ASAI Security ResearchIndependent public-source research
Public reviewread only

Requirement-centered standards map

Standards and framework map

Start with an enterprise AI security requirement, then see which standards, safeguards, control objectives, and threat references can help you evaluate it.

Vendor-focused view

Requirements connected to Microsoft Purview DSPM for AI's public claims

12 security requirements with strong or limited public support determine which rows appear. This does not mean the vendor implements or conforms to a framework.

Security requirements12connected to this vendor's public claims
Standards and reference types6standards, controls, and threats
Documented connections88each connection explains its strength
Individual references331identifiers, clauses, controls, or risks

How to read this map

Each row starts with one security requirement

References share a row because they help address the same requirement. They are not interchangeable. Each label explains how closely a reference aligns with that requirement.

Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.
Contributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

Standards and framework connections

Read across each requirement

Important references remain visible without hover. Open a framework research view for market-wide context, or start from a vendor page to see only references connected to that vendor's public claims.

AI usage inventory

Maintain an inventory of AI tools, services, models, agents, software as a service (SaaS) AI capabilities, data flows, and provider relationships.

Govern · Identify · Monitor
Unmanaged AI · Strong public supportBusiness-app AI inventory · Strong public supportApproved AI activity · Strong public support
8 connections · 20 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

GOVERN 1.6MAP 1.1MAP 1.4

Closely addresses this security requirement.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

ID.AM-02ID.AM-04ID.AM-07

Closely addresses this security requirement.

Specific reference

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

A.4.2A.4.3A.4.4

Provides related context; confirm whether it applies in your environment.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
  • 2.1Establish and Maintain a Software InventoryIG1+
  • 3.8Document Data FlowsIG2+
  • 15.1Establish and Maintain an Inventory of Service ProvidersIG1+
LLMAgentMCP

Project-curated baseline alignment. CIS inventories software, data flows, and service providers; the AI-specific asset model comes from the linked large language model (LLM), Agent, and Model Context Protocol (MCP) companion guides.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

DSP-03IAM-03STA-08UEM-04

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

AML.T0007AML.T0084

Threat discovery references clarify which AI artifacts and agent configurations defenders must know exist.

Specific reference
OWASP Top 10 for LLM ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

LLM03:2025

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for Agentic ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

ASI04

Contributes to the requirement without representing an equivalent control.

Specific reference
AI usage monitoring

Monitor AI usage, user activity, prompts, responses, provider calls, runtime actions, and anomalous behavior.

Monitor · Detect · Operate
Unmanaged AI · Strong public supportApproved AI activity · Strong public supportAgent runtime telemetry · Limited public support
8 connections · 27 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

MEASURE 2.4MEASURE 3.1MANAGE 4.1

Closely addresses this security requirement.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

DE.CM-01DE.CM-03DE.CM-06DE.CM-09

Closely addresses this security requirement.

Specific reference

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

9.1A.6.2.6A.6.2.8

Closely addresses this security requirement.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
  • 8.2Collect Audit LogsIG1+
  • 8.5Collect Detailed Audit LogsIG2+
  • 8.9Centralize Audit LogsIG2+
  • 8.11Conduct Audit Log ReviewsIG2+
LLMAgentMCP

Project-curated baseline alignment. These safeguards establish audit-log collection, detail, centralization, and review; AI telemetry scope must still be confirmed.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

LOG-03LOG-07LOG-12LOG-14LOG-15LOG-16

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

AML.M0024AML.T0053AML.T0080AML.T0086

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for LLM ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

LLM10:2025

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for Agentic ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

ASI08ASI10

Contributes to the requirement without representing an equivalent control.

Specific reference
unapproved AI control

Enforce policy against unapproved AI tools or unsafe AI interactions through blocking, coaching, allowlists, or runtime controls.

Protect · Deploy · Operate
Unapproved AI control · Limited public supportBrowser and app controls · Strong public supportGenerative AI app security · Limited public support
8 connections · 24 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

GOVERN 1.2MAP 1.6MANAGE 2.4

Contributes to the requirement without representing an equivalent control.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Contributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

PR.AA-05DE.CM-09RS.MA

Contributes to the requirement without representing an equivalent control.

Framework category

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

A.9.2A.9.3A.9.4

Provides related context; confirm whether it applies in your environment.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
  • 2.5Allowlist Authorized SoftwareIG2+
  • 2.7Allowlist Authorized ScriptsIG3+
  • 9.3Maintain and Enforce Network-Based URL FiltersIG2+
LLMAgentMCP

Project-curated baseline alignment. Allowlisting and URL filtering support enforcement, but do not by themselves establish prompt-, model-, agent-, or tool-aware policy controls.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AIS-11GRC-09TVM-13UEM-02

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

AML.M0020AML.M0021AML.M0030

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for LLM ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

LLM01:2025LLM06:2025

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for Agentic ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

ASI01ASI02ASI10

Contributes to the requirement without representing an equivalent control.

Specific reference
AI data protection

Prevent sensitive data exposure through prompts, responses, files, retrieval, memory, embeddings, or AI-connected workflows.

Protect · Operate · Monitor
Prompt and data protection · Strong public supportGenerative AI app security · Limited public supportApproved AI activity · Strong public support
8 connections · 35 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

MEASURE 2.7MEASURE 2.10MANAGE 4.1

Closely addresses this security requirement.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

PR.DS-01PR.DS-02PR.DS-10

Closely addresses this security requirement.

Specific reference

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

A.7.3A.7.4A.7.5A.7.6

Provides related context; confirm whether it applies in your environment.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
  • 3.2Establish and Maintain a Data InventoryIG1+
  • 3.3Configure Data Access Control ListsIG1+
  • 3.8Document Data FlowsIG2+
  • 3.10Encrypt Sensitive Data in TransitIG2+
  • 3.11Encrypt Sensitive Data at RestIG2+
  • 3.13Deploy a Data Loss Prevention SolutionIG3+
  • 3.14Log Sensitive Data AccessIG3+
LLMAgentMCP

Project-curated baseline alignment. CIS data safeguards provide the operational baseline; AI prompt, response, retrieval, memory, and embedding coverage still requires product-specific evidence.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

CEK-03DSP-17DSP-20DSP-22IAM-16UEM-11

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

AML.M0012AML.M0019AML.M0031AML.T0024AML.T0057AML.T0082AML.T0086

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for LLM ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

LLM02:2025LLM07:2025LLM08:2025

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for Agentic ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

ASI03ASI06

Contributes to the requirement without representing an equivalent control.

Specific reference
generative AI application security

Secure large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, tool calls, application programming interfaces (APIs), model interactions, and runtime behavior.

Develop · Test · Release · Deploy · Operate
Generative AI app security · Limited public supportPrompt and data protection · Strong public supportUnapproved AI control · Limited public supportAI gateway and tool controls · Limited public support
8 connections · 46 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

MEASURE 2.7MEASURE 2.13MANAGE 4.1

Contributes to the requirement without representing an equivalent control.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Contributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

PR.DS-10DE.CM-09RS.MA-02RS.MA-03

Contributes to the requirement without representing an equivalent control.

Specific reference

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

A.6.2.4A.6.2.5A.6.2.6A.6.2.8

Provides related context; confirm whether it applies in your environment.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
  • 16.1Establish and Maintain a Secure Application Development ProcessIG2+
  • 16.2Establish and Maintain a Process to Accept and Address Software VulnerabilitiesIG2+
  • 16.6Establish and Maintain a Severity Rating System and Process for Application VulnerabilitiesIG2+
  • 16.10Apply Secure Design Principles in Application ArchitecturesIG2+
  • 16.12Implement Code-Level Security ChecksIG3+
  • 16.13Conduct Application Penetration TestingIG3+
LLMAgentMCP

Project-curated baseline alignment. CIS secure-development safeguards structure application assurance; AI-specific attack classes and runtime controls remain separate test requirements.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AIS-05AIS-08AIS-09AIS-10AIS-11AIS-13AIS-15TVM-07TVM-13

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AML.M0015AML.M0020AML.M0029AML.M0032AML.M0033AML.T0051AML.T0054AML.T0067AML.T0070AML.T0077AML.T0105

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for LLM ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

LLM01:2025LLM04:2025LLM05:2025LLM06:2025LLM08:2025

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for Agentic ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

ASI01ASI02ASI05ASI06

Closely addresses this security requirement.

Specific reference
AI governance, risk, and compliance operations

Maintain accountable AI inventory, policy, risk assessments, approvals, exceptions, regulatory mappings, third-party oversight, and audit evidence across the AI lifecycle.

Govern · Identify · Assess · Approve · Monitor
AI governance · Limited public supportApproved AI activity · Strong public supportBusiness-app AI inventory · Strong public support
8 connections · 20 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

GOVERN 1.2GOVERN 1.6MANAGE 3.1

Closely addresses this security requirement.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Contributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

GV.RMID.AM-07

Contributes to the requirement without representing an equivalent control.

Framework category

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

A.9.2A.9.3A.10.2

Closely addresses this security requirement.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsRelated context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.
  • 2.1Establish and Maintain a Software InventoryIG1+
  • 14.1Establish and Maintain a Security Awareness ProgramIG1+
  • 15.2Establish and Maintain a Service Provider Management PolicyIG2+
  • 17.1Designate Personnel to Manage Incident HandlingIG1+
LLMAgentMCP

Project-curated operational baseline only. CIS supports inventory, awareness, provider policy, and incident ownership, but it does not replace an AI management system or regulatory assessment workflow.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

GRC-09STA-08LOG-16

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

AML.M0024AML.T0084

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for LLM ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

LLM03:2025

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for Agentic ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

ASI04ASI10

Contributes to the requirement without representing an equivalent control.

Specific reference
Third-party and software as a service (SaaS) AI risk

Understand and monitor AI risk introduced by external software as a service (SaaS), AI providers, embedded AI features, and supplier services.

Govern · Identify · Detect
Business-app AI inventory · Strong public supportUnmanaged AI · Strong public support
8 connections · 32 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

GOVERN 6.1GOVERN 6.2MAP 4.1MANAGE 3.1

Closely addresses this security requirement.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

GV.SCID.AM-04DE.CM-06

Closely addresses this security requirement.

Framework category

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

A.10.2A.10.3

Provides related context; confirm whether it applies in your environment.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.
  • 15.1Establish and Maintain an Inventory of Service ProvidersIG1+
  • 15.2Establish and Maintain a Service Provider Management PolicyIG2+
  • 15.3Classify Service ProvidersIG2+
  • 15.4Ensure Service Provider Contracts Include Security RequirementsIG2+
  • 15.5Assess Service ProvidersIG3+
  • 15.6Monitor Service ProvidersIG3+
  • 15.7Securely Decommission Service ProvidersIG3+
LLMAgentMCP

Project-curated alignment to the full CIS service-provider lifecycle. AI-specific provider scope and evidence expectations come from this project's normalized requirement and the companion guides.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

STA-01STA-08STA-09STA-10STA-13STA-16

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AML.M0014AML.M0023AML.T0010AML.T0058AML.T0104AML.T0109AML.T0111

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for LLM ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

LLM03:2025LLM04:2025

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for Agentic ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

ASI04

Closely addresses this security requirement.

Specific reference
Agentic telemetry and behavior monitoring

Observe agent steps, plans, goals, memory, delegation, tool use, and anomalies during runtime.

Operate · Monitor · Detect
Agent runtime telemetry · Limited public support
8 connections · 34 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

MEASURE 2.4MEASURE 3.1MANAGE 4.1

Contributes to the requirement without representing an equivalent control.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

DE.CM-01DE.CM-09DE.AE

Closely addresses this security requirement.

Framework category

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

9.1A.6.2.6A.6.2.8

Closely addresses this security requirement.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
  • 8.2Collect Audit LogsIG1+
  • 8.5Collect Detailed Audit LogsIG2+
  • 8.9Centralize Audit LogsIG2+
  • 8.11Conduct Audit Log ReviewsIG2+
AgentMCP

Project-curated baseline alignment. Audit-log safeguards support telemetry operations; the Agent and Model Context Protocol (MCP) guides supply the relevant AI runtime interpretation.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

LOG-03LOG-07LOG-12LOG-14LOG-15LOG-16MDS-10SEF-06

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AML.M0024AML.M0031AML.T0053AML.T0080AML.T0086AML.T0099AML.T0101

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for LLM ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

LLM06:2025LLM10:2025

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for Agentic ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

ASI02ASI06ASI08ASI10

Closely addresses this security requirement.

Specific reference
Agent-to-agent and tool communication security

Secure trust, authorization, message flows, tool access, and communication between agents, tools, application programming interfaces (APIs), and external services.

Identify · Protect · Deploy · Monitor
Agent runtime telemetry · Limited public supportGenerative AI app security · Limited public supportAI gateway and tool controls · Limited public support
8 connections · 36 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

MEASURE 2.7MAP 4.2MANAGE 4.1

Contributes to the requirement without representing an equivalent control.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

ID.AM-03PR.AA-02PR.AA-04DE.CM-01

Closely addresses this security requirement.

Specific reference

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

A.6.2.4A.6.2.8A.10.2

Provides related context; confirm whether it applies in your environment.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
  • 5.1Establish and Maintain an Inventory of AccountsIG1+
  • 6.1Establish an Access Granting ProcessIG1+
  • 6.2Establish an Access Revoking ProcessIG1+
  • 6.5Require MFA for Administrative AccessIG1+
  • 6.8Define and Maintain Role-Based Access ControlIG3+
  • 8.2Collect Audit LogsIG1+
AgentMCP

Project-curated baseline alignment. Account, access, administrative MFA, role, and log safeguards support agent-to-tool trust; protocol-specific authorization still requires Model Context Protocol (MCP) and product evidence.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AIS-08AIS-11IAM-15IAM-18IPY-03LOG-12

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AML.M0026AML.M0028AML.M0032AML.M0033AML.T0053AML.T0080AML.T0086AML.T0099AML.T0110

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for LLM ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

LLM06:2025

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for Agentic ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

ASI02ASI04ASI07ASI08

Closely addresses this security requirement.

Specific reference
non-human identity (NHI) and AI-agent identity governance

Manage identities, credentials, privileges, secrets, service accounts, and lifecycle for AI agents and other non-human identities.

Govern · Protect · Deploy · Operate
Agent identity · Limited public supportBusiness-app AI inventory · Strong public support
8 connections · 34 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

GOVERN 6.1MAP 4.2MANAGE 3.1

Contributes to the requirement without representing an equivalent control.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Closely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

PR.AA-01PR.AA-02PR.AA-03PR.AA-05

Closely addresses this security requirement.

Specific reference

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

A.4.2A.10.2

Provides related context; confirm whether it applies in your environment.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

CIS Critical Security ControlsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.
  • 5.1Establish and Maintain an Inventory of AccountsIG1+
  • 5.4Restrict Administrator Privileges to Dedicated Administrator AccountsIG1+
  • 6.1Establish an Access Granting ProcessIG1+
  • 6.2Establish an Access Revoking ProcessIG1+
  • 6.3Require MFA for Externally-Exposed ApplicationsIG1+
  • 6.5Require MFA for Administrative AccessIG1+
  • 6.8Define and Maintain Role-Based Access ControlIG3+
AgentMCP

Project-curated baseline alignment. CIS account and access safeguards apply to non-human identities when implemented that way; the Agent and Model Context Protocol (MCP) guides provide the explicit AI context.

Specific reference · research-team interpretation

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

IAM-03IAM-05IAM-12IAM-14IAM-15IAM-18LOG-13

Closely addresses this security requirement.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AML.M0026AML.M0027AML.M0028AML.T0055AML.T0083AML.T0091AML.T0098AML.T0113

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for LLM ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

LLM06:2025

Contributes to the requirement without representing an equivalent control.

Specific reference
OWASP Top 10 for Agentic ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

ASI03ASI07

Closely addresses this security requirement.

Specific reference
AI FinOps and cost accountability

Attribute AI usage and spend to accountable owners, workflows, agents, models, and business units while enforcing budget, rate-limit, and routing controls.

Govern · Operate · Optimize
Approved AI activity · Strong public supportAgent runtime telemetry · Limited public support
7 connections · 22 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

NIST AI RMF PlaybookContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

GOVERN 1.6MAP 1.4MANAGE 3.2

Contributes to the requirement without representing an equivalent control.

Specific reference

NIST CSF 2.0

Enterprise cybersecurity outcomes

NIST Cybersecurity Framework 2.0Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

GV.RMID.AM-07DE.CM-09

Provides related context; confirm whether it applies in your environment.

Framework category

ISO/IEC 42001

AI management-system clauses and controls

ISO/IEC 42001Related context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

A.9.2A.9.3

Provides related context; confirm whether it applies in your environment.

Specific reference · research-team interpretation

CIS Controls v8.1

Prioritized safeguards and implementation groups

No clearly supported connection

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

BCR-02GRC-02I&S-02LOG-14

Contributes to the requirement without representing an equivalent control.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

MITRE ATLASClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

AML.M0004AML.T0029AML.T0034AML.T0034.000AML.T0034.001AML.T0034.002

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for LLM ApplicationsClosely aligned
?Closely alignedThe framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.

LLM06:2025LLM10:2025

Closely addresses this security requirement.

Specific reference
OWASP Top 10 for Agentic ApplicationsContributes
?ContributesThe framework reference helps address the requirement but is not equivalent to it.

ASI02ASI08

Contributes to the requirement without representing an equivalent control.

Specific reference
Licensing and packaging model

Publicly available licensing model, packaging approach, and buyer-relevant commercial structure.

Commercial
Licensing · Strong public support
1 connections · 1 references Open requirement

NIST AI RMF

AI risk governance and lifecycle outcomes

No clearly supported connection

NIST CSF 2.0

Enterprise cybersecurity outcomes

No clearly supported connection

ISO/IEC 42001

AI management-system clauses and controls

No clearly supported connection

CIS Controls v8.1

Prioritized safeguards and implementation groups

No clearly supported connection

CSA AICM

AI control objectives for customer implementation

CSA AI Controls MatrixRelated context
?Related contextThe framework reference provides relevant context, but its applicability must be confirmed during evaluation.

STA-11

AICM addresses the primary service and contractual agreement, not comparative price or license metrics.

Specific reference

Threat and failure references

MITRE ATLAS and OWASP AI risk catalogs

No clearly supported connection

CIS Controls v8.1

Cyber-hygiene baseline with AI-specific companion guidance

The research team selected the CIS safeguard connections shown here; they are guidance, not official CIS mappings. The official 2026 companion guides explain how CIS Controls apply to three AI environments.

LLM

Applies CIS Controls v8.1 to prompts, context handling, model access, sensitive data, and LLM operations.

Open official guide ↗
Agent

Applies CIS Controls v8.1 to agent planning, tool use, delegated actions, identity, and runtime behavior.

Open official guide ↗
MCP

Applies CIS Controls v8.1 to MCP tool access, non-human identity, authorization, logging, and protocol operations.

Open official guide ↗

Source guide

What each standard or framework contributes

Use each source for the job it is designed to do. Vendor implementation and product effectiveness still require separate evidence.

Current source

NIST AI RMF Playbook

AI RMF 1.0 Playbook

AI risk management reference for governance, mapping, measurement, and lifecycle management. Useful for structuring diligence questions, but not a standalone selection model, certification proxy, or substitute for enterprise-specific risk, architecture, and operating requirements.

Connected requirements
13
Individual references
39
Current source

NIST Cybersecurity Framework 2.0

v2.0 (NIST CSWP 29, February 2024)

Cybersecurity outcome lens (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER). NIST IR 8596 Cyber AI Profile deferred until it exits draft; subcategory IDs in this project map to CSF 2.0 directly and remain stable when the AI Profile lands.

Connected requirements
12
Individual references
39
Current source

CIS Critical Security Controls

v8.1 with 2026 AI Companion Guides

Prioritized cyber-hygiene safeguards with AI-specific interpretation for large language model (LLM), agent, and Model Context Protocol (MCP) environments. This project maps normalized AI security requirements to relevant CIS safeguards as a research interpretation; it does not present an official CIS mapping, implementation assessment, or certification result.

Connected requirements
11
Individual references
58
Current source

ISO/IEC 42001

ISO/IEC 42001:2023

AI management system lens for procurement diligence prompts and auditor discussion. Mappings are indicative clause/control alignments only; they are not a certification proxy, vendor assurance substitute, or evidence that a product satisfies ISO/IEC 42001.

Connected requirements
12
Individual references
35
Informational source

OWASP GenAI Security Solutions Landscape

Q2/Q3 2026

Market and lifecycle lens for large language model (LLM) and generative AI AppSec/SecOps capabilities.

Connected requirements
11
Individual references
27
Informational source

OWASP Agentic AI Security Solutions Landscape

Q2/Q3 2026

Market and lifecycle lens for agentic AI, agent-to-agent (A2A), tool, memory, non-human identity (NHI), and runtime controls.

Connected requirements
12
Individual references
31
Current source

MITRE ATLAS

2026.06

Adversary-behavior lens for AI systems. Technique and mitigation references describe threat paths and defensive hypotheses; they do not establish that a vendor prevents, detects, or responds to the behavior.

Connected requirements
12
Individual references
71
Current source

OWASP Top 10 for LLM Applications

2025 (v2.0)

Application failure-mode lens for large language model (LLM) systems. Mappings identify risks a requirement should address and are not proof of product efficacy or OWASP endorsement.

Connected requirements
13
Individual references
25
Current source

OWASP Top 10 for Agentic Applications

2026

Agentic failure-mode lens covering autonomy, tools, identity, memory, multi-agent communication, cascading effects, and oversight.

Connected requirements
13
Individual references
31
Current source

CSA AI Controls Matrix

v1.1 (June 22, 2026)

Vendor-neutral control-objective lens. This project uses the official AI Customer implementation publication with 247 controls across 18 domains; a mapped control is a diligence and test target, not evidence of implementation.

Connected requirements
14
Individual references
71
Current source

Open FAIR

O-RA 2.0.1 / O-RT 3.0.1

Business-loss scenario and quantitative risk-analysis structure. Scenario templates are modeled, but event frequency, vulnerability, and loss magnitude remain explicit enterprise inputs.

Connected requirements
0
Individual references
0

Commercial Metadata

Point-in-time public research

Licensing and packaging context. Not a security framework.

Connected requirements
3
Individual references
3

This map organizes research. Certification, audit conclusions, framework conformance, vendor control implementation, and product effectiveness require separate evidence.