{
  "_about": "Primary-source references cited by the matrix. Every control's sources[] and mapping evidence.ref resolve to these ids.",
  "version": "1.2",
  "generated_at": "2026-06-28T04:07:14.224Z",
  "count": 75,
  "references": [
    {
      "id": "aisvs",
      "title": "OWASP AISVS (Artificial Intelligence Security Verification Standard) v1.0; testable AI security requirements across 12 chapters at three verification levels (C9 Orchestration & Agentic Action and C10 MCP Security are the agent-specific chapters)",
      "url": "https://github.com/OWASP/AISVS",
      "type": "framework",
      "date": "2026"
    },
    {
      "id": "imda-mgf",
      "title": "Singapore IMDA / AI Verify Foundation, Model AI Governance Framework (MGF) for Agentic AI v1.5 (20 May 2026, updated 5 Jun 2026); four dimensions: assess and bound risks, make humans accountable, technical controls, end-user responsibility",
      "url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/factsheets/2026/updated-model-ai-governance-framework-for-agentic-ai",
      "type": "framework",
      "date": "2026"
    },
    {
      "id": "owasp-asi-2026",
      "title": "OWASP Top 10 for Agentic Applications 2026",
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "type": "framework",
      "date": "2025-12-09"
    },
    {
      "id": "owasp-nhi-2025",
      "title": "OWASP Non-Human Identities Top 10 (2025)",
      "url": "https://owasp.org/www-project-non-human-identities-top-10/",
      "type": "framework",
      "date": "2025"
    },
    {
      "id": "owasp-llm-2025",
      "title": "OWASP Top 10 for LLM Applications (2025)",
      "url": "https://genai.owasp.org/llm-top-10/",
      "type": "framework",
      "date": "2025"
    },
    {
      "id": "owasp-agentic-threats",
      "title": "OWASP Agentic AI, Threats and Mitigations",
      "url": "https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/",
      "type": "framework",
      "date": "2025"
    },
    {
      "id": "csa-aicm",
      "title": "CSA AI Controls Matrix (AICM) v1.1.0 — 247 control objectives across 18 domains (released 2026-06-22); four-stakeholder responsibility model; crosswalked to NIST AI 600-1 / ISO 42001 / EU AI Act. This crosswalk is re-audited cell-by-cell against the v1.1 catalog: the IAM, AIS, LOG, STA, and TVM domains renumbered from v1.0.3, and all cited ids were corrected and per-cell evidenced (see CORRECTIONS.md). The STAR AI tags are re-derived against the v1.1 AI-Specific control set (32 controls; 14 of ours map to one).",
      "url": "https://cloudsecurityalliance.org/blog/2025/07/10/introducing-the-csa-ai-controls-matrix-a-comprehensive-framework-for-trustworthy-ai",
      "type": "framework",
      "date": "2025-07-10",
      "flagship": true
    },
    {
      "id": "csa-maestro",
      "title": "CSA MAESTRO, seven-layer agentic threat model (L1-L7)",
      "url": "https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro",
      "type": "framework",
      "date": "2025-02-06",
      "flagship": true
    },
    {
      "id": "nist-ai-rmf",
      "title": "NIST AI Risk Management Framework (Govern/Map/Measure/Manage)",
      "url": "https://www.nist.gov/itl/ai-risk-management-framework",
      "type": "framework",
      "date": "2023"
    },
    {
      "id": "nist-ai-600-1",
      "title": "NIST AI 600-1, Generative AI Profile (the doc AICM crosswalks to)",
      "url": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence",
      "type": "framework",
      "date": "2024-07"
    },
    {
      "id": "nist-nccoe-agent-id",
      "title": "NIST NCCoE, Accelerating the Adoption of Software and AI Agent Identity and Authorization (concept paper, no control IDs)",
      "url": "https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd",
      "type": "framework",
      "date": "2026-02-05"
    },
    {
      "id": "nist-cosais",
      "title": "NIST SP 800-53 Control Overlays for Securing AI Systems (COSAiS); multi-agent overlay forthcoming, no published control IDs yet",
      "url": "https://csrc.nist.gov/projects/cosais",
      "type": "framework",
      "date": "2026",
      "claim": false
    },
    {
      "id": "nist-caisi",
      "title": "NIST CAISI (the center), AI Agent Standards Initiative (the program, launched Feb 17 2026)",
      "url": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative",
      "type": "framework",
      "date": "2026-02-17"
    },
    {
      "id": "iso-42001",
      "title": "ISO/IEC 42001:2023, AI management system (Annex A controls A.2-A.10)",
      "url": "https://www.iso.org/standard/42001",
      "type": "standard",
      "date": "2023"
    },
    {
      "id": "iso-ai-series",
      "title": "ISO/IEC 27090 (AI security), 27091 (AI privacy), 42005 (AI impact assessment)",
      "url": "https://www.iso.org/committee/6794475.html",
      "type": "standard",
      "date": "2025"
    },
    {
      "id": "eu-ai-act-art12",
      "title": "EU AI Act Article 12, record-keeping (automatic event logging over the system lifetime; retention set elsewhere)",
      "url": "https://artificialintelligenceact.eu/article/12/",
      "type": "regulation",
      "date": "2024"
    },
    {
      "id": "eu-ai-act-art26",
      "title": "EU AI Act Article 26(6), deployer obligation to retain automatically generated logs for at least 6 months",
      "url": "https://artificialintelligenceact.eu/article/26/",
      "type": "regulation",
      "date": "2024"
    },
    {
      "id": "eu-ai-act-art9",
      "title": "EU AI Act Article 9, risk management system",
      "url": "https://artificialintelligenceact.eu/article/9/",
      "type": "regulation",
      "date": "2024"
    },
    {
      "id": "cisa-agentic",
      "title": "CISA — Careful Adoption of Agentic Artificial Intelligence (AI) Services (5 risk classes: privilege, design/config, behavioural, structural, accountability)",
      "url": "https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services",
      "type": "framework",
      "date": "2026-05-01"
    },
    {
      "id": "mitre-atlas",
      "title": "MITRE ATLAS, adversarial threat landscape for AI systems (AML.T… technique IDs; agentic techniques added v5.x)",
      "url": "https://atlas.mitre.org",
      "type": "framework",
      "date": "2026"
    },
    {
      "id": "mitre-attack",
      "title": "MITRE ATT&CK, enterprise technique IDs (e.g. T1567 Exfiltration Over Web Service)",
      "url": "https://attack.mitre.org",
      "type": "framework",
      "date": "2026"
    },
    {
      "id": "aws-scoping-matrix",
      "title": "AWS Agentic AI Security Scoping Matrix, scopes agent risk by level of agency",
      "url": "https://aws.amazon.com/blogs/security/the-agentic-ai-security-scoping-matrix-a-framework-for-securing-autonomous-ai-systems/",
      "type": "framework",
      "date": "2025-11-21"
    },
    {
      "id": "cosai-oasis",
      "title": "Coalition for Secure AI (CoSAI) at OASIS, cross-vendor standards venue",
      "url": "https://www.coalitionforsecureai.org/",
      "type": "framework",
      "date": "2025"
    },
    {
      "id": "anthropic-attack-navigator",
      "title": "Anthropic, LLM ATT&CK Navigator + ARiES (832 accounts, 13,873 actions, 482 techniques, all 14 tactics; ARiES additive scoring)",
      "url": "https://www.anthropic.com/research/attack-navigator",
      "type": "research",
      "date": "2026-06-03"
    },
    {
      "id": "anthropic-gtg1002",
      "title": "Anthropic, Disrupting the first AI-orchestrated cyber-espionage campaign (GTG-1002)",
      "url": "https://www.anthropic.com/news/disrupting-AI-espionage",
      "type": "research",
      "date": "2025-11-13"
    },
    {
      "id": "anthropic-mcp",
      "title": "Anthropic, Model Context Protocol (agent-to-tool standard)",
      "url": "https://www.anthropic.com/news/model-context-protocol",
      "type": "spec",
      "date": "2024-11-25"
    },
    {
      "id": "anthropic-glasswing",
      "title": "Anthropic, Project Glasswing (defensive frontier-capability program)",
      "url": "https://www.anthropic.com/glasswing",
      "type": "vendor",
      "date": "2026",
      "claim": true
    },
    {
      "id": "google-secure-agents",
      "title": "Google, An Introduction to Google's Approach for Secure AI Agents (three principles: human controllers, limited powers, observable actions)",
      "url": "https://research.google/pubs/an-introduction-to-googles-approach-for-secure-ai-agents/",
      "type": "vendor",
      "date": "2025-05"
    },
    {
      "id": "google-saif2",
      "title": "Google, SAIF 2.0 + Agent Risk Map (donated to CoSAI)",
      "url": "https://blog.google/innovation-and-ai/technology/safety-security/ai-security-frontier-strategy-tools/",
      "type": "vendor",
      "date": "2025-10-06"
    },
    {
      "id": "deepmind-agi-safety",
      "title": "Google DeepMind, An Approach to Technical AGI Safety and Security (arXiv 2504.01849)",
      "url": "https://arxiv.org/abs/2504.01849",
      "type": "research",
      "date": "2025-04"
    },
    {
      "id": "deepmind-ai-control",
      "title": "Google DeepMind, Securing the future of AI agents (AI Control Roadmap; detection tiers D1-D4, response tiers R1-R3; internal agents as insider threat)",
      "url": "https://deepmind.google/blog/securing-the-future-of-ai-agents/",
      "type": "research",
      "date": "2026-06-18"
    },
    {
      "id": "ms-failure-taxonomy",
      "title": "Microsoft AI Red Team, Taxonomy of Failure Mode in Agentic AI Systems (memory poisoning flagged insidious)",
      "url": "https://www.microsoft.com/en-us/security/blog/2025/04/24/new-whitepaper-outlines-the-taxonomy-of-failure-modes-in-ai-agents/",
      "type": "vendor",
      "date": "2025-04-24"
    },
    {
      "id": "ms-agent-governance-toolkit",
      "title": "Microsoft, Agent Governance Toolkit (open source; maps all 10 OWASP agentic risks to deterministic runtime enforcement; DID + Ed25519)",
      "url": "https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/",
      "type": "vendor",
      "date": "2026-04-02"
    },
    {
      "id": "ms-entra-agent-id",
      "title": "Microsoft, Entra Agent ID (non-human identity for agents in the directory)",
      "url": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "type": "vendor",
      "date": "2025",
      "claim": true
    },
    {
      "id": "ms-mxc",
      "title": "Microsoft Execution Containers (MXC), policy-driven agent sandbox: Process → Session (current) → Micro-VM (roadmap)",
      "url": "https://github.com/microsoft/mxc",
      "type": "vendor",
      "date": "2026-06-02",
      "claim": true
    },
    {
      "id": "ms-agent365",
      "title": "Microsoft, Agent 365 (registry/control plane for agents; shadow-agent discovery)",
      "url": "https://techcommunity.microsoft.com/blog/agent-365-blog",
      "type": "vendor",
      "date": "2026",
      "claim": true
    },
    {
      "id": "openai-governing-agentic",
      "title": "OpenAI, Practices for Governing Agentic AI Systems (oversight, interruptibility, accountability)",
      "url": "https://openai.com/index/practices-for-governing-agentic-ai-systems/",
      "type": "vendor",
      "date": "2023-12"
    },
    {
      "id": "openai-preparedness-v2",
      "title": "OpenAI, Preparedness Framework v2 (tracked-risk thresholds, deployment gating)",
      "url": "https://openai.com/index/preparedness-framework/",
      "type": "vendor",
      "date": "2025-04-15"
    },
    {
      "id": "openai-agent-builder-safety",
      "title": "OpenAI, Agent Builder safety guide (prompt-injection mitigations)",
      "url": "https://developers.openai.com/api/docs/guides/agent-builder-safety",
      "type": "vendor",
      "date": "2025",
      "claim": true
    },
    {
      "id": "openai-bug-bounty",
      "title": "OpenAI, Safety Bug Bounty (Bugcrowd; agentic abuse and safety)",
      "url": "https://openai.com/index/safety-bug-bounty/",
      "type": "vendor",
      "date": "2026-03-25"
    },
    {
      "id": "okta-cross-app-access",
      "title": "Okta, Cross App Access (OAuth extension for agent-to-app delegation)",
      "url": "https://www.okta.com/newsroom/press-releases/okta-introduces-cross-app-access-to-help-secure-ai-agents-in-the/",
      "type": "vendor",
      "date": "2025-06-23",
      "claim": true
    },
    {
      "id": "auth0-genai",
      "title": "Okta / Auth0, Auth for GenAI (async authorization, RAG authz, Token Vault)",
      "url": "https://www.okta.com/newsroom/press-releases/auth0-platform-innovation/",
      "type": "vendor",
      "date": "2025-04-09",
      "claim": true
    },
    {
      "id": "ping-identity-ai",
      "title": "Ping Identity, Identity for AI (Agent IAM Core, Agent Gateway, Agent Detection)",
      "url": "https://press.pingidentity.com/2026-03-24-Ping-Identity-Defines-the-Runtime-Identity-Standard-for-Autonomous-AI",
      "type": "vendor",
      "date": "2026-03-24",
      "claim": true
    },
    {
      "id": "a2a-spec",
      "title": "Agent2Agent (A2A) Protocol v1.0.0 (Linux Foundation), signed Agent Cards (optional JWS/JCS)",
      "url": "https://a2a-protocol.org/v1.0.0/specification/",
      "type": "spec",
      "date": "2026"
    },
    {
      "id": "databricks-dasf3",
      "title": "Databricks, AI Security Framework (DASF) v3.0 (97 risks, 73 controls; Unity Catalog / Unity AI Gateway governance)",
      "url": "https://www.databricks.com/blog/agentic-ai-security-new-risks-and-controls-databricks-ai-security-framework-dasf-v30",
      "type": "vendor",
      "date": "2026-03-20",
      "claim": true
    },
    {
      "id": "crowdstrike-aidr",
      "title": "CrowdStrike, Securing AI Where It Executes / Falcon AIDR (endpoint as runtime enforcement point; OS process-lineage)",
      "url": "https://www.crowdstrike.com/en-us/blog/what-security-teams-need-to-know-about-openclaw-ai-super-agent/",
      "type": "vendor",
      "date": "2026",
      "claim": true
    },
    {
      "id": "beyondidentity-ceros",
      "title": "Beyond Identity, Ceros (agentic AI trust layer for MCP; device-bound passkeys)",
      "url": "https://www.beyondidentity.com/resource/introducing-ceros-the-agentic-ai-trust-layer-now-open-for-public-preview",
      "type": "vendor",
      "date": "2026-06-16",
      "claim": true
    },
    {
      "id": "rfc8693",
      "title": "RFC 8693, OAuth 2.0 Token Exchange (delegation via act claim, impersonation, may_act)",
      "url": "https://www.rfc-editor.org/info/rfc8693/",
      "type": "standard",
      "date": "2020-01"
    },
    {
      "id": "oauth21",
      "title": "OAuth 2.1 (IETF draft, not yet an RFC)",
      "url": "https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-1",
      "type": "spec",
      "date": "2026"
    },
    {
      "id": "oidc-ciba",
      "title": "OpenID Connect CIBA Core 1.0 (Final), decoupled out-of-band approval",
      "url": "https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0-final.html",
      "type": "standard",
      "date": "2021"
    },
    {
      "id": "mcp-authorization",
      "title": "MCP Authorization, OAuth 2.1 resource-server model + RFC 9728 + RFC 8707 (cite dated revision)",
      "url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization",
      "type": "spec",
      "date": "2025-11-25"
    },
    {
      "id": "spiffe",
      "title": "SPIFFE, workload identity standard (SVIDs; short-lived, auto-rotated). SPIRE = reference implementation",
      "url": "https://spiffe.io/docs/latest/spiffe-about/overview/",
      "type": "standard",
      "date": "2025"
    },
    {
      "id": "ngac",
      "title": "NGAC, Next Generation Access Control (ANSI/INCITS 565-2020; NIST SP 800-178 is a comparison paper)",
      "url": "https://csrc.nist.gov/pubs/sp/800/178/final",
      "type": "standard",
      "date": "2020"
    },
    {
      "id": "did-vc",
      "title": "W3C DID Core v1.0 + Verifiable Credentials Data Model v2.0 (portable non-human identity)",
      "url": "https://www.w3.org/TR/did-1.0/",
      "type": "standard",
      "date": "2025-05-15"
    },
    {
      "id": "openssf-model-signing",
      "title": "OpenSSF Model Signing (OMS) + Sigstore model-transparency (sign and verify model weights)",
      "url": "https://github.com/sigstore/model-transparency",
      "type": "standard",
      "date": "2025"
    },
    {
      "id": "agentdojo",
      "title": "AgentDojo, prompt-injection / tool-misuse benchmark (629 injection cases)",
      "url": "https://github.com/ethz-spylab/agentdojo",
      "type": "benchmark",
      "date": "2025"
    },
    {
      "id": "injecagent",
      "title": "InjecAgent, indirect prompt-injection benchmark for tool-using agents",
      "url": "https://github.com/uiuc-kang-lab/InjecAgent",
      "type": "benchmark",
      "date": "2024"
    },
    {
      "id": "agent-security-bench",
      "title": "Agent Security Bench (ASB), memory-poisoning + IPI evaluation",
      "url": "https://arxiv.org/abs/2410.02644",
      "type": "benchmark",
      "date": "2025"
    },
    {
      "id": "garak",
      "title": "garak, LLM vulnerability scanner (jailbreak, injection, leakage probes)",
      "url": "https://github.com/NVIDIA/garak",
      "type": "benchmark",
      "date": "2025"
    },
    {
      "id": "promptfoo",
      "title": "promptfoo, LLM/agent red-team and eval harness (CI-gateable)",
      "url": "https://www.promptfoo.dev/",
      "type": "benchmark",
      "date": "2025"
    },
    {
      "id": "gvisor",
      "title": "gVisor (runsc), userspace kernel / syscall interception sandbox",
      "url": "https://gvisor.dev",
      "type": "vendor",
      "date": "2025"
    },
    {
      "id": "firecracker",
      "title": "Firecracker / Kata Containers, hypervisor-backed micro-VM isolation",
      "url": "https://firecracker-microvm.github.io",
      "type": "vendor",
      "date": "2025"
    },
    {
      "id": "aws-egress-domains",
      "title": "AWS, controlling which domains AI agents can reach (SNI filtering + Route 53 DNS Firewall)",
      "url": "https://aws.amazon.com/blogs/machine-learning/control-which-domains-your-ai-agents-can-access/",
      "type": "vendor",
      "date": "2025"
    },
    {
      "id": "claude-sandbox-bypass",
      "title": "Claude Code network-allowlist bypass (SOCKS5 null-byte hostname), real egress-escape regression case",
      "url": "https://oddguan.com/blog/second-time-same-sandbox-anthropic-claude-code-network-allowlist-bypass-data-exfiltration/",
      "type": "research",
      "date": "2025"
    },
    {
      "id": "gitguardian-mcp-secrets",
      "title": "GitGuardian, secrets found in MCP configuration files (credential-in-context exposure)",
      "url": "https://blog.gitguardian.com/",
      "type": "research",
      "date": "2026",
      "claim": true
    },
    {
      "id": "owasp-finbot-ctf",
      "title": "OWASP GenAI, FinBot CTF (agentic abuse capture-the-flag)",
      "url": "https://genai.owasp.org/",
      "type": "benchmark",
      "date": "2025"
    },
    {
      "id": "aismm",
      "title": "CSA AI Security Maturity Model (AISMM) v3.7 — flagship CSA maturity model (2026-05-07) with a per-control AICM v1.0.3 crosswalk",
      "type": "framework",
      "date": "2026-05-07",
      "flagship": true,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-security-maturity-model"
    },
    {
      "id": "cisa-sbom-ai",
      "title": "CISA — Software Bill of Materials for AI: Minimum Elements (7 clusters: metadata, system-level properties, models, datasets, infrastructure, security properties, KPIs)",
      "url": "https://www.cisa.gov/resources-tools/resources/software-bill-materials-ai-minimum-elements",
      "type": "regulation",
      "date": "2026-05-12"
    },
    {
      "id": "plaskett-coding-agent-security",
      "title": "Alex Plaskett — An Introduction to AI Coding Agent Security (public v2.0): permission models, sandbox escapes, agent tools, config files & hooks, and untrusted-workspace attacks across Claude Code, Cursor, and Codex",
      "type": "research",
      "date": "2026",
      "claim": true
    },
    {
      "id": "semantic-sanitizer-ref",
      "title": "Reference implementation: in-path Semantic Parameter Sanitizer (fail-closed; deterministic SQL/shell/script/override patterns + null-byte strip, optional fine-tuned classifier) — project artifact",
      "type": "research",
      "date": "2026"
    },
    {
      "id": "biv-skills",
      "title": "Wu, Li & Liu — Behavioral Integrity Verification for AI Agent Skills (arXiv 2605.11770): 49,943 skills, ~80% deviate from declared behavior, 18.9% adversarial, 5% multi-stage attack chains; BIV via static analysis + capability extraction",
      "url": "https://arxiv.org/abs/2605.11770",
      "type": "research",
      "date": "2026-05-12"
    },
    {
      "id": "containment-gap",
      "title": "The Containment Gap: How Deployed Agentic AI Frameworks Fail Public-Facing Safety Requirements (arXiv 2606.12797) — audits LangChain/AutoGPT/OpenAI Agents SDK; memory-integrity (P3) and reasoning/execution-separation (P1/P2) failures; one memory-poisoning write corrupts 5 backends; 2 deterministic sub-ms interventions",
      "url": "https://arxiv.org/abs/2606.12797",
      "type": "research",
      "date": "2026-06"
    },
    {
      "id": "csa-agent-survey",
      "title": "CSA + Strata Identity — Securing Autonomous AI Agents (2026 survey, ~285 practitioners): 40% have agents in production, only 18% highly confident in agent IAM, 84% doubt passing an agent-behavior compliance audit, ownership fragmented across Security 39% / IT 32% / AI 13%",
      "url": "https://cloudsecurityalliance.org/artifacts/securing-autonomous-ai-agents",
      "type": "framework",
      "date": "2026",
      "flagship": true
    },
    {
      "id": "ms-pyrit",
      "title": "Microsoft Azure AI Foundry control plane + PyRIT (Python Risk Identification Tool): task adherence, prompt shields, automated agent red-teaming",
      "url": "https://github.com/Azure/PyRIT",
      "type": "vendor",
      "date": "2026",
      "claim": true
    },
    {
      "id": "nist-fasttrack",
      "title": "NIST / FedRAMP fast-track agentic-AI policy direction (expected/forthcoming): cryptographic agent identity (SPIFFE/DID) + mandatory pre-execution checks / kill-switches for high-stakes automation",
      "type": "regulation",
      "date": "2026",
      "claim": true
    }
  ]
}