Pressure-test the function
Pressure-test the function.
Pick the function. Ace runs the maturity read: posture for the unit, not a skills quiz for one person.
Each function opens its own maturity check — governance and autonomy on two ladders, joined by the gate. Open to run; research access to save.
Aligned with the Cloud Security Alliance (CSA) AI Security Maturity Model (AISMM) and AI Controls Matrix (AICM). Not a CSA certification or STAR listing.
First look instead? The ten-minute Quick Mythos Vulnerability Assessment→
Maturity measures the organisation, function by function. For the personal read of the same map, gaps and path and proof, cross to Build the defender’s skills →
Live assess
Run it, don’t just read it.
The unit’s armour: function posture on two ladders, joined by the gate. Pick a function above, then start or reassess on screen. Open to run; research access to save.
Selected function
Identity Security
8 questions · 2 categories
Standards lenses · one spine
Assess once on the AI Controls Matrix. ISO, NIST, and AI-CAIQ are lenses on those answers — not a second questionnaire.
Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.
Sample reports
See a finished report before you start.
Four fictional organisations, one MECE set of function reads. Open any row; the report carries the numbers.
Board-grade consultancy reads
Self-assessed sample data, never client results.
Exhibits · the living standards map
Assess once. Read against every standard.
A navigation map of how the Cloud Security Alliance (CSA) methodology docks to the standards you already run, not a conformance attestation. Assess once on the AI Controls Matrix; every standard here is a lens on that one read. SOC 2 and PCI DSS arrive via the CCM bridge. General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), and India Digital Personal Data Protection Act, 2023 (DPDP) are leveraged from skill tags — see the panel below when shown.
AI Security Maturity Model: The maturity read: how far your AI governance and management system has climbed. That is the same ground the NIST AI RMF (Govern and Manage) and the ISO/IEC 42001 AI management system cover.
Foundational inheritance · the CCM bridge
Dock the baseline you already run.See what each regime still cannot reach.
The AI Controls Matrix (AICM) extends the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM). For shared control ids, CSA’s own CCM crosswalk reaches the foundational standards below — including AICPA Trust Services Criteria 2017 (SOC 2) and Payment Card Industry Data Security Standard (PCI DSS). Reach varies by regime (cells marked “No Mapping” do not count). The remainder of 247 objectives is outside that dock — for NIST CSF v2.0, that delta is 63.
Two CSA-authoritative hops: AICM→CCM by shared control id (the documented design of AICM), CCM→standard by CSA’s published CCM v4.0.13 mapping. Gap levels are not re-labelled across the bridge. HIPAA, GDPR, and India DPDP are not CCM columns — leverage the skill-mediated panel. NIST SSDF is not mapped in any source here and is omitted, not inferred.
Privacy & payments · leveraged from skills
Regimes the CSA sheets omit: joined through the skill catalog.
Modeled skill-mediated map: published skills tagged to General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), India Digital Personal Data Protection Act, 2023 (DPDP), or Payment Card Industry Data Security Standard (PCI DSS) join to their AI Controls Matrix (AICM) domain. Control ids appear only when a skill already lists them — never invented articles.
Modeled skill-mediated map: published skills tagged to a privacy or payments regime are joined to their AI Controls Matrix (AICM) domain (and control id only when the skill already lists aicm_controls). Not a Cloud Security Alliance (CSA) sheet crosswalk — leverage the skill catalog, do not invent article IDs. 5 of 18 AICM domains carry at least one of these regime tags via skills.