ContributesSpecific reference · research-team interpretation
AI usage inventory
Maintain an inventory of AI tools, services, models, agents, software as a service (SaaS) AI capabilities, data flows, and provider relationships.
Framework references2.1Establish and Maintain a Software InventoryIG1+3.8Document Data FlowsIG2+15.1Establish and Maintain an Inventory of Service ProvidersIG1+
LifecycleGovern · Identify · Monitor
Security requirements with public support2 requirements with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS inventories software, data flows, and service providers; the AI-specific asset model comes from the linked large language model (LLM), Agent, and Model Context Protocol (MCP) companion guides.
Strong public supportUnapproved AI use discoveryDiscover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
- Public claims reviewed
- 1
- Next question to verify
- An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.
Review source claims →Strong public supportApproved AI usage monitoringMonitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
- Public claims reviewed
- 1
- Next question to verify
- Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims → ContributesSpecific reference · research-team interpretation
AI usage monitoring
Monitor AI usage, user activity, prompts, responses, provider calls, runtime actions, and anomalous behavior.
Framework references8.2Collect Audit LogsIG1+8.5Collect Detailed Audit LogsIG2+8.9Centralize Audit LogsIG2+8.11Conduct Audit Log ReviewsIG2+
LifecycleMonitor · Detect · Operate
Security requirements with public support3 requirements with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. These safeguards establish audit-log collection, detail, centralization, and review; AI telemetry scope must still be confirmed.
Strong public supportUnapproved AI use discoveryDiscover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
- Public claims reviewed
- 1
- Next question to verify
- An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.
Review source claims →Strong public supportApproved AI usage monitoringMonitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
- Public claims reviewed
- 1
- Next question to verify
- Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims →Limited public supportAction-taking agent monitoringObserve and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
- Public claims reviewed
- 1
- Next question to verify
- A test agent run captures plan, steps, tool calls, outcome, and timestamps.
Review source claims → ContributesSpecific reference · research-team interpretation
unapproved AI control
Enforce policy against unapproved AI tools or unsafe AI interactions through blocking, coaching, allowlists, or runtime controls.
Framework references2.5Allowlist Authorized SoftwareIG2+2.7Allowlist Authorized ScriptsIG3+9.3Maintain and Enforce Network-Based URL FiltersIG2+
LifecycleProtect · Deploy · Operate
Security requirements with public support2 requirements with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. Allowlisting and URL filtering support enforcement, but do not by themselves establish prompt-, model-, agent-, or tool-aware policy controls.
Strong public supportControls for unapproved AI useBlock, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
- Public claims reviewed
- 1
- Next question to verify
- A policy blocks, coaches, redirects, or contains a test interaction with an unapproved AI destination.
Review source claims →Strong public supportGenerative AI application securityProtect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
- Public claims reviewed
- 1
- Next question to verify
- A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims → ContributesSpecific reference · research-team interpretation
AI data protection
Prevent sensitive data exposure through prompts, responses, files, retrieval, memory, embeddings, or AI-connected workflows.
Framework references3.2Establish and Maintain a Data InventoryIG1+3.3Configure Data Access Control ListsIG1+3.8Document Data FlowsIG2+3.10Encrypt Sensitive Data in TransitIG2+3.11Encrypt Sensitive Data at RestIG2+3.13Deploy a Data Loss Prevention SolutionIG3+3.14Log Sensitive Data AccessIG3+
LifecycleProtect · Operate · Monitor
Security requirements with public support3 requirements with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS data safeguards provide the operational baseline; AI prompt, response, retrieval, memory, and embedding coverage still requires product-specific evidence.
Strong public supportSensitive-data protection for generative AIDetect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
- Public claims reviewed
- 1
- Next question to verify
- Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
Review source claims →Strong public supportGenerative AI application securityProtect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
- Public claims reviewed
- 1
- Next question to verify
- A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims →Strong public supportApproved AI usage monitoringMonitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
- Public claims reviewed
- 1
- Next question to verify
- Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims → ContributesSpecific reference · research-team interpretation
generative AI application security
Secure large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, tool calls, application programming interfaces (APIs), model interactions, and runtime behavior.
Framework references16.1Establish and Maintain a Secure Application Development ProcessIG2+16.2Establish and Maintain a Process to Accept and Address Software VulnerabilitiesIG2+16.6Establish and Maintain a Severity Rating System and Process for Application VulnerabilitiesIG2+16.10Apply Secure Design Principles in Application ArchitecturesIG2+16.12Implement Code-Level Security ChecksIG3+16.13Conduct Application Penetration TestingIG3+
LifecycleDevelop · Test · Release · Deploy · Operate
Security requirements with public support4 requirements with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. CIS secure-development safeguards structure application assurance; AI-specific attack classes and runtime controls remain separate test requirements.
Strong public supportGenerative AI application securityProtect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
- Public claims reviewed
- 1
- Next question to verify
- A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims →Strong public supportSensitive-data protection for generative AIDetect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
- Public claims reviewed
- 1
- Next question to verify
- Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
Review source claims →Strong public supportControls for unapproved AI useBlock, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
- Public claims reviewed
- 1
- Next question to verify
- A policy blocks, coaches, redirects, or contains a test interaction with an unapproved AI destination.
Review source claims →Strong public supportAI gateway, tool-connection, and runtime controlsMediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
- Public claims reviewed
- 1
- Next question to verify
- A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
Review source claims → Related contextSpecific reference · research-team interpretation
AI governance, risk, and compliance operations
Maintain accountable AI inventory, policy, risk assessments, approvals, exceptions, regulatory mappings, third-party oversight, and audit evidence across the AI lifecycle.
Framework references2.1Establish and Maintain a Software InventoryIG1+14.1Establish and Maintain a Security Awareness ProgramIG1+15.2Establish and Maintain a Service Provider Management PolicyIG2+17.1Designate Personnel to Manage Incident HandlingIG1+
LifecycleGovern · Identify · Assess · Approve · Monitor
Security requirements with public support1 requirement with public support
Companion-guide relevanceLLMAgentMCP
Project-curated operational baseline only. CIS supports inventory, awareness, provider policy, and incident ownership, but it does not replace an AI management system or regulatory assessment workflow.
Strong public supportApproved AI usage monitoringMonitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
- Public claims reviewed
- 1
- Next question to verify
- Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims → ContributesSpecific reference · research-team interpretation
AI assurance, red teaming, and supply-chain security
Test models, applications, retrieval-augmented generation (RAG) systems, agents, coding workflows, and AI artifacts before release and continuously thereafter, with reproducible findings and remediation gates.
Framework references16.1Establish and Maintain a Secure Application Development ProcessIG2+16.2Establish and Maintain a Process to Accept and Address Software VulnerabilitiesIG2+16.4Establish and Manage an Inventory of Third-Party Software ComponentsIG2+16.6Establish and Maintain a Severity Rating System and Process for Application VulnerabilitiesIG2+16.10Apply Secure Design Principles in Application ArchitecturesIG2+16.12Implement Code-Level Security ChecksIG3+16.13Conduct Application Penetration TestingIG3+
LifecycleDevelop · Test · Release · Monitor
Security requirements with public support1 requirement with public support
Companion-guide relevanceLLMAgentMCP
Project-curated baseline alignment. Secure development, component inventory, code checks, and penetration testing support assurance; AI red-team methods and model artifacts require additional evidence.
Limited public supportAI coding-agent and workstation securityDiscover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.
- Public claims reviewed
- 1
- Next question to verify
- A test coding agent and its skills, hooks, extensions, or Model Context Protocol (MCP) tools appear in an attributable inventory.
Review source claims → Closely alignedSpecific reference · research-team interpretation
Third-party and software as a service (SaaS) AI risk
Understand and monitor AI risk introduced by external software as a service (SaaS), AI providers, embedded AI features, and supplier services.
Framework references15.1Establish and Maintain an Inventory of Service ProvidersIG1+15.2Establish and Maintain a Service Provider Management PolicyIG2+15.3Classify Service ProvidersIG2+15.4Ensure Service Provider Contracts Include Security RequirementsIG2+15.5Assess Service ProvidersIG3+15.6Monitor Service ProvidersIG3+15.7Securely Decommission Service ProvidersIG3+
LifecycleGovern · Identify · Detect
Security requirements with public support1 requirement with public support
Companion-guide relevanceLLMAgentMCP
Project-curated alignment to the full CIS service-provider lifecycle. AI-specific provider scope and evidence expectations come from this project's normalized requirement and the companion guides.
Strong public supportUnapproved AI use discoveryDiscover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
- Public claims reviewed
- 1
- Next question to verify
- An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.
Review source claims → ContributesSpecific reference · research-team interpretation
Agentic telemetry and behavior monitoring
Observe agent steps, plans, goals, memory, delegation, tool use, and anomalies during runtime.
Framework references8.2Collect Audit LogsIG1+8.5Collect Detailed Audit LogsIG2+8.9Centralize Audit LogsIG2+8.11Conduct Audit Log ReviewsIG2+
LifecycleOperate · Monitor · Detect
Security requirements with public support2 requirements with public support
Companion-guide relevanceAgentMCP
Project-curated baseline alignment. Audit-log safeguards support telemetry operations; the Agent and Model Context Protocol (MCP) guides supply the relevant AI runtime interpretation.
Limited public supportAction-taking agent monitoringObserve and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
- Public claims reviewed
- 1
- Next question to verify
- A test agent run captures plan, steps, tool calls, outcome, and timestamps.
Review source claims →Limited public supportAgent-to-agent communication securityAuthorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
- Public claims reviewed
- 1
- Next question to verify
- An agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.
Review source claims → ContributesSpecific reference · research-team interpretation
Agent-to-agent and tool communication security
Secure trust, authorization, message flows, tool access, and communication between agents, tools, application programming interfaces (APIs), and external services.
Framework references5.1Establish and Maintain an Inventory of AccountsIG1+6.1Establish an Access Granting ProcessIG1+6.2Establish an Access Revoking ProcessIG1+6.5Require MFA for Administrative AccessIG1+6.8Define and Maintain Role-Based Access ControlIG3+8.2Collect Audit LogsIG1+
LifecycleIdentify · Protect · Deploy · Monitor
Security requirements with public support4 requirements with public support
Companion-guide relevanceAgentMCP
Project-curated baseline alignment. Account, access, administrative MFA, role, and log safeguards support agent-to-tool trust; protocol-specific authorization still requires Model Context Protocol (MCP) and product evidence.
Limited public supportAgent-to-agent communication securityAuthorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
- Public claims reviewed
- 1
- Next question to verify
- An agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.
Review source claims →Limited public supportAction-taking agent monitoringObserve and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
- Public claims reviewed
- 1
- Next question to verify
- A test agent run captures plan, steps, tool calls, outcome, and timestamps.
Review source claims →Strong public supportGenerative AI application securityProtect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
- Public claims reviewed
- 1
- Next question to verify
- A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims →Strong public supportAI gateway, tool-connection, and runtime controlsMediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
- Public claims reviewed
- 1
- Next question to verify
- A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
Review source claims → ContributesSpecific reference · research-team interpretation
non-human identity (NHI) and AI-agent identity governance
Manage identities, credentials, privileges, secrets, service accounts, and lifecycle for AI agents and other non-human identities.
Framework references5.1Establish and Maintain an Inventory of AccountsIG1+5.4Restrict Administrator Privileges to Dedicated Administrator AccountsIG1+6.1Establish an Access Granting ProcessIG1+6.2Establish an Access Revoking ProcessIG1+6.3Require MFA for Externally-Exposed ApplicationsIG1+6.5Require MFA for Administrative AccessIG1+6.8Define and Maintain Role-Based Access ControlIG3+
LifecycleGovern · Protect · Deploy · Operate
Security requirements with public support2 requirements with public support
Companion-guide relevanceAgentMCP
Project-curated baseline alignment. CIS account and access safeguards apply to non-human identities when implemented that way; the Agent and Model Context Protocol (MCP) guides provide the explicit AI context.
Limited public supportAI agent identity and permissionsRegister AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.
- Public claims reviewed
- 1
- Next question to verify
- A test agent is registered with a unique identity, accountable owner, purpose, and permitted resources.
Review source claims →Limited public supportAgent-to-agent communication securityAuthorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
- Public claims reviewed
- 1
- Next question to verify
- An agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.
Review source claims →