The OWASP AI Exchange connects AI threats to controls
The OWASP AI Exchange provides a lifecycle map for moving from AI governance and threat analysis to testing, operations, and residual-risk decisions.
Автор: Tim Crouch
Больше из серии AI SecurityThe OWASP AI Exchange is a working security handbook. It covers governance, data protection, threat modeling, development-time attacks, runtime application risks, testing, privacy, and control selection. Its value is the connection between these subjects: teams can start with a use case, identify relevant threats, estimate likelihood and impact, select controls, assign responsibility, and continue evaluating residual risk.
CISSP Domain 1, Security and Risk Management, provides the organizing lens. The Exchange expects an AI inventory, clear ownership, risk acceptance, supplier accountability, and continuous reassessment. It treats AI security as a managed decision process rather than a catalogue of technical attacks. That is especially useful when controls span product, data, security, privacy, and business teams.
Domain 3, Security Architecture and Engineering, appears in its threat models and security matrix. The document distinguishes risks arising through use, model development, surrounding applications, data, and integrations. Architects can connect trust boundaries and system components to controls instead of assuming that a protected model means a protected service.
Domains 6 and 8 bring evidence into the lifecycle. Security Assessment and Testing includes model-focused exercises, misuse cases, application testing, and verification that selected safeguards work. Software Development Security addresses poisoning, development-environment compromise, source or configuration leakage, insecure output handling, and supply-chain dependencies.
Domain 7, Security Operations, ensures the analysis survives deployment. Monitoring, incident handling, feedback, control adjustment, and renewed assessment are required as systems and attacks evolve.
No organization will implement all 140-plus pages at once. The practical approach is to use the Exchange as a reference architecture: define the AI system, choose the sections that match its lifecycle and exposure, document selected controls, and record what remains. Its breadth is the point. AI security crosses governance, architecture, development, testing, and operations, and gaps usually appear where one team assumes another team owns the problem.