Using NIST AI RMF to Build an AISecOps Program
NIST AI RMF gives an AI security program its operating model: govern the work, map the context, measure the risk, and manage what happens next.
reading series / 5 notes
Read these in order, or jump directly to the problem you are working on.
NIST AI RMF gives an AI security program its operating model: govern the work, map the context, measure the risk, and manage what happens next.
The OWASP LLM Top 10 turns common language-model failure modes into security requirements, tests, telemetry, and response plans.
The OWASP Agentic Top 10 moves security beyond model output and into goals, tools, identities, memory, delegation, and runtime control.
MITRE ATLAS gives AI security teams a shared map of adversary behavior for threat modeling, detection engineering, red teaming, and incident response.
I am using the Foundry Citadel reference platform to test how identity, network isolation, gateway policy, observability, and agent lifecycle controls fit together in a governed Azure deployment.