{"version":"1.0","functions":[{"code":"GV","name":"Govern","ordinal":1,"description":"Establish accountability, policy, and risk ownership for AI systems."},{"code":"DS","name":"Discover","ordinal":2,"description":"Know what AI you have, what data feeds it, and where it is exposed."},{"code":"SC","name":"Secure","ordinal":3,"description":"Protect data, models, pipelines, and interactions from compromise."},{"code":"DT","name":"Detect","ordinal":4,"description":"See attacks against and through AI systems in time to act."},{"code":"RS","name":"Respond","ordinal":5,"description":"Contain, recover, and learn when AI systems are attacked or misbehave."},{"code":"AS","name":"Assure","ordinal":6,"description":"Prove security continuously through testing, evaluation, and audit."}],"families":[{"id":"AS.1","function_code":"AS","name":"Pre-Deployment Assurance","ordinal":1,"description":null},{"id":"AS.2","function_code":"AS","name":"Continuous Validation","ordinal":2,"description":null},{"id":"AS.3","function_code":"AS","name":"Audit & Conformance","ordinal":3,"description":null},{"id":"DS.1","function_code":"DS","name":"AI Asset Inventory","ordinal":1,"description":null},{"id":"DS.2","function_code":"DS","name":"Data Provenance & Classification","ordinal":2,"description":null},{"id":"DS.3","function_code":"DS","name":"Exposure Mapping","ordinal":3,"description":null},{"id":"DT.1","function_code":"DT","name":"Telemetry & Logging","ordinal":1,"description":null},{"id":"DT.2","function_code":"DT","name":"Threat Detection","ordinal":2,"description":null},{"id":"DT.3","function_code":"DT","name":"Model & Pipeline Monitoring","ordinal":3,"description":null},{"id":"GV.1","function_code":"GV","name":"Accountability & Policy","ordinal":1,"description":null},{"id":"GV.2","function_code":"GV","name":"Risk Management","ordinal":2,"description":null},{"id":"GV.3","function_code":"GV","name":"Third-Party & Supply Chain Governance","ordinal":3,"description":null},{"id":"GV.4","function_code":"GV","name":"Workforce & Culture","ordinal":4,"description":null},{"id":"RS.1","function_code":"RS","name":"AI Incident Response","ordinal":1,"description":null},{"id":"RS.2","function_code":"RS","name":"Containment & Recovery","ordinal":2,"description":null},{"id":"RS.3","function_code":"RS","name":"Disclosure & Learning","ordinal":3,"description":null},{"id":"SC.1","function_code":"SC","name":"Data Security","ordinal":1,"description":null},{"id":"SC.2","function_code":"SC","name":"Model Protection","ordinal":2,"description":null},{"id":"SC.3","function_code":"SC","name":"Supply Chain Security","ordinal":3,"description":null},{"id":"SC.4","function_code":"SC","name":"Input & Interaction Hardening","ordinal":4,"description":null},{"id":"SC.5","function_code":"SC","name":"Output & Action Safety","ordinal":5,"description":null},{"id":"SC.6","function_code":"SC","name":"Infrastructure & Pipeline","ordinal":6,"description":null},{"id":"SC.7","function_code":"SC","name":"Agentic AI Security","ordinal":7,"description":null}],"frameworks":[{"code":"aicm","name":"CSA AI Controls Matrix (AICM)","version":null,"url":"https://cloudsecurityalliance.org"},{"code":"atlas","name":"MITRE ATLAS","version":"5.6.0","url":"https://atlas.mitre.org"},{"code":"iso_42001","name":"ISO/IEC 42001","version":"2023","url":"https://www.iso.org/standard/42001"},{"code":"nist_800_53","name":"NIST SP 800-53","version":"Rev 5","url":"https://csrc.nist.gov/pubs/sp/800/53/r5/final"},{"code":"nist_ai_rmf","name":"NIST AI Risk Management Framework","version":"1.0","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"code":"omb","name":"OMB Memoranda (Federal AI)","version":"M-24-10","url":null},{"code":"oscal","name":"NIST OSCAL","version":null,"url":"https://pages.nist.gov/OSCAL"},{"code":"owasp_llm","name":"OWASP Top 10 for LLM Applications","version":"2025","url":"https://genai.owasp.org"},{"code":"saif","name":"Google Secure AI Framework (SAIF)","version":null,"url":"https://saif.google"},{"code":"sans_aismm","name":"SANS AI Security Maturity Model","version":null,"url":"https://www.sans.org"}],"tags":[{"code":"agentic","name":"Agentic AI"}],"counts":{"controls":65,"families":23,"mappings":201}}