Frameworks and standards
Risk frameworks, standards, and foundational security references
Risk frameworks 46
- MITRE ATLASatlas.mitre.org
- NIST AI Risk Management Frameworknvlpubs.nist.gov
- Google SAIF Mapsaif.google
- Pillar Security - AI Riskpillar.security
- MIT AI Risk Repositoryairisk.mit.edu
- AI Security Forumaisecurity.forum
- Cybersecurity Framework Profile for Artificial Intelligence (NIST IR 8596)nvlpubs.nist.gov
- SL5 Standard for AI Security: A NIST SP 800-53 Overlay for Frontier AI Infrastructurestandard.sl5.org
- NIST AI 800-4: Challenges to the Monitoring of Deployed AI Systemsnvlpubs.nist.gov
- AI Resilience Maturity Modelgithub.com
- AI Risk Databaseairisk.io
- AI Risks that Could Lead to Catastrophe - CAISsafe.ai
- AI Risk Databasesafety.google
- AI Risk Databasewhitehouse.gov
- Introducing the Frontier Safety Frameworkdeepmind.google
- Cybersecurity AI (CAI), the framework fgithub.com
- openrisk is a tool that generatgithub.com
- NIST RFI: Security Considerations for AI Agents — Public Comments (NIST-2025-0035)regulations.gov
- Mythos-Ready Assessment Framework (CSA)labs.cloudsecurityalliance.org
- 2023 CWE Top 25 Most Dangerous Software Weaknessescwe.mitre.org
- Agentic Trust Controls - agentic security and governance controls for ISO 27001 and ISO 42001trustcontrols.ai
- AI Defense Matrix - a framework for defending AI systems aligned with NIST CSF 2.0aidefensematrix.com
- Announcing CVSS v4.0 - FIRST presentationfirst.org
- AVID Taxonomy Library - AI Vulnerability Database failure mode taxonomyavidml.org
- Bugcrowd Vulnerability Rating Taxonomy - baseline priority ratings for common vulnerabilitiesbugcrowd.com
- CISA Stakeholder-Specific Vulnerability Categorization - SSVCcisa.gov
- Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systemsarxiv.org
- CSA AI Security Maturity Modelcloudsecurityalliance.org
- ENISA Multilayer Framework for Good Cybersecurity Practices for AIenisa.europa.eu
- How Material is That Hackhowmaterialisthathack.org
- Introducing EPSS v4 - Exploit Prediction Scoring Systemempiricalsecurity.com
- Mission Assurance Security Standard MA-S2 for Softwarema-s2.com
- MITRE ATLASatlas.mitre.org
- MITRE ATLAS - Tacticsatlas.mitre.org
- MITRE Fight Fraud Framework - F3, TTP knowledge base for cyber fraudgithub.com
- NIST AI 100-2 E2023: Adversarial Machine Learning - A Taxonomy and Terminology of Attacks and Mitigationscsrc.nist.gov
- NIST AI 100-2e2023: Adversarial Machine Learning - A Taxonomy and Terminology of Attacks and Mitigationsnvlpubs.nist.gov
- NIST AI RMF Playbookairc.nist.gov
- NIST IR 8397 - Guidelines on Minimum Standards for Developer Verification of Softwarenvlpubs.nist.gov
- NIST Secure Software Development Framework - SSDF and SP 800-218A for Generative AIcsrc.nist.gov
- NIST SP 1353 - Using AI for Cybersecurity Framework 2.0 Analysis and Reportingcsrc.nist.gov
- NIST SP 800-161r1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizationsnvlpubs.nist.gov
- NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizationsnvlpubs.nist.gov
- RiskRubric - AI risk assessment frameworkriskrubric.ai
- The NIST Cybersecurity Framework CSF 2.0nvlpubs.nist.gov
- Zoom VISS - Vulnerability Impact Scoring System calculatorviss.zoom.com
OWASP 23
- OWASP Top 10 for LLM Applications 2025genai.owasp.org
- Agent Name Service (ANS) for Secure Al Agent Discovery v1.0genai.owasp.org
- A very brief, one-line description of your projectowasp.org
- Solutions Landscapegenai.owasp.org
- www-project-top-10-for-large-language-model-applications/assets/PDFgithub.com
- Meetingsgithub.com
- OWASP GenAI Data Security Risks and Mitigations 2026docs.google.com
- OWASP AI Security Visualizerricokomenda.github.io
- OWASP Agentic Skills Top 10 - Skill Security Assessment Checklistowasp.org
- OWASP Agentic Skills Top 10 Whitepaperowasp.org
- OWASP AI Agent Security Cheat Sheetgithub.com
- OWASP AI Exchangeowasp.org
- OWASP AISVS - AI Security Verification Standard 1.0 PDF buildgithub.com
- OWASP APTS - Autonomous Penetration Testing Standardgithub.com
- OWASP Calls to Build a Unified Framework for Global Vulnerability Intelligenceowasp.org
- OWASP GenAI Crosswalk - mapping GenAI and agentic security risks to 25 frameworksgenai-security-project.github.io
- OWASP IoT Security Testing Guideowasp.org
- OWASP Netryx - modular Java web security frameworkgithub.com
- OWASP OASIS - AppSec community validating credible fixes for open source softwareowasp-oasis.org
- OWASP Security Champions Guideowasp.org
- OWASP Top 10 API vulnerabilities - Web Security Academyportswigger.net
- OWASP Top 10 for LLM Applications - GenAI-LLM-Top10 repogithub.com
- The Top 10 OWASP Top 10sgithub.com
Security benchmarks 2
Security landscape 24
- Security for AI: The New Wave of Startups Racing to Secure themenlovc.com
- Security and compliance proxy for LLM APIsgithub.com
- Independent AI Oversight Layer — monitgithub.com
- Enhance AI security and governance across multi-model and multi-clotechcommunity.microsoft.com
- LLM Safeguards: Security Privacy Compliance Anti Hallucination: Danyoutu.be
- 2023 Cybersecurity Market Review - Disruption and Resiliencereturnonsecurity.com
- 2025 CWE Top 25 Most Dangerous Software Weaknessescwe.mitre.org
- 2026 AI Threat Landscape Reporthiddenlayer.com
- A Field Guide to the AI Security Marketzeltser.com
- AI Security Companies List - Tejas Cyber Networkglobalcyberhackathon.com
- Ankita Gupta shares Top 12 tools for LLM security from Austin API Summit talkx.com
- C2PA - content provenance and authenticity standardc2pa.org
- CISA Product Security Bad Practices - guidance for software manufacturerscisa.gov
- CISA Secure by Design - Shifting the Balance of Cybersecurity Riskcisa.gov
- Cybersecurity Forecast 2026 - Google Cloudservices.google.com
- GenAI Security - The Comprehensive Guideshadown.github.io
- Latio - compare cybersecurity tools and vendor reviewslist.latio.tech
- MITRE Security Automation Framework SAF - Normalizesaf.mitre.org
- NIST IR 8517 - Hardware Security Failure Scenarios: Potential Hardware Weaknessesnvlpubs.nist.gov
- OpenAI: Disrupting Malicious Uses of AI - February 2026 Threat Reportcdn.openai.com
- RSAC Innovation Sandbox security startup competitionrsaconference.com
- Security Titles - standardizing cybersecurity job titlessecuritytitles.com
- WEF Global Cybersecurity Outlook 2025reports.weforum.org
- Y Combinator's Summer 2023 Cybersecurity, Privacy, and Trust Startupsstrategyofsecurity.com