ai · security · skills

Pressure-test the function

Pressure-test the function.

Pick the function. Ace runs the maturity read: posture for the unit, not a skills quiz for one person.

Each function opens its own maturity check — governance and autonomy on two ladders, joined by the gate. Open to run; research access to save.

Aligned with the Cloud Security Alliance (CSA) AI Security Maturity Model (AISMM) and AI Controls Matrix (AICM). Not a CSA certification or STAR listing.

First look instead? The ten-minute Quick Mythos Vulnerability Assessment

Maturity measures the organisation, function by function. For the personal read of the same map, gaps and path and proof, cross to Build the defender’s skills →

Live assess

Run it, don’t just read it.

The unit’s armour: function posture on two ladders, joined by the gate. Pick a function above, then start or reassess on screen. Open to run; research access to save.

Selected function

Identity Security

8 questions · 2 categories

Leadership view: the board scorecard · research access →

Standards lenses · one spine

Assess once on the AI Controls Matrix. ISO, NIST, and AI-CAIQ are lenses on those answers — not a second questionnaire.

Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.

Sample reports

See a finished report before you start.

Four fictional organisations, one MECE set of function reads. Open any row; the report carries the numbers.

Board-grade consultancy reads

GlobexGovernance ahead of adoption
InitechEarly days · honest starting point

Self-assessed sample data, never client results.

Exhibits · the living standards map

Assess once. Read against every standard.

One methodology, every standardAssess once
AISMMAI Security Maturity Model3 domains · 12 categories · L1 to L5AICMAI Controls Matrix18 domains · 247 control objectivesCCMCloud Controls MatrixThe foundational dock you already runNIST AI RMFAI risk management frameNIST CSF 2.0Cybersecurity outcomesNIST SP 800-53Control catalogSOC 2Service organization controlsPCI DSSPayment card securityISO/IEC 42001AI management systemEU AI ActLegal obligations overlayISO/IEC 27001Information security (ISMS)ISO/IEC 27017Cloud security controlsISO/IEC 27018Cloud PII protection

A navigation map of how the Cloud Security Alliance (CSA) methodology docks to the standards you already run, not a conformance attestation. Assess once on the AI Controls Matrix; every standard here is a lens on that one read. SOC 2 and PCI DSS arrive via the CCM bridge. General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), and India Digital Personal Data Protection Act, 2023 (DPDP) are leveraged from skill tags — see the panel below when shown.

AI Security Maturity Model: The maturity read: how far your AI governance and management system has climbed. That is the same ground the NIST AI RMF (Govern and Manage) and the ISO/IEC 42001 AI management system cover.

Foundational inheritance · the CCM bridge

Dock the baseline you already run.See what each regime still cannot reach.

The AI Controls Matrix (AICM) extends the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM). For shared control ids, CSA’s own CCM crosswalk reaches the foundational standards below — including AICPA Trust Services Criteria 2017 (SOC 2) and Payment Card Industry Data Security Standard (PCI DSS). Reach varies by regime (cells marked “No Mapping” do not count). The remainder of 247 objectives is outside that dock — for NIST CSF v2.0, that delta is 63.

NIST CSF v2.0184/247 via CCM bridge · 16/18 domains · delta 63
NIST 800-53 rev 5186/247 via CCM bridge · 16/18 domains · delta 61
AICPA TSC 2017 (SOC 2)137/247 via CCM bridge · 16/18 domains · delta 110
PCI DSS v3.2.1129/247 via CCM bridge · 16/18 domains · delta 118
PCI DSS v4.0144/247 via CCM bridge · 16/18 domains · delta 103

Two CSA-authoritative hops: AICM→CCM by shared control id (the documented design of AICM), CCM→standard by CSA’s published CCM v4.0.13 mapping. Gap levels are not re-labelled across the bridge. HIPAA, GDPR, and India DPDP are not CCM columns — leverage the skill-mediated panel. NIST SSDF is not mapped in any source here and is omitted, not inferred.

Privacy & payments · leveraged from skills

Regimes the CSA sheets omit: joined through the skill catalog.

Modeled skill-mediated map: published skills tagged to General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), India Digital Personal Data Protection Act, 2023 (DPDP), or Payment Card Industry Data Security Standard (PCI DSS) join to their AI Controls Matrix (AICM) domain. Control ids appear only when a skill already lists them — never invented articles.

General Data Protection Regulation (GDPR)Domains: A&A, DSP, GRC, SEF, STA
205 skills · 5/18 domains
Health Insurance Portability and Accountability Act (HIPAA)Domains: DSP, GRC, SEF
32 skills · 3/18 domains
India Digital Personal Data Protection Act, 2023 (DPDP)Domains: DSP, GRC
2 skills · 2/18 domains
Payment Card Industry Data Security Standard (PCI DSS)Domains: GRC
1 skills · 1/18 domains

Modeled skill-mediated map: published skills tagged to a privacy or payments regime are joined to their AI Controls Matrix (AICM) domain (and control id only when the skill already lists aicm_controls). Not a Cloud Security Alliance (CSA) sheet crosswalk — leverage the skill catalog, do not invent article IDs. 5 of 18 AICM domains carry at least one of these regime tags via skills.