Standards & Frameworks
This section catalogues the authoritative standards and frameworks that define AI security and governance practice. Each page cites the final, in-force instrument with its identifier and a resolvable URL.
In This Section
| Standard | Identifier | Scope | Primary Source |
|---|---|---|---|
| NIST AI Risk Management Framework | NIST AI 100-1 | AI risk governance, core functions, profiles | NIST AI RMF |
| NIST Generative AI Profile | NIST AI 600-1 | GAI-specific risk mapping, 12 risk areas, 400+ actions | NIST AI 600-1 |
| ISO/IEC 42001:2023 | ISO/IEC 42001:2023 | AI management system, Annex A controls, conformity assessment | ISO 42001 |
| EU AI Act | Regulation (EU) 2024/1689 | Prohibited AI, high-risk requirements, GPAI obligations | EUR-Lex |
| OWASP LLM Top 10 | OWASP LLM Top 10 (2025) | LLM01–LLM10 vulnerability taxonomy | OWASP |
| MITRE ATLAS | MITRE ATLAS v2.3 | Adversarial tactics, techniques, and case studies | MITRE ATLAS |
How to Use This Section
- Start with the framework that matches your regulatory context (EU AI Act for EU deployments, ISO 42001 for certifiable management systems, NIST AI RMF for US federal or voluntary alignment).
- Map threats from MITRE ATLAS and OWASP LLM Top 10 to your system architecture.
- Implement controls from the Defences section aligned to the framework requirements.
- Prepare evidence using the Governance section for audits and conformity assessments.
Cross-Framework Mapping
The Standards Comparison page provides a detailed mapping of requirements across AI RMF, ISO 42001, EU AI Act, and OWASP — identifying overlaps, gaps, and where a single control satisfies multiple frameworks.