ai · security · skills

Controls · spine & crosswalk

One control spine.Assess once. Close with evidence.

For auditors and compliance leads: the AI Controls Matrix (AICM) is the MECE partition — 18 domains, 247 control objectives. NIST, ISO, and AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) reads are lenses on that one assess, not a second quiz. Jump a block below when you already know which part you need.

AICM domains, one assess4 domains · 45 controls

STA · Risk & Provider Assessment & Management

Supply Chain Management, Transparency, and Accountability

Providers and components in the AI supply chain need named accountability.

16 control objectives21 fitted skills
Analyzing SBOM For Supply Chain VulnerabilitiesDetecting Typosquatting Packages In Npm PypiImplementing Sigstore For Software Signing
Open STAdrill →

Procedural: How the practice runs: providers, supply chain, privacy, incidents.

Situation · what this is for

A usable control reference, not a catalogue dump.

You already answer to more than one regime. This page names the spine this research site runs on, how external standards map onto it, and what produces evidence — skills, tools, and ownership — without listing every control inline.

Step 1

Name the spine

AI Controls Matrix (AICM) is the MECE partition - one assess covers the control surface.

Step 2

Read the lens they asked for

NIST, ISO, AI-CAIQ and peers are lenses on that assess, not a second quiz.

Step 3

Close with evidence

Skills, tools, and ownership tell you what produces the artifact the auditor can file.

Maturity pressure-tests roll up through 12 AI Security Maturity Model (AISMM) categories onto this same AICM surface. 16 published instruments and 8 mapped regimes sit on that spine.

Lenses · assess once

When they ask for NIST or ISO, point here.

Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.

One methodology, every standardAssess once
AISMMAI Security Maturity Model3 domains · 12 categories · L1 to L5AICMAI Controls Matrix18 domains · 247 control objectivesCCMCloud Controls MatrixThe foundational dock you already runNIST AI RMFAI risk management frameNIST CSF 2.0Cybersecurity outcomesNIST SP 800-53Control catalogSOC 2Service organization controlsPCI DSSPayment card securityISO/IEC 42001AI management systemEU AI ActLegal obligations overlayISO/IEC 27001Information security (ISMS)ISO/IEC 27017Cloud security controlsISO/IEC 27018Cloud PII protection

A navigation map, not a conformance attestation: assess once on the AI Controls Matrix and read every standard as a lens on that one run. Privacy regimes arrive from skill tags in the panel below.

AI Security Maturity Model: The maturity read. The lit standards cover the same governance ground.

Spine · Foundational · Structural · Procedural

Three AISMM domains. One AICM spine.

Cycle the bands: each AI Security Maturity Model (AISMM) domain discloses its categories and the AI Controls Matrix (AICM) domains that roll up to them.

AISMM domains, AICM controls4 · 73

AI Security Maturity Model · Foundational

73 control objectives

01Governance2 AICM · 30

Who decides what, who is accountable, and how the rules are kept.

02Organization Management1 AICM · 9

How the organisation is structured and how change is controlled.

03IAM1 AICM · 18

Identity and Access Management: who can do what, with which credentials.

04Security Monitoring1 AICM · 16

Watching for trouble; logging what happened so it can be investigated.

One AI Controls Matrix (AICM) partition · 18 domains · 247 objectives. AISMM is the maturity lens, not a second catalog.

Foundational: The ground floor every function needs before AI specifics enter: governance, identity, monitoring.

Foundational inheritance · the CCM bridge

Dock the baseline you already run.See what each regime still cannot reach.

The AI Controls Matrix (AICM) extends the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM). For shared control ids, CSA’s own CCM crosswalk reaches the foundational standards below — including AICPA Trust Services Criteria 2017 (SOC 2) and Payment Card Industry Data Security Standard (PCI DSS). Reach varies by regime (cells marked “No Mapping” do not count). The remainder of 247 objectives is outside that dock — for NIST CSF v2.0, that delta is 63.

NIST CSF v2.0184/247 via CCM bridge · 16/18 domains · delta 63
NIST 800-53 rev 5186/247 via CCM bridge · 16/18 domains · delta 61
AICPA TSC 2017 (SOC 2)137/247 via CCM bridge · 16/18 domains · delta 110
PCI DSS v3.2.1129/247 via CCM bridge · 16/18 domains · delta 118
PCI DSS v4.0144/247 via CCM bridge · 16/18 domains · delta 103

Two CSA-authoritative hops: AICM→CCM by shared control id (the documented design of AICM), CCM→standard by CSA’s published CCM v4.0.13 mapping. Gap levels are not re-labelled across the bridge. HIPAA, GDPR, and India DPDP are not CCM columns — leverage the skill-mediated panel. NIST SSDF is not mapped in any source here and is omitted, not inferred.

Skills · regime leverage

Regimes the skill catalog already reaches.

Privacy & payments · leveraged from skills

Regimes the CSA sheets omit: joined through the skill catalog.

Modeled, from the skill catalog, not a Cloud Security Alliance sheet: published skills already tagged to a privacy or payments law, read against the control domain they touch.

General Data Protection Regulation (GDPR)205 skills · 5/18 domains
Which control domains?

Audit & Assurance · Data Security and Privacy Lifecycle Management · Governance, Risk and Compliance · Security Incident Management, E-Discovery, & Cloud Forensics · Supply Chain Management, Transparency, and Accountability

Health Insurance Portability and Accountability Act (HIPAA)32 skills · 3/18 domains
Which control domains?

Data Security and Privacy Lifecycle Management · Governance, Risk and Compliance · Security Incident Management, E-Discovery, & Cloud Forensics

India Digital Personal Data Protection Act, 2023 (DPDP)2 skills · 2/18 domains
Which control domains?

Data Security and Privacy Lifecycle Management · Governance, Risk and Compliance

Payment Card Industry Data Security Standard (PCI DSS)1 skill · 1/18 domains
Which control domains?

Governance, Risk and Compliance

Four ways in · one answer

Demand, obligation, instrument, ownership.

Mutually exclusive entry points onto the same domain detail. Open one. Leave with a takeaway — expand the catalog only when you already know what you are hunting.

Demand: AICM domain

Start from the control area. One AI Controls Matrix (AICM) domain opens objectives, audit guidance, and fitted skills - not a second questionnaire.

Pick a domain on the map above, then open the full drill page for that domain.

Use the domain map
Browse the demand catalog (power users)

All 18 control domains. Open one to see the skills inside — every skill belongs to exactly one.

CCCChange Control and Configuration ManagementTargeted capability expansion wave
DCSDatacenter SecurityInherited platform capability
IPYInteroperability & PortabilityTargeted capability expansion wave

Where next

Leave with a next move.

Pressure-test a function

Run the org maturity read on the same AICM spine — gate held between autonomy and control.

Open maturity

Build defender skills

Track 2: personal mastery on the same controls, seat by seat — gaps and path, nothing saved.

Open skills

Board and sample lenses

See every finished sample — board, function, mastery, and standards lenses — in one Reports index.

Open reports
Aligned with the Cloud Security Alliance (CSA) AI Controls Matrix (AICM) and AI Security Maturity Model (AISMM). Not a CSA certification or STAR listing. Verbatim control specifications stay research-access / owner-gated; public viewers get structure, counts, and samples.