ASAI Security ResearchIndependent public-source research
Public reviewread only

Vendor-focused standards view

NIST Cybersecurity Framework 2.0 for Harness AI Security / Traceable

See how Harness AI Security / Traceable's public claims connect to security requirements and NIST Cybersecurity Framework 2.0 references.

What this page shows

Requirements connected to Harness AI Security / Traceable's public claims

Only requirements with strong or limited public support appear. The framework references identify what to investigate; they do not establish implementation, conformance, certification, or product effectiveness.

Versionv2.0 (NIST CSWP 29, February 2024)Current source
Related requirements9security questions in this research
Security requirements with public support5strong or limited public support
References29identifiers, clauses, safeguards, or categories

How to use this map

Framework connections help structure your evaluation

Each connection shows how a security requirement relates to this framework. Public vendor claims are shown separately, and deployed effectiveness still requires confirmation or testing.

Closely aligned
4
Contributes
4
Related context
1

Requirement connections

From Harness AI Security / Traceable's public claims to questions to verify

Each row starts with a security requirement that has public support, then shows the connected framework references and the next question to verify.

Closely alignedSpecific reference

AI usage inventory

Maintain an inventory of AI tools, services, models, agents, software as a service (SaaS) AI capabilities, data flows, and provider relationships.

Framework references

ID.AM-02 · ID.AM-04 · ID.AM-07

Lifecycle

Govern · Identify · Monitor

Security requirements with public support

1 requirement with public support

Limited public supportApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims →
How this could be implemented

AI asset inventory · vendor/provider inventory · AI app discovery · model/application programming interface (API)/provider catalog

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Use this for inventory/discovery claims. Do not infer control or blocking from visibility-only language. ISO 42001 excerpt: A.4.2 "identify and document relevant resources"; A.4.3 "data resources utilized"; A.4.4 "tooling resources utilized".

Closely alignedSpecific reference

AI usage monitoring

Monitor AI usage, user activity, prompts, responses, provider calls, runtime actions, and anomalous behavior.

Framework references

DE.CM-01 · DE.CM-03 · DE.CM-06 · DE.CM-09

Lifecycle

Monitor · Detect · Operate

Security requirements with public support

1 requirement with public support

Limited public supportApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims →
How this could be implemented

prompt logs · user activity · provider telemetry · agent step tracing · tool call logging

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Monitoring claims should identify what is monitored and where the telemetry comes from. ISO 42001 excerpt: 9.1 "what needs to be monitored"; A.6.2.6 "system and performance monitoring"; A.6.2.8 "event logs should be enabled".

ContributesFramework category

unapproved AI control

Enforce policy against unapproved AI tools or unsafe AI interactions through blocking, coaching, allowlists, or runtime controls.

Framework references

PR.AA-05 · DE.CM-09 · RS.MA

Lifecycle

Protect · Deploy · Operate

Security requirements with public support

1 requirement with public support

Strong public supportGenerative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Public claims reviewed
1
Next question to verify
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims →
How this could be implemented

blocking · allowlists · browser enforcement · policy coaching · large language model (LLM) firewall · tool allowlists

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Distinguish hard blocking from warning, coaching, logging, or after-the-fact reporting. ISO 42001 excerpt: A.9.2 "processes for the responsible use"; A.9.3 "objectives to guide"; A.9.4 "intended uses".

Closely alignedSpecific reference

AI data protection

Prevent sensitive data exposure through prompts, responses, files, retrieval, memory, embeddings, or AI-connected workflows.

Framework references

PR.DS-01 · PR.DS-02 · PR.DS-10

Lifecycle

Protect · Operate · Monitor

Security requirements with public support

3 requirements with public support

Strong public supportSensitive-data protection for generative AI

Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.

Public claims reviewed
1
Next question to verify
Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
Review source claims →
Strong public supportGenerative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Public claims reviewed
1
Next question to verify
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims →
Limited public supportApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims →
How this could be implemented

data loss prevention (DLP) · redaction · sensitive data detection · output filtering · memory scoping · data-in-use protection

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Require source language that ties data protection to AI use, not generic encryption alone. ISO 42001 excerpt: A.7.3 "acquisition and selection"; A.7.4 "requirements for data quality"; A.7.5 "recording the provenance"; A.7.6 "data preparation methods".

ContributesSpecific reference

generative AI application security

Secure large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, tool calls, application programming interfaces (APIs), model interactions, and runtime behavior.

Framework references

PR.DS-10 · DE.CM-09 · RS.MA-02 · RS.MA-03

Lifecycle

Develop · Test · Release · Deploy · Operate

Security requirements with public support

3 requirements with public support

Strong public supportGenerative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Public claims reviewed
1
Next question to verify
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims →
Strong public supportSensitive-data protection for generative AI

Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.

Public claims reviewed
1
Next question to verify
Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
Review source claims →
Limited public supportAI gateway, tool-connection, and runtime controls

Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.

Public claims reviewed
1
Next question to verify
A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
Review source claims →
How this could be implemented

prompt injection defense · large language model (LLM) app scanning · retrieval-augmented generation (RAG) security · guardrails · model/application interaction security

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Use for large language model (LLM) application controls. Separate from employee AI usage governance when possible. ISO 42001 excerpt: A.6.2.4 "verification and validation measures"; A.6.2.5 "deployment plan"; A.6.2.6 "ongoing operation"; A.6.2.8 "event logs".

ContributesFramework category

AI governance, risk, and compliance operations

Maintain accountable AI inventory, policy, risk assessments, approvals, exceptions, regulatory mappings, third-party oversight, and audit evidence across the AI lifecycle.

Framework references

GV.RM · ID.AM-07

Lifecycle

Govern · Identify · Assess · Approve · Monitor

Security requirements with public support

1 requirement with public support

Limited public supportApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims →
How this could be implemented

AI system registry · risk tiering · policy workflow · regulatory mapping · approval and exception workflow · audit evidence

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Governance evidence must show accountable workflow or decision evidence, not technical inventory alone. ISO 42001 excerpt: A.9.2 "processes for the responsible use"; A.9.3 "objectives to guide"; A.10.2 "allocated between".

ContributesSpecific reference

AI assurance, red teaming, and supply-chain security

Test models, applications, retrieval-augmented generation (RAG) systems, agents, coding workflows, and AI artifacts before release and continuously thereafter, with reproducible findings and remediation gates.

Framework references

PR.DS-10 · DE.CM-09 · RS.MA-02

Lifecycle

Develop · Test · Release · Monitor

Security requirements with public support

1 requirement with public support

Strong public supportAI assurance and adversarial testing

Test models, applications, retrieval-augmented generation (RAG) systems, and agents before release and continuously thereafter using adversarial probes, evaluation suites, attack simulation, and security release gates.

Public claims reviewed
1
Next question to verify
A controlled test campaign exercises an AI model, application, or agent against named AI attack classes.
Review source claims →
How this could be implemented

AI red teaming · attack simulation · continuous evaluation · model scanning · AI bill of materials (AI-BOM) · coding-agent policy · release gate

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Keep pre-deployment testing, artifact integrity, and coding-agent controls distinguishable from runtime blocking. ISO 42001 excerpt: A.6.2.4 "verification and validation measures"; A.6.2.5 "deployment plan"; A.6.2.6 "ongoing operation".

Closely alignedSpecific reference

Agent-to-agent and tool communication security

Secure trust, authorization, message flows, tool access, and communication between agents, tools, application programming interfaces (APIs), and external services.

Framework references

ID.AM-03 · PR.AA-02 · PR.AA-04 · DE.CM-01

Lifecycle

Identify · Protect · Deploy · Monitor

Security requirements with public support

2 requirements with public support

Strong public supportGenerative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Public claims reviewed
1
Next question to verify
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
Review source claims →
Limited public supportAI gateway, tool-connection, and runtime controls

Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.

Public claims reviewed
1
Next question to verify
A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
Review source claims →
How this could be implemented

agent-to-agent (A2A) registry · mutual TLS (mTLS) · inter-agent authorization · connector contracts · tool schemas · message logs

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Do not map agent-to-agent (A2A) unless a source mentions agents, tools, connectors, protocols, or machine-to-machine authorization. ISO 42001 has no direct agent-to-agent (A2A) security control. ISO 42001 excerpt: A.6.2.4 "verification and validation measures"; A.6.2.8 "event logs"; A.10.2 "allocated between".

Related contextFramework category

AI FinOps and cost accountability

Attribute AI usage and spend to accountable owners, workflows, agents, models, and business units while enforcing budget, rate-limit, and routing controls.

Framework references

GV.RM · ID.AM-07 · DE.CM-09

Lifecycle

Govern · Operate · Optimize

Security requirements with public support

1 requirement with public support

Limited public supportApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Public claims reviewed
1
Next question to verify
Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Review source claims →
How this could be implemented

AI spend attribution · runaway token burn detection · budget enforcement · rate limits · model routing · owner-based cost reporting

What public claims cannot prove

Public claims identify what to verify. They do not confirm control implementation or deployed effectiveness.

Why this connection is included

Keep this separate from licensing. Require source language about operational usage, spend, budgets, rate limits, model routing, or owner attribution. ISO 42001 excerpt: A.9.2 "responsible use of AI systems"; A.9.3 "objectives to guide".

This page organizes research. Audit conclusions, certification assessments, control implementation statements, and vendor endorsements require separate evidence.