Skip to content

VIII · The Security Governanceoverview

Part VIII · The Security Governance

Frameworks are not interchangeable, and treating them as one pile is why AI governance work stalls. Part VIII separates them by altitude - risk process, control set, management system, law - shows which question each one answers, shows how to measure where a program stands with OWASP AIMA (VIII.5 · OWASP AIMA - running an AI maturity assessment), and then cross-maps the regimes you are most likely to be asked about.

The last chapter is the practical one. VIII.7 · The advisor’s playbook is how to run this as an engagement rather than a reading list, and One system, end to end walks a single system from idea to production through everything in the book.

The frameworks

VIII.1 Frameworks & standards - four altitudes Threat taxonomies, control frameworks, governance systems, and certifiable standards - and how to cross-walk one control across all of them. govern · 11 min read VIII.2 Google SAIF - the controls layer Google's Secure AI Framework in depth: the six core elements, four components, fifteen risks, six control categories, the Risk Map, the Risk Assessment tool, SAIF 2.0 for agents, and CoSAI - and how to actually apply it. govern · 14 min read VIII.3 NIST AI RMF - the risk process The NIST AI Risk Management Framework in depth: the four functions (Govern, Map, Measure, Manage), the seven trustworthiness characteristics, and the Generative AI Profile - and how to run it as a process. govern · 10 min read VIII.4 ISO/IEC 42001, verification & maturity AISVS, AIVSS, and AIMA - the standards, scoring, and maturity models that turn a red-team into a verified, benchmarked posture. govern · 13 min read VIII.5 OWASP AIMA - running an AI maturity assessment How to run the OWASP AI Maturity Assessment in practice: the eight domains, the two scoring methods, and worked examples for a client engagement and for adopting it inside your own organization. govern · 15 min read

The obligations

VIII.6 Jurisdictions - Singapore, the EU, the US & UK Singapore's secure-by-design, risk-based regime and the EU AI Act - the local instruments an accredited tester assesses against, mapped outward. govern · 14 min read

The engagement

VIII.7 The advisor's playbook Turning the playbook into a method - assess, explain, recommend - plus running an AI risk assessment and standing up a governance program. govern · 10 min read