ai · security · skills
← Assessments

What a finished pack can look like

Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.

Govern · maturity coverage · 2 of 4

Your team adopted AI before you decided anything.

Security Operations. Answer for Northwind Retail.

Pick the line that matches where you are today, least to most mature. Each question is a real control objective; the verification note says where to confirm it. 12/12 to answer.

Re-assessing Northwind Retail. A rated sample: illustrative answers are loaded, nothing is saved. Change what improved and the maturity and the gate recompute live.

Security Monitoring
LOG-01Is there a documented logging & monitoring policy covering your AI systems and the data they touch?
LOG-03Are AI-relevant events — model calls, data access, anomalous prompts — actively monitored and alerted on?
LOG-02Are those audit logs protected from tampering and retained per policy?
LOG-05Are monitoring alerts triaged and responded to with tracked metrics (e.g. MTTR)?
Incident Response
SEF-01Is there a documented incident-response policy that covers AI-specific incidents?
SEF-03Do incident-response plans explicitly cover AI failure modes — model abuse, jailbreaks, data leakage?
SEF-04Are those plans tested — tabletop or live — against AI incident scenarios?
SEF-05Do you track incident-response metrics for AI incidents?
Model Security
MDS-02Are model artifacts scanned for integrity and tampering before deployment?
MDS-06Is adversarial-attack analysis — red-teaming, jailbreak testing — run against in-scope models?
AI Supported Development and Supply Chain Security
TVM-05Are detections updated from current AI threat intelligence?
Data Security
DSP-04Is data flowing through AI systems classified, so monitoring can prioritise sensitive flows?