Explore frameworks, threats, controls, vendors, research, and learning paths in one linked view. The graph is JSON-backed and structured for future graph-database migration.
AI management system standard for governance, accountability, and continual improvement.
Maps well to policy workflows, evidence management, and internal controls.
Information security management standard used to anchor AI security controls.
Useful where AI workloads inherit enterprise security control requirements.
Threat-driven taxonomy for common large language model attack paths.
Maps directly to prompt injection, leakage, abuse, and supply chain threats.
Adversary tactics and techniques for AI and machine learning attack analysis.
Supports threat-informed defense for model, data, and agent abuse scenarios.
Cloud Security Alliance guidance for AI control mapping and cloud assurance.
Connects AI governance to cloud security architecture and control inventories.
Regulatory framework for risk-based AI governance and documentation.
Relevant for control traceability, high-risk AI workflows, and compliance readiness.
Malicious instructions that alter model behavior or bypass policy boundaries.
Frequently mitigated with prompt inspection, guardrails, and contextual policy enforcement.
Hidden malicious instructions embedded in retrieved content or external data.
Requires content inspection, retrieval filtering, and output protection.
Incorrect or fabricated model output presented with undue confidence.
Mitigated with evaluation, guardrails, retrieval controls, and review workflows.
Extraction or replication of model behavior, weights, prompts, or sensitive configuration.
Requires access governance, watermarking, telemetry, and monitoring.
Tampering with training data, fine-tuning data, or model artifacts.
Defended through supply chain controls, validation, and red team testing.
Sensitive or regulated data disclosed through prompts, outputs, or logs.
Reduced with DLP, content controls, encryption, and classification.
Corruption of retrieval sources that influence model answers.
Mitigated with retrieval filtering, source trust controls, and monitoring.
Attacks against embeddings, indexes, or retrieval stores used in AI systems.
Requires access control, segmentation, and integrity monitoring.
Unapproved AI services or tools used outside governance controls.
Detected through discovery, monitoring, and identity-aware policy.
Abuse of autonomous or semi-autonomous agent workflows.
Managed through least privilege, tool allow lists, and runtime monitoring.
Misuse of Model Context Protocol tools, servers, or connectors.
Needs identity enforcement, allow lists, and session logging.
Sensitive prompt content exposed through logs, model responses, or users.
Address with output filtering, logging controls, and data minimization.
Compromise of models, packages, connectors, or dependencies used by AI systems.
Reduced with model evaluation, secrets management, and integrity controls.
Central policy and routing layer for AI traffic.
Acts as the control plane between users, applications, and model providers.
Inline prompt inspection and filtering control.
Best placed before model invocation and tool execution.
Validation of generated outputs before delivery.
Often combined with moderation, policy checks, and redaction.
Policy boundaries for safe and intended AI behavior.
Effective when paired with policy engine, logging, and review loops.
Moderation and safety classification for AI inputs and outputs.
Use with moderation rules, brand safety, and escalation workflows.
Identity control plane for user and service access.
Supports SSO, conditional access, and session governance.
Role-based access control for AI systems and tools.
Best applied to model access, tool use, and operational approvals.
Managed lifecycle for API keys, tokens, and credentials.
Should integrate with KMS, vaults, and CI/CD pipelines.
Data loss prevention for prompts, context, and outputs.
Requires classification, policy tuning, and exception handling.
Encryption for data at rest, in transit, and in protected workflows.
Pair with key management, certificates, and service boundaries.
Security event collection and correlation for AI telemetry.
Should ingest AI events, model calls, and policy outcomes.
Automated response orchestration for AI-related alerts and incidents.
Use playbooks to contain model abuse, data leakage, and policy violations.
Audit and operational logging for AI workflows.
Capture model requests, responses, prompt actions, and policy decisions.
Ongoing monitoring of model behavior, policy events, and anomalies.
May include alerting, baselining, and operational dashboards.
Testing and validation of model behavior before release.
Use structured test suites, adversarial prompts, and acceptance thresholds.
Controls applied during live AI execution.
Supports inline and out-of-band enforcement.
Adversarial validation of models, prompts, and agent workflows.
Exercises should cover prompt attacks, tool abuse, and retrieval manipulation.
Managed OpenAI service in Azure for enterprise AI workloads.
Often used with Azure policy controls, content safety, and logging.
AWS foundation model platform for enterprise AI services.
Integrates with IAM, CloudTrail, and governance-oriented workflows.
Google Cloud AI platform for model operations and deployment.
Works with Cloud Logging, DLP, and multi-region cloud control patterns.
Enterprise model provider with Claude models.
Usually controlled through SSO, gateways, and logging pipelines.
Enterprise model provider and API platform.
Should be paired with policy enforcement, telemetry, and access governance.
Google model family for enterprise AI applications.
Commonly paired with Google Cloud telemetry and DLP.
Open-weight model family for self-managed deployments.
Requires stronger model validation and runtime monitoring.
Model provider used in enterprise and self-managed scenarios.
Should be coupled with control validation and logging.
Retrieval stores and embedding indexes for RAG applications.
Needs access controls, integrity checks, and poisoning resistance.
Application framework for orchestrating LLM and tool workflows.
Needs guardrails, prompt controls, and runtime monitoring.
Application orchestration framework for AI-enabled systems.
Should be paired with identity, logging, and policy controls.
Model Context Protocol for tool and context integration.
Needs authentication, tool allow lists, and session logging.
Frameworks for agent orchestration and tool calling.
Should use least privilege, sandboxing, and runtime detection.
Platforms that centralize AI routing, policy, and telemetry.
Commonly used with identity, logging, and content controls.
Data security posture management platforms for AI data exposure control.
Often supports classification, discovery, and policy workflows.
Products that monitor and enforce controls during live AI execution.
Used inline or out of band for live prompts and model calls.
Monitoring and assurance platforms for model behavior and drift.
Often integrates with CI/CD and observability stacks.
Tools for policy lifecycle, accountability, and governance evidence.
Useful for control mapping, approvals, and governance workflows.
Controls for moderation, policy enforcement, and unsafe content handling.
Typically used for prompts, responses, and multimodal content.
Platforms that detect, filter, and govern prompt-based attacks.
Works alongside gateways, moderation, and runtime controls.
Identity and access vendors relevant to AI system control planes.
Applies to users, services, and machine identities.
Enterprise platform vendor with identity, data, and AI security capabilities.
Relevant across identity, governance, DLP, and AI service layers.
Enterprise model provider with admin controls and access governance.
Should be wrapped with identity, logging, and output controls.
Model provider for governed enterprise AI workloads.
Usually depends on customer-side governance and monitoring.
Cloud platform vendor with Bedrock, guardrails, and security services.
Supports identity, logging, and policy integration.
Cloud AI platform vendor with Vertex AI and security tooling.
Pairs well with logging, DLP, and control mappings.
Identity security and privileged access vendor relevant to AI access control.
Supports secrets management and machine identity controls.
Identity governance vendor relevant to AI access certification and reviews.
Useful for identity governance in AI workflows and approvals.
Prompt security vendor focused on guardrails and content policy enforcement.
Often used inline between users and model endpoints.
Model security and red teaming vendor for AI supply chain assurance.
Supports release validation and adversarial testing.
Runtime detection and model threat protection vendor.
Useful for operational monitoring and AI incident response.
Employee AI governance and prompt protection vendor.
Combines prompt security, governance, and endpoint controls.
Research article on enterprise prompt and response security evaluation.
Useful for control selection, vendor review, and deployment planning.
Research article on runtime detection and enforcement for AI systems.
Useful for evaluating inline and out-of-band detection patterns.
Original evaluation methodology for enterprise AI security scoring.
Maps security, governance, compliance, deployment, identity, monitoring, data protection, and supportability.
Framework convergence and evidence readiness research for AI security programs.
Useful for standards mapping, compliance, and audit preparation.
Framework for evaluating AI vendors without rankings or proprietary scoring claims.
Connects capabilities, deployment fit, integrations, and enterprise support model.
How enterprise architecture teams redesign control planes for secure AI adoption.
Useful for architecture reviews, platform engineering, and cloud planning.
Market and threat trends shaping the AI security landscape.
Useful for SOC planning, red team scoping, and governance decisions.
Hands-on lab for testing prompt injection scenarios and mitigations.
Pairs with red team exercises and content safety control testing.
Lab for retrieval security, DLP, and poisoning resistance patterns.
Useful for vector database and context trust evaluation.
Lab for model and dependency integrity validation.
Use for model evaluation, artifact review, and secrets validation.
Executive learning path for governance, risk, and operating model decisions.
Focus on policy, risk reporting, and decision traceability.
Architecture path for control plane design and platform integration.
Focus on identity, gateways, telemetry, and deployment boundaries.
Operational path for monitoring, detection, and incident response.
Focus on logs, SIEM, SOAR, and runtime detection.
Hands-on path for adversarial AI testing and scenario development.
Focus on abuse cases, adversarial prompts, and validation exercises.
Path for framework mapping, evidence, and regulatory readiness.
Focus on ISO, NIST, and EU AI Act mapping.