Several frameworks help organisations structure AI security and risk management.
NIST AI Risk Management Framework
A voluntary US framework organised around govern, map, measure and manage. Companion profiles address generative AI risks.
MITRE ATLAS
A knowledge base of adversary tactics and techniques against AI systems, modelled on MITRE ATT&CK, with case studies. Useful for threat modelling and red teaming.
OWASP Resources
The Top 10 for LLM Applications and related guides on agentic AI security give practical, developer-focused risks and mitigations.
ISO/IEC 42001
An international standard for AI management systems, certifiable like ISO 27001, covering governance and risk processes.
Government Guidance
National cybersecurity agencies have jointly published guidelines for secure AI system development and deployment.
Regulation
Laws such as the EU AI Act include cybersecurity and robustness requirements for certain AI systems.
Using Them
- Use ISO 42001 or NIST AI RMF for overall governance.
- Use OWASP and ATLAS for technical threat modelling and testing.
- Map controls to existing security programmes rather than creating parallel ones.