Agentic AI Security — Interactive Framework Map

Structured Minds — Agentic AI Security Curriculum
STRUCTURED MINDS An Agentic-AI Security Curriculum in three levels — and a map of when to use every framework The Multiverse School · build → govern → research · 312 frameworks catalogued The full reference library — handouts + 900+ linked sources: themultiverse.school/x/agentic-ai-security-library 1 LEVEL 1 Agentic SDLC + AI User How we ship agents safely — from user & abuse cases to a hardened build 2 LEVEL 2 AI Alignment & Governance Make it trustworthy & accountable — alignment, standards, safety cases 3 LEVEL 3 Research Frameworks The frontier — 312 structuring frameworks across 14 constellations 1 · AI User & Requirements Personas & Anti-personas who acts, who abuses Jobs-To-Be-Done (JTBD) the task, not the feature User Stories As-a-user, I want… Abuse Cases how a real user turns hostile Misuse Cases unintended-but-plausible paths Human-in-the-Loop (HITL) where a person approves Value-Sensitive Design stakeholder values as reqs Participatory / Co-design build with, not for RACI for agent actions who owns each act Agent 'nutrition labels' declared scope & limits 2 · Secure SDLC Canon • Microsoft SDL • OWASP SAMM • BSIMM • NIST SSDF (800-218) • OWASP ASVS • OWASP Proactive Controls • SLSA (supply-chain) • DevSecOps / Shift-Left • CISA Secure-by-Design 3 · Threat Modeling • STRIDE • LINDDUN (privacy) • PASTA • Attack Trees • DREAD • Cyber Kill Chain • MITRE ATT&CK • MITRE ATLAS (AI) • CSA MAESTRO (agentic) • Trike · OCTAVE 4 · Agentic Build Patterns • OWASP Agentic Top 10 (2026) • MCP security cheat sheets • Least-privilege tools · sandboxing CaMeL control/data separation • Dual-LLM pattern • Guardrails: LlamaFirewall · Progent • Agent identity: OAuth/OIDC · scoped tokens • Memory integrity · RAG hygiene 5 · Test & Assure the Build • Red-teaming (manual + automated) • Benchmarks: AgentDojo · ASB · RAS-Eval • MCPSecBench • SAST / DAST + CI security gates • Eval harness: AgentAuditor • Adversarial / chaos testing 1 · Technical Alignment • RLHF · RLAIF • Constitutional AI • Scalable Oversight • Debate • Weak-to-strong generalization • Mechanistic Interpretability • Dangerous-capability evals (METR · Apollo) • Specification gaming · reward hacking • Corrigibility · instrumental convergence • Model / behavior spec 2 · Governance & Standards • NIST AI RMF + AI 600-1 (GenAI) • ISO/IEC 42001 (AI mgmt system) • ISO/IEC 23894 (AI risk) • ISO/IEC 27090 (AI security) • EU AI Act • OECD AI Principles • Model Cards · System Cards • Datasheets for Datasets • Responsible Scaling Policies (ASL) • Google SAIF · Microsoft RAI 3 · Risk & Safety Cases • Safety Cases (claim-argument-evidence) • Bow-tie analysis • Defense-in-Depth · Swiss Cheese • FMEA • STPA / STAMP (system-theoretic) • Risk matrices & capability tiering • AI Incident Database (AIID) • Third-party audit & assurance 4 · Assurance & Evidence • Evals as evidence • Capability thresholds & gates • Conformity assessment (EU AI Act) • Transparency / system reports • Compliance mapping (controls→reqs) • Bug bounties for AI Surveys & Taxonomies 20 in dossier • LASM 7-layer model • TrustAgent • Agentic Security Survey Threat Models 33 in dossier • ATFAA → SHIELD • SoK: Attack Surface • Viral Agent Loop Defense Frameworks 38 in dossier • Layered defense-in-depth • Policy enforcement • Lifecycle controls Guardrails & Runtime 18 in dossier • LlamaFirewall • Progent • GuardAgent · AIRGuard Benchmarks & Evals 25 in dossier • AgentDojo • Agent Security Bench • RAS-Eval · ST-WebAgent Red-Team & Attack 30 in dossier • Automated agent red-team • Jailbreak-for-agents • Env. injection Prompt Injection 15 in dossier • CaMeL • Spotlighting • Dual-LLM pattern MCP Security 13 in dossier • MCPSecBench • Tool-poisoning defenses • MCP threat model Multi-Agent / A2A 9 in dossier • Multi-Agent Security • A2A protocol security • Cascade defenses Identity & Authz 25 in dossier • Scoped agent tokens • Agent IAM • Capability control Governance & Assurance 39 in dossier • Agent audit frameworks • Accountability • Trust frameworks Formal Verification 15 in dossier • SMT-validated compliance • Provable guardrails • Policy proofs Standards Bodies 23 in dossier • NIST · ISO • CSA MAESTRO · AICM • OWASP · MITRE ATLAS Certifications 8 in dossier • OWASP-aligned tracks • TryHackMe AI1 • CSA TAISE META-MAP When & where to reach for each framework IDEATE Personas · JTBD Abuse / misuse cases DESIGN STRIDE · LINDDUN MAESTRO · ATLAS Threat models BUILD OWASP Agentic 10 Least-priv · CaMeL Guardrails · identity TEST Red-team AgentDojo · ASB MCPSecBench RELEASE Model/System cards Safety case RSP / ASL gate OPERATE Runtime firewalls Monitoring · evals Incident (AIID) GOVERN NIST AI RMF ISO 42001 · EU AI Act Audit · assurance TECHNICAL ▲ ORGANIZATIONAL ▼ ◀ BUILD-TIME RUN-TIME ▶ Build · Technical Threat models OWASP Agentic 10 CaMeL · sandboxing SLSA · SSDF Run · Technical Guardrails / firewall Runtime monitors Red-team evals Formal checks Build · Org SDL · SAMM · BSIMM Personas · RACI Model cards Safety case Run · Org NIST AI RMF ISO 42001 · EU Act Audit / assurance Incident response

Tour mode

Space / next · previous
Home / End first / last
19 jump to frame

Explore mode

Click any highlighted region to zoom in.
Click further-in regions to drill deeper.
Backspace / Esc — zoom back out
O — return to overview

Anywhere

M — toggle mode
T — toggle frame list
F — fullscreen · R — restart
0 / 0 Tour