ai · security · skills

Controls · spine & crosswalk

One control spine.Assess once. Close with evidence.

For auditors and compliance leads: the AI Controls Matrix (AICM) is the MECE partition — 18 domains, 247 control objectives. NIST, ISO, and AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) reads are lenses on that one assess, not a second quiz. Jump a block below when you already know which part you need.

AICM domains, one assess5 domains · 73 controls

GRC · Governance

Governance, Risk and Compliance

Who owns AI risk, who decides, and how policy becomes operating practice.

15 control objectives97 fitted skills
Implementing GDPR Data Protection ControlsImplementing GDPR Data Subject Access RequestImplementing ISO 27001 Information Security Management
Open GRCdrill →

Foundational: Ground floor every function needs before AI-specific controls land.

Situation · what this is for

A usable control reference, not a catalogue dump.

You already answer to more than one regime. This page names the spine this research site runs on, how external standards map onto it, and what produces evidence — skills, tools, and ownership — without listing every control inline.

Step 1

Name the spine

AI Controls Matrix (AICM) is the MECE partition - one assess covers the control surface.

Step 2

Read the lens they asked for

NIST, ISO, AI-CAIQ and peers are lenses on that assess, not a second quiz.

Step 3

Close with evidence

Skills, tools, and ownership tell you what produces the artifact the auditor can file.

Maturity pressure-tests roll up through 12 AI Security Maturity Model (AISMM) categories onto this same AICM surface. 16 published instruments and 8 mapped regimes sit on that spine.

Lenses · assess once

When they ask for NIST or ISO, point here.

Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.

One methodology, every standardAssess once
AISMMAI Security Maturity Model3 domains · 12 categories · L1 to L5AICMAI Controls Matrix18 domains · 247 control objectivesCCMCloud Controls MatrixThe foundational dock you already runNIST AI RMFAI risk management frameNIST CSF 2.0Cybersecurity outcomesNIST SP 800-53Control catalogSOC 2Service organization controlsPCI DSSPayment card securityISO/IEC 42001AI management systemEU AI ActLegal obligations overlayISO/IEC 27001Information security (ISMS)ISO/IEC 27017Cloud security controlsISO/IEC 27018Cloud PII protection

A navigation map, not a conformance attestation: assess once on the AI Controls Matrix and read every standard as a lens on that one run. Privacy regimes arrive from skill tags in the panel below.

AI Security Maturity Model: The maturity read. The lit standards cover the same governance ground.

Spine · Foundational · Structural · Procedural

Three AISMM domains. One AICM spine.

Cycle the bands: each AI Security Maturity Model (AISMM) domain discloses its categories and the AI Controls Matrix (AICM) domains that roll up to them.

AISMM domains, AICM controls4 · 73

AI Security Maturity Model · Foundational

73 control objectives

01Governance2 AICM · 30

Who decides what, who is accountable, and how the rules are kept.

02Organization Management1 AICM · 9

How the organisation is structured and how change is controlled.

03IAM1 AICM · 18

Identity and Access Management: who can do what, with which credentials.

04Security Monitoring1 AICM · 16

Watching for trouble; logging what happened so it can be investigated.

One AI Controls Matrix (AICM) partition · 18 domains · 247 objectives. AISMM is the maturity lens, not a second catalog.

Foundational: The ground floor every function needs before AI specifics enter: governance, identity, monitoring.

Foundational inheritance · the CCM bridge

Dock the baseline you already run.See what each regime still cannot reach.

The AI Controls Matrix (AICM) extends the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM). For shared control ids, CSA’s own CCM crosswalk reaches the foundational standards below — including AICPA Trust Services Criteria 2017 (SOC 2) and Payment Card Industry Data Security Standard (PCI DSS). Reach varies by regime (cells marked “No Mapping” do not count). The remainder of 247 objectives is outside that dock — for NIST CSF v2.0, that delta is 63.

NIST CSF v2.0184/247 via CCM bridge · 16/18 domains · delta 63
NIST 800-53 rev 5186/247 via CCM bridge · 16/18 domains · delta 61
AICPA TSC 2017 (SOC 2)137/247 via CCM bridge · 16/18 domains · delta 110
PCI DSS v3.2.1129/247 via CCM bridge · 16/18 domains · delta 118
PCI DSS v4.0144/247 via CCM bridge · 16/18 domains · delta 103

Two CSA-authoritative hops: AICM→CCM by shared control id (the documented design of AICM), CCM→standard by CSA’s published CCM v4.0.13 mapping. Gap levels are not re-labelled across the bridge. HIPAA, GDPR, and India DPDP are not CCM columns — leverage the skill-mediated panel. NIST SSDF is not mapped in any source here and is omitted, not inferred.

Skills · regime leverage

Regimes the skill catalog already reaches.

Privacy & payments · leveraged from skills

Regimes the CSA sheets omit: joined through the skill catalog.

Modeled, from the skill catalog, not a Cloud Security Alliance sheet: published skills already tagged to a privacy or payments law, read against the control domain they touch.

General Data Protection Regulation (GDPR)205 skills · 5/18 domains
Which control domains?

Audit & Assurance · Data Security and Privacy Lifecycle Management · Governance, Risk and Compliance · Security Incident Management, E-Discovery, & Cloud Forensics · Supply Chain Management, Transparency, and Accountability

Health Insurance Portability and Accountability Act (HIPAA)32 skills · 3/18 domains
Which control domains?

Data Security and Privacy Lifecycle Management · Governance, Risk and Compliance · Security Incident Management, E-Discovery, & Cloud Forensics

India Digital Personal Data Protection Act, 2023 (DPDP)2 skills · 2/18 domains
Which control domains?

Data Security and Privacy Lifecycle Management · Governance, Risk and Compliance

Payment Card Industry Data Security Standard (PCI DSS)1 skill · 1/18 domains
Which control domains?

Governance, Risk and Compliance

Four ways in · one answer

Demand, obligation, instrument, ownership.

Mutually exclusive entry points onto the same domain detail. Open one. Leave with a takeaway — expand the catalog only when you already know what you are hunting.

Ownership: SSRM evidence

Shared Security Responsibility Model (SSRM): owned, shared, or inherited. Auditors care who produces the artifact - not only that a control exists.

Use the ownership lens for the AI-Customer chair read, then pressure-test the function that owns the gap.

Open ownership lens
Browse the ownership catalog (power users)

The same 69 core skills, read along the shared-responsibility line — given how you consume AI, which controls are yours to own? Each skill is tagged by the posture it answers to (Operated · Procured) and, when it is shared or inherited, the provider on the other side.

This is where the Bought posture from the home lands: who owns which control across the line between you and your provider. Operated is what your org built and runs; Procured is what it bought in.

Our authored read of the Shared Security Responsibility Model (SSRM), scoped to the core set — a navigation affordance, not a measured claim.

ai-vendor-privacy-due-diligence-art28ProcuredAP
GRC · Governance, Risk and Compliance
analyzing-email-headers-for-phishing-investigationOperatedProcured
SEF · Security Incident Management, E-Discovery, & Cloud Forensics
analyzing-security-logs-with-splunkOperatedProcured
SEF · Security Incident Management, E-Discovery, & Cloud Forensics
assessing-an-ai-vendor-with-ai-caiqProcuredAP
STA · Supply Chain Management, Transparency, and Accountability
attesting-ai-authored-code-provenance-in-pull-requestsOperated
AIS · Application & Interface Security
auditing-terraform-infrastructure-for-securityOperated
I&S · Infrastructure Security
authoring-model-cards-and-system-documentationOperated
GRC · Governance, Risk and Compliance
automating-ioc-enrichmentOperatedProcured
TVM · Threat & Vulnerability Management
bounding-agent-autonomy-and-tool-scopes-least-privilegeOperatedProcured
MDS · Model Security
building-detection-rule-with-splunk-splOperatedProcured
LOG · Logging and Monitoring
building-detection-rules-with-sigmaOperatedProcured
LOG · Logging and Monitoring
building-identity-governance-lifecycle-processOperatedProcured
IAM · Identity & Access Management
building-incident-timeline-with-timesketchOperatedProcured
SEF · Security Incident Management, E-Discovery, & Cloud Forensics
building-malware-incident-communication-templateOperatedProcured
SEF · Security Incident Management, E-Discovery, & Cloud Forensics
building-threat-intelligence-enrichment-in-splunkOperatedProcured
LOG · Logging and Monitoring
building-vulnerability-aging-and-sla-trackingOperatedProcured
TVM · Threat & Vulnerability Management
collecting-evidence-for-a-privacy-compliance-auditOperatedProcured
A&A · Audit & Assurance
collecting-threat-intelligence-with-mispOperatedProcured
TVM · Threat & Vulnerability Management
conducting-a-gdpr-data-protection-impact-assessmentOperatedProcured
GRC · Governance, Risk and Compliance
conducting-phishing-incident-responseOperatedProcured
SEF · Security Incident Management, E-Discovery, & Cloud Forensics
configuring-windows-event-logging-for-detectionOperatedProcured
UEM · Universal Endpoint Management
detecting-container-drift-at-runtimeOperatedProcured
I&S · Infrastructure Security
detecting-insider-data-exfiltration-via-dlpOperatedProcured
LOG · Logging and Monitoring
embedded-vendor-ai-feature-inventory-and-toggleProcuredAP
STA · Supply Chain Management, Transparency, and Accountability
enforcing-ide-ai-assistant-dlp-and-approved-endpointsOperated
DSP · Data Security and Privacy Lifecycle Management
gating-hallucinated-and-slopsquatted-dependenciesOperated
STA · Supply Chain Management, Transparency, and Accountability
gating-irreversible-agent-actions-with-human-approvalOperatedProcured
IAM · Identity & Access Management
generating-a-gdpr-article-30-ropa-from-system-inventoriesOperatedProcured
GRC · Governance, Risk and Compliance
generating-an-ai-bom-in-ci-with-cyclonedxOperated
STA · Supply Chain Management, Transparency, and Accountability
hardening-docker-containers-for-productionOperated
I&S · Infrastructure Security
hardening-windows-endpoint-with-cis-benchmarkOperatedProcured
UEM · Universal Endpoint Management
implementing-aes-encryption-for-data-at-restOperatedProcured
CEK · Cryptography, Encryption & Key Management
implementing-disk-encryption-with-bitlockerOperatedProcured
UEM · Universal Endpoint Management
implementing-endpoint-detection-with-wazuhOperatedProcured
LOG · Logging and Monitoring
implementing-kill-switch-and-rollback-for-autonomous-agentsOperatedProcured
MDS · Model Security
implementing-log-forwarding-with-fluentdOperatedProcured
LOG · Logging and Monitoring
implementing-semgrep-for-custom-sast-rulesOperated
AIS · Application & Interface Security
implementing-threat-modeling-with-mitre-attackOperatedProcured
LOG · Logging and Monitoring
india-dpdp-act-2023-obligationsOperatedProcured
GRC · Governance, Risk and Compliance
integrating-sast-into-github-actions-pipelineOperated
AIS · Application & Interface Security
performing-cloud-asset-inventory-with-cartographyOperatedProcured
I&S · Infrastructure Security
performing-cryptographic-audit-of-applicationOperatedProcured
CEK · Cryptography, Encryption & Key Management
performing-ioc-enrichment-automationOperatedProcured
LOG · Logging and Monitoring
performing-physical-intrusion-assessmentOperatedProcured
TVM · Threat & Vulnerability Management
performing-privacy-impact-assessmentOperatedProcured
GRC · Governance, Risk and Compliance
performing-threat-modeling-with-owasp-threat-dragonOperatedProcured
AIS · Application & Interface Security
performing-web-application-penetration-testOperatedProcured
TVM · Threat & Vulnerability Management
scanning-ai-generated-code-for-license-and-ip-contaminationOperated
STA · Supply Chain Management, Transparency, and Accountability
scanning-containers-with-trivy-in-cicdOperated
AIS · Application & Interface Security

Where next

Leave with a next move.

Pressure-test a function

Run the org maturity read on the same AICM spine — gate held between autonomy and control.

Open maturity

Build defender skills

Track 2: personal mastery on the same controls, seat by seat — gaps and path, nothing saved.

Open skills

Board and sample lenses

See every finished sample — board, function, mastery, and standards lenses — in one Reports index.

Open reports
Aligned with the Cloud Security Alliance (CSA) AI Controls Matrix (AICM) and AI Security Maturity Model (AISMM). Not a CSA certification or STAR listing. Verbatim control specifications stay research-access / owner-gated; public viewers get structure, counts, and samples.