AIS

Application & Interface Security

Domain definition — mapping in progress (source: AI Controls Matrix (AICM) Introductory Guidance).

15

Control objectives

96

Skills

22

Cross-cutting

—

Objectives fitted

AISMM maturity context

App Security · Structural domain

L1 InitialL2 RepeatableL3 DefinedL4 CapableL5 Efficient

A lens, not a partition. How AISMM adoption works →

Control objectives

The exact things this domain must do. Each carries an authoritative crosswalk to 8 external control sets (Cloud Security Alliance (CSA) AI Controls Matrix (AICM) v1.1.0). Fitted skills are drawn from the pool below as fits are evidenced.

Application and Interface Security Policy and ProceduresAIS-01

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 2 steps
Application Provider — 6 steps
Model Provider — 5 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Application Security Baseline RequirementsAIS-02

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 3 steps
Application Provider — 5 steps
Model Provider — 6 steps
Orchestrated Services Provider — 8 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Application Security MetricsAIS-03

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4ISO/IEC 27701CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 10 steps
Application Provider — 4 steps
Model Provider — 5 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Secure Application Development LifecycleAIS-04

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 8 steps
Cloud Service Provider — 7 steps
Application Provider — 6 steps
Model Provider — 7 steps
Orchestrated Services Provider — 3 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Application Security TestingAIS-05

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 4 steps
Cloud Service Provider — 7 steps
Application Provider — 6 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Secure Application DeploymentAIS-06

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 9 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Application Vulnerability RemediationAIS-07

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 8 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

API SecurityAIS-08

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 5 steps
Application Provider — 3 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Input ValidationAIS-09

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 7 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Output ValidationAIS-10

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 7 steps
Application Provider — 6 steps
Model Provider — 7 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Agents Security BoundariesAIS-11

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 8 steps
Cloud Service Provider — 5 steps
Application Provider — 6 steps
Model Provider — 5 steps
Orchestrated Services Provider — 7 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Source Code ManagementAIS-12

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 4 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

AI SandboxingAIS-13

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 4 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

AI Cache ProtectionAIS-14

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 4 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Prompt DifferentiationAIS-15

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 4 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Standard names and gap levels shown; the specific clause references and full control text are available to the owner.

Skill pool — AIS

Building Devsecops Pipeline With Gitlab CIExploiting Excessive Data Exposure In APIExploiting Prototype Pollution In JavascriptImplementing API Gateway Security ControlsImplementing Devsecops Security ScanningImplementing Semgrep For Custom SAST RulesPerforming Blind Ssrf ExploitationPerforming Graphql Introspection AttackPerforming Subdomain Enumeration With SubfinderTesting API Authentication WeaknessesTesting For Host Header InjectionTesting Oauth2 Implementation Flaws

Sample view. 12 of 96 skill names shown; the full list is available to the owner.