The Defender’s Guide to AI Agents·Appendix C

AI Agent Security: Framework Crosswalk

Crosswalk to the published frameworks

Mapping this guide onto the frameworks your auditors, customers and regulators already use. Everything below was verified against the primary source in September 2026, and several of the frameworks changed materially in the preceding six months - if you are working from an older crosswalk, the notes at the end list what has moved.

First, the distinction that makes a crosswalk honest.

Four different kinds of thing get mapped together in tables like this, and conflating them is how a document ends up implying that your own recommendations are somebody’s standard.

KindExamples in this guideHow to treat it
Framework requirementISO/IEC 42001 Annex A controls; NIST AI RMF subcategories; EU AI Act logging obligationsAuditable. Someone can hold you to it.
Threat taxonomyOWASP Top 10 for Agentic Applications; MITRE ATLAS techniquesA shared vocabulary for what can go wrong. Not a control list, and not compliance.
Emerging conventionOpenTelemetry generative-AI attributes; the common event schema’s AI profile; the OWASP Agent Observability StandardReal, useful, and none of it is stable. Build adapters, not dependencies.
Our recommendationThe digest-bound approval in 5.9; the downstream confirmation join in 5.10; the evidence tiers in 5.8No published precedent for agents. Argue them on merit, not authority.

C.1  The five surfaces against the threat taxonomies

SurfaceOWASP Agentic 2026OWASP LLM 2026MITRE ATLAS techniques
Context ASI01 Agent Goal Hijack LLM01:2026 Prompt Injection
LLM08:2026 Hidden Context Exposure
AML.T0051 LLM Prompt Injection (.000 Direct, .001 Indirect, .002 Triggered) · AML.T0093 Prompt Infiltration via Public-Facing Application · AML.T0094 Delay Execution of LLM Instructions · AML.T0070 RAG Poisoning
Tools ASI02 Tool Misuse and Exploitation
ASI04 Agentic Supply Chain Vulnerabilities
ASI05 Unexpected Code Execution (RCE)
LLM03:2026 Excessive Agency
LLM04:2026 Supply Chain
AML.T0053 AI Agent Tool Invocation · AML.T0110 AI Agent Tool Poisoning (.000 Definition and Instructions, .001 Implementation, .002 Runtime Response) · AML.T0109 AI Supply Chain Rug Pull · AML.T0010.005 AI Supply Chain Compromise: AI Agent Tool · AML.T0098 AI Agent Tool Credential Harvesting
Memory ASI06 Memory & Context Poisoning LLM05:2026 Data and Model Poisoning
LLM09:2026 Vector and Embedding Weaknesses
AML.T0080 AI Agent Context Poisoning (.000 Memory, .001 Thread) · AML.T0099 AI Agent Tool Data Poisoning
Identity ASI03 Identity and Privilege Abuse
ASI09 Human-Agent Trust Exploitation
ASI10 Rogue Agents
LLM03:2026 Excessive Agency AML.T0083 Credentials from AI Agent Configuration · AML.T0081 Modify AI Agent Configuration · AML.T0103 Deploy AI Agent · AML.T0084 Discover AI Agent Configuration
Orchestration ASI07 Insecure Inter-Agent Communication
ASI08 Cascading Failures
LLM06:2026 Unbounded Consumption AML.T0118 Autonomous AI Agent Communication (.000 via Shared Artifacts, .001 Direct) · AML.T0124 Autonomous Attack Orchestration · AML.T0034.002 Agentic Resource Consumption
Egress
(stage 6 of the chain)
- LLM02:2026 Sensitive Information Disclosure
LLM10:2026 Improper Output Handling
AML.T0086 Exfiltration via AI Agent Tool Invocation · AML.T0126 Automated Collection · AML.T0127 Data Staged

Note the asymmetry. The agentic list is organized by what the attacker achieves; the technique catalog by how. They are complementary and neither is a control set. If an assessor asks you to “comply with” either, the honest answer is that neither is a compliance instrument.

C.2  The controls against the management frameworks

This guideISO/IEC 42001:2023NIST AI RMF 1.0Status
Agent inventory with named owners (Chapter 10)A.3.2 AI roles and responsibilities · A.4.4 Tooling resourcesGOVERN 1, GOVERN 2 · MAP 1Requirement
Intended use written down (Chapter 9)A.9.4 Intended use of the AI systemMAP 1, MAP 2Requirement
Sixteen event families (5.6)A.6.2.8 AI system event logsMEASURE 2 · MANAGE 4Requirement names the control; the families are ours
Correlation spine (5.5)A.6.2.8 · A.6.2.6 Operation and monitoringMEASURE 2Convention (trace context is stable; the AI attributes are not)
Evidence tiers (5.8)A.6.2.8 · A.8.4 Communication of incidentsMANAGE 4Ours. EU AI Act sets a retention floor for in-scope systems
Approval binding (5.9)A.9.2 Processes for responsible useMANAGE 1, MANAGE 2Ours. The requirement is published; the mechanism is not
Downstream confirmation (5.10)A.6.2.6MEASURE 2, MEASURE 4Ours. No published precedent found
Telemetry suppression as a signal (5.11)A.6.2.6 · A.6.2.8MEASURE 2 · MANAGE 4Established as adversary technique; absent from the AI taxonomy
Identity separation (Chapter 7)A.9.2 · A.9.4MANAGE 1Architecture. No framework mandates it
Authority ladder (Chapter 7)A.9.2 · Clause 6.1.4 Impact assessmentMANAGE 1, MANAGE 2Requirement implies it; the ladder is a design
Pinning and change classes (Chapter 8)Clause 6.3 Planning of changes · A.10.3 SuppliersMANAGE 3 · GOVERN 6Requirement
Eval set on a schedule (Chapter 8)A.6.2.4 Verification and validation · A.6.2.6MEASURE 1, MEASURE 2, MEASURE 4Requirement
Containment ladder (Chapter 12)A.8.4 · A.9.2MANAGE 4Mechanisms established; agent framing emerging
Readiness measures (Chapter 13)A.6.2.6 · Clause 9 Performance evaluationMEASURE 3, MEASURE 4Ours. No published benchmark exists

The NIST profile for generative AI (AI 600-1, July 2024) remains the current companion to the framework. Three agent-specific NIST efforts are in progress and none has published output - in particular, the control overlay for AI agent systems is on the roadmap and does not yet exist. Do not let anyone cite it at you.

C.3  Where FedRAMP fits

FedRAMP is included here because it is frequently mentioned beside NIST and ISO in U.S. federal AI programs, but it is a different kind of instrument. It provides reusable assessment evidence for a specific cloud service offering. It does not replace the agency's authorization decision, define an AI management system or supply an agent-security control catalog.

InstrumentWhat it answersWhat it does not answer
ISO/IEC 42001How an organization establishes and improves an AI management system.Whether a specific cloud offering has completed a U.S. federal security assessment.
NIST AI RMFHow an organization can govern, map, measure and manage AI risk.Whether a cloud offering or the agency system using it is authorized.
FedRAMPWhether a specific cloud service offering has reusable federal security-assessment evidence.Whether the complete agent workflow, integrations and agency use are authorized, well governed or operationally safe.

Practical rule: use the Marketplace to verify the offering, the provider's package to understand inherited controls, and the agency authorization process to evaluate the full AI-agent system and its use.

C.4  Five gaps in the published frameworks

These are not criticisms. They are places where, if you build what this guide describes, you will find nothing to map it to - and knowing that in advance saves an argument in a design review.

  1. The AI threat taxonomy has no technique for suppressing telemetry. Its defense-evasion tactic covers evading the model, not evading the observer. Map that behavior to the general adversary framework instead, where disabling cloud logging is long established and both major SIEM vendors ship detections for it against AI platforms.
  2. The common event schema has no AI or agent event class. As of August 2026 AI is a profile and a set of objects layered onto existing classes; an agent tool call is modeled as API activity. Workable, but you are normalizing into your own shape either way.
  3. The agent control standard is not a control catalog. Published at v0.1 preview in September 2026, it specifies middleware hook points - input, output, tool call, memory, lifecycle - and runtime policy tiers. There are no numbered control families to crosswalk against. Map to the hooks, not to controls that do not exist.
  4. No convention correlates across organizations. When your agent delegates to a partner’s, nothing makes the two audit trails cross-referenceable. Inside your estate this is solvable today; across a boundary, record it as accepted risk.
  5. The community detection format has no AI log-source taxonomy. Which is why agent detection content does not travel between tools the way endpoint content does.

C.5  What changed recently, and what it breaks

  • A new agentic top ten exists (December 2025) with its own identifiers, separate from the long-standing list for language-model applications.
  • That language-model list was itself replaced in 2026. Ranks moved substantially and one entry was renamed and rescoped from system-prompt leakage to hidden context exposure. The project’s own per-risk web pages still serve the previous edition - cite the current document, not the site.
  • The technique catalog restructured in 2026, separating content version from format version, renaming one tactic, and adding roughly thirty agent and autonomy techniques plus four agent-specific mitigations. It also gained a platform field, so agentic techniques can now be filtered directly. Tooling pinned to the old distribution path silently produces a 2025-era mapping.
  • The generative-AI telemetry conventions moved repositories and now cover workflow, planning and memory operations as well as the original agent and tool spans, plus attributes for the tool protocol. Everything remains at development status; nothing is stable.

SourcesLast verified 17 September 2026

  1. OWASP Top 10 for Agentic Applications 2026, released December 2025. genai.owasp.org
  2. OWASP Top 10 for LLM Applications 2026, released August 2026. Note the project’s per-risk pages still show the 2025 edition. genai.owasp.org
  3. OWASP Agent Control Standard v0.1 (public preview), September 2026 - hook points and policy tiers, not a numbered control catalog. genai.owasp.org
  4. MITRE ATLAS, content version 2026.08 / format 6.0.0, released 1 September 2026. Technique identifiers above are taken from the official distribution rather than the website. atlas.mitre.org · github.com/mitre-atlas/atlas-data
  5. NIST AI Risk Management Framework 1.0 (AI 100-1), January 2023, and the Generative AI Profile (AI 600-1), July 2024. nist.gov
  6. NIST control overlays for securing AI systems - project page; the AI agent overlay is planned and unpublished. csrc.nist.gov/projects/cosais
  7. ISO/IEC 42001:2023. Clause and Annex A references are to the 2023 edition. iso.org/standard/42001
  8. FedRAMP 2026 guidance on using certified cloud services, the scope of FedRAMP and certification-status verification in the Marketplace. agency use · scope · Marketplace
  9. Adversary technique for disabling or modifying cloud logging. attack.mitre.org

About the author

Jessen Kurien is a cybersecurity leader and the author of The Defender’s Guide to AI Agents. His 18+ years in cybersecurity include nearly 15 years at Microsoft, work as part of the founding team of the Microsoft Threat Intelligence Center, and detection engineering leadership in Microsoft Defender XDR. His work connects investigations, detection engineering and security operations with the evidence and accountability needed for AI security and governance.

Meet Jessen

Connect with Jessen Speaking, workshops and training

This guide will go out of date.

Providers change how their logs work, models get retired, and new cases get disclosed. Ask to be told when this changes — no newsletter, just the updates.

Get told when it changes

Download the complete guide (PDF)

The telemetry contract, detection specifications, framework mappings and checklists are also published as files — the defender pack, CC BY 4.0, free to reuse.