The AICM Playbook
A structural guide from regulatory framework to frontline telemetry. The standards tell you what and why. This is the layer that tells you how — and who owns each piece when the stack is shared across five providers.
Policy documents and SOC dashboards speak different languages. Most AI governance programs stall in the space between them — a binder that satisfies an auditor but never changes a single alert rule. The AICM is the bridge.
NIST AI RMF 1.0, the NIST AI 600-1 Generative AI Profile, ISO/IEC 42001, and the EU AI Act. They define the “what” and “why” of trustworthy AI — but stop short of the granular “how” for cloud infrastructure.
243+ control objectives across 18 security domains. Vendor-agnostic, and specific enough to assign to an engineer. This is the operational blueprint the frameworks assume you already have.
Adversarial technique mapping, incident profiling, and SOC alerting — direct mitigation of data poisoning, indirect prompt injection, and adversarial tampering.
Eighteen domains, grouped by the job they do. Oversight sits above everything; foundational resilience carries the weight underneath. The four load-bearing groups in between are where AI-specific work actually happens.

Eighteen CSA AICM domains, arranged as a load-bearing structure.
Governance, Risk & Compliance · Audit & Assurance · Supply chain management, Transparency & Accountability.
Application & Interface Security · Model Security. The two domains with the least prior art in your existing security program.
Data Security & Privacy Lifecycle · Cryptography, Encryption & Key Management.
Identity & Access Management · Universal Endpoint Management · Human Resources. Agents are identities too.
Logging & Monitoring · Threat & Vulnerability Management · Security Incident Management and Forensics.
Infrastructure Security · Datacenter Security · Interoperability & Portability · Business Continuity · Change Control & Configuration Management.
Domain grouping is AssuredPosture’s operational reading of the CSA AI Controls Matrix. Domain names and codes are CSA’s.
AI risk is inherited upward. Every layer absorbs the unresolved risk of the one beneath it, and the customer at the top inherits all of it. Gaps appear wherever two parties each assume the other owns a control.

Risk inheritance flows upward. The AI customer sits at the top of the stack and inherits everything below it.
A single request crosses five trust boundaries. Each one has a control that belongs to it — and a failure mode when it is missing.
Filters adversarial patterns before anything reaches the model.
AIS
Secures cached generative memory against cross-tenant extraction.
AIS
Enforces strict need-to-know boundaries on tools and plugins.
IAM
Cryptographic checksum validation of model state before execution.
MDS
Blocks malicious code execution and policy-violating generation.
AIS
Retrieval-augmented generation is where most mid-market AI deployments quietly become high-risk. The question is not whether an indirect prompt injection will land — it is what the model can reach when one does.

Left: every connected store is in reach. Right: one authorized bucket, scoped to the task.
One model, unfettered access to every connected store
Without strict identity isolation, a single successful indirect prompt injection grants the model everything the connector can see — six databases, or sixty. The compromise is not the injection. It is the topology that made the injection worth attempting.
Least-privilege retrieval, one authorized bucket at a time
The model reaches exactly one authorized store, scoped to the task. An injection that succeeds still touches nothing it was not already entitled to. Containment is architectural, not reactive.
Threat intelligence is only useful when it terminates in a control someone owns. This is the join.
| Vector / Threat Class | Target Surface | AICM Mitigation Domain |
|---|---|---|
| Adversarial ML — indirect prompt injection | Application interface and training pipelines | AIS — secure SDLC and application security testing |
| STRIDE — tampering | Core model artifacts | MDS — model artifact scanning and robustness against adversarial attack |
| STRIDE — repudiation | Governance and action logging | GRC risk management program with LOG audit log accountability |
| STRIDE — information disclosure | Retrieval connectors and cached context | DSP data protection by design with AIS cache protection |
Mapped at domain level. Specific control objectives within each domain are selected and confirmed against the AICM release in force during your engagement.
Identical domains demand radically different tactics depending on the state of the environment. Teams that run one playbook for both end up testing what is already live, and monitoring what was never tested.
Rigorous testing, vulnerability discovery, containment validation
Continuous monitoring, real-time detection, operational resilience
AI systems have to be broken deliberately, in isolation, before they are trusted in front of anyone. The sandbox is not a formality — it is the only place where failure is free.
Verify that pre-production logs capture full prompt–response pairs, so a suspected prompt leak can actually be investigated rather than guessed at.
Validate model documentation against observed model behaviour and internal privacy policy before staging. Documentation that was never tested is a claim, not a control.
Aggressive penetration testing aimed specifically at model evasion and boundary logic — input injection, resource exhaustion, privacy leak probes, policy violation triggers.

The containment sandbox: stress the model where the blast radius is zero.
Once deployed, posture shifts from static testing to continuous anomaly detection. The controls stop being things you did and become things you watch.

Anomaly score, prompt volume, and exfiltration risk, tracked as first-class operational signals.
Real-time alerts for high-risk prompt patterns across both input and output event logs — anomaly score, prompt volume, and exfiltration risk tracked as first-class signals.
Strict change-management monitoring for encryption keys, generating alerts on unauthorized rotation attempts before they become silent access.
Managed endpoints configured with data loss prevention to catch exfiltration through AI application outputs — the exit path most programs never instrument.
Third-party integrations are the weakest link in the AI lifecycle. Data providers, base model APIs, and plugin vendors all reach your enterprise core — and each arrives with terms someone should have read.

Every third-party path into the enterprise core passes a supply chain control gate — or it is an unmanaged entry point.
A strict Bill of Materials for the entire service supply chain, so underlying model dependencies are tracked rather than assumed. You cannot assess a component you cannot name.
Service agreements that legally bind third parties to specific shared-responsibility, logging, and data privacy requirements — not marketing assurances.
Leadership-sponsored governance whenever a deviation from AI acceptable-use policy occurs. Undocumented exceptions become the de facto policy within a quarter.
As AI moves from reactive chatbots to proactive, autonomous ecosystems, the control plane — not the model — becomes the thing you are actually defending.

The agentic control plane: many autonomous nodes, one governed execution fabric.
As AI moves from reactive chatbots to proactive, autonomous agentic ecosystems, the attack surface expands non-linearly. An agent is an identity, a network client, and an execution context at once. Mastering tactical controls now is not a compliance exercise — it is the prerequisite for operating agents at all.
Establish strict agent access restrictions (IAM), robust API security (AIS), and verifiable model integrity (MDS) today. Those three lay the immutable foundation everything agentic will be built on — and they are achievable inside a quarter at mid-market scale.
Our position: most organizations do not need all 243+ controls. They need the twenty or so that match their architecture, their data, and their actual threat exposure — implemented properly, owned by name, and evidenced. That is the engagement.
Attribution. The AI Controls Matrix (AICM) is created, maintained, and published by the Cloud Security Alliance. Domain names, domain codes, and the shared responsibility model referenced on this page are CSA’s work. AssuredPosture is an independent consultancy that implements and translates the AICM for mid-market organizations; the groupings, commentary, diagrams, and operational guidance on this page are ours. We are not affiliated with, sponsored by, or endorsed by CSA. Control objectives are referenced at domain level only; specific objectives are selected and confirmed against the AICM release in force at the time of each engagement. Framework references include NIST AI RMF 1.0, NIST AI 600-1, ISO/IEC 42001, the EU AI Act, and STRIDE, each the property of their respective owners.
One free assessment maps where you stand across the AICM domains that apply to you — and gives you a prioritized, owned path to close the gaps.
Request a Free Assessment