(Accuracy = Integrity = Quality = Trust) > Progress > Speed > Cost

Mappings

How the rules cross to the frameworks you already use.

This page is a navigational crosswalk from the pack's mapped rules to security and AI-governance frameworks. It is not a claim of endorsement or compliance: no framework publisher endorses, sponsors, or is affiliated with this pack, and a mapping asserts a relationship of ideas, not certification against a standard.

The crosswalk carries 957 mappings from 105 of the pack's rules to 514 identifiers across 17 frameworks. Every mapped identifier is validated against a pinned-edition manifest before it can ship; the counts here are generated from that live state, never hand-entered.

Methodology and limits

How the crosswalk is built, and what it does not claim

The mappings are part of the rules themselves. Each mapped rule records, in its own source, the framework identifiers it maps to, and every one is checked in continuous integration against a pinned-edition manifest of that framework's identifiers. An identifier that is not in the pinned edition cannot ship, so a fabricated or mistyped mapping is caught before publication rather than after.

  • Five relation kinds. The wording of each mapping follows the framework's type: a rule supports a control, aligns with guidance, addresses a risk, mitigates a technique, or mitigates a weakness.
  • Each mapping carries its fit. A tight mapping is a direct, one-to-one correspondence; a broad mapping is a looser, thematic relation. The fit is shown next to every identifier and in both exports.
  • Identifiers and published titles only. Only control, guidance, risk, technique, and weakness identifiers and the frameworks' own published titles are reproduced, as navigational pointers; some frameworks (NIST AI RMF, for example) label an item with a full sentence, reproduced verbatim as that item's published title. No further specification prose, requirement text, control or clause bodies, figures, or tables from any framework are reproduced.
  • What absence means. This is a first-cut, curated set that will grow. The absence of a mapping does not mean a rule is irrelevant to a framework; it means no mapping has been asserted yet. A pinned edition may also lag a framework's most recent release.
  • ISO/IEC entries. The two ISO/IEC entries reproduce clause and control numbers with their short headings only, as pointers to a licensed copy of the standard, never any clause or Annex body text.

Framework registry

The frameworks in the crosswalk

Each framework is pinned to a single edition. The edition-stability badge reads stable for a settled published edition, beta for a pre-release edition, and snapshot for a point-in-time capture of a moving source. For a full-edition manifest the last column states how many of that edition's identifiers the current rules reference; for a curated subset it states the count referenced, with no edition total.

FrameworkPublisherEditionRelationEdition stabilityIdentifiers referenced
CSA AI Controls MatrixCloud Security Alliance1.1.0supports controlstable79 referenced (curated subset)
CSA Cloud Controls MatrixCloud Security Alliance4.1.0supports controlstable57 referenced (curated subset)
ISO/IEC 23894:2023 AI guidance on risk managementISO/IEC2023aligns with guidancestable14 referenced (curated subset)
ISO/IEC 42001:2023 AI management systemISO/IEC2023supports controlstable18 referenced (curated subset)
MITRE ATLASMITRE2026.06mitigates techniquesnapshot67 referenced (curated subset)
MITRE CWEMITRE4.20mitigates weaknesssnapshot72 referenced (curated subset)
NIST SP 800-53 Security and Privacy ControlsNISTRev 5 (catalog 5.2.0)supports controlstable67 referenced (curated subset)
NIST AI Risk Management FrameworkNIST1.0 (NIST AI 100-1)aligns with guidancestable24 referenced (curated subset)
NIST Secure Software Development FrameworkNIST1.1 (SP 800-218)supports controlstable20 referenced (curated subset)
OWASP API Security Top 10OWASP Foundation2023addresses riskstable8 referenced (curated subset)
OWASP Top 10 for Agentic ApplicationsOWASP Foundation2026addresses riskstable9 referenced (curated subset)
OWASP Application Security Verification StandardOWASP Foundation5.0.0supports controlstable13 referenced (curated subset)
OWASP Cheat Sheet SeriesOWASP Foundationcommit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)aligns with guidancesnapshot27 referenced (curated subset)
OWASP Top 10 for LLM ApplicationsOWASP Foundation2026addresses riskstable10 of 10
OWASP MCP Top 10OWASP Foundation2025addresses riskbeta10 of 10
OWASP Top 10 Proactive ControlsOWASP Foundation4.0.0supports controlstable9 referenced (curated subset)
OWASP Top 10 (Web Application Security Risks)OWASP Foundation2025addresses riskstable10 of 10

Forward view

By rule

Every rule that carries at least one mapping, in AIQT priority order. Open a rule to see the frameworks it maps to and the identifiers under each, with the fit noted in parentheses.

Claims about the work rest on observation

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.12: Transparency and explainability (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
A completeness claim enumerates its set

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.12: Transparency and explainability (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
Corroborate external claims

View this rule on GitHub

  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0067.000: Citations (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
    • MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context. (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM07: Misinformation (tight)
Evidence-grounded completion

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.12: Transparency and explainability (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
A guard is only as good as its input

View this rule on GitHub

  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MEASURE 2.13: Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. (broad)
    • MAP 2.3: Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection, and construct validation. (tight)
Measured and estimated figures stay separate

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.12: Transparency and explainability (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MEASURE 1.1: Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation. (broad)
No fabrication

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.12: Transparency and explainability (broad)
    • B.5: Risk sources related to machine learning (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
    • MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context. (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM07: Misinformation (tight)
Read before characterizing

View this rule on GitHub

  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
    • MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context. (broad)
Capture the reference when the claim is made

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.7.5: Data provenance (tight)
Reproduce a defect before fixing it

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-2: Flaw Remediation (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • RV.1.2: Test code to confirm new vulnerabilities (broad)
A current timestamp is read from the clock

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AU-8: Time Stamps (broad)
Validate an inferred premise before acting

View this rule on GitHub

  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
Anything wrong is fixed first

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-2: Flaw Remediation (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (broad)
Branch and merge only on green

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.7: Maintainability (broad)
    • B.7: System life cycle issues (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.1.3: Processes for responsible design and development of AI systems (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-10: Developer Configuration Management (broad)
    • CM-3: Configuration Change Control (tight)
    • CM-3(2): Testing, Validation, and Documentation of Changes (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PS.1.1: Protect stored code with least privilege (broad)
    • PW.7.1: Decide on code review and analysis (broad)
Cut branches from the live protected line and re-home after a rewrite

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.1.3: Processes for responsible design and development of AI systems (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-10: Developer Configuration Management (broad)
    • CM-3: Configuration Change Control (tight)
    • CM-3(2): Testing, Validation, and Documentation of Changes (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.7.1: Decide on code review and analysis (broad)
A check fails closed on input it cannot read

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-17: Fail-safe Procedures (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • error-handling: Error Handling Cheat Sheet (broad)
Commit identity

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.3.2: AI roles and responsibilities (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 2.1: Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PS.1.1: Protect stored code with least privilege (broad)
Gate discipline

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-3(2): Testing, Validation, and Documentation of Changes (broad)
    • SA-11: Developer Testing and Evaluation (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PO.4.1: Define software security check criteria (broad)
    • PW.8.2: Perform and document code testing (tight)
Verify licence compatibility before introducing third-party material

View this rule on GitHub

  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented. (broad)
No concealed failure

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.12: Transparency and explainability (broad)
    • 6.7: Recording and reporting (tight)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-11: Developer Testing and Evaluation (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. (tight)
    • MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (tight)
Protected-branch integrity

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.7: Maintainability (broad)
    • B.7: System life cycle issues (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.1.3: Processes for responsible design and development of AI systems (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-3: Configuration Change Control (tight)
    • CM-5: Access Restrictions for Change (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.7.1: Decide on code review and analysis (broad)
    • PS.1.1: Protect stored code with least privilege (tight)
A required step remains required under friction

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • 10.2: Nonconformity and corrective action (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (broad)
A rerun pass does not erase an earlier failure

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-2: Flaw Remediation (broad)
Separate task changes from pre-existing work

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-3: Configuration Change Control (broad)
A launched task stays observable

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • 6.7: Recording and reporting (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.6: AI system operation and monitoring (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (broad)
Validation is a gate on apply

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-11: Developer Testing and Evaluation (broad)
    • CM-3(2): Testing, Validation, and Documentation of Changes (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.7.1: Decide on code review and analysis (broad)
    • PW.8.1: Decide on executable code testing (broad)
Workers produce inert data

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
    • B.4: Level of automation (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.1.3: Processes for responsible design and development of AI systems (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0053: AI Agent Tool Invocation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AC-6: Least Privilege (tight)
    • CM-5: Access Restrictions for Change (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.7.2: Perform code review and analysis (broad)
    • PS.1.1: Protect stored code with least privilege (tight)
A behavioural change carries a check that fails without it

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-3(2): Testing, Validation, and Documentation of Changes (broad)
    • SA-11: Developer Testing and Evaluation (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.8.2: Perform and document code testing (broad)
Defence in depth by default

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-8: Security and Privacy Engineering Principles (broad)
A verification finding is fixed, not argued away

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-11: Developer Testing and Evaluation (broad)
    • SI-2: Flaw Remediation (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
    • MANAGE 2.3: Procedures are followed to respond to and recover from a previously unknown risk when it is identified. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PO.4.1: Define software security check criteria (broad)
    • PW.7.2: Perform code review and analysis (broad)
High-assurance verification

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-3(2): Testing, Validation, and Documentation of Changes (broad)
    • SA-11(3): Independent Verification of Assessment Plans and Evidence (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.2.1: Review software design against security requirements (broad)
    • PW.7.2: Perform code review and analysis (broad)
Isolate verifiers and judge by their result signal

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-11(3): Independent Verification of Assessment Plans and Evidence (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. (broad)
    • MEASURE 2.13: Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. (broad)
Match the surrounding code

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.7: Maintainability (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
Minimize external dependencies in favour of standard libraries

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-8: Security and Privacy Engineering Principles (broad)
Propose a guardrail when an error reveals a gap

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • 10.2: Nonconformity and corrective action (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 2.3: Procedures are followed to respond to and recover from a previously unknown risk when it is identified. (tight)
Prefer the smallest correct change

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.7: Maintainability (broad)
Surface a counterproductive instruction before executing it

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • 6.2: Communication and consultation (broad)
    • A.2: Accountability (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.3.3: Reporting of concerns (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (broad)
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (tight)
A test's verdict comes from the code, not its surroundings

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-8(29): Repeatable and Documented Procedures (broad)
    • SA-11: Developer Testing and Evaluation (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.8.2: Perform and document code testing (broad)
Verifier diversity

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.4: AI system verification and validation (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-11(3): Independent Verification of Assessment Plans and Evidence (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. (broad)
    • MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.7.1: Decide on code review and analysis (broad)
Maintain an AI toolchain register

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.4.4: Tooling resources (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-8: System Component Inventory (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 1.6: Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. (tight)
Assess and advise are discussion only

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
    • B.4: Level of automation (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.9.2: Processes for responsible use of AI systems (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (broad)
    • MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (broad)
Change record

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • 6.7: Recording and reporting (tight)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • 7.5.2: Creating and updating documented information (broad)
    • 7.5.3: Control of documented information (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-3: Configuration Change Control (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PO.3.3: Generate artifacts from security tools (broad)
Change record has a curated public face

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.8.5: Information for interested parties (broad)
Clarify before acting

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • 6.2: Communication and consultation (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
    • MAP 1.6: System requirements (e.g., "the system shall respect the privacy of its users") are elicited from and understood by relevant AI actors. (broad)
Continue by default

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • B.4: Level of automation (broad)
Express authorization before execution

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
    • B.4: Level of automation (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.9.2: Processes for responsible use of AI systems (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (broad)
    • MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (broad)
Human oversight and the autonomy threshold

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
    • A.10: Safety (broad)
    • B.4: Level of automation (tight)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.3.2: AI roles and responsibilities (broad)
    • A.9.2: Processes for responsible use of AI systems (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0053: AI Agent Tool Invocation (broad)
    • AML.T0086: Exfiltration via AI Agent Tool Invocation (broad)
    • AML.T0101: Data Destruction via AI Agent Tool Invocation (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (tight)
    • MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (tight)
Reconcile the record against reality

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CA-7: Continuous Monitoring (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 1.5: Ongoing monitoring and periodic review of the risk management process and its outcomes are planned. (broad)
Records first

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • 6.7: Recording and reporting (tight)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • 7.5.2: Creating and updating documented information (broad)
    • 7.5.3: Control of documented information (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 1.4: The risk management process and its outcomes are established through transparent policies, procedures, and other controls. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.1.2: Track security requirements and design decisions (tight)
Close each session on green

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • 8.1: Operational planning and control (broad)
Resume from the durable handoff

View this rule on GitHub

  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • 8.1: Operational planning and control (broad)
Trust recovery and escalation

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
    • A.12: Transparency and explainability (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (tight)
Autonomy steps down after a confirmed trust loss

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (broad)
    • MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (tight)
Decision classification before enacting

View this rule on GitHub

  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (tight)
    • B.4: Level of automation (tight)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.9.2: Processes for responsible use of AI systems (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (tight)
    • MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (tight)
Background work during CI waits

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-3(2): Testing, Validation, and Documentation of Changes (broad)
Cost tier

View this rule on GitHub

  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities. (broad)
    • MAP 1.5: Organizational risk tolerances are determined and documented. (broad)
Classify content by sensitivity tier

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • DSP-10: Sensitive Data Transfer (broad)
    • DSP-17: Sensitive Data Protection (broad)
    • DSP-24: Data Differentiation and Relevance (broad)
    • IAM-16: Knowledge Access Control - Need to Know (broad)
    • DSP-04: Data Classification (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • DSP-10: Sensitive Data Transfer (broad)
    • DSP-17: Sensitive Data Protection (broad)
    • DSP-04: Data Classification (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • MP-3: Media Marking (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V14: Data Protection (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM02: Sensitive Information Disclosure (broad)
Egress goes only to expected destinations

View this rule on GitHub

  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0025: Exfiltration via Cyber Means (broad)
    • AML.T0086: Exfiltration via AI Agent Tool Invocation (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-610: Externally Controlled Reference to a Resource in Another Sphere (broad)
    • CWE-923: Improper Restriction of Communication Channel to Intended Endpoints (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SC-7: Boundary Protection (broad)
    • AC-4: Information Flow Enforcement (tight)
    • SC-7(5): Deny by Default - Allow by Exception (tight)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI02: Tool Misuse and Exploitation (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM02: Sensitive Information Disclosure (broad)
Keep secrets out

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • DSP-17: Sensitive Data Protection (broad)
    • LOG-08: Audit Logs Sanitization (broad)
    • AIS-12: Source Code Management (tight)
    • IAM-14: Credentials Management (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • DSP-17: Sensitive Data Protection (broad)
    • LOG-08: Audit Logs Sanitization (broad)
    • IAM-14: Credentials Management (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0082: RAG Credential Harvesting (broad)
    • AML.T0083: Credentials from AI Agent Configuration (broad)
    • AML.T0098: AI Agent Tool Credential Harvesting (broad)
    • AML.T0055: Unsecured Credentials (tight)
    • AML.T0095.000: Code Repositories (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-798: Use of Hard-coded Credentials (broad)
    • CWE-532: Insertion of Sensitive Information into Log File (tight)
    • CWE-540: Inclusion of Sensitive Information in Source Code (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • IA-5(7): No Embedded Unencrypted Static Authenticators (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V14: Data Protection (broad)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • secrets-management: Secrets Management Cheat Sheet (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM02: Sensitive Information Disclosure (broad)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP01: Token Mismanagement & Secret Exposure (tight)
Retrieval enforces the requester's authorization

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • IAM-18: Agent Access Restriction (broad)
    • IAM-05: Least Privilege (tight)
    • IAM-15: Authorization Mechanisms (tight)
    • IAM-16: Knowledge Access Control - Need to Know (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • IAM-05: Least Privilege (tight)
    • IAM-15: Authorization Mechanisms (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.8: Privacy (broad)
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0053: AI Agent Tool Invocation (broad)
    • AML.T0082: RAG Credential Harvesting (broad)
    • AML.T0085: Data from AI Services (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-285: Improper Authorization (broad)
    • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy') (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AC-3: Access Enforcement (tight)
    • AC-6: Least Privilege (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI03: Identity and Privilege Abuse (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP07: Insufficient Authentication & Authorization (tight)
No cross-context bleed

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-14: AI Cache Protection (broad)
    • IAM-16: Knowledge Access Control - Need to Know (broad)
    • AIS-11: Agents Security Boundaries (tight)
    • I&S-06: Segmentation and Segregation (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • I&S-06: Segmentation and Segregation (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.8: Privacy (broad)
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0057: LLM Data Leakage (broad)
    • AML.T0080: AI Agent Context Poisoning (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (broad)
    • CWE-653: Improper Isolation or Compartmentalization (broad)
    • CWE-488: Exposure of Data Element to Wrong Session (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AC-4: Information Flow Enforcement (tight)
    • SC-4: Information in Shared System Resources (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP10: Context Injection & Over-Sharing (tight)
No disclosure of secrets or hidden context

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-15: Prompt Differentiation (broad)
    • DSP-17: Sensitive Data Protection (broad)
    • IAM-16: Knowledge Access Control - Need to Know (broad)
    • TVM-13: Guardrails (broad)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • DSP-17: Sensitive Data Protection (broad)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.8: Privacy (broad)
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0082: RAG Credential Harvesting (broad)
    • AML.T0098: AI Agent Tool Credential Harvesting (broad)
    • AML.T0056: Extract LLM System Prompt (tight)
    • AML.T0057: LLM Data Leakage (tight)
    • AML.T0069: Discover LLM System Information (tight)
    • AML.T0084: Discover AI Agent Configuration (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere (broad)
    • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AC-4: Information Flow Enforcement (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM02: Sensitive Information Disclosure (tight)
    • LLM08: Hidden Context Exposure (tight)
Rotate a leaked secret

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • SEF-07: Incident Management and Response (broad)
    • CEK-12: Key Rotation (tight)
    • CEK-19: Key Compromise (tight)
    • IAM-14: Credentials Management (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • SEF-07: Incident Management and Response (broad)
    • CEK-12: Key Rotation (tight)
    • CEK-19: Key Compromise (tight)
    • IAM-14: Credentials Management (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0012: Valid Accounts (broad)
    • AML.T0091.000: Application Access Token (broad)
    • AML.T0091.001: Web Session Cookie (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • IR-4: Incident Handling (broad)
    • IA-5: Authenticator Management (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 2.3: Procedures are followed to respond to and recover from a previously unknown risk when it is identified. (broad)
    • MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. (broad)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • secrets-management: Secrets Management Cheat Sheet (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP01: Token Mismanagement & Secret Exposure (tight)
Strong authentication

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • IAM-13: Strong Authentication (tight)
    • IAM-14: Credentials Management (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • IAM-13: Strong Authentication (tight)
    • IAM-14: Credentials Management (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0012: Valid Accounts (broad)
    • AML.T0055: Unsecured Credentials (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-306: Missing Authentication for Critical Function (broad)
    • CWE-798: Use of Hard-coded Credentials (broad)
    • CWE-287: Improper Authentication (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • IA-5(5): Change Authenticators Prior to Delivery (broad)
    • IA-5(7): No Embedded Unencrypted Static Authenticators (broad)
    • IA-2: Identification and Authentication (Organizational Users) (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.1.3: Use standardized security features and services (broad)
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP API Security Top 10 (2023): addresses risk
    • API2: Broken Authentication (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V6: Authentication (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • authentication: Authentication Cheat Sheet (tight)
    • multifactor-authentication: Multifactor Authentication Cheat Sheet (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A07: Authentication Failures (tight)
Least-privilege authorization

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • IAM-16: Knowledge Access Control - Need to Know (broad)
    • IAM-17: Output Modification and Special Authorization (broad)
    • IAM-18: Agent Access Restriction (broad)
    • IAM-05: Least Privilege (tight)
    • IAM-15: Authorization Mechanisms (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • IAM-05: Least Privilege (tight)
    • IAM-15: Authorization Mechanisms (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0053: AI Agent Tool Invocation (broad)
    • AML.T0082: RAG Credential Harvesting (broad)
    • AML.T0085: Data from AI Services (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-284: Improper Access Control (broad)
    • CWE-862: Missing Authorization (tight)
    • CWE-863: Incorrect Authorization (tight)
    • CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AC-3: Access Enforcement (tight)
    • AC-6: Least Privilege (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP API Security Top 10 (2023): addresses risk
    • API1: Broken Object Level Authorization (tight)
    • API3: Broken Object Property Level Authorization (tight)
    • API5: Broken Function Level Authorization (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V8: Authorization (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • mass-assignment: Mass Assignment Cheat Sheet (broad)
    • authorization: Authorization Cheat Sheet (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C1: Implement Access Control (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A01: Broken Access Control (tight)
Configuration that executes on load is treated as code

View this rule on GitHub

  • MITRE CWE (4.20): mitigates weakness
    • CWE-829: Inclusion of Functionality from Untrusted Control Sphere (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-7: Software, Firmware, and Information Integrity (broad)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI05: Unexpected Code Execution (RCE) (tight)
Sound cryptography

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • CEK-03: Data Protection (broad)
    • CEK-04: Encryption Algorithm (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • CEK-03: Data Protection (broad)
    • CEK-04: Encryption Algorithm (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.8: Privacy (broad)
    • A.11: Security (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-311: Missing Encryption of Sensitive Data (broad)
    • CWE-295: Improper Certificate Validation (tight)
    • CWE-327: Use of a Broken or Risky Cryptographic Algorithm (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SC-8: Transmission Confidentiality and Integrity (broad)
    • SC-28: Protection of Information at Rest (broad)
    • SC-13: Cryptographic Protection (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V12: Secure Communication (broad)
    • V11: Cryptography (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • cryptographic-storage: Cryptographic Storage Cheat Sheet (tight)
    • transport-layer-security: Transport Layer Security Cheat Sheet (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C2: Use Cryptography to Protect Data (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A04: Cryptographic Failures (tight)
Trusted, pinned dependency provenance

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • MDS-12: Open Model Risk Assessment (broad)
    • TVM-06: External Library Vulnerabilities (broad)
    • UEM-02: Application and Service Approval (broad)
    • MDS-02: Model Artifact Scanning (tight)
    • MDS-09: Model Signing/Ownership Verification (tight)
    • STA-01: Supply Chain Risk Management Policies and Procedures (tight)
    • STA-08: Supply Chain Inventory (tight)
    • STA-09: Service Bill of Material (BOM) (tight)
    • STA-10: Supply Chain Risk Management (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • TVM-06: External Library Vulnerabilities (broad)
    • UEM-02: Application and Service Approval (broad)
    • STA-01: Supply Chain Risk Management Policies and Procedures (tight)
    • STA-08: Supply Chain Inventory (tight)
    • STA-09: Service Bill of Material (BOM) (tight)
    • STA-10: Supply Chain Risk Management (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
    • B.5: Risk sources related to machine learning (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.4.4: Tooling resources (broad)
    • A.10.3: Suppliers (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0018.002: Embed Malware (broad)
    • AML.T0111: AI Supply Chain Reputation Inflation (broad)
    • AML.T0112.001: AI Artifacts (broad)
    • AML.T0010.001: AI Software (tight)
    • AML.T0010.003: Model (tight)
    • AML.T0010.005: AI Agent Tool (tight)
    • AML.T0011.000: Unsafe AI Artifacts (tight)
    • AML.T0011.001: Malicious Package (tight)
    • AML.T0011.002: Poisoned AI Agent Tool (tight)
    • AML.T0104: Publish Poisoned AI Agent Tool (tight)
    • AML.T0109: AI Supply Chain Rug Pull (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-1357: Reliance on Insufficiently Trustworthy Component (broad)
    • CWE-494: Download of Code Without Integrity Check (tight)
    • CWE-829: Inclusion of Functionality from Untrusted Control Sphere (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SR-3: Supply Chain Controls and Processes (tight)
    • SR-4: Provenance (tight)
    • SR-11: Component Authenticity (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 6.1: Policies and procedures are in place that address AI risks associated with third-party entities. (broad)
    • MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PO.3.2: Securely deploy and maintain toolchains (broad)
    • PW.4.1: Acquire well-secured third-party components (tight)
    • PW.4.4: Verify third-party components meet requirements (tight)
  • OWASP API Security Top 10 (2023): addresses risk
    • API9: Improper Inventory Management (broad)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI04: Agentic Supply Chain Vulnerabilities (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • software-supply-chain-security: Software Supply Chain Security Cheat Sheet (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM04: Supply Chain (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP04: Software Supply Chain Attacks & Dependency Tampering (tight)
    • MCP09: Shadow MCP Servers (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A03: Software Supply Chain Failures (tight)
    • A08: Software or Data Integrity Failures (tight)
Fail closed in security-relevant paths

View this rule on GitHub

  • MITRE CWE (4.20): mitigates weakness
    • CWE-636: Not Failing Securely ('Failing Open') (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • error-handling: Error Handling Cheat Sheet (broad)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A10: Mishandling of Exceptional Conditions (tight)
Validate federated identity and token flows

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • IAM-13: Strong Authentication (broad)
    • IAM-14: Credentials Management (broad)
    • IAM-15: Authorization Mechanisms (broad)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • IAM-13: Strong Authentication (broad)
    • IAM-14: Credentials Management (broad)
    • IAM-15: Authorization Mechanisms (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-287: Improper Authentication (broad)
    • CWE-304: Missing Critical Step in Authentication (tight)
    • CWE-347: Improper Verification of Cryptographic Signature (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V9: Self-contained Tokens (tight)
    • V10: OAuth and OIDC (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • json-web-token: JSON Web Token Cheat Sheet (tight)
    • oauth2: OAuth2 Cheat Sheet (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C7: Secure Digital Identities (broad)
Validate and contain uploaded files

View this rule on GitHub

  • MITRE CWE (4.20): mitigates weakness
    • CWE-434: Unrestricted Upload of File with Dangerous Type (tight)
    • CWE-646: Reliance on File Name or Extension of Externally-Supplied File (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V5: File Handling (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • file-upload: File Upload Cheat Sheet (tight)
Guardrail configuration is integrity-protected

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AC-6(1): Authorize Access to Security Functions (broad)
    • SI-7: Software, Firmware, and Information Integrity (broad)
    • CM-3: Configuration Change Control (tight)
    • CM-5: Access Restrictions for Change (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP02: Privilege Escalation via Scope Creep (tight)
Human authorization for consequential actions

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • CCC-05: Change Agreements (broad)
    • CCC-04: Unauthorized Change Protection (tight)
    • GRC-15: Human supervision (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • CCC-05: Change Agreements (broad)
    • CCC-04: Unauthorized Change Protection (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
    • A.10: Safety (broad)
    • B.4: Level of automation (tight)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.9.2: Processes for responsible use of AI systems (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0053: AI Agent Tool Invocation (broad)
    • AML.T0086: Exfiltration via AI Agent Tool Invocation (broad)
    • AML.T0081: Modify AI Agent Configuration (tight)
    • AML.T0101: Data Destruction via AI Agent Tool Invocation (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-862: Missing Authorization (broad)
    • CWE-451: User Interface (UI) Misrepresentation of Critical Information (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-3: Configuration Change Control (tight)
    • CM-5: Access Restrictions for Change (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight. (tight)
    • MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies. (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM03: Excessive Agency (tight)
Validate external input at the boundary

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-08: API Security (broad)
    • AIS-09: Input Validation (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • AIS-04: Secure Application Development Lifecycle (broad)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.9: Robustness (broad)
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0049: Exploit Public-Facing Application (broad)
    • AML.T0050: Command and Scripting Interpreter (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (broad)
    • CWE-20: Improper Input Validation (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-10: Information Input Validation (tight)
    • SI-10(5): Restrict Inputs to Trusted Sources and Approved Formats (tight)
    • SI-10(6): Injection Prevention (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V2: Validation and Business Logic (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • input-validation: Input Validation Cheat Sheet (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C3: Validate all Input & Handle Exceptions (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A05: Injection (tight)
Trust between agents is earned, not inherited

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • IAM-05: Least Privilege (broad)
    • IAM-13: Strong Authentication (broad)
    • IAM-15: Authorization Mechanisms (broad)
    • AIS-11: Agents Security Boundaries (tight)
    • IAM-18: Agent Access Restriction (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • IAM-05: Least Privilege (broad)
    • IAM-12: Unique Identities (broad)
    • IAM-13: Strong Authentication (broad)
    • IAM-15: Authorization Mechanisms (broad)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0051.001: Indirect (broad)
    • AML.T0053: AI Agent Tool Invocation (broad)
    • AML.T0073: Impersonation (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-501: Trust Boundary Violation (broad)
    • CWE-272: Least Privilege Violation (tight)
    • CWE-290: Authentication Bypass by Spoofing (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AC-3: Access Enforcement (broad)
    • AC-6: Least Privilege (broad)
    • IA-9: Service Identification and Authentication (tight)
    • SI-10: Information Input Validation (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI10: Rogue Agents (broad)
    • ASI03: Identity and Privilege Abuse (tight)
    • ASI07: Insecure Inter-Agent Communication (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • ai-agent-security: AI Agent Security Cheat Sheet (broad)
    • mcp-security: MCP Security Cheat Sheet (broad)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP07: Insufficient Authentication & Authorization (tight)
Key management

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • CEK-01: Encryption and Key Management Policy and Procedures (broad)
    • CEK-10: Key Generation (tight)
    • CEK-11: Key Purpose (tight)
    • CEK-12: Key Rotation (tight)
    • CEK-13: Key Revocation (tight)
    • CEK-14: Key Destruction (tight)
    • CEK-21: Key Inventory Management (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • CEK-01: Encryption and Key Management Policy and Procedures (broad)
    • CEK-10: Key Generation (tight)
    • CEK-11: Key Purpose (tight)
    • CEK-12: Key Rotation (tight)
    • CEK-13: Key Revocation (tight)
    • CEK-14: Key Destruction (tight)
    • CEK-21: Key Inventory Management (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0012: Valid Accounts (broad)
    • AML.T0055: Unsecured Credentials (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-323: Reusing a Nonce, Key Pair in Encryption (broad)
    • CWE-321: Use of Hard-coded Cryptographic Key (tight)
    • CWE-324: Use of a Key Past its Expiration Date (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • IA-5(7): No Embedded Unencrypted Static Authenticators (tight)
    • SC-12: Cryptographic Key Establishment and Management (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V11: Cryptography (broad)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • key-management: Key Management Cheat Sheet (tight)
Least-privilege tool and file access

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-13: AI Sandboxing (broad)
    • IAM-10: Management of Privileged Access Roles (broad)
    • UEM-02: Application and Service Approval (broad)
    • IAM-05: Least Privilege (tight)
    • IAM-18: Agent Access Restriction (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • IAM-10: Management of Privileged Access Roles (broad)
    • UEM-02: Application and Service Approval (broad)
    • IAM-05: Least Privilege (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0053: AI Agent Tool Invocation (broad)
    • AML.T0086: Exfiltration via AI Agent Tool Invocation (broad)
    • AML.T0098: AI Agent Tool Credential Harvesting (broad)
    • AML.T0101: Data Destruction via AI Agent Tool Invocation (broad)
    • AML.T0112.000: Local AI Agent (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-269: Improper Privilege Management (broad)
    • CWE-250: Execution with Unnecessary Privileges (tight)
    • CWE-272: Least Privilege Violation (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SC-39: Process Isolation (broad)
    • AC-6: Least Privilege (tight)
    • CM-7: Least Functionality (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI02: Tool Misuse and Exploitation (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM03: Excessive Agency (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP02: Privilege Escalation via Scope Creep (tight)
Redact sensitive content from logs

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • DSP-17: Sensitive Data Protection (broad)
    • LOG-08: Audit Logs Sanitization (tight)
    • LOG-09: Log Records (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • DSP-08: Data Privacy by Design and Default (broad)
    • DSP-17: Sensitive Data Protection (broad)
    • LOG-08: Audit Logs Sanitization (tight)
    • LOG-09: Log Records (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.8: Privacy (broad)
    • A.11: Security (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.8: AI system recording of event logs (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0055: Unsecured Credentials (broad)
    • AML.T0063: Discover AI Model Outputs (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (broad)
    • CWE-532: Insertion of Sensitive Information into Log File (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AU-3(3): Limit Personally Identifiable Information Elements (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V16: Security Logging and Error Handling (broad)
Social pressure is not authorization

View this rule on GitHub

  • MITRE CWE (4.20): mitigates weakness
    • CWE-807: Reliance on Untrusted Inputs in a Security Decision (tight)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI09: Human-Agent Trust Exploitation (tight)
Encode output for its sink

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-10: Output Validation (broad)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • AIS-04: Secure Application Development Lifecycle (broad)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0050: Command and Scripting Interpreter (broad)
    • AML.T0113: Steal Web Session Cookie (broad)
    • AML.T0077: LLM Response Rendering (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-116: Improper Encoding or Escaping of Output (broad)
    • CWE-838: Inappropriate Encoding for Output Context (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-10(6): Injection Prevention (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V1: Encoding and Sanitization (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • cross-site-scripting-prevention: Cross Site Scripting Prevention Cheat Sheet (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A05: Injection (broad)
Generated output is untrusted input

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-05: Application Security Testing (broad)
    • AIS-09: Input Validation (broad)
    • AIS-13: AI Sandboxing (broad)
    • TVM-13: Guardrails (broad)
    • AIS-10: Output Validation (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • AIS-04: Secure Application Development Lifecycle (broad)
    • AIS-05: Application Security Testing (broad)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.9: Robustness (broad)
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0050: Command and Scripting Interpreter (broad)
    • AML.T0077: LLM Response Rendering (tight)
    • AML.T0102: Generate Malicious Commands (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-20: Improper Input Validation (broad)
    • CWE-1426: Improper Validation of Generative AI Output (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-11: Developer Testing and Evaluation (broad)
    • SI-10(6): Injection Prevention (tight)
    • SI-15: Information Output Filtering (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.1: Organizational policies and practices are in place to foster a critical thinking and safety-first mindset. (broad)
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
    • MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
    • PW.7.1: Decide on code review and analysis (broad)
    • PW.8.1: Decide on executable code testing (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V1: Encoding and Sanitization (tight)
    • V2: Validation and Business Logic (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • cross-site-scripting-prevention: Cross Site Scripting Prevention Cheat Sheet (tight)
    • injection-prevention: Injection Prevention Cheat Sheet (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM10: Improper Output Handling (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C3: Validate all Input & Handle Exceptions (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A05: Injection (broad)
Referenced instructions are pinned and re-verified

View this rule on GitHub

  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0010: AI Supply Chain Compromise (broad)
    • AML.T0051: LLM Prompt Injection (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-353: Missing Support for Integrity Check (broad)
    • CWE-494: Download of Code Without Integrity Check (broad)
    • CWE-829: Inclusion of Functionality from Untrusted Control Sphere (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM03: Excessive Agency (broad)
Resist data, model, and memory poisoning

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • MDS-06: Adversarial Attack Analysis (broad)
    • MDS-07: Robustness against Adversarial Attack / Model Hardening (broad)
    • DSP-21: Data Poisoning Prevention & Detection (tight)
    • DSP-23: Data Integrity Check (tight)
    • MDS-01: Training Pipeline Security (tight)
    • MDS-08: Model Integrity Checks (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
    • B.5: Risk sources related to machine learning (broad)
    • A.4: Availability and quality of training and test data (tight)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.7.3: Acquisition of data (broad)
    • A.7.4: Quality of data for AI systems (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0010.002: Data (broad)
    • AML.T0066: Retrieval Content Crafting (broad)
    • AML.T0018.000: Poison AI Model (tight)
    • AML.T0020: Poison Training Data (tight)
    • AML.T0059: Erode Dataset Integrity (tight)
    • AML.T0070: RAG Poisoning (tight)
    • AML.T0071: False RAG Entry Injection (tight)
    • AML.T0080: AI Agent Context Poisoning (tight)
    • AML.T0099: AI Agent Tool Data Poisoning (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-348: Use of Less Trusted Source (broad)
    • CWE-345: Insufficient Verification of Data Authenticity (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-7: Software, Firmware, and Information Integrity (tight)
    • SI-10(5): Restrict Inputs to Trusted Sources and Approved Formats (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI06: Memory & Context Poisoning (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM05: Data and Model Poisoning (tight)
    • LLM09: Vector and Embedding Weaknesses (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP03: Tool Poisoning (tight)
Prefer removing a path over constraining or monitoring it

View this rule on GitHub

  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AC-6: Least Privilege (broad)
    • SC-7: Boundary Protection (broad)
    • CM-7: Least Functionality (tight)
A preview makes no change

View this rule on GitHub

  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI09: Human-Agent Trust Exploitation (tight)
Higher-trust instructions outrank lower-trust ones

View this rule on GitHub

  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0051: LLM Prompt Injection (broad)
    • AML.T0054: LLM Jailbreak (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-1427: Improper Neutralization of Input Used for LLM Prompting (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM01: Prompt Injection (broad)
Protect audit records from the actors they record

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • LOG-04: Audit Logs Access and Accountability (broad)
    • LOG-02: Audit Logs Protection (tight)
    • LOG-10: Audit Records Protection (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • LOG-04: Audit Logs Access and Accountability (broad)
    • LOG-02: Audit Logs Protection (tight)
    • LOG-10: Audit Records Protection (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-732: Incorrect Permission Assignment for Critical Resource (broad)
    • CWE-471: Modification of Assumed-Immutable Data (MAID) (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AU-9: Protection of Audit Information (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V16: Security Logging and Error Handling (broad)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • logging: Logging Cheat Sheet (broad)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP08: Lack of Audit and Telemetry (broad)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A09: Security Logging & Alerting Failures (broad)
Reject known-vulnerable dependency versions

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • TVM-03: Vulnerability Identification (broad)
    • TVM-06: External Library Vulnerabilities (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • TVM-03: Vulnerability Identification (broad)
    • TVM-06: External Library Vulnerabilities (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-1395: Dependency on Vulnerable Third-Party Component (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • RA-5: Vulnerability Monitoring and Scanning (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.4.4: Verify third-party components meet requirements (tight)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI04: Agentic Supply Chain Vulnerabilities (broad)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • vulnerable-dependency-management: Vulnerable Dependency Management Cheat Sheet (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM04: Supply Chain (broad)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP04: Software Supply Chain Attacks & Dependency Tampering (broad)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C6: Keep your Components Secure (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A03: Software Supply Chain Failures (tight)
Publish artefacts with verifiable integrity

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • MDS-09: Model Signing/Ownership Verification (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-345: Insufficient Verification of Data Authenticity (broad)
    • CWE-353: Missing Support for Integrity Check (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-7: Software, Firmware, and Information Integrity (broad)
    • SR-4: Provenance (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PS.3.2: Maintain provenance data (SBOM) per release (broad)
    • PS.2.1: Provide software integrity verification information (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • software-supply-chain-security: Software Supply Chain Security Cheat Sheet (broad)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A08: Software or Data Integrity Failures (broad)
Deserialize untrusted data only as data

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-09: Input Validation (broad)
    • MDS-02: Model Artifact Scanning (broad)
    • MDS-13: Secure Model Format (broad)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • AIS-04: Secure Application Development Lifecycle (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-20: Improper Input Validation (broad)
    • CWE-502: Deserialization of Untrusted Data (tight)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI05: Unexpected Code Execution (RCE) (broad)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • deserialization: Deserialization Cheat Sheet (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A08: Software or Data Integrity Failures (broad)
Secure by default configuration

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • CCC-06: Change Management Baseline (broad)
    • CCC-07: Detection of Baseline Deviation (broad)
    • AIS-02: Application Security Baseline Requirements (tight)
    • I&S-04: OS Hardening and Base Controls (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • CCC-06: Change Management Baseline (broad)
    • CCC-07: Detection of Baseline Deviation (broad)
    • AIS-02: Application Security Baseline Requirements (tight)
    • I&S-04: OS Hardening and Base Controls (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0049: Exploit Public-Facing Application (broad)
    • AML.T0063: Discover AI Model Outputs (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-1188: Initialization of a Resource with an Insecure Default (tight)
    • CWE-1269: Product Released in Non-Release Configuration (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CM-6: Configuration Settings (tight)
    • CM-7: Least Functionality (tight)
    • SI-11: Error Handling (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.9.1: Define a secure default configuration baseline (tight)
    • PW.9.2: Implement and document secure default settings (tight)
  • OWASP API Security Top 10 (2023): addresses risk
    • API8: Security Misconfiguration (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V13: Configuration (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C5: Secure By Default Configurations (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A02: Security Misconfiguration (tight)
Security logging with traceable context

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • LOG-01: Logging and Monitoring Policy and Procedures (broad)
    • LOG-07: Logging Scope (tight)
    • LOG-09: Log Records (tight)
    • LOG-12: Transaction/Activity Logging (tight)
    • LOG-13: Access Control Logs (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • LOG-01: Logging and Monitoring Policy and Procedures (broad)
    • LOG-07: Logging Scope (tight)
    • LOG-09: Log Records (tight)
    • LOG-12: Transaction/Activity Logging (tight)
    • LOG-13: Access Control Logs (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.2: Accountability (broad)
    • A.11: Security (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.8: AI system recording of event logs (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-778: Insufficient Logging (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • AU-2: Event Logging (tight)
    • AU-3: Content of Audit Records (tight)
    • AU-12: Audit Record Generation (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. (broad)
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V16: Security Logging and Error Handling (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • logging: Logging Cheat Sheet (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP08: Lack of Audit and Telemetry (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C9: Implement Security Logging and Monitoring (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A09: Security Logging & Alerting Failures (tight)
Secure session and token handling

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • CEK-03: Data Protection (broad)
    • IAM-13: Strong Authentication (broad)
    • IAM-14: Credentials Management (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • CEK-03: Data Protection (broad)
    • IAM-13: Strong Authentication (broad)
    • IAM-14: Credentials Management (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0055: Unsecured Credentials (broad)
    • AML.T0091.000: Application Access Token (broad)
    • AML.T0091.001: Web Session Cookie (broad)
    • AML.T0113: Steal Web Session Cookie (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-522: Insufficiently Protected Credentials (broad)
    • CWE-331: Insufficient Entropy (tight)
    • CWE-352: Cross-Site Request Forgery (CSRF) (tight)
    • CWE-613: Insufficient Session Expiration (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • IA-5: Authenticator Management (broad)
    • SC-23: Session Authenticity (tight)
    • SC-23(1): Invalidate Session Identifiers at Logout (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.5.1: Follow secure coding practices (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V7: Session Management (tight)
    • V9: Self-contained Tokens (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • cross-site-request-forgery-prevention: Cross-Site Request Forgery Prevention Cheat Sheet (broad)
    • session-management: Session Management Cheat Sheet (tight)
Validate server-initiated requests

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-09: Input Validation (broad)
    • I&S-09: Network Defense (broad)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • AIS-04: Secure Application Development Lifecycle (broad)
    • I&S-09: Network Defense (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-918: Server-Side Request Forgery (SSRF) (tight)
  • OWASP API Security Top 10 (2023): addresses risk
    • API7: Server Side Request Forgery (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • server-side-request-forgery-prevention: Server Side Request Forgery Prevention Cheat Sheet (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C10: Stop Server Side Request Forgery (tight)
Resolve privileged filesystem paths against symlink races

View this rule on GitHub

  • MITRE CWE (4.20): mitigates weakness
    • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition (broad)
    • CWE-59: Improper Link Resolution Before File Access ('Link Following') (tight)
    • CWE-363: Race Condition Enabling Link Following (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V5: File Handling (broad)
Threat-model new trust boundaries before implementation

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • TVM-04: Threat Analysis and Modelling (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • TVM-04: Threat Analysis and Modelling (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • 6.4.2: Risk identification (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-8: Security and Privacy Engineering Principles (broad)
    • SA-11(2): Threat Modeling and Vulnerability Analyses (tight)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.1.1: Use risk modeling to assess software risk (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • threat-modeling: Threat Modeling Cheat Sheet (tight)
  • OWASP Top 10 Proactive Controls (4.0.0): supports control
    • C4: Address Security from the Start (tight)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A06: Insecure Design (broad)
Validate tool arguments before use

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-09: Input Validation (tight)
    • AIS-11: Agents Security Boundaries (tight)
    • AIS-13: AI Sandboxing (tight)
    • IAM-18: Agent Access Restriction (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • AIS-04: Secure Application Development Lifecycle (broad)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0050: Command and Scripting Interpreter (broad)
    • AML.T0102: Generate Malicious Commands (broad)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (broad)
    • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') (broad)
    • CWE-20: Improper Input Validation (tight)
    • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-10: Information Input Validation (tight)
    • SI-10(6): Injection Prevention (tight)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI05: Unexpected Code Execution (RCE) (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V2: Validation and Business Logic (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP05: Command Injection & Execution (broad)
  • OWASP Top 10 (Web Application Security Risks) (2025): addresses risk
    • A05: Injection (broad)
Untrusted content is data, not instructions

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-09: Input Validation (broad)
    • AIS-11: Agents Security Boundaries (broad)
    • DSP-24: Data Differentiation and Relevance (broad)
    • TVM-02: Malware and Malicious Instructions Protection Policy and Procedures (broad)
    • TVM-13: Guardrails (broad)
    • AIS-15: Prompt Differentiation (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • AIS-04: Secure Application Development Lifecycle (broad)
    • TVM-02: Malware and Malicious Instructions Protection Policy and Procedures (broad)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.9: Robustness (broad)
    • A.11: Security (broad)
    • B.5: Risk sources related to machine learning (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0068: LLM Prompt Obfuscation (broad)
    • AML.T0070: RAG Poisoning (broad)
    • AML.T0078: Drive-by Compromise (broad)
    • AML.T0080: AI Agent Context Poisoning (broad)
    • AML.T0092: Manipulate User LLM Chat History (broad)
    • AML.T0094: Delay Execution of LLM Instructions (broad)
    • AML.T0099: AI Agent Tool Data Poisoning (broad)
    • AML.T0051.000: Direct (tight)
    • AML.T0051.001: Indirect (tight)
    • AML.T0051.002: Triggered (tight)
    • AML.T0054: LLM Jailbreak (tight)
    • AML.T0093: Prompt Infiltration via Public-Facing Application (tight)
    • AML.T0100: AI Agent Clickbait (tight)
    • AML.T0110: AI Agent Tool Poisoning (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-1427: Improper Neutralization of Input Used for LLM Prompting (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-10(6): Injection Prevention (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • llm-prompt-injection-prevention: LLM Prompt Injection Prevention Cheat Sheet (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM01: Prompt Injection (tight)
  • OWASP MCP Top 10 (2025): addresses risk
    • MCP06: Intent Flow Subversion (tight)
    • MCP10: Context Injection & Over-Sharing (tight)
Verify a dependency exists before adding it

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-12: Source Code Management (broad)
    • MDS-02: Model Artifact Scanning (broad)
    • MDS-12: Open Model Risk Assessment (broad)
    • STA-09: Service Bill of Material (BOM) (broad)
    • TVM-06: External Library Vulnerabilities (broad)
    • UEM-02: Application and Service Approval (broad)
    • STA-08: Supply Chain Inventory (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • STA-01: Supply Chain Risk Management Policies and Procedures (broad)
    • STA-03: SSRM Supply Chain (broad)
    • STA-09: Service Bill of Material (BOM) (broad)
    • TVM-06: External Library Vulnerabilities (broad)
    • UEM-02: Application and Service Approval (broad)
    • STA-08: Supply Chain Inventory (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.11: Security (broad)
    • B.5: Risk sources related to machine learning (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0011.001: Malicious Package (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-1357: Reliance on Insufficiently Trustworthy Component (broad)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 6.1: Policies and procedures are in place that address AI risks associated with third-party entities. (broad)
    • MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. (broad)
  • NIST Secure Software Development Framework (1.1 (SP 800-218)): supports control
    • PW.4.1: Acquire well-secured third-party components (tight)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM04: Supply Chain (tight)
Bounded consumption and safe failure

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • AIS-13: AI Sandboxing (broad)
    • MDS-11: Model Failure (broad)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • I&S-02: Capacity and Resource Planning (broad)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.9: Robustness (broad)
    • A.11: Security (broad)
    • B.4: Level of automation (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.6.2.6: AI system operation and monitoring (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0046: Spamming AI System with Chaff Data (broad)
    • AML.T0029: Denial of AI Service (tight)
    • AML.T0034.000: Excessive Queries (tight)
    • AML.T0034.001: Resource-Intensive Queries (tight)
    • AML.T0034.002: Agentic Resource Consumption (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-674: Uncontrolled Recursion (broad)
    • CWE-834: Excessive Iteration (broad)
    • CWE-400: Uncontrolled Resource Consumption (tight)
    • CWE-770: Allocation of Resources Without Limits or Throttling (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SC-5: Denial-of-service Protection (tight)
    • SC-6: Resource Availability (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP API Security Top 10 (2023): addresses risk
    • API4: Unrestricted Resource Consumption (tight)
  • OWASP Top 10 for Agentic Applications (2026): addresses risk
    • ASI08: Cascading Failures (tight)
  • OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04)): aligns with guidance
    • denial-of-service: Denial of Service Cheat Sheet (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM06: Unbounded Consumption (tight)
A destructive operation requires a verified restore path

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • BCR-08: Backup (broad)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • BCR-08: Backup (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • CP-9: System Backup (broad)
    • CP-9(1): Testing for Reliability and Integrity (broad)
    • CP-10: System Recovery and Reconstitution (broad)
    • CP-9(2): Test Restoration Using Sampling (tight)
Minimize personal data sent to AI services

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • DSP-17: Sensitive Data Protection (broad)
    • DSP-08: Data Privacy by Design and Default (tight)
    • DSP-12: Limitation of Purpose in Personal Data Processing (tight)
    • DSP-22: Privacy Enhancing Technologies (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • DSP-17: Sensitive Data Protection (broad)
    • DSP-08: Data Privacy by Design and Default (tight)
    • DSP-12: Limitation of Purpose in Personal Data Processing (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.8: Privacy (broad)
  • ISO/IEC 42001:2023 AI management system (2023): supports control
    • A.7.6: Data preparation (broad)
  • MITRE ATLAS (2026.06): mitigates technique
    • AML.T0024.000: Infer Training Data Membership (broad)
    • AML.T0024.001: Invert AI Model (broad)
    • AML.T0057: LLM Data Leakage (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor (broad)
    • CWE-201: Insertion of Sensitive Information Into Sent Data (tight)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SI-19: De-identification (broad)
    • SI-12(1): Limit Personally Identifiable Information Elements (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • MAP 4.2: Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V14: Data Protection (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM02: Sensitive Information Disclosure (tight)
Honour residency, retention, and deletion

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • DSP-11: Personal Data Access, Reversal, Rectification and Deletion (tight)
    • DSP-16: Data Retention and Deletion (tight)
    • DSP-19: Data Location (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • DSP-11: Personal Data Access, Reversal, Rectification and Deletion (tight)
    • DSP-16: Data Retention and Deletion (tight)
    • DSP-19: Data Location (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.8: Privacy (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-9(5): Processing, Storage, and Service Location (tight)
    • SI-12: Information Management and Retention (tight)
    • SI-12(3): Information Disposal (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented. (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V14: Data Protection (broad)
Bind personal-data use to its authorized purpose

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • DSP-12: Limitation of Purpose in Personal Data Processing (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • DSP-12: Limitation of Purpose in Personal Data Processing (tight)
  • ISO/IEC 23894:2023 AI guidance on risk management (2023): aligns with guidance
    • A.8: Privacy (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • PT-2: Authority to Process Personally Identifiable Information (tight)
    • PT-3: Personally Identifiable Information Processing Purposes (tight)
  • NIST AI Risk Management Framework (1.0 (NIST AI 100-1)): aligns with guidance
    • GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented. (broad)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V14: Data Protection (broad)
Fixtures and examples use synthetic data

View this rule on GitHub

  • CSA AI Controls Matrix (1.1.0): supports control
    • DSP-15: Limitation of Production Data Use (tight)
  • CSA Cloud Controls Matrix (4.1.0): supports control
    • DSP-15: Limitation of Production Data Use (tight)
  • MITRE CWE (4.20): mitigates weakness
    • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor (broad)
    • CWE-531: Inclusion of Sensitive Information in Test Code (broad)
  • NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0)): supports control
    • SA-3(2): Use of Live or Operational Data (tight)
    • SA-15(9): Use of Live Data (tight)
  • OWASP Application Security Verification Standard (5.0.0): supports control
    • V14: Data Protection (broad)
  • OWASP Top 10 for LLM Applications (2026): addresses risk
    • LLM02: Sensitive Information Disclosure (broad)

Reverse view

By framework

The same mappings read the other way. Open a framework to see each of its identifiers that a rule references, and the rules that reference it. Identifiers that no rule references are not listed; the registry above states the coverage honestly instead.

CSA AI Controls Matrix (1.1.0)

supports control. 79 identifiers referenced from a curated subset of the edition.

CSA Cloud Controls Matrix (4.1.0)

supports control. 57 identifiers referenced from a curated subset of the edition.

ISO/IEC 23894:2023 AI guidance on risk management (2023)

aligns with guidance. 14 identifiers referenced from a curated subset of the edition.

ISO/IEC 42001:2023 AI management system (2023)

supports control. 18 identifiers referenced from a curated subset of the edition.

MITRE ATLAS (2026.06)

mitigates technique. 67 identifiers referenced from a curated subset of the edition.

MITRE CWE (4.20)

mitigates weakness. 72 identifiers referenced from a curated subset of the edition.

NIST SP 800-53 Security and Privacy Controls (Rev 5 (catalog 5.2.0))

supports control. 67 identifiers referenced from a curated subset of the edition.

NIST AI Risk Management Framework (1.0 (NIST AI 100-1))

aligns with guidance. 24 identifiers referenced from a curated subset of the edition.

NIST Secure Software Development Framework (1.1 (SP 800-218))

supports control. 20 identifiers referenced from a curated subset of the edition.

OWASP API Security Top 10 (2023)

addresses risk. 8 identifiers referenced from a curated subset of the edition.

OWASP Top 10 for Agentic Applications (2026)

addresses risk. 9 identifiers referenced from a curated subset of the edition.

OWASP Application Security Verification Standard (5.0.0)

supports control. 13 identifiers referenced from a curated subset of the edition.

OWASP Cheat Sheet Series (commit f54d8ded2764010ecacd0deb87e1586da32d41dd (2026-07-04))

aligns with guidance. 27 identifiers referenced from a curated subset of the edition.

OWASP Top 10 for LLM Applications (2026)

addresses risk. 10 of 10 identifiers referenced.

OWASP MCP Top 10 (2025)

addresses risk. 10 of 10 identifiers referenced.

OWASP Top 10 Proactive Controls (4.0.0)

supports control. 9 identifiers referenced from a curated subset of the edition.

OWASP Top 10 (Web Application Security Risks) (2025)

addresses risk. 10 of 10 identifiers referenced.

Sources, exports, and attribution

Take the data, and where it comes from

The full crosswalk is available as data for governance tooling:

  • mappings.csv: flat, one row per rule-and-identifier pair, the join key most GRC tools expect.
  • mappings.json: the framework registry once, plus a flat array of every mapping.

Attribution and licensing for every framework referenced here are recorded in the project NOTICE. Framework identifiers and titles remain the property of their respective publishers where applicable (some, such as NIST material, are US-government public-domain works). No framework publisher endorses, sponsors, or is affiliated with this pack, and no publisher's name or marks are used to imply endorsement.