scorecards.
Maintain an inventory of AI tools, services, models, agents, software as a service (SaaS) AI capabilities, data flows, and provider relationships.
Framework references
2.1Establish and Maintain a Software InventoryIG1+
3.8Document Data FlowsIG2+
15.1Establish and Maintain an Inventory of Service ProvidersIG1+
Lifecycle
Govern · Identify · Monitor
Security requirements with public support
1 requirement with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS inventories software, data flows, and service providers; the AI-specific asset model comes from the linked large language model (LLM), Agent, and Model Context Protocol (MCP) companion guides.
Limited public supportApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Monitor AI usage, user activity, prompts, responses, provider calls, runtime actions, and anomalous behavior.
Framework references
8.2Collect Audit LogsIG1+
8.5Collect Detailed Audit LogsIG2+
8.9Centralize Audit LogsIG2+
8.11Conduct Audit Log ReviewsIG2+
Lifecycle
Monitor · Detect · Operate
Security requirements with public support
1 requirement with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. These safeguards establish audit-log collection, detail, centralization, and review; AI telemetry scope must still be confirmed.
Limited public supportApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Enforce policy against unapproved AI tools or unsafe AI interactions through blocking, coaching, allowlists, or runtime controls.
Framework references
2.5Allowlist Authorized SoftwareIG2+
2.7Allowlist Authorized ScriptsIG3+
9.3Maintain and Enforce Network-Based URL FiltersIG2+
Lifecycle
Protect · Deploy · Operate
Security requirements with public support
1 requirement with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. Allowlisting and URL filtering support enforcement, but do not by themselves establish prompt-, model-, agent-, or tool-aware policy controls.
Strong public supportGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Public claims reviewed
1
Next question to verify
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Prevent sensitive data exposure through prompts, responses, files, retrieval, memory, embeddings, or AI-connected workflows.
Framework references
3.2Establish and Maintain a Data InventoryIG1+
3.3Configure Data Access Control ListsIG1+
3.8Document Data FlowsIG2+
3.10Encrypt Sensitive Data in TransitIG2+
3.11Encrypt Sensitive Data at RestIG2+
3.13Deploy a Data Loss Prevention SolutionIG3+
3.14Log Sensitive Data AccessIG3+
Lifecycle
Protect · Operate · Monitor
Security requirements with public support
3 requirements with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS data safeguards provide the operational baseline; AI prompt, response, retrieval, memory, and embedding coverage still requires product-specific evidence.
Strong public supportSensitive-data protection for generative AI
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Public claims reviewed
1
Next question to verify
Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Public claims reviewed
1
Next question to verify
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Secure large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, tool calls, application programming interfaces (APIs), model interactions, and runtime behavior.
Framework references
16.1Establish and Maintain a Secure Application Development ProcessIG2+
16.2Establish and Maintain a Process to Accept and Address Software VulnerabilitiesIG2+
16.6Establish and Maintain a Severity Rating System and Process for Application VulnerabilitiesIG2+
16.10Apply Secure Design Principles in Application ArchitecturesIG2+
16.12Implement Code-Level Security ChecksIG3+
16.13Conduct Application Penetration TestingIG3+
Lifecycle
Develop · Test · Release · Deploy · Operate
Security requirements with public support
3 requirements with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS secure-development safeguards structure application assurance; AI-specific attack classes and runtime controls remain separate test requirements.
Strong public supportGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Public claims reviewed
1
Next question to verify
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Public claims reviewed
1
Next question to verify
Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
Review source claims →Limited public supportAI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Public claims reviewed
1
Next question to verify
A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
Related contextSpecific reference · research-team interpretation
AI governance, risk, and compliance operations
Maintain accountable AI inventory, policy, risk assessments, approvals, exceptions, regulatory mappings, third-party oversight, and audit evidence across the AI lifecycle.
Framework references
2.1Establish and Maintain a Software InventoryIG1+
14.1Establish and Maintain a Security Awareness ProgramIG1+
15.2Establish and Maintain a Service Provider Management PolicyIG2+
17.1Designate Personnel to Manage Incident HandlingIG1+
Lifecycle
Govern · Identify · Assess · Approve · Monitor
Security requirements with public support
1 requirement with public support
Companion-guide relevanceLLMAgentMCP
Project-curated operational baseline only. CIS supports inventory, awareness, provider policy, and incident ownership, but it does not replace an AI management system or regulatory assessment workflow.
Limited public supportApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Secure trust, authorization, message flows, tool access, and communication between agents, tools, application programming interfaces (APIs), and external services.
Framework references
5.1Establish and Maintain an Inventory of AccountsIG1+
6.1Establish an Access Granting ProcessIG1+
6.2Establish an Access Revoking ProcessIG1+
6.5Require MFA for Administrative AccessIG1+
6.8Define and Maintain Role-Based Access ControlIG3+
8.2Collect Audit LogsIG1+
Lifecycle
Identify · Protect · Deploy · Monitor
Security requirements with public support
2 requirements with public support
Companion-guide relevanceAgentMCP
Project-curated baseline alignment. Account, access, administrative MFA, role, and log safeguards support agent-to-tool trust; protocol-specific authorization still requires Model Context Protocol (MCP) and product evidence.
Strong public supportGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Public claims reviewed
1
Next question to verify
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims →Limited public supportAI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Public claims reviewed
1
Next question to verify
A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
This page organizes research. Audit conclusions, certification assessments, control implementation statements, and vendor endorsements require separate evidence.