All Resources

Frameworks & Standards

20

OWASP, NIST, MITRE, and industry security frameworks

OWASP AI Exchange

Open-source framework for AI security controls, governance, and threat classification maintained by OWASP.

owaspgovernancecontrols+1

MITRE ATLAS

Tactical classification of adversary behavior and TTPs against AI systems, maintained by MITRE.

mitreadversarial-tacticsttps+1

OWASP Top 10 for LLM Applications

Taxonomy of the ten most critical LLM security risks including prompt injection and insecure output handling.

owaspprompt-injectionvulnerability-taxonomy

ISO/IEC 27090

International standard providing guidelines for AI system security management and risk assessment.

isostandardsgovernance+1

OpenCRE

Cross-reference engine mapping security standards and controls across OWASP, NIST, ISO, and more.

standard-alignmentcontrol-mappingcross-reference

AI Security Matrix

OWASP framework for identifying threats across analytical, discriminative, and generative AI systems.

threat-modelingmatrixowasp

AI Program Quickstart (G.U.A.R.D)

Enterprise governance framework providing a structured approach to building AI security programs.

enterprise-governanceprogram-managementowasp

Dual LLM Pattern

Architectural defense pattern using separate privileged and quarantined LLMs to prevent injection attacks.

architectureinjection-defensedesign-pattern

Arcanum Prompt Injection Taxonomy

Open-source taxonomy classifying prompt injections across intent, technique, evasion, and input vectors.

prompt-injectionclassificationtaxonomy

AI Supply Chain Management

OWASP framework for managing vendor and model risk across the AI supply chain lifecycle.

supply-chainvendor-riskmodel-risk

AI Security Testing

OWASP methodology and tool guidance for systematic AI security testing and evaluation.

testing-methodologytoolsowasp

AI Privacy Section

OWASP guidance on data protection and GDPR compliance for AI systems processing personal data.

privacygdprdata-protection+1

Data Poisoning (Dev-time)

OWASP framework covering training data integrity threats and defenses during model development.

data-poisoningtraining-integritydevelopment

Evasion Attacks (Input)

OWASP classification of input-based evasion attacks that manipulate AI decision boundaries.

evasionadversarial-inputdecision-manipulation

AI Security Essentials

OWASP summary of essential AI security principles and minimum viable controls.

essentialsfoundationalowasp

Cisco AI Security Taxonomy

Cisco's integrated safety and security taxonomy for classifying AI defense requirements.

ciscotaxonomysafety-security

Composite Detection Guide

Framework for building correlated attack chain detections across multiple AI security signals.

detectionattack-chainscorrelation

AgentBench

Multi-dimensional benchmark for evaluating LLM agent performance and security characteristics.

benchmarkagent-evaluationperformance

Pangea Attack Taxonomy

Taxonomy mapping LLM attack types to specific remediation strategies.

taxonomyattack-classificationremediation

AI Risk Taxonomy

MIT-maintained risk mapping framework covering AI security threats across deployment scenarios.

risk-taxonomythreat-mappingmit

Know a resource we're missing?

This directory is community curated. Submit a pull request to add your favorite AI security resources.

Contribute on GitHub