VI · The Security Assessmentoverview
Part VI · The Security Assessment
The layers tell you what exists. This part tells you what to do about it. Frame the system, model the threats, run the test, and score the result in a way that survives review.
Frame the Scope of Work
VI.1 Security, safety & who is actually attacking you Safety is unintended harm; security is an adversary - and three structural properties break traditional appsec. concept · 6 min read VI.2 The five boundaries Two reusable maps: the four-region attack surface and the model lifecycle where attacks and controls attach. concept · 3 min read VI.3 Threat modeling for AI systems Why STRIDE breaks on AI, what MAESTRO adds, the AI-specific lenses, and a practical modern workflow. concept · 5 min readExecute the work
VI.4 The AI red-team playbook A standalone offensive reference: threat-model, recon, exploit each AI surface, chain to impact, report - with worked examples. runbook · 18 min read VI.5 Running the engagement How to run, score, and report a high-harm red-team session, and slot it into Singapore's accreditation toolchain. runbook · 5 min readAssess the risks
VI.6 Capability & assurance evaluation The methodology for measuring CBRN, cyber, and AI-R&D capability - uplift studies, proxies, and grading - without generating the hazard. runbook · 13 min read