Mission and audience
Make AI use visible, accountable, threat-informed, data-aware, access-controlled, monitored, and governable across its lifecycle.
AI security is not separate from cybersecurity. It intensifies existing concerns around data, software supply chains, identity, cloud services, monitoring, model behavior, human oversight, and risk decisions.
Guided phase
Establish context and accountability
Understand stakeholders and obligations and assign leadership, roles, and authorities for AI risk.
Actions to take
- Inventory stakeholders, affected communities, obligations, and intended use.
- Assign accountable model, data, product, security, privacy, and risk owners.
- Define prohibited, restricted, and high-impact use cases.
Stakeholder Needs and Expectations
Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood
Legal, Regulatory, and Contractual Requirements
Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
Leadership Accountability and Risk-Aware Culture
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Roles, Responsibilities, and Authorities
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Guided phase
Inventory systems, data, and dependencies
Maintain visibility into AI services, models, datasets, software, suppliers, and lifecycle state.
Actions to take
- Inventory models, versions, prompts, tools, connectors, datasets, and providers.
- Track provenance, licensing, data rights, and external dependencies.
- Monitor supplier and model-service changes.
Software, Service, and System Inventories
Inventories of software, services, and systems managed by the organization are maintained
Data and Metadata Inventories
Inventories of data and corresponding metadata for designated data types are maintained
Asset Life-Cycle Management
Systems, hardware, software, services, and data are managed throughout their life cycles
Monitor Supplier and Third-Party Risk
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
Guided phase
Assess AI risk
Use consistent risk objectives and methods to identify threats, likelihood, impact, and response options.
Actions to take
- Threat-model misuse, prompt injection, data leakage, model theft, supply-chain compromise, and unsafe autonomy.
- Assess security, privacy, safety, legal, and mission impacts together.
- Document uncertainty, assumptions, and human oversight requirements.
Risk Management Objectives
Risk management objectives are established and agreed to by organizational stakeholders
Cybersecurity in Enterprise Risk Management
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
Standardized Risk Method
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Identify Internal and External Threats
Internal and external threats to the organization are identified and recorded
Estimate Threat Likelihood and Impact
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
Understand Inherent Risk
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Guided phase
Protect AI data and access
Limit authorization and protect data at rest, in transit, and during processing.
Actions to take
- Scope model, tool, data, and administrative permissions.
- Protect secrets, retrieval sources, training data, prompts, outputs, and logs.
- Constrain agent tools and high-impact actions.
Manage Permissions and Authorizations
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Protect Data at Rest
The confidentiality, integrity, and availability of data-at-rest are protected
Protect Data in Transit
The confidentiality, integrity, and availability of data-in-transit are protected
Protect Data in Use
The confidentiality, integrity, and availability of data-in-use are protected
Guided phase
Monitor, manage change, and improve
Observe AI runtime behavior, manage exceptions, and improve from testing and operations.
Actions to take
- Monitor model, agent, tool, data, access, and policy events.
- Test abuse cases, failure modes, and kill or rollback procedures.
- Track drift, exceptions, incidents, and improvement actions.
Monitor Computing and Runtime Environments
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Manage Changes and Exceptions
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
Improvements from Evaluations
Improvements are identified from evaluations
Improvements from Operations
Improvements are identified from execution of operational processes, procedures, and activities
Completion evidence
What should exist when this playbook is working?
- AI system, model, data, tool, provider, and owner inventory.
- Documented intended use, prohibited use, and high-impact decision criteria.
- AI threat model and integrated risk assessment.
- Access, data, secret, tool, and environment safeguards.
- Monitoring, evaluation, red-team, incident, rollback, and deactivation evidence.
- Governance decisions, exceptions, model changes, and improvement records.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.