Reference Library

Framework Library

ASRA synthesizes multiple recognized security, risk, governance and AI assurance references. This library shows the primary frameworks used to inform the assessment methodology and provides direct links to their official sources.

Summaries are short, independently written paraphrases. Full framework text is not reproduced here — use the official source link for the authoritative document.

Some standards are published under paid licence. Links point to the official catalogue page, not to free full text.

NIST AI RMF

Per-question mapped reference

NIST AI Risk Management Framework (AI RMF 1.0)

Issuing organization
National Institute of Standards and Technology (NIST)
Version / edition
1.0
Purpose and coverage
A voluntary framework for governing, mapping, measuring and managing risks across the AI lifecycle.
How ASRA uses it
Primary backbone for governance, risk classification, measurement and management questions across ASRA domains.
View official source

NIST GenAI Profile

Per-question mapped reference

NIST AI 600-1 — Generative AI Profile

Issuing organization
National Institute of Standards and Technology (NIST)
Version / edition
NIST AI 600-1
Purpose and coverage
A generative-AI overlay to the AI RMF describing risks unique to, or amplified by, generative systems and suggested actions.
How ASRA uses it
Applied to generative-AI specific questions covering content risk, data and model risk, disclosure and third-party GenAI use.
View official source

NIST CSF

Structural / supporting reference

NIST Cybersecurity Framework (CSF 2.0)

Issuing organization
National Institute of Standards and Technology (NIST)
Version / edition
2.0
Purpose and coverage
A widely used cybersecurity framework organizing security outcomes into govern, identify, protect, detect, respond and recover functions.
How ASRA uses it
Structural reference for ASRA's protection, detection, response and recovery domain design and control language.
View official source

ISO/IEC 42001

Per-question mapped reference

ISO/IEC 42001 — Artificial intelligence management systems

Issuing organization
ISO/IEC
Version / edition
2023
Purpose and coverage
An international management-system standard for establishing, operating and continually improving an AI management system.
How ASRA uses it
Thematic reference for governance, roles and authorities, risk treatment, documentation and continual improvement questions.
View official source

ISO/IEC 27001

Structural / supporting reference

ISO/IEC 27001 — Information security management systems

Issuing organization
ISO/IEC
Version / edition
2022
Purpose and coverage
An international management-system standard for information security, including risk treatment and control selection.
How ASRA uses it
Structural reference for information security management expectations that AI systems inherit.
View official source

CSA AICM

Per-question mapped reference

CSA AI Controls Matrix (AICM)

Issuing organization
Cloud Security Alliance (CSA)
Version / edition
v1.1
Purpose and coverage
A control matrix of AI-specific control objectives across security, governance and lifecycle domains, with mappings to major standards.
How ASRA uses it
Domain-level reference for AI control coverage in discovery, supply chain, data protection and threat and vulnerability management.
View official source

MITRE ATLAS

Per-question mapped reference

MITRE ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems

Issuing organization
MITRE
Purpose and coverage
A knowledge base of real-world adversary tactics and techniques targeting AI-enabled systems.
How ASRA uses it
Used for threat modeling, adversarial validation, detection engineering and incident traceability questions.
View official source

OWASP GenAI

Per-question mapped reference

OWASP Top 10 for Large Language Model Applications / GenAI Security guidance

Issuing organization
OWASP GenAI Security Project
Version / edition
2025
Purpose and coverage
Community guidance on the most critical security risks in large language model and generative AI applications.
How ASRA uses it
Referenced for prompt injection, sensitive information disclosure, supply chain, output handling and consumption risks.
View official source

OWASP Agentic

Per-question mapped reference

OWASP guidance for Agentic Applications / Agentic AI security

Issuing organization
OWASP GenAI Security Project
Purpose and coverage
Community guidance on security risks specific to agentic AI applications, including tool use, identity and autonomy.
How ASRA uses it
Referenced for agent goal hijack, tool misuse, privilege abuse, memory poisoning, containment and rogue-agent questions.
View official source

ASRA is an independent assessment. Framework references indicate methodological grounding and traceability only. They do not represent certification, formal compliance, endorsement, or validation by the framework owner.