Controls · spine & crosswalk
One control spine.Assess once. Close with evidence.
For auditors and compliance leads: the AI Controls Matrix (AICM) is the MECE partition — 18 domains, 247 control objectives. NIST, ISO, and AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) reads are lenses on that one assess, not a second quiz. Jump a block below when you already know which part you need.
GRC · Governance
Governance, Risk and Compliance
Who owns AI risk, who decides, and how policy becomes operating practice.
Foundational: Ground floor every function needs before AI-specific controls land.
Situation · what this is for
A usable control reference, not a catalogue dump.
You already answer to more than one regime. This page names the spine this research site runs on, how external standards map onto it, and what produces evidence — skills, tools, and ownership — without listing every control inline.
Step 1
Name the spine
AI Controls Matrix (AICM) is the MECE partition - one assess covers the control surface.
Step 2
Read the lens they asked for
NIST, ISO, AI-CAIQ and peers are lenses on that assess, not a second quiz.
Step 3
Close with evidence
Skills, tools, and ownership tell you what produces the artifact the auditor can file.
Maturity pressure-tests roll up through 12 AI Security Maturity Model (AISMM) categories onto this same AICM surface. 16 published instruments and 8 mapped regimes sit on that spine.
Lenses · assess once
When they ask for NIST or ISO, point here.
Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.
A navigation map, not a conformance attestation: assess once on the AI Controls Matrix and read every standard as a lens on that one run. Privacy regimes arrive from skill tags in the panel below.
AI Security Maturity Model: The maturity read. The lit standards cover the same governance ground.
Spine · Foundational · Structural · Procedural
Three AISMM domains. One AICM spine.
Cycle the bands: each AI Security Maturity Model (AISMM) domain discloses its categories and the AI Controls Matrix (AICM) domains that roll up to them.
AI Security Maturity Model · Foundational
73 control objectives
One AI Controls Matrix (AICM) partition · 18 domains · 247 objectives. AISMM is the maturity lens, not a second catalog.
Foundational: The ground floor every function needs before AI specifics enter: governance, identity, monitoring.
Foundational inheritance · the CCM bridge
Dock the baseline you already run.See what each regime still cannot reach.
The AI Controls Matrix (AICM) extends the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM). For shared control ids, CSA’s own CCM crosswalk reaches the foundational standards below — including AICPA Trust Services Criteria 2017 (SOC 2) and Payment Card Industry Data Security Standard (PCI DSS). Reach varies by regime (cells marked “No Mapping” do not count). The remainder of 247 objectives is outside that dock — for NIST CSF v2.0, that delta is 63.
Two CSA-authoritative hops: AICM→CCM by shared control id (the documented design of AICM), CCM→standard by CSA’s published CCM v4.0.13 mapping. Gap levels are not re-labelled across the bridge. HIPAA, GDPR, and India DPDP are not CCM columns — leverage the skill-mediated panel. NIST SSDF is not mapped in any source here and is omitted, not inferred.
Skills · regime leverage
Regimes the skill catalog already reaches.
Privacy & payments · leveraged from skills
Regimes the CSA sheets omit: joined through the skill catalog.
Modeled, from the skill catalog, not a Cloud Security Alliance sheet: published skills already tagged to a privacy or payments law, read against the control domain they touch.
Four ways in · one answer
Demand, obligation, instrument, ownership.
Mutually exclusive entry points onto the same domain detail. Open one. Leave with a takeaway — expand the catalog only when you already know what you are hunting.
Instrument: Tool evidence
A published tool closes evidence only where it maps onto control objectives. The instrument lens shows which domains a tool can actually support.
Browse the demoted instrument catalog when you already know the tool name.
Open instrument lens→Browse the instrument catalog (power users)
How these are used
A list of tools is not a capability. See how an LLM calls an instrument and runs a skill against a target, an app, data, a process, or a vendor →
The three lanes stay separate by design: a tester grades a control, a control is never graded by itself. Domain tags are a lens, not a partition — an instrument may carry several.
tester
Testers
Probe a skill or a target to surface what breaks — the attack side of the bench.
Garak
Apache-2.0NVIDIA / Garak contributors
Validates skill
- detecting-ai-model-prompt-injection-attacks
- detect-system-prompt-extraction
Spine step
Test →PyRIT
MITMicrosoft AI Red Team
Validates skill
- detecting-ai-model-prompt-injection-attacks
- implementing-llm-guardrails-for-security
Spine step
Test →Promptfoo
MITPromptfoo Inc.
Validates skill
- detecting-ai-model-prompt-injection-attacks
- detect-mcp-adversarial-input-corpus
Spine step
Test →SkillGuard
Apache-2.0Built in-house — SkillBOM + capability inference for AI skill packages. Infers seven powers by reading code rather than trusting declared metadata, runs nine detectors with negation and defensive-context brakes tuned for a corpus that quotes attacks as teaching material, decodes base64/hex/url payloads before matching, and flags cross-skill capability chains as co-reference risk. Grades on new-and-unreviewed, not on zero findings
Validates skill
No skill bound yet.
Spine step
Baseline →Nuclei
MITProjectDiscovery
Validates skill
- performing-external-network-penetration-test
- performing-authenticated-vulnerability-scan
Spine step
Test →Semgrep
LGPL-2.1-onlySemgrep Inc. (formerly r2c)
Validates skill
- implementing-semgrep-for-custom-sast-rules
- integrating-sast-into-github-actions-pipeline
Spine step
Test →Trivy
Apache-2.0Aqua Security
Validates skill
- performing-container-security-scanning-with-trivy
- scanning-docker-images-with-trivy
- scanning-containers-with-trivy-in-cicd
Spine step
Test →Presidio
MITMicrosoft
Validates skill
- implementing-data-loss-prevention-with-microsoft-purview
Spine step
Test →YARA
BSD-3-ClauseVirusTotal / YARA contributors
Validates skill
- performing-malware-triage-with-yara
- performing-yara-rule-development-for-detection
- performing-threat-hunting-with-yara-rules
Spine step
Test →Sigma
DRL-1.1SigmaHQ
Validates skill
- building-detection-rules-with-sigma
Spine step
Test →Volatility 3
verifyVolatility Foundation
Validates skill
- performing-memory-forensics-with-volatility3
- performing-memory-forensics-with-volatility3-plugins
- conducting-memory-forensics-with-volatility
Spine step
Test →corpus
Corpora
Fixed input sets that fix a baseline — the same stimulus, run before and after.
AdvBench
MITAcademic — Zou et al. (Universal and Transferable Adversarial Attacks, 2023)
Validates skill
Establishes a baseline — bound to the baseline step, not a single skill.
Spine step
Baseline →control
Controls
Mitigations placed in front of the model — what a tester grades, never graded by itself.
Llama Guard
verifyMeta AI
Validates skill
- implementing-llm-guardrails-for-security
Spine step
Troubleshoot →NeMo Guardrails
Apache-2.0NVIDIA
Validates skill
- implementing-llm-guardrails-for-security
Spine step
Troubleshoot →Where next
Leave with a next move.
Pressure-test a function
Run the org maturity read on the same AICM spine — gate held between autonomy and control.
Open maturity→Build defender skills
Track 2: personal mastery on the same controls, seat by seat — gaps and path, nothing saved.
Open skills→Board and sample lenses
See every finished sample — board, function, mastery, and standards lenses — in one Reports index.
Open reports→