365Architect

Standards & Frameworks

This section catalogues the authoritative standards and frameworks that define AI security and governance practice. Each page cites the final, in-force instrument with its identifier and a resolvable URL.

In This Section

Standard Identifier Scope Primary Source
NIST AI Risk Management Framework NIST AI 100-1 AI risk governance, core functions, profiles NIST AI RMF
NIST Generative AI Profile NIST AI 600-1 GAI-specific risk mapping, 12 risk areas, 400+ actions NIST AI 600-1
ISO/IEC 42001:2023 ISO/IEC 42001:2023 AI management system, Annex A controls, conformity assessment ISO 42001
EU AI Act Regulation (EU) 2024/1689 Prohibited AI, high-risk requirements, GPAI obligations EUR-Lex
OWASP LLM Top 10 OWASP LLM Top 10 (2025) LLM01–LLM10 vulnerability taxonomy OWASP
MITRE ATLAS MITRE ATLAS v2.3 Adversarial tactics, techniques, and case studies MITRE ATLAS

How to Use This Section

  1. Start with the framework that matches your regulatory context (EU AI Act for EU deployments, ISO 42001 for certifiable management systems, NIST AI RMF for US federal or voluntary alignment).
  2. Map threats from MITRE ATLAS and OWASP LLM Top 10 to your system architecture.
  3. Implement controls from the Defences section aligned to the framework requirements.
  4. Prepare evidence using the Governance section for audits and conformity assessments.

Cross-Framework Mapping

The Standards Comparison page provides a detailed mapping of requirements across AI RMF, ISO 42001, EU AI Act, and OWASP — identifying overlaps, gaps, and where a single control satisfies multiple frameworks.

Share

Keyboard Shortcuts

⌘ K
Open search
/
Focus search
?
Show shortcuts
b
Toggle bookmark
Alt+←
Previous page
Alt+→
Next page
Esc
Close overlay