The Defender’s Guide to AI Agents·Appendix C
AI Agent Security: Framework Crosswalk
By Jessen Kurien · CISM, CISA, ISO/IEC 42001 Lead Implementer & Lead Auditor ·
Crosswalk to the published frameworks
Mapping this guide onto the frameworks your auditors, customers and regulators already use. Everything below was verified against the primary source in September 2026, and several of the frameworks changed materially in the preceding six months - if you are working from an older crosswalk, the notes at the end list what has moved.
First, the distinction that makes a crosswalk honest.
Four different kinds of thing get mapped together in tables like this, and conflating them is how a document ends up implying that your own recommendations are somebody’s standard.
| Kind | Examples in this guide | How to treat it |
|---|---|---|
| Framework requirement | ISO/IEC 42001 Annex A controls; NIST AI RMF subcategories; EU AI Act logging obligations | Auditable. Someone can hold you to it. |
| Threat taxonomy | OWASP Top 10 for Agentic Applications; MITRE ATLAS techniques | A shared vocabulary for what can go wrong. Not a control list, and not compliance. |
| Emerging convention | OpenTelemetry generative-AI attributes; the common event schema’s AI profile; the OWASP Agent Observability Standard | Real, useful, and none of it is stable. Build adapters, not dependencies. |
| Our recommendation | The digest-bound approval in 5.9; the downstream confirmation join in 5.10; the evidence tiers in 5.8 | No published precedent for agents. Argue them on merit, not authority. |
C.1 The five surfaces against the threat taxonomies
| Surface | OWASP Agentic 2026 | OWASP LLM 2026 | MITRE ATLAS techniques |
|---|---|---|---|
| Context | ASI01 Agent Goal Hijack | LLM01:2026 Prompt Injection LLM08:2026 Hidden Context Exposure |
AML.T0051 LLM Prompt Injection (.000 Direct, .001 Indirect, .002 Triggered) · AML.T0093 Prompt Infiltration via Public-Facing Application · AML.T0094 Delay Execution of LLM Instructions · AML.T0070 RAG Poisoning |
| Tools | ASI02 Tool Misuse and Exploitation ASI04 Agentic Supply Chain Vulnerabilities ASI05 Unexpected Code Execution (RCE) |
LLM03:2026 Excessive Agency LLM04:2026 Supply Chain |
AML.T0053 AI Agent Tool Invocation · AML.T0110 AI Agent Tool Poisoning (.000 Definition and Instructions, .001 Implementation, .002 Runtime Response) · AML.T0109 AI Supply Chain Rug Pull · AML.T0010.005 AI Supply Chain Compromise: AI Agent Tool · AML.T0098 AI Agent Tool Credential Harvesting |
| Memory | ASI06 Memory & Context Poisoning | LLM05:2026 Data and Model Poisoning LLM09:2026 Vector and Embedding Weaknesses |
AML.T0080 AI Agent Context Poisoning (.000 Memory, .001 Thread) · AML.T0099 AI Agent Tool Data Poisoning |
| Identity | ASI03 Identity and Privilege Abuse ASI09 Human-Agent Trust Exploitation ASI10 Rogue Agents |
LLM03:2026 Excessive Agency | AML.T0083 Credentials from AI Agent Configuration · AML.T0081 Modify AI Agent Configuration · AML.T0103 Deploy AI Agent · AML.T0084 Discover AI Agent Configuration |
| Orchestration | ASI07 Insecure Inter-Agent Communication ASI08 Cascading Failures |
LLM06:2026 Unbounded Consumption | AML.T0118 Autonomous AI Agent Communication (.000 via Shared Artifacts, .001 Direct) · AML.T0124 Autonomous Attack Orchestration · AML.T0034.002 Agentic Resource Consumption |
| Egress (stage 6 of the chain) |
- | LLM02:2026 Sensitive Information Disclosure LLM10:2026 Improper Output Handling |
AML.T0086 Exfiltration via AI Agent Tool Invocation · AML.T0126 Automated Collection · AML.T0127 Data Staged |
Note the asymmetry. The agentic list is organized by what the attacker achieves; the technique catalog by how. They are complementary and neither is a control set. If an assessor asks you to “comply with” either, the honest answer is that neither is a compliance instrument.
C.2 The controls against the management frameworks
| This guide | ISO/IEC 42001:2023 | NIST AI RMF 1.0 | Status |
|---|---|---|---|
| Agent inventory with named owners (Chapter 10) | A.3.2 AI roles and responsibilities · A.4.4 Tooling resources | GOVERN 1, GOVERN 2 · MAP 1 | Requirement |
| Intended use written down (Chapter 9) | A.9.4 Intended use of the AI system | MAP 1, MAP 2 | Requirement |
| Sixteen event families (5.6) | A.6.2.8 AI system event logs | MEASURE 2 · MANAGE 4 | Requirement names the control; the families are ours |
| Correlation spine (5.5) | A.6.2.8 · A.6.2.6 Operation and monitoring | MEASURE 2 | Convention (trace context is stable; the AI attributes are not) |
| Evidence tiers (5.8) | A.6.2.8 · A.8.4 Communication of incidents | MANAGE 4 | Ours. EU AI Act sets a retention floor for in-scope systems |
| Approval binding (5.9) | A.9.2 Processes for responsible use | MANAGE 1, MANAGE 2 | Ours. The requirement is published; the mechanism is not |
| Downstream confirmation (5.10) | A.6.2.6 | MEASURE 2, MEASURE 4 | Ours. No published precedent found |
| Telemetry suppression as a signal (5.11) | A.6.2.6 · A.6.2.8 | MEASURE 2 · MANAGE 4 | Established as adversary technique; absent from the AI taxonomy |
| Identity separation (Chapter 7) | A.9.2 · A.9.4 | MANAGE 1 | Architecture. No framework mandates it |
| Authority ladder (Chapter 7) | A.9.2 · Clause 6.1.4 Impact assessment | MANAGE 1, MANAGE 2 | Requirement implies it; the ladder is a design |
| Pinning and change classes (Chapter 8) | Clause 6.3 Planning of changes · A.10.3 Suppliers | MANAGE 3 · GOVERN 6 | Requirement |
| Eval set on a schedule (Chapter 8) | A.6.2.4 Verification and validation · A.6.2.6 | MEASURE 1, MEASURE 2, MEASURE 4 | Requirement |
| Containment ladder (Chapter 12) | A.8.4 · A.9.2 | MANAGE 4 | Mechanisms established; agent framing emerging |
| Readiness measures (Chapter 13) | A.6.2.6 · Clause 9 Performance evaluation | MEASURE 3, MEASURE 4 | Ours. No published benchmark exists |
The NIST profile for generative AI (AI 600-1, July 2024) remains the current companion to the framework. Three agent-specific NIST efforts are in progress and none has published output - in particular, the control overlay for AI agent systems is on the roadmap and does not yet exist. Do not let anyone cite it at you.
C.3 Where FedRAMP fits
FedRAMP is included here because it is frequently mentioned beside NIST and ISO in U.S. federal AI programs, but it is a different kind of instrument. It provides reusable assessment evidence for a specific cloud service offering. It does not replace the agency's authorization decision, define an AI management system or supply an agent-security control catalog.
| Instrument | What it answers | What it does not answer |
|---|---|---|
| ISO/IEC 42001 | How an organization establishes and improves an AI management system. | Whether a specific cloud offering has completed a U.S. federal security assessment. |
| NIST AI RMF | How an organization can govern, map, measure and manage AI risk. | Whether a cloud offering or the agency system using it is authorized. |
| FedRAMP | Whether a specific cloud service offering has reusable federal security-assessment evidence. | Whether the complete agent workflow, integrations and agency use are authorized, well governed or operationally safe. |
Practical rule: use the Marketplace to verify the offering, the provider's package to understand inherited controls, and the agency authorization process to evaluate the full AI-agent system and its use.
C.4 Five gaps in the published frameworks
These are not criticisms. They are places where, if you build what this guide describes, you will find nothing to map it to - and knowing that in advance saves an argument in a design review.
- The AI threat taxonomy has no technique for suppressing telemetry. Its defense-evasion tactic covers evading the model, not evading the observer. Map that behavior to the general adversary framework instead, where disabling cloud logging is long established and both major SIEM vendors ship detections for it against AI platforms.
- The common event schema has no AI or agent event class. As of August 2026 AI is a profile and a set of objects layered onto existing classes; an agent tool call is modeled as API activity. Workable, but you are normalizing into your own shape either way.
- The agent control standard is not a control catalog. Published at v0.1 preview in September 2026, it specifies middleware hook points - input, output, tool call, memory, lifecycle - and runtime policy tiers. There are no numbered control families to crosswalk against. Map to the hooks, not to controls that do not exist.
- No convention correlates across organizations. When your agent delegates to a partner’s, nothing makes the two audit trails cross-referenceable. Inside your estate this is solvable today; across a boundary, record it as accepted risk.
- The community detection format has no AI log-source taxonomy. Which is why agent detection content does not travel between tools the way endpoint content does.
C.5 What changed recently, and what it breaks
- A new agentic top ten exists (December 2025) with its own identifiers, separate from the long-standing list for language-model applications.
- That language-model list was itself replaced in 2026. Ranks moved substantially and one entry was renamed and rescoped from system-prompt leakage to hidden context exposure. The project’s own per-risk web pages still serve the previous edition - cite the current document, not the site.
- The technique catalog restructured in 2026, separating content version from format version, renaming one tactic, and adding roughly thirty agent and autonomy techniques plus four agent-specific mitigations. It also gained a platform field, so agentic techniques can now be filtered directly. Tooling pinned to the old distribution path silently produces a 2025-era mapping.
- The generative-AI telemetry conventions moved repositories and now cover workflow, planning and memory operations as well as the original agent and tool spans, plus attributes for the tool protocol. Everything remains at development status; nothing is stable.
SourcesLast verified 17 September 2026
- OWASP Top 10 for Agentic Applications 2026, released December 2025. genai.owasp.org
- OWASP Top 10 for LLM Applications 2026, released August 2026. Note the project’s per-risk pages still show the 2025 edition. genai.owasp.org
- OWASP Agent Control Standard v0.1 (public preview), September 2026 - hook points and policy tiers, not a numbered control catalog. genai.owasp.org
- MITRE ATLAS, content version 2026.08 / format 6.0.0, released 1 September 2026. Technique identifiers above are taken from the official distribution rather than the website. atlas.mitre.org · github.com/mitre-atlas/atlas-data
- NIST AI Risk Management Framework 1.0 (AI 100-1), January 2023, and the Generative AI Profile (AI 600-1), July 2024. nist.gov
- NIST control overlays for securing AI systems - project page; the AI agent overlay is planned and unpublished. csrc.nist.gov/projects/cosais
- ISO/IEC 42001:2023. Clause and Annex A references are to the 2023 edition. iso.org/standard/42001
- FedRAMP 2026 guidance on using certified cloud services, the scope of FedRAMP and certification-status verification in the Marketplace. agency use · scope · Marketplace
- Adversary technique for disabling or modifying cloud logging. attack.mitre.org
About the author
Jessen Kurien is a cybersecurity leader and the author of The Defender’s Guide to AI Agents. His 18+ years in cybersecurity include nearly 15 years at Microsoft, work as part of the founding team of the Microsoft Threat Intelligence Center, and detection engineering leadership in Microsoft Defender XDR. His work connects investigations, detection engineering and security operations with the evidence and accountability needed for AI security and governance.
This guide will go out of date.
Providers change how their logs work, models get retired, and new cases get disclosed. Ask to be told when this changes — no newsletter, just the updates.
Download the complete guide (PDF)
The telemetry contract, detection specifications, framework mappings and checklists are also published as files — the defender pack, CC BY 4.0, free to reuse.