ai · security · skills

Perspective · for Compliance

Three kinds of artifact compete for one decision.

Choosing an AI-security framework isn’t “which is best.” Three different things claim the job: open control standards, paywalled analyst frameworks, and management-system standards written for auditors — and they are not interchangeable.

Open control standardsCSA AI Controls Matrix · AI Security Maturity Model · AI-CAIQfree, testable, per-controlAnalyst frameworksForrester AEGIS · Gartner AI TRiSMsharp framing, client-licensedManagement standards & lawISO 42001 · NIST AI RMF · EU AI Actthe compliance surface

Pick the wrong one to build on and every skill, assessment answer, and maturity claim has to be re-anchored later.

The real decision

Not “which framework is best,” but: which one can be the spine — the thing everything attaches to — and which are better used as lenses over it.

“Which framework do we anchor the whole practice on — and where do the analyst lenses actually add?”

The answer

CSA is the spine. The analyst frameworks are lenses over it.

The spine has to be something your clients can audit the rubric they’re graded against. Only the open standard qualifies — the Cloud Security Alliance AI Controls Matrix (AICM), AI Security Maturity Model (AISMM), and AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) — the analyst frameworks are sharper at naming the problem, but paywalled and ungradeable.

Forrester AEGIS — least agency, continuous assuranceGartner AI TRiSM — layers, guardian agentsLENSES ↓THE SPINE · CSA AICM + AISMM + AI-CAIQ/STAR247 testable objectives · 12 maturity categories · a public assurance loop — every skill & answer attaches hereMAPS UP TO ↑ISO/IEC 42001 · NIST AI RMF · EU AI Act · BSI AIC4 (the compliance surface)

AEGIS publishes no maturity model, no autonomy ladder, no public assessment, and lives in a $1,495 report — a fine lens, the wrong spine.

Where it lands in the app

One spine, many lenses: integrated, not ignored.

The analyst insight is absorbed, not discarded: AEGIS’s least agency is the autonomy gate; TRiSM’s guardian-agent layers inform the autonomy read. Above the 18-domain spine sits the 8-function ownership lens, the maturity radar, the gate, and the loop.

The full function→domain ownership map, the AI Security Maturity Model (AISMM) ladders, and the ISO/EU/BSI crosswalk live on the compliance method page — the same spine, walked in depth.

Browse the control spine →The compliance walkthrough
← Back to Insights

Subscribe for the next essay.