Reference Library
Framework Library
ASRA synthesizes multiple recognized security, risk, governance and AI assurance references. This library shows the primary frameworks used to inform the assessment methodology and provides direct links to their official sources.
Summaries are short, independently written paraphrases. Full framework text is not reproduced here — use the official source link for the authoritative document.
Some standards are published under paid licence. Links point to the official catalogue page, not to free full text.
NIST AI RMF
Per-question mapped referenceNIST AI Risk Management Framework (AI RMF 1.0)
- Issuing organization
- National Institute of Standards and Technology (NIST)
- Version / edition
- 1.0
- Purpose and coverage
- A voluntary framework for governing, mapping, measuring and managing risks across the AI lifecycle.
- How ASRA uses it
- Primary backbone for governance, risk classification, measurement and management questions across ASRA domains.
NIST GenAI Profile
Per-question mapped referenceNIST AI 600-1 — Generative AI Profile
- Issuing organization
- National Institute of Standards and Technology (NIST)
- Version / edition
- NIST AI 600-1
- Purpose and coverage
- A generative-AI overlay to the AI RMF describing risks unique to, or amplified by, generative systems and suggested actions.
- How ASRA uses it
- Applied to generative-AI specific questions covering content risk, data and model risk, disclosure and third-party GenAI use.
NIST CSF
Structural / supporting referenceNIST Cybersecurity Framework (CSF 2.0)
- Issuing organization
- National Institute of Standards and Technology (NIST)
- Version / edition
- 2.0
- Purpose and coverage
- A widely used cybersecurity framework organizing security outcomes into govern, identify, protect, detect, respond and recover functions.
- How ASRA uses it
- Structural reference for ASRA's protection, detection, response and recovery domain design and control language.
ISO/IEC 42001
Per-question mapped referenceISO/IEC 42001 — Artificial intelligence management systems
- Issuing organization
- ISO/IEC
- Version / edition
- 2023
- Purpose and coverage
- An international management-system standard for establishing, operating and continually improving an AI management system.
- How ASRA uses it
- Thematic reference for governance, roles and authorities, risk treatment, documentation and continual improvement questions.
ISO/IEC 27001
Structural / supporting referenceISO/IEC 27001 — Information security management systems
- Issuing organization
- ISO/IEC
- Version / edition
- 2022
- Purpose and coverage
- An international management-system standard for information security, including risk treatment and control selection.
- How ASRA uses it
- Structural reference for information security management expectations that AI systems inherit.
CSA AICM
Per-question mapped referenceCSA AI Controls Matrix (AICM)
- Issuing organization
- Cloud Security Alliance (CSA)
- Version / edition
- v1.1
- Purpose and coverage
- A control matrix of AI-specific control objectives across security, governance and lifecycle domains, with mappings to major standards.
- How ASRA uses it
- Domain-level reference for AI control coverage in discovery, supply chain, data protection and threat and vulnerability management.
MITRE ATLAS
Per-question mapped referenceMITRE ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems
- Issuing organization
- MITRE
- Purpose and coverage
- A knowledge base of real-world adversary tactics and techniques targeting AI-enabled systems.
- How ASRA uses it
- Used for threat modeling, adversarial validation, detection engineering and incident traceability questions.
OWASP GenAI
Per-question mapped referenceOWASP Top 10 for Large Language Model Applications / GenAI Security guidance
- Issuing organization
- OWASP GenAI Security Project
- Version / edition
- 2025
- Purpose and coverage
- Community guidance on the most critical security risks in large language model and generative AI applications.
- How ASRA uses it
- Referenced for prompt injection, sensitive information disclosure, supply chain, output handling and consumption risks.
OWASP Agentic
Per-question mapped referenceOWASP guidance for Agentic Applications / Agentic AI security
- Issuing organization
- OWASP GenAI Security Project
- Purpose and coverage
- Community guidance on security risks specific to agentic AI applications, including tool use, identity and autonomy.
- How ASRA uses it
- Referenced for agent goal hijack, tool misuse, privilege abuse, memory poisoning, containment and rogue-agent questions.
ASRA is an independent assessment. Framework references indicate methodological grounding and traceability only. They do not represent certification, formal compliance, endorsement, or validation by the framework owner.