Reskill · EWS
Endpoint & Workload Security
The agent executed on the host to finish its task, and EDR saw a trusted process do something it never does.
Telling autonomous action from compromise, on the same endpoint, is the skill.
Start with these skills
- Approve what runs, including AI tools
- Keep endpoints compatible with the controls
- Inventory every endpoint that touches AI
- Manage endpoints to the policy floor
- Lock screens by default
The rung you have to reach
No AI Security Maturity Model (AISMM) ladder maps here yet.
The AISMM model does not yet carry a maturity category for this function’s remit. Baseline it through the diagnostic instead; the rung follows when the model does.
Your syllabus
The plays that climb the rung.
Endpoint & AI-tool posture
Keep every endpoint that runs AI tools at the policy floor: inventory, harden, encrypt, detect, and wipe when lost.
Moves: Managed endpoints meeting the AI-tool posture baseline ↑
Show the exact control IDs (for your security & GRC team)
L2 UEM-01, UEM-04, UEM-05 · L3 UEM-08, UEM-09, UEM-11 · L4 UEM-13, LOG-12
Autonomy must not outrun maturity. The gate holds each rung until its controls are evidenced. The gate framework: eight gates, three lanes →