Start with an enterprise AI security requirement, then see which standards, safeguards, control objectives, and threat references can help you evaluate it.
Vendor-focused view
Requirements connected to Elvex's public claims
0 security requirements with strong or limited public support determine which rows appear. This does not mean the vendor implements or conforms to a framework.
Security requirements0connected to this vendor's public claims
Standards and reference types6standards, controls, and threats
Documented connections0each connection explains its strength
Individual references0identifiers, clauses, controls, or risks
How to read this map
Each row starts with one security requirement
References share a row because they help address the same requirement. They are not interchangeable. Each label explains how closely a reference aligns with that requirement.
Closely aligned ?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.Contributes ?ContributesThe framework reference helps address the requirement but is not equivalent to it.Related context ?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.
Standards and framework connections
Read across each requirement
Important references remain visible without hover. Open a framework research view for market-wide context, or start from a vendor page to see only references connected to that vendor's public claims.
CIS Controls v8.1
Cyber-hygiene baseline with AI-specific companion guidance
The research team selected the CIS safeguard connections shown here; they are guidance, not official CIS mappings. The official 2026 companion guides explain how CIS Controls apply to three AI environments.
Use each source for the job it is designed to do. Vendor implementation and product effectiveness still require separate evidence.
Current source
NIST AI RMF Playbook
AI RMF 1.0 Playbook
AI risk management reference for governance, mapping, measurement, and lifecycle management. Useful for structuring diligence questions, but not a standalone selection model, certification proxy, or substitute for enterprise-specific risk, architecture, and operating requirements.
Connected requirements
13
Individual references
39
Current source
NIST Cybersecurity Framework 2.0
v2.0 (NIST CSWP 29, February 2024)
Cybersecurity outcome lens (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER). NIST IR 8596 Cyber AI Profile deferred until it exits draft; subcategory IDs in this project map to CSF 2.0 directly and remain stable when the AI Profile lands.
Connected requirements
12
Individual references
39
Current source
CIS Critical Security Controls
v8.1 with 2026 AI Companion Guides
Prioritized cyber-hygiene safeguards with AI-specific interpretation for large language model (LLM), agent, and Model Context Protocol (MCP) environments. This project maps normalized AI security requirements to relevant CIS safeguards as a research interpretation; it does not present an official CIS mapping, implementation assessment, or certification result.
Connected requirements
11
Individual references
58
Current source
ISO/IEC 42001
ISO/IEC 42001:2023
AI management system lens for procurement diligence prompts and auditor discussion. Mappings are indicative clause/control alignments only; they are not a certification proxy, vendor assurance substitute, or evidence that a product satisfies ISO/IEC 42001.
Connected requirements
12
Individual references
35
Informational source
OWASP GenAI Security Solutions Landscape
Q2/Q3 2026
Market and lifecycle lens for large language model (LLM) and generative AI AppSec/SecOps capabilities.
Connected requirements
11
Individual references
27
Informational source
OWASP Agentic AI Security Solutions Landscape
Q2/Q3 2026
Market and lifecycle lens for agentic AI, agent-to-agent (A2A), tool, memory, non-human identity (NHI), and runtime controls.
Connected requirements
12
Individual references
31
Current source
MITRE ATLAS
2026.06
Adversary-behavior lens for AI systems. Technique and mitigation references describe threat paths and defensive hypotheses; they do not establish that a vendor prevents, detects, or responds to the behavior.
Connected requirements
12
Individual references
71
Current source
OWASP Top 10 for LLM Applications
2025 (v2.0)
Application failure-mode lens for large language model (LLM) systems. Mappings identify risks a requirement should address and are not proof of product efficacy or OWASP endorsement.
Vendor-neutral control-objective lens. This project uses the official AI Customer implementation publication with 247 controls across 18 domains; a mapped control is a diligence and test target, not evidence of implementation.
Connected requirements
14
Individual references
71
Current source
Open FAIR
O-RA 2.0.1 / O-RT 3.0.1
Business-loss scenario and quantitative risk-analysis structure. Scenario templates are modeled, but event frequency, vulnerability, and loss magnitude remain explicit enterprise inputs.
Connected requirements
0
Individual references
0
Commercial reference
Commercial Metadata
Point-in-time public research
Licensing and packaging context. Not a security framework.
Connected requirements
3
Individual references
3
This map organizes research. Certification, audit conclusions, framework conformance, vendor control implementation, and product effectiveness require separate evidence.