ai · security · skills

Sample consultancy report

Northwind Retail: Security Operations

Where AI has moved into this function, whether the controls kept up, and the one move that earns the next rung. Read in five minutes; decided in one meeting.

Prepared on
The aisecurityskills function diagnostic
Basis
Cloud Security Alliance (CSA) AI Controls Matrix (AICM) · AI Security Maturity Model (AISMM) × AI Cyber Maturity Model (AI-CMM)
Evidence state
Illustrative · fictional organisation
Issued
18 Jul 2026
01

The verdict

Autonomy is pressing the gate: triage and enrichment already run augmented while measured response and tested playbooks still trail.

Northwind Retail's security operations function reads at L2.8 governance against L2.2 autonomy: a mid-band retail posture where the gate still holds, but the margin is thinner than it looks. Logging and incident-response foundations are written and running; model integrity and threat-intel detections are in place. What presses the gate is the climb already underway on alert triage and enrichment while MTTR tracking, AI-scenario exercises, and response metrics remain only partial. Governance must finish those measured rungs before autonomy claims another step.

Governance

L2.8

AI Security Maturity Model (AISMM) · how well it is secured

Autonomy

L2.2

AI Cyber Maturity Model (AI-CMM) · how far AI has gone

The gate

Shut

autonomy is running ahead of its controls

02

Where this function stands

The whole method in one drawing. Governance runs across, autonomy runs up, and the staircase is the gate: each governance level earned is the autonomy an organisation may responsibly claim.

Northwind Retail on the governance-and-autonomy gridGovernance from L1 to L5 across, autonomy from L1 to L4 up. The gate staircase marks the autonomy each governance level has earned. Northwind Retail sits at governance 2.8, autonomy 2.2, inside the governed region.Ungoverned: ahead of controlsGoverned: earned autonomyNorthwind Retail today · L2.8 / L2.2L1L2L3L4L5L1L2L3L4Governance (AISMM) → each level earned is autonomy allowedAutonomy (AI-CMM) ↑
The gate is the product’s one rule: autonomy must never outrun governance. This function sits at L2.8 governance, which allows autonomy up to L2 — and it runs at L2.2, inside the line. Climbing the wall, not the drop.
03

What was measured

Two ladders, one instrument. Each answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control; a category claims a level only when that tier is evidenced, and an absent control caps it. The same rule scores every live run.

How well it is secured

L2.8

InitialRepeatableDefinedCapableEfficient

The CSA AI Security Maturity Model (AISMM): every answer maps to an AI Controls Matrix (AICM) control, and a level is claimed only when the tier is evidenced.

How far AI has gone

L2.2

ManualAssistedAugmentedAutonomous

The AI Cyber Maturity Model (AI-CMM): where the human sits in each workflow — in, on, then over the loop. our model · calibrated to SAE J3016.

Security MonitoringL3 Defined · 3 of 4 evidenced

Held below the next tier: tier 4 not yet evidenced

Incident ResponseL3 Defined · 2 of 4 evidenced

Held below the next tier: tier 4 not yet evidenced

Model SecurityL3 Defined · 2 of 2 evidenced
AI Supported Development and Supply Chain SecurityL3 Defined · 1 of 1 evidenced
Data SecurityL2 Repeatable · 1 of 1 evidenced
04

Findings

Three, ranked, classified by what leadership does with each: act on a priority, protect a strength, and hold a deliberate choice.

  1. 01Priority

    Measured response trails the autonomy already claimed on triage

    Alert triage and enrichment run augmented, yet monitoring MTTR, AI-scenario tabletops, and incident-response metrics stay partial. That is the pressure on the gate: autonomy has moved ahead of the measured evidence the Capable rung requires.

    The exact control ids (for your security and governance, risk and compliance team)

    LOG-05 · SEF-04 · SEF-05

  2. 02Strength

    Monitoring and IR foundations are written and running

    Logging policy, AI-event monitoring, tamper-protected retention, and an IR policy that names AI failure modes are implemented. Model-artifact scanning and adversarial analysis sit underneath that floor. The mid-band read is earned here.

    The exact control ids (for your security and governance, risk and compliance team)

    LOG-01 · LOG-03 · LOG-02 · SEF-01 · SEF-03

  3. 03By design

    Model defence stays Defined while triage climbs

    Artifact scanning, adversarial analysis, and threat-intel detection updates are implemented and held at Defined on purpose. Documentation stays manual and investigation assisted so the composite adopt average does not close the gate while measured IR evidence catches up.

    The exact control ids (for your security and governance, risk and compliance team)

    MDS-02 · MDS-06 · TVM-05

05

The climb

Direction, not a how-to: the next rung, and the governance that must move before autonomy does.

  1. Next quarter

    Close the three partials: track alert MTTR, exercise AI incident scenarios, and publish IR metrics so Capable evidence matches the autonomy triage already runs.

  2. Two quarters

    With measured response evidenced, lift investigation one autonomy rung and re-assess: the gate stays open only if governance moved first.

  3. Continuous

    Hold model-integrity scanning and threat-intel detection updates through each catalog change; re-run the diagnostic after material SOC tooling shifts.

06

About this instrument

What a reader should carry out of the room: how the diagnostic works, how progress is tracked, and what the practice is for.

One questionnaire, two reads

Every answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control. Read one way, the answers grade the function: governance versus autonomy, joined by the gate. Read the other way, the same answers name the skills each person in the function must acquire. Diagnosis and reskilling from one sitting.

Tracked, not judged

The first run is a baseline, never a verdict. Re-assess after the work and the radar overlays the previous run, so leadership sees movement, not a grade. The compatible-standard packs (ISO/IEC, the National Institute of Standards and Technology, and the CSA AI Consensus Assessments Initiative Questionnaire) are lenses on the same answers: assess once, report many ways.

Direction, not a solution

AI is a moving target, so the report names the next rung and the governance that must move first — never a vendor stack or a how-to. The gate keeps the climb honest: autonomy is claimed only after the controls that catch it are in place.

Derived at build time from the Northwind posture config through the live function-diagnostic scorer: the same questions, tiers, and gate every real run uses. A bank change re-derives this sample automatically; nothing here is hand-scored.

Northwind Retail is a fictional organisation; the postures are self-assessed sample data, never client results. Nothing in this report is certification, and no standards body has reviewed it.