DISC-001
Enterprise AI Inventory
Does the organization maintain a centralized inventory of AI systems, models, AI-enabled applications and AI services?
ASRA v2
Assess the current operating state of AI security across ten domains. Select the maturity description that most closely reflects the assessed scope. Do not enter confidential or sensitive company information.
Methodology
ASRA is grounded in recognized industry frameworks and security practices, including NIST AI RMF, NIST CSF, ISO/IEC 42001, ISO/IEC 27001, CSA AI Controls Matrix, MITRE ATLAS, and OWASP guidance for generative and agentic AI. The assessment operationalizes these references into practical questions, maturity signals, risk indicators, and actionable recommendations.
It also draws on the NIST Generative AI Profile (NIST AI 600-1) for generative-AI specific risks and safeguards.
Framework alignment indicates estimated maturity coverage based on assessment responses. It does not represent certification, formal compliance, or an audit.
Demo / Pilot mode
Use these scenarios to review scoring, priorities and the results experience. Synthetic profiles are test fixtures, not benchmarks or recommended target scores.
Risk context
These context values do not change maturity. They influence exposure, autonomy, resilience and the order of recommended priorities.
Does the assessed scope use AI agents?
Does the assessed scope use Generative AI?
Strategic technology platforms already in use
Optional and local to this browser. These selections never change maturity, exposure or priority scores — they only tailor the technology guidance inside Action Packs.
Discovery
Know the AI estate, including embedded AI, models, agents, tools, dependencies and data flows.
DISC-001
Does the organization maintain a centralized inventory of AI systems, models, AI-enabled applications and AI services?
DISC-002
Can the organization identify AI services and tools used outside formally approved processes?
DISC-003
Can the organization identify AI capabilities embedded in third-party SaaS and enterprise applications?
DISC-004
Are the models and material model versions used by critical AI systems identified and tracked?
DISC-005
Does the organization maintain visibility of production AI agents and the tools, APIs or systems they can invoke?
Agent-specific
DISC-006
Can the organization identify the key data sources, retrieval sources and destinations used by critical AI workloads?
Risk
Classify AI according to business criticality, sensitive data, autonomy, privilege, exposure and human oversight.
RISK-001
Are AI systems classified according to business criticality and potential operational impact?
RISK-002
Is AI risk classification influenced by the sensitivity of data the system can access, generate or expose?
RISK-003
Does AI risk classification consider autonomy, privileges and the ability to execute business actions?
Agent-specific
RISK-004
Does AI risk classification account for customer exposure, regulated decisions and legal or regulatory impact?
RISK-005
Is the adequacy of human oversight evaluated relative to the consequence of an incorrect or unsafe AI action?
Governance
Make ownership, sponsorship, approvals, risk acceptance and incident authority explicit and operational.
GOV-001
Is there a defined operating model for AI governance and AI security governance?
GOV-002
Are responsibilities for AI risk, security, data access, model approval, monitoring, incidents and lifecycle management formally assigned?
GOV-003
Does every critical production AI system have an accountable business owner?
GOV-004
Does every production AI agent capable of executing business actions have an accountable human sponsor or owner?
Agent-specific
GOV-005
Is authority explicitly assigned for approving increases in AI autonomy or authority?
Agent-specific
GOV-006
Can the organization identify who formally accepts residual risk for high-risk AI deployments?
GOV-007
Are third-party AI services, embedded AI and external models subject to defined security and risk review before adoption or material change?
GOV-008
Is authority clearly defined to disable, contain, investigate and restore AI systems during an incident?
Threat Modeling
Model threats specific to GenAI, models, data, agents, tools and AI supply chains.
THRT-001
Are AI-specific threats incorporated into architecture and application threat modeling?
THRT-002
Does threat modeling address direct and indirect prompt injection, context manipulation and malicious retrieved content?
GenAI-specific
THRT-003
Does threat modeling address data poisoning, RAG poisoning, model manipulation, model theft or extraction where relevant?
THRT-004
Does threat modeling address excessive agency, tool abuse, credential misuse, agent impersonation and delegation abuse?
Agent-specific
THRT-005
Does threat modeling include models, libraries, datasets, plugins, connectors, MCP/tool endpoints and third-party AI dependencies?
Secure AI SDLC
Embed security into design, build, test, deploy, operate and retire phases.
SDLC-001
Are AI security and risk requirements defined during design before implementation begins?
SDLC-002
Are models, datasets, libraries and material AI dependencies reviewed for provenance and integrity during development?
SDLC-003
Are credentials, secrets and non-human identities used by AI workloads governed throughout development and deployment?
SDLC-004
Are applicable AI-specific security tests required before production deployment?
SDLC-005
Are AI permissions, data access, tools, configurations and autonomy reviewed before production deployment?
SDLC-006
Are AI systems, models, agents, identities, credentials and data access formally retired when no longer needed?
Protection
Protect identity, data, models, applications, agents, infrastructure and supply-chain dependencies.
PROT-001
Are identities used by AI applications and agents uniquely identifiable, owned and lifecycle-managed?
PROT-002
Are AI applications and agents restricted to the minimum privileges required for their approved purpose?
Agent-specific
PROT-003
Are AI access to sensitive data and retrieval sources governed according to existing data classification and authorization policies?
PROT-004
Are controls applied to reduce inappropriate sensitive-data disclosure through AI inputs, outputs and generated content?
GenAI-specific
PROT-005
Are permissions, provenance and integrity of RAG and retrieval sources protected against unauthorized access or manipulation?
GenAI-specific
PROT-006
Are critical models subject to provenance, integrity, version and approval controls?
PROT-007
Are appropriate input, output, isolation and execution controls implemented for AI-enabled applications?
GenAI-specific
PROT-008
Are the tools, APIs and systems an AI agent can invoke explicitly authorized and constrained?
Agent-specific
PROT-009
Are action boundaries, transaction limits, approval requirements and rapid disablement capabilities defined for autonomous or semi-autonomous agents?
Agent-specific
PROT-010
Are third-party models, libraries, datasets, connectors and tool endpoints subject to security, provenance and change controls?
Validation
Challenge assumptions with adversarial testing, AI red teaming and resilience validation.
VAL-001
Are critical AI systems tested for adversarial behavior before production?
VAL-002
Are applicable systems tested for prompt injection, indirect injection and sensitive-data leakage?
GenAI-specific
VAL-003
Are production agents tested for excessive agency, tool abuse, privilege escalation, unsafe delegation and unauthorized actions?
Agent-specific
VAL-004
Does the organization perform structured AI red teaming for systems whose risk warrants it?
VAL-005
Are critical AI systems tested for outage, degradation, unsafe behavior and dependency failure scenarios?
Monitoring
Observe AI activity, distinguish autonomous actions and detect abuse, change and anomalous behavior.
MON-001
Does the organization collect security-relevant telemetry for critical AI applications, models, agents and tools?
MON-002
Can the organization reconstruct what a production AI agent did during a security investigation?
Agent-specific
MON-003
Can security operations distinguish user actions, AI recommendations and autonomous AI actions?
Agent-specific
MON-004
Are detections defined for abnormal AI usage, sensitive-data exposure, privilege abuse, suspicious tool use or anomalous agent behavior?
MON-005
Are material changes in models, AI providers, tools, permissions or dependencies monitored for security impact?
IR & Resilience
Contain AI-specific incidents and keep critical business processes operating through AI failures and provider disruption.
IR-001
Does incident response include playbooks for AI-specific scenarios?
IR-002
Can the organization quickly disable or isolate a compromised or unsafe AI agent and revoke its credentials and tool access?
Agent-specific
IR-003
Can the organization preserve relevant prompts, outputs, agent actions, identities, tool calls and model/context information for investigation?
IR-004
Are fallback and continuity plans defined for critical business processes that depend on AI services?
IR-005
Has the organization assessed concentration risk and exit or substitution options for critical external AI dependencies?
Measure
Measure AI risk and maturity, report material exposure and continuously improve controls.
MEAS-001
Are meaningful AI security KPIs and KRIs defined and reviewed?
MEAS-002
Is material AI risk integrated into executive or board-level risk reporting where appropriate?
MEAS-003
Is AI security maturity and exposure reassessed periodically and after material system changes?
MEAS-004
Are AI security improvement actions prioritized, owned and tracked to completion based on business exposure?
MEAS-005
Are findings from incidents, red teaming, validation, audits and operational telemetry used to improve AI controls and governance?