MDS

Model Security

Domain definition — mapping in progress (source: AI Controls Matrix (AICM) Introductory Guidance).

13

Control objectives

18

Skills

11

Cross-cutting

—

Objectives fitted

AISMM maturity context

Model Security · Structural domain

L1 InitialL2 RepeatableL3 DefinedL4 CapableL5 Efficient

A lens, not a partition. How AISMM adoption works →

Control objectives

The exact things this domain must do. Each carries an authoritative crosswalk to 3 external control sets (Cloud Security Alliance (CSA) AI Controls Matrix (AICM) v1.1.0). Fitted skills are drawn from the pool below as fits are evidenced.

Training Pipeline SecurityMDS-01

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 2 steps
Cloud Service Provider — 4 steps
Application Provider — 7 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Model Artifact ScanningMDS-02

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 4 steps
Cloud Service Provider — 6 steps
Application Provider — 17 steps
Model Provider — 9 steps
Orchestrated Services Provider — 13 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Model DocumentationMDS-03

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 3 steps
Cloud Service Provider — 5 steps
Application Provider — 6 steps
Model Provider — 7 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Model Documentation RequirementsMDS-04

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 1 step
Cloud Service Provider — 3 steps
Application Provider — 3 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Model Documentation ValidationMDS-05

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 3 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Adversarial Attack AnalysisMDS-06

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 6 steps
Application Provider — 9 steps
Model Provider — 9 steps
Orchestrated Services Provider — 10 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Robustness against Adversarial Attack / Model HardeningMDS-07

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 1 step
Cloud Service Provider — 4 steps
Application Provider — 5 steps
Model Provider — 6 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Model Integrity ChecksMDS-08

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 1 step
Cloud Service Provider — 5 steps
Application Provider — 6 steps
Model Provider — 7 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Model Signing/Ownership VerificationMDS-09

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 3 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Model Continuous MonitoringMDS-10

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 3 steps
Cloud Service Provider — 4 steps
Application Provider — 6 steps
Model Provider — 7 steps
Orchestrated Services Provider — 7 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Model FailureMDS-11

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 4 steps
Application Provider — 8 steps
Model Provider — 7 steps
Orchestrated Services Provider — 7 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Open Model Risk AssessmentMDS-12

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 2 steps
Cloud Service Provider — 4 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Secure Model FormatMDS-13

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 2 steps
Cloud Service Provider — 3 steps
Application Provider — 5 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Standard names and gap levels shown; the specific clause references and full control text are available to the owner.

Skill pool — MDS

Detecting AI Model Prompt Injection AttacksImplementing LLM Guardrails For SecurityDetect MCP Adversarial Input CorpusDetect MCP Model Artifact TamperingDetect System Prompt ExtractionRunning Prompt Injection Red Team As A CI GateGating Eval And Safety Regression Before DeployImplementing Content Safety Output FilteringDetecting And Grounding Hallucinations In High Impact UseChild Safety Output Controls For GenaiSelecting Fairness Metrics And Running Disparate Impact TestsBounding Agent Autonomy And Tool Scopes Least Privilege

Sample view. 12 of 18 skill names shown; the full list is available to the owner.