Blog

Reference

18 articles on AI security reference.

Reference11 min

Unbounded consumption in LLM applications — OWASP LLM Top 10 explained

OWASP reframed model-DoS as Unbounded Consumption, covering all uncontrolled resource drains. What reviews must now check.

Reference11 min

ISO 42001 certification — what the external audit actually checks

What an ISO 42001 external auditor samples at Stage 2, the nonconformity categories, and evidence gaps that recur most.

Reference10 min

Security review for agentic AI procurement — a buyer's checklist

Eight security areas procurement teams must address before an agentic AI system reaches production. A structured buyer checklist.

Reference10 min

Assessing third-party AI vendors — the questions procurement skips

AI vendor risk assessment beyond SOC 2: model governance, incident notification, and the evidence to re-assess when vendors change models.

Reference14 min

OWASP Agentic Top 10 mapped to required controls

OWASP Agentic Top 10 threats mapped to controls, lifecycle gates, and evidence -- a working checklist for your AI Committee, not just a list.

Reference10 min

MCP Server Security Review Checklist (2025)

Structured checklist for MCP server review: transport, authentication, tool manifest, context injection surface, dependencies, and evidence requirements.

Reference14 min

The OWASP Agentic Top 10, explained for security reviewers

OWASP Agentic Top 10 explained for practitioners: each threat category with actionable controls and evidence requirements a security reviewer can use.

Reference12 min

NIST AI RMF vs ISO 42001 — Which Framework to Choose

NIST AI RMF vs ISO 42001: the two leading AI governance frameworks compared across structure, certification, and evidence.

Reference11 min

The ISO 42001 evidence checklist for security reviews

Every evidence artefact an ISO 42001 audit will request, mapped by control domain and aligned to what AI security reviews already produce.

Reference10 min

Vetting third-party MCP servers before you connect them

Every third-party MCP server extends your agent's attack surface. The vetting process: source review, manifest audit, permission scope, and evidence.

Reference11 min

AI risk assessment under ISO 42001

ISO 42001 requires a documented AI risk assessment. What it must cover, how it differs from IT risk assessments, and what complete looks like.

Reference13 min

ISO 42001 Annex A Controls Explained (Plain Language)

Each ISO 42001 Annex A control domain explained in plain language, with the evidence that demonstrates conformance.

Reference10 min

Assessing the AI feature inside SaaS you already bought

Vendors are adding AI to SaaS you already trust. Those features introduce risks the original assessment missed. The supplemental review defined.

Reference11 min

ISO 42001 vs ISO 27001 — what is new for AI

Already hold ISO 27001? Here's what ISO 42001 adds for AI -- new requirements vs. controls you can extend from your existing ISMS.

Reference12 min

The AI security review checklist, by lifecycle gate

A lifecycle-gate checklist for AI security reviews: intake through production, with gate-specific questions and evidence needs.

Reference10 min

The AI section your vendor security questionnaire is missing

The AI vendor risk assessment questionnaire your procurement process is missing — model governance, re-assessment triggers, incident notification.

Reference12 min

ISO 42001, explained for security teams

ISO 42001 explained for security teams: what the AI management system standard requires, how it differs from 27001, and what auditors expect.

Reference14 min

The OWASP LLM Top 10, mapped to controls

OWASP LLM Top 10 mapped to specific controls, lifecycle gates, and verification evidence. From threat name to actionable review artefact.