Skip to content

AI Security Frameworks and Standards

An overview of frameworks for managing AI security: NIST AI RMF, MITRE ATLAS, ISO/IEC 42001, OWASP and more.

Editorial team 1 min read

Several frameworks help organisations structure AI security and risk management.

NIST AI Risk Management Framework

A voluntary US framework organised around govern, map, measure and manage. Companion profiles address generative AI risks.

MITRE ATLAS

A knowledge base of adversary tactics and techniques against AI systems, modelled on MITRE ATT&CK, with case studies. Useful for threat modelling and red teaming.

OWASP Resources

The Top 10 for LLM Applications and related guides on agentic AI security give practical, developer-focused risks and mitigations.

ISO/IEC 42001

An international standard for AI management systems, certifiable like ISO 27001, covering governance and risk processes.

Government Guidance

National cybersecurity agencies have jointly published guidelines for secure AI system development and deployment.

Regulation

Laws such as the EU AI Act include cybersecurity and robustness requirements for certain AI systems.

Using Them

  • Use ISO 42001 or NIST AI RMF for overall governance.
  • Use OWASP and ATLAS for technical threat modelling and testing.
  • Map controls to existing security programmes rather than creating parallel ones.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025