TVM

Threat & Vulnerability Management

Domain definition — mapping in progress (source: AI Controls Matrix (AICM) Introductory Guidance).

13

Control objectives

164

Skills

70

Cross-cutting

—

Objectives fitted

AISMM maturity context

AI Supported Development and Supply Chain Security · Procedural domain

L1 InitialL2 RepeatableL3 DefinedL4 CapableL5 Efficient

A lens, not a partition. How AISMM adoption works →

Control objectives

The exact things this domain must do. Each carries an authoritative crosswalk to 9 external control sets (Cloud Security Alliance (CSA) AI Controls Matrix (AICM) v1.1.0). Fitted skills are drawn from the pool below as fits are evidenced.

Threat and Vulnerability Management Policy and ProceduresTVM-01

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 13 steps
Application Provider — 11 steps
Model Provider — 10 steps
Orchestrated Services Provider — 10 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Malware and Malicious Instructions Protection Policy and ProceduresTVM-02

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 11 steps
Application Provider — 9 steps
Model Provider — 9 steps
Orchestrated Services Provider — 9 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Vulnerability IdentificationTVM-03

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 3 steps
Cloud Service Provider — 9 steps
Application Provider — 7 steps
Model Provider — 7 steps
Orchestrated Services Provider — 7 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Threat Analysis and ModellingTVM-04

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 14 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Detection UpdatesTVM-05

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 9 steps
Application Provider — 7 steps
Model Provider — 7 steps
Orchestrated Services Provider — 7 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

External Library VulnerabilitiesTVM-06

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 9 steps
Application Provider — 7 steps
Model Provider — 7 steps
Orchestrated Services Provider — 7 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Penetration TestingTVM-07

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 12 steps
Application Provider — 9 steps
Model Provider — 9 steps
Orchestrated Services Provider — 9 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Vulnerability Remediation ScheduleTVM-08

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 7 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Vulnerability PrioritizationTVM-09

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 2 steps
Cloud Service Provider — 7 steps
Application Provider — 3 steps
Model Provider — 3 steps
Orchestrated Services Provider — 3 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Threat ResponseTVM-10

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 10 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Vulnerability Management ReportingTVM-11

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 9 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Vulnerability Management MetricsTVM-12

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 8 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

GuardrailsTVM-13

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Standard names and gap levels shown; the specific clause references and full control text are available to the owner.

Skill pool — TVM

Analyzing Android Malware With ApktoolAnalyzing Macro Malware In Office DocumentsAnalyzing Supply Chain Malware ArtifactsBuilding Patch Tuesday Response ProcessConducting Full Scope Red Team EngagementDetecting Fileless Malware TechniquesExploiting Nopac CVE 2021 42278 42287Implementing Epss Score For Vulnerability PrioritizationPerforming Active Directory Bloodhound AnalysisPerforming CVE Prioritization With Kev CatalogPerforming Malware Triage With YaraPerforming Threat Intelligence Sharing With Misp

Sample view. 12 of 164 skill names shown; the full list is available to the owner.