ai · security · skills

Pressure-test the function

Pressure-test the function.

Pick the function. Hermes Agent runs the maturity read: posture for the unit, not a skills quiz for one person.

Pick a function and its maturity check loads below: two ladders, joined by the gate. Open to run, and nothing is stored.

Aligned with the Cloud Security Alliance maturity model and controls matrix; not a certification or STAR listing.

First look instead? The ten-minute Quick Mythos Vulnerability Assessment

Personal read instead? Build the defender’s skills →

Autonomy rises. So does the bar.On track
12345GovernanceOrg managementIdentity & accessSecurity monitoringInfra security & resilienceModel securityApp securityData securityRisk & provider assessmentAI dev & supply chainPrivacy & complianceIncident responseFoundationalStructuralProcedural
Human bottleneck82%
Safety net needed22%

Manual: The human is the safety net. Low autonomy asks little of your controls.

Live assess

Run it, don’t just read it.

The unit’s armour: function posture on two ladders, joined by the gate. Pick a function above, then start on screen. Open to run, and nothing is stored.

Selected function

Identity Security

8 questions · 2 categories

Standards lenses · one spine

Assess once on the AI Controls Matrix. ISO, NIST, and AI-CAIQ are lenses on those answers — not a second questionnaire.

Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.

Sample reports

See a finished report before you start.

One finished function read per fictional organisation. Full board, mastery, and standards lenses live in Reports.

Self-assessed sample data, never client results. All reports →

Exhibits · the living standards map

Assess once. Read against every standard.

Open the living standards map
One methodology, every standardAssess once
AISMMAI Security Maturity Model3 domains · 12 categories · L1 to L5AICMAI Controls Matrix18 domains · 247 control objectivesCCMCloud Controls MatrixThe foundational dock you already runNIST AI RMFAI risk management frameNIST CSF 2.0Cybersecurity outcomesNIST SP 800-53Control catalogSOC 2Service organization controlsPCI DSSPayment card securityISO/IEC 42001AI management systemEU AI ActLegal obligations overlayISO/IEC 27001Information security (ISMS)ISO/IEC 27017Cloud security controlsISO/IEC 27018Cloud PII protection

A navigation map, not a conformance attestation: assess once on the AI Controls Matrix and read every standard as a lens on that one run. Privacy regimes arrive from skill tags in the panel below.

AI Security Maturity Model: The maturity read. The lit standards cover the same governance ground.

The depth behind this map lives one level down: every standards lens as a finished sample → and, for members, the full control spine and crosswalk →

The method

How a function climbs, and where SkillGuard fits.

You raise a function by applying ready-made skills. Adopting a skill is itself a supply-chain risk, so SkillGuard admits every skill before it is applied. It is the gate on this one step, not a tool off to the side.

01 · Diagnose

Read the function

The maturity check finds the gate-blocking gaps: the controls sitting below target.

02 · Prescribe

Fit the skills

The reading names the ready-made skills that close each gap, the capability to add.

03 · Pre-check

SkillGuard admits

Every prescribed skill passes the scan before it can be applied.

See the pre-check →
04 · Apply

Move the lever

Only admitted skills are applied: the People, Process, or Technology change that raises the control.

05 · Re-assess

Watch it move

Re-run the check: governance rises, the gate opens, autonomy may climb, safely.

↻ Re-assess feeds the next diagnose, each turn earning the next rung.

Upstream · what stocks 02 Prescribe

02 Prescribe draws from a living library, and a governed autonomous agent (Hermes) keeps it current: it watches the field and proposes new skills from a chat window, inside a gate of three tools it cannot cross. SkillGuard admits what it proposes, so the loop never runs on unvetted capability. How we govern our own agent →