<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Cyber Leader - Balanced Security]]></title><description><![CDATA[At The Cyber Leader, I explore how cybersecurity, certification, and leadership intersect — helping you make confident, balanced decisions in a complex digital world.]]></description><link>https://blog.balancedsec.com</link><image><url>https://substackcdn.com/image/fetch/$s_!oEm3!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9dbef-0854-45bc-8021-52f35936f646_450x450.png</url><title>The Cyber Leader - Balanced Security</title><link>https://blog.balancedsec.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 16 Aug 2026 19:42:30 GMT</lastBuildDate><atom:link href="https://blog.balancedsec.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jeffery Moore]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[jefferymoore@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[jefferymoore@substack.com]]></itunes:email><itunes:name><![CDATA[Jeffery Moore]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jeffery Moore]]></itunes:author><googleplay:owner><![CDATA[jefferymoore@substack.com]]></googleplay:owner><googleplay:email><![CDATA[jefferymoore@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jeffery Moore]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Assume the Model Gets Fooled]]></title><description><![CDATA[The 2026 OWASP LLM Top 10]]></description><link>https://blog.balancedsec.com/p/assume-the-model-gets-fooled</link><guid isPermaLink="false">https://blog.balancedsec.com/p/assume-the-model-gets-fooled</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 07 Aug 2026 13:03:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZXte!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZXte!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZXte!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png 424w, https://substackcdn.com/image/fetch/$s_!ZXte!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png 848w, https://substackcdn.com/image/fetch/$s_!ZXte!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!ZXte!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZXte!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:147402,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/209999499?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZXte!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png 424w, https://substackcdn.com/image/fetch/$s_!ZXte!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png 848w, https://substackcdn.com/image/fetch/$s_!ZXte!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!ZXte!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a6fad25-52b4-4db6-8bb7-148328fd5298_2400x1350.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The just-released OWASP Top 10 for LLM Applications includes some interesting changes. It opens with a sentence that frames the rest of the document:</p><blockquote><p>Stop trying to build a model that cannot be fooled. Build the system around it, so that when the model is fooled, and it will be, nothing important breaks.</p></blockquote><p>That&#8217;s a new stance, one overdue in hindsight, because it follows from a very specific technical fact. A language model reads its system prompt, the user&#8217;s question, a retrieved document, and a tool&#8217;s output as one token stream. Current architecture doesn&#8217;t separate an instruction from data. That&#8217;s just how it&#8217;s built.</p><p>So that means that you don&#8217;t close prompt injection in the same way as SQL injection. You need to limit or bound what a successful injection can reach. There are three general boundaries that do work. </p><p>The first is what tools the model can call. On its own, a model produces text. It can&#8217;t read a file, send an email, or query a database until a developer gives it a function to call or invoke. So a list of registered tools is essentially the complete set of actions that a model can take. Which means that anything not on the list is out of the reach of an agent.</p><p>So the tool list is essentially an authorization decision, and falls into CISSP domain 5. Here, the agent is the subject, and the tools are its permission set. The traditional rule is to grant the minimum necessary to do the job.</p><p>What changes is how much weight that rule carries. Since the agent can be talked into doing things, whatever it&#8217;s permitted to do, anyone who can get text in front of it is effectively now permissioned. Least privilege stops being hygiene to follow, and becomes the only thing standing between a successful injection and what is within the agent&#8217;s reach.</p><p>That&#8217;s the &#8220;confused deputy&#8221; problem, <a href="https://dl.acm.org/doi/10.1145/54289.871709">named by Norm Hardy in 1988</a>, after a compiler that would overwrite the system&#8217;s billing file. The user didn&#8217;t have permissions to touch that file, but the compiler did. And the compiler had no way to tell its own business from a file a user had handed it. The user passed a filename. A filename indicates which file, not who&#8217;s allowed to touch it. So the compiler had to supply the authority itself, and its own was the only authority it had. Hardy&#8217;s fix was to make the deputy act with the caller&#8217;s authority, and OWASP arrived at the same place. </p><p>Their mitigation is to execute tools in the user&#8217;s context, and preserve that context across chained tools and agent calls, never falling back on the agent&#8217;s own broader service account. Essentially, the agent should use the user&#8217;s permissions, and it should ensure the next agent uses that same permission set.</p><p>Note that deciding which tools should be used, and how much authority each has to operate, are important and separate decisions. Reducing the number of tools but leaving their elevated permission scope doesn&#8217;t reduce the risk.</p><p>What the agent <em>remembers between sessions</em> is important. Agents can carry long-term memory forward between sessions via RAG or vector store, and these memories get pulled back into the context window each session and read as trustworthy. Because the model has no way of telling a memory it formed from one that someone else planted, one poisoned entry can be used in a subsequent session.</p><p>This idea relates to traditional data storage handling as defined in CISSP Domain 2. In this case, a memory needs to be classified with a retention limit, and controls placed over who can access and modify it. Typically in this context, a memory is treated like a product feature, which is why it ends up as an asset in your environment with no owner or associated retention policy.</p>
      <p>
          <a href="https://blog.balancedsec.com/p/assume-the-model-gets-fooled">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Why AI Still Can't Write a Good CISSP Question]]></title><description><![CDATA[AI gets CISSP facts right and the judgment wrong. Here's why generating your practice questions with ChatGPT can train you to fail the exam.]]></description><link>https://blog.balancedsec.com/p/why-ai-still-cant-write-a-good-cissp</link><guid isPermaLink="false">https://blog.balancedsec.com/p/why-ai-still-cant-write-a-good-cissp</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Sat, 25 Jul 2026 00:05:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lE94!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lE94!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lE94!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png 424w, https://substackcdn.com/image/fetch/$s_!lE94!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png 848w, https://substackcdn.com/image/fetch/$s_!lE94!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!lE94!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lE94!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:101883,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/208256037?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lE94!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png 424w, https://substackcdn.com/image/fetch/$s_!lE94!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png 848w, https://substackcdn.com/image/fetch/$s_!lE94!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!lE94!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85fce036-e4b5-4509-99e3-2b724c9fa93f_2400x1350.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most people studying for the CISSP in 2026 have at least tried using AI to help them learn. It makes sense because the technology is everywhere and it feels like a cheat code. You request a detailed study plan and a dozen CISSP-like practice questions, and within seconds you&#8217;re off and running. Why not? The exam has a reputation for being difficult, and it can be hard to evaluate any prep platform without spending time with it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I want to make the case that while AI can be useful in some areas for exam preparation, relying on chat tools to generate adequate exam-level practice questions may increase your risk of problems on exam day. These risks may not be obvious. AI is good at producing questions based on technical criteria but misses the mark on the type of questions you&#8217;ll likely see on the exam.</p><h2>The CISSP isn&#8217;t really testing what you know</h2><p>A CISSP question doesn&#8217;t normally use simple recall or fact-only formats. You&#8217;re often provided a short scenario and four options that all seem reasonable, asking which is the BEST answer or which one you&#8217;d do FIRST. People call the exam &#8220;a mile wide and an inch deep&#8221;, but the deeper truth is that its goal is to test judgment. Weaving together sometimes disparate technical, safety, cost, and business goals, a scenario can force you to make choices in the face of ambiguity. CISOs face the same sort of judgment daily. </p><p>That&#8217;s part of what makes the CISSP difficult, and what a good practice question needs to reproduce. A question that only checks whether you memorized a definition helps you train just some of the required muscle. The actual exam gives you two or more plausible answers, and your job is to pick the one that best fits the criteria. If you don&#8217;t use practice tests that reinforce that process, you&#8217;re not preparing well.</p><p>And this is exactly the part that trips AI models up.</p><h2>Where AI breaks down</h2><p>When you ask a model to write CISSP questions, it can fail in a few very specific and sometimes subtle ways.</p><p>AI tends to reuse words from the stem (the core part of a test question that sets up the problem) in the correct answer. In other words, it leaves fingerprints. It also makes the right answer more complete: usually a bit longer, and more qualified because it&#8217;s trying to make the correct answer airtight. These fingerprints can be subtle. Many candidates may learn to pick the most complete, familiar-sounding option and get the answer right more often than they should. That trains pattern-matching, a habit that doesn&#8217;t work well on the real exam.</p><p>The most obvious version of the AI fingerprint, where the right answer is simply the longest, is the easiest to catch. A harder one is the answer that is the same length as other options, but still gives itself away by adding more complete conditions. Of course, a word count misses this. Finding this fingerprint means examining the option to see if it is doing more work than others.</p><p>As we also know, AI makes up shit, usually with complete confidence. Ask enough questions, and the chat model will eventually invent a framework, miscategorize a control, or assign a requirement to the wrong standard. If you don&#8217;t catch it, you end up memorizing the wrong thing and carrying that error into the exam.</p><p>One of the most important issues is that AI can&#8217;t reliably understand or judge the more complex business-integrated, multi-component (or multidimensional) scenarios. It even trips on the terms FIRST versus BEST. It&#8217;s great at &#8220;which encryption algorithm fits this requirement.&#8221; It struggles with &#8220;the company just discovered x, what do you do first.&#8221; Especially where three or four options are defensible, and the answer depends on business alignment AND the right order of operations. The model will revert to the technical fix because that&#8217;s how it was trained.</p><p>This last issue is the one I&#8217;ve spent the most time on.</p><h2>Teaching a machine what &#8220;CISSP-worthy&#8221; means</h2><p>While building the Academy, I&#8217;ve developed an AI rubric, or &#8220;AI judge,&#8221; to rate questions like a human examiner. I write a question or a model drafts one, and the judge scores it. Is the right answer truly the single best one, or is there a defensible tie? Does it rely on judgment or a technical detail? Does it carry any fingerprints or tells?</p><p>The judge isn&#8217;t all-knowing, and it often doesn&#8217;t get it right. Current &#8220;frontier models&#8221; (Opus, Gemini, GPT-5x) all make very similar grading mistakes. They rate more technically oriented answers as harder, so a question loaded with technical distractors looks difficult to them. Even when, to a human thinking like a CISO, the answer is obvious. This is basically &#8220;hard by technicality, easy by judgment.&#8221; If AI wrote the question and then also tried grading it, it&#8217;s usually blind to its own fingerprints in the answer.</p><p>So the judge never has the final say. I use it as a detector, not a decision-maker. It surfaces suspects (&#8220;this one smells like a tell,&#8221; &#8220;these two options might both be right&#8221;), and it&#8217;s a human&#8217;s job to make a judgment call. I also pay attention when the judge expresses uncertainty. I ask it to run multiple iterations, and when its answers split, that split is something to evaluate. A question the judge can&#8217;t decide on is usually right on the border. And again, a person needs to review and make a decision.</p><p>As an example, I recently reviewed a question about securing a software supply chain, with plenty of &#8220;technical machinery.&#8221; The kind of question that feels hard. The keyed &#8220;best&#8221; answer was reasonably based on a component that was authentic and unaltered. But from a security manager&#8217;s perspective, the real question wasn&#8217;t &#8220;is the component authentic.&#8221; It&#8217;s &#8220;do we trust the source at all?&#8221; The judge rated it fine. Only reading it as a manager, not an engineer, caught that the better answer.</p><p>There&#8217;s an underlying reason and a term for this. AI is fluent at the lower rungs of Bloom&#8217;s Taxonomy: remembering and understanding. But the CISSP lives in the higher ones: applying, analyzing, evaluating.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fj9z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fj9z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png 424w, https://substackcdn.com/image/fetch/$s_!Fj9z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png 848w, https://substackcdn.com/image/fetch/$s_!Fj9z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!Fj9z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fj9z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png" width="1456" height="1165" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1165,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:106838,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/208256037?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fj9z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png 424w, https://substackcdn.com/image/fetch/$s_!Fj9z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png 848w, https://substackcdn.com/image/fetch/$s_!Fj9z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!Fj9z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b2cb8c-5bee-4f7a-9b9a-7afb71789bc8_1600x1280.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once you reach a certain level of technical competence, the technical distractors stop being tempting, and the correct question becomes obvious. It still may look like a CISSP question, but it doesn&#8217;t really behave like one.</p><p>None of this came together in a single clean formula. It took many versions of the rubric, and I still tune it by hand because &#8220;what makes a question CISSP-prep-worthy&#8221; is a craft, and one you can only partly automate. The judge narrows it down. But a person makes the call, and that division of labor is important to how the Academy operates.</p><h2>Why I built the Academy</h2><p>The trouble I kept running into, with both linear question banks and the AI-generated kind, is what led me to build a CISSP study platform called the Academy.</p><p>That &#8220;judge narrows it down, but the person makes the call&#8221; split isn&#8217;t a slogan. I use AI as a tool, but the real decisions, such as &#8220;Is this the single best answer? Is this judgment or trivia? Does this train the muscle the exam tests?&#8221; rest with a human who has taken the exam. That&#8217;s the line AI models can&#8217;t cross yet.</p><p>I looked for a single product that did all that but couldn&#8217;t find one, so I started building it. Every question is crafted to be worthy of the test bank and to build your readiness as the end goal. </p><p>Every question comes with a full explanation, not only why the key is right but why each distractor is wrong, since understanding why the tempting answers are incorrect helps build judgment. </p><p>None of it&#8217;s magic. It&#8217;s work done by hand where it must be and helped by AI where it&#8217;s safe.</p><h2>The shortcut that isn&#8217;t there</h2><p>The CISSP is hard because it tests judgment, and judgment is the one thing that still doesn&#8217;t get generated from a prompt. The tools got better. The people who write good questions became faster. But the shortcut, the one where you generate a stack of questions and grind them until you pass, still isn&#8217;t there, because question creation that is truly exam-prep worthy needs a human.</p><p>Use AI. It&#8217;s a great study partner. Just don&#8217;t hand it the one job it can&#8217;t yet do.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Build Your CISSP Study Plan Around Your Weak Spots]]></title><description><![CDATA[I&#8217;ve seen a lot of CISSP study plans that are basically a reading schedule in a costume.]]></description><link>https://blog.balancedsec.com/p/build-your-cissp-study-plan-around</link><guid isPermaLink="false">https://blog.balancedsec.com/p/build-your-cissp-study-plan-around</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 17 Jul 2026 13:01:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rN2x!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rN2x!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rN2x!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png 424w, https://substackcdn.com/image/fetch/$s_!rN2x!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png 848w, https://substackcdn.com/image/fetch/$s_!rN2x!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!rN2x!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rN2x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:182724,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/207320630?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rN2x!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png 424w, https://substackcdn.com/image/fetch/$s_!rN2x!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png 848w, https://substackcdn.com/image/fetch/$s_!rN2x!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!rN2x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62301b1-de79-42f3-962a-25e9e3a70d09_2400x1350.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>I&#8217;ve seen a lot of CISSP study plans that are basically a reading schedule in a costume. Start with the Official Study Guide chapter one in week one, chapter two in week two, and so on until exam day. It feels organized. It&#8217;s also one reason why capable people walk out of the test center surprised.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>A calendar tells you what to read. It doesn&#8217;t tell you where you're weak, and the CISSP exam is good at finding weak spots: it&#8217;s adaptive. It finds the edges of what you know and keeps pushing there. So a plan that treats all eight domains as equal, and treats &#8220;I read it&#8221; as &#8220;I know it,&#8221; is preparing you for a version of the exam that doesn&#8217;t exist. If you want the fuller picture of why strong candidates come up short, I covered the <a href="https://blog.balancedsec.com/p/why-people-fail-the-cissp">six most common traps</a>. Let&#8217;s talk about how to build a plan that avoids them from day one.</p><p>Here&#8217;s the approach I&#8217;d use, and it starts before you open a book.</p><h2>Step 1: Set a real runway, then take a baseline</h2><p>Two questions before you schedule anything.</p><p>First, how long do you actually have? For most people with a few years of security experience, three to six months of consistent study is realistic. Less experience, or a big gap in one domain, pushes you toward the longer end. For a candid look at what actually makes the exam hard, <a href="https://blog.balancedsec.com/p/how-difficult-is-the-cissp-exam">I've broken it down here</a>. Set the runway to your life, not to a template.</p><p>Second, where are you starting? Take a diagnostic before you build anything: a set of practice questions across all eight domains done cold. You&#8217;re not trying to pass. You&#8217;re finding the floor. If you have the Sybex Official Study Guide, you already own a clean way to do this. Its 40-question Assessment Test covers all eight domains. Take it directly by hand in the book, or register the book on the <a href="https://www.wiley.com/go/sybextestprep">Wiley Efficient Learning portal</a>, answer a quick question to confirm you own it, and take it online to see how you scored.</p><p>If your score comes back low, don&#8217;t sweat it. It just flags the domains that need the most focus first. Score above 90 percent, and you&#8217;re working from a strong base already. Either way, that result is what the plan gets built around.</p><h2>The core idea: study by weak concept, not by domain</h2><p>This is the part most plans get backward. CISSP questions are multidomain by design. A single scenario can pull from risk management, cryptography, and network security at once, so a shaky concept in one area quietly drags down your performance across several. That means &#8220;study Domain 3 this week&#8221; is the wrong unit of work. The right unit is the concept you keep missing.</p><p>So the plan isn&#8217;t a march through eight domains in order. It&#8217;s a loop. Surface your weak concepts, study those specifically, then confirm they&#8217;re fixed. The domains are the map. Your misses are the itinerary.</p><h2>The three-phase plan</h2><h3>Phase 1: Anchor</h3><p>Before you can find weak spots efficiently, you need a spine: a structured first pass that gives you the shape of all eight domains so nothing is a total blank. Weight this pass the way the exam weights the domains. Domain 1 is 16 percent and touches everything, so it earns more of your early attention than the 10 percent domains. Work through each domain enough to grasp its structure. My domain walkthroughs are built for exactly this pass, <a href="https://blog.balancedsec.com/p/understanding-cissp-domain-1-security">Domain 1</a> through <a href="https://blog.balancedsec.com/p/understanding-cissp-domain-8-software">Domain 8</a>, each mapped to the ISC2 outline, with the <a href="https://blog.balancedsec.com/p/cissp-cbk-explainer">CBK explainer</a> as the one-page overview if you want it first.</p><p>Anchor is the shortest phase. Its only job is to get you to the point where a practice question makes sense, so the real work can start.</p><h3>Phase 2: Diagnose and target</h3><p>This is where most of your time goes, and it&#8217;s the loop that moves the needle.</p><p>Take practice questions in small batches, twenty to fifty at a time. As you go, keep a running list of every question you got wrong, didn&#8217;t recognize, or felt shaky on, regardless of which domain it came from. Study everything on that list. Then take another batch and do it again. Each round rewrites your list toward the concepts you haven&#8217;t locked in yet, and pulls your time toward your weak areas without you having to guess where they are.</p><p>The discipline is boring, and it works. Rinse and repeat until your list stops filling up with the same concepts.</p><h3>Phase 3: Simulate and sharpen</h3><p>In the final stretch, shift from learning to performing. Take full-length, CAT-style practice sessions under real-time pressure so the format becomes a constant. Practice the pacing, roughly a question a minute, and practice the mindset the exam rewards: answering as a risk-aware manager, not as the hands-on technician who wants to go fix the box. That question-reading skill has its own <a href="https://blog.balancedsec.com/p/strategy-guide-for-answering-difficult">step-by-step method</a>, and it&#8217;s worth drilling on its own. Anything that still surfaces here goes to final cleanup.</p><h2>Use your practice questions the right way</h2><p>A practice question is worth far more than a right-or-wrong score if you work it correctly. For each one:</p><ul><li><p>Read the question first, without the answers, and try to answer it in your head.</p></li><li><p>Read all the choices, then reread the whole thing to look for the qualifier you missed.</p></li><li><p>Before you pick, explain to yourself why the right answer is right and why each other option is wrong.</p></li></ul><p>That last step is the whole game. If you can land the correct answer but can&#8217;t say why a distractor is wrong, that distractor&#8217;s topic is a weak concept hiding inside a question you got right. Most people run through hundreds of questions chasing a percentage. You&#8217;ll get more from fifty worked this way than five hundred clicked through on autopilot.</p><h2>How to know you&#8217;re ready</h2><p>Ready isn&#8217;t &#8220;I finished the book.&#8221; It&#8217;s a pattern: your scores hold steady across mixed full-length sets, and you can explain your reasoning, including why the wrong answers are wrong, on a consistent basis. When your weak-concept list keeps coming back nearly empty, and your timing is comfortable, book the exam. If you&#8217;re planning a second attempt rather than a first, the <a href="https://blog.balancedsec.com/p/the-art-of-the-cissp-retake">retake has its own strategy</a> built around your score report.</p><h2>If you&#8217;re short on time</h2><p>Working full-time while you study is the normal case (even if that means full-time on a job hunt). If your runway is tight, protect Phase 2. Trim the Anchor pass to the heaviest domains, shorten Phase 3, but do not skip the diagnose-and-target loop. It&#8217;s the phase correlated with passing. An hour a day spent on your real weak spots beats a weekend re-reading what you already know.</p><h2>The plan on one page</h2><p>I put the three-phase structure into a blank weekly template you can fill in for your own runway. <a href="https://www.balancedsec.com/cissp">Grab the free template on the CISSP resources page</a> and adapt it to your timeline and your baseline.</p><p>This plan is a method, and the method is manual. You run your own diagnostic, keep your own miss list, and re-sequence your own weeks as your weak spots move. That&#8217;s doable, and plenty of people pass doing exactly this with free resources. My <a href="https://github.com/jefferywmoore/CISSP-Study-Resources">study notes on GitHub</a> are always free and a fine place to start.</p><p>If you&#8217;d rather not run the loop by hand, that&#8217;s the problem the <a href="https://academy.balancedsec.com/?utm_source=blog.balancedsec.com&amp;utm_medium=referral&amp;utm_campaign=build-your-cissp-study-plan">BalancedSec Academy</a> was built to solve. It does the diagnosing for you: an adaptive engine and a real question bank that find your weak concepts and rebuild your schedule as you go, plus the book, <em>CISSP: A Balanced Approach</em>. Same basic method as above. The Academy just runs it for you, and founding-beta access is open if you want it.</p><p>Either way, start with the diagnostic. The plan follows from what it tells you.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Art of the CISSP Retake ]]></title><description><![CDATA[Strategy, Timing, and the Mindset for the next Round]]></description><link>https://blog.balancedsec.com/p/the-art-of-the-cissp-retake</link><guid isPermaLink="false">https://blog.balancedsec.com/p/the-art-of-the-cissp-retake</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 10 Jul 2026 13:03:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NGov!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NGov!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NGov!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png 424w, https://substackcdn.com/image/fetch/$s_!NGov!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png 848w, https://substackcdn.com/image/fetch/$s_!NGov!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!NGov!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NGov!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170267,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/206338114?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NGov!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png 424w, https://substackcdn.com/image/fetch/$s_!NGov!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png 848w, https://substackcdn.com/image/fetch/$s_!NGov!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!NGov!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f34591b-2d4a-4eeb-af54-1f36590ee289_2400x1350.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://blog.balancedsec.com/p/why-people-fail-the-cissp">People fail the CISSP</a> for several common reasons. Examples include choosing the technically perfect answer over the business-aligned one, misreading the adaptive format, and failing to prioritize studying weak domains. Failing the CISSP is more common than the celebratory LinkedIn posts would have you believe. The exam is broad; the Computerized Adaptive Testing (CAT) format can be challenging, and plenty of sharp, experienced practitioners walk out of the testing center disappointed on their first try. If that&#8217;s you, you&#8217;re in good company. The failure doesn&#8217;t define you or your abilities; it points you in the direction you should grow and spend your time.</p><p>A retake adds a few new parameters and reframes the focus on your next steps. The first time, you&#8217;re building coverage across eight domains. The test format and cadence are new. The second time, you already have a map of the terrain and a new guide to weak areas provided directly from ISC2. The job now is to read that map correctly, understand how the exam actually scores you, and pick a timeline that matches how close you came.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>Your new playbook</h2><p>Before you plan anything, let&#8217;s get the boundaries straight. ISC2 enforces mandatory waiting periods between attempts (isc2.org/exams/after-your-exam):</p><ul><li><p>After your first failure, you can retest after <strong>30 test-free days.</strong></p></li><li><p>If you need a second retake, you have to be <strong>60 test-free days</strong> from your most recent attempt.</p></li><li><p>For a third or subsequent failure, there must be a <strong>90-day test-free gap</strong> before trying again.</p></li><li><p>You can attempt any ISC2 exam up to <strong>4 times in a rolling 12-month period</strong>.</p></li></ul><p>Don&#8217;t confuse that mandatory cooling-off period with your study runway. They&#8217;re two separate clocks. That first 30-day window is only the earliest ISC2 will let you back in the chair. How long you actually take to prepare is your call, and it should depend on how far off you were, not on how fast the rules allow.</p><p>One money-saving note. If you bought ISC2&#8217;s Peace of Mind Protection before your first attempt, you have a second voucher already, valid for 180 days from purchase with a 30-day gap between sittings (isc2.org/landing/exam-peace-of-mind). If you didn&#8217;t buy it up front, you can&#8217;t add it retroactively. The exam itself is a meaningful cost (check ISC2&#8217;s <a href="https://www.isc2.org/register-for-exam/isc2-exam-pricing">current pricing page</a> for the exact figure in your region), so factor that into your budget and timeline.</p><h2>Read your diagnostic report before you touch a book</h2><p>If you fail the exam, ISC2 provides a diagnostic breakdown of the eight domains. There&#8217;s no numerical score. Instead, you get three proficiency tiers per domain: Below Proficiency, Near Proficiency, and Above Proficiency, plus a rank ordering of domains by how well you did. That ranking is really useful in planning your strategy for the next attempt.</p><p>Work it in this order:</p><p><strong>Below Proficiency first.</strong> A &#8220;below proficiency&#8221; mark isn&#8217;t a verdict on how hard you worked. The Common Body of Knowledge is enormous, and it&#8217;s easy for a domain to get less time than it needed, or for some threads to come loose on exam day. Treat the label as a signal for where focused effort pays off most. Here are some ideas on a few approaches that tend to work better than rereading the domain cover to cover (which may be part of the reason the threads slipped the first time):</p><ul><li><p><strong>Narrow before you dig.</strong> Use ISC2&#8217;s exam outline as a checklist and rate each objective in the domain: solid, shaky, or new. The &#8220;below&#8221; score almost always traces to a few specific areas, not the whole domain, which turns a mountain into a short list.</p></li><li><p><strong>Get the shape first, then the details.</strong> Sketch the domain&#8217;s structure so that concepts have a frame to hang on to. They stick better on a structure than as a flat list of facts.</p></li><li><p><strong>Hear it explained a different way.</strong> If one pass through the OSG didn&#8217;t land, a second identical pass may be doomed to the same fate. A video or a different author on that one topic can frame it in the way that finally clicks.</p></li><li><p><strong>Explain it out loud.</strong> Try teaching the concept in plain language to a study partner or just to the room. Wherever you stall is the precise spot to study next.</p></li><li><p><strong>Anchor it to something real.</strong> Tie the concept to a breach, a control you&#8217;ve actually used, or a situation from work. That&#8217;s also the shape the exam asks it in, so it does double duty.</p></li><li><p><strong>Then bring practice questions back in.</strong> Once the concept is back in place, questions become the way to test it and to study the reasoning behind every option. Spend as long on why the wrong answers are wrong as on why the right one is right.</p></li></ul><p><strong>Near Proficiency second.</strong> A Near mark means you&#8217;re already close to the passing line, so these are the cheapest points to win. Close them with targeted practice rather than a full rebuild.</p><p><strong>Above Proficiency last.</strong> Light passive review to keep it warm. Don&#8217;t spend your best hours here out of comfort.</p><p>One factor cuts across all three tiers: domain weight. A weak mark costs more in a heavy domain. Domain 1 leads at 16%, and four more tie at 13% each (Security Architecture, Communication and Network, IAM, and Security Operations), together two-thirds of the exam, so a gap there is worth closing first. The same gap in Asset Security or Software Development Security (10% each) moves your overall score less. Spend your best hours where weak meets heavy.</p><p>Reading the report is the easy part. The real work is turning that ranking into a sequenced, time-boxed plan you&#8217;ll actually follow, and then holding to it.</p><h2>How the CAT actually scores you (and the myth that wastes retakers&#8217; time)</h2><p>This is where a lot of retake advice goes wrong, so it&#8217;s worth reviewing.</p><p>CISSP CAT scoring is <strong>compensatory</strong>. There is no per-domain pass mark. Your pass or fail comes down to a single overall ability estimate measured against one standard (700 on a 0 to 1000 scale) across all the operational items you answer. Strong performance in one area genuinely offsets weakness in another. ISC2&#8217;s scoring FAQ says it directly: its exams are &#8220;compensatory,&#8221; so &#8220;a higher number of items answered correctly in one domain [can] compensate for a lower performance in another domain,&#8221; and &#8220;a single pass/fail result is calculated on the total of all operational items&#8221; (<a href="https://www.isc2.org/register-for-exam/exam-scoring-faqs">ISC2 exam-scoring FAQ</a>).</p><p>Why does Domain 1 keep coming up? Not because the engine &#8220;targets&#8221; it or because fixing it cascades into your architecture score. It&#8217;s simpler: at 16%, Domain 1 is the largest single block of the exam, so it gives you the most compensatory headroom. Nothing more mystical than weight.</p><p>The engine picks each question to sit near a 50% chance you&#8217;ll get it right, tuned to its current read on your ability. Answer well, and the estimate climbs, and the questions get harder. Miss one and it eases off. So the harder your items feel, the higher the engine currently rates you, which means difficulty isn&#8217;t meaningless.</p><p>The trouble is you can&#8217;t read it reliably from the chair. Every item is aimed at your personal edge, so it feels punishing whether you&#8217;re passing or failing. About a quarter of the items aren&#8217;t even scored. They&#8217;re pretest questions being trialed for future exams, and you can&#8217;t tell them from the real ones. And you never see your own estimate. Expect it to feel hard, take that as the format doing its job, and don&#8217;t try to grade yourself mid-exam.</p><p>Where the exam ends, though, is a signal. It stops early once it&#8217;s 95% confident you&#8217;re clearly above or clearly below the line (after a 100-item minimum), and runs to its 150-item maximum only when you&#8217;re close enough that it can&#8217;t reach that confidence. So a fail at the short end means the algorithm got sure quickly, and a fail near 150 items means you were sitting right on the boundary. Both tell you how hard to push next time.</p><p>For reference, the current CISSP CAT is 100-150 items over 3 hours, post-April 2024 (see <a href="https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline">the ISC2.org exam outline</a>).</p><h2>Pick your timeline from where you landed</h2><p>Match your study runway to your diagnostic, not to the calendar minimum.</p><p><strong>The 30-day sharpen.</strong> For candidates who ran near the 150-item ceiling with mostly Near ratings, you were close. Spend the first week on frameworks and mindset, the middle two weeks drilling your two or three softest domains, and the final stretch on timed practice and pacing. Rest before exam day.</p><p><strong>The 90-day reset.</strong> The right choice for most retakers. Month one, rebuild your weakest domains from primary sources and draw the connections between technical controls and the governance behind them. Month two, shift to applied practice with a running error log (what you missed, why your reasoning failed, what the better answer protects). Month three, full-length timed simulations to build stamina.</p><p><strong>The 180-day rebuild.</strong> For candidates sitting below in four or more domains, or anyone fitting study around a demanding job (and life). Treat it as a fresh cycle through all eight domains, then layer in study-group discussion and heavy simulation in the back third. Explaining a concept out loud to another candidate is one of the fastest ways to find out whether you actually know it.</p><h2>The mindset shift that decides most retakes</h2><p>The most common reason strong technical people fail the CISSP is answering as an engineer when the exam wants a manager or owner perspective. I wrote a full method for working on hard questions in &#8220;<a href="https://blog.balancedsec.com/p/strategy-guide-for-answering-difficult">Strategy Guide for Answering Difficult CISSP Questions</a>&#8221;, so I&#8217;ll keep it short here. The engineer reaches for the immediate technical fix. The exam usually rewards the governance move: assess the risk, follow the process, align with the incident response plan, and the organization&#8217;s risk tolerance.</p><p>Treat that as a tiebreaker, not an iron law. Plenty of questions have a correct technical answer. What decides the right path is the qualifier in the question. Watch for MOST, LEAST, FIRST, and BEST, because they can completely change the answer. A useful habit under a wall of technical detail: read the final sentence first. CISSP items often bury a high-level policy question at the end of a paragraph of noise.</p><p>One retake-specific warning. If you&#8217;re reusing a question bank you&#8217;ve seen before, you&#8217;re now testing your memory of answers, not your understanding. Force yourself to state the principle behind each answer before you pick it. If you can&#8217;t explain why the other three options fail, score it as a miss even if you &#8220;knew&#8221; it was C.</p><h2>How my resources fit</h2><p>Everything above works with any good materials. Here&#8217;s how mine fit&#8212;one is free for good, and one is free for now.</p><p><strong>Always free: the <a href="https://github.com/jefferywmoore/CISSP-Study-Resources">BalancedSec GitHub study notes</a>.</strong> They condense the ISC2 Study Guide domain by domain along the exam outline, so they double as a distilled primary text and the checklist for your rebuild. No signup, no cost, and they stay that way. If you use nothing else of mine, consider these.</p><p><strong>Free for now: the <a href="https://academy.balancedsec.com/">BalancedSec Academy</a> (founding beta).</strong> This is the piece for the hard part: turning your weak domains into a plan you actually work. It runs CAT-style practice that surfaces weak areas, builds a study plan that adapts to them and your exam date, drills the owner/manager mindset through scenario questions, and includes my book, CISSP: A Balanced Approach, in-app (organized around ISC2 exam objectives). It&#8217;s in founding beta, so it&#8217;s free while that lasts.</p><p>A retake isn&#8217;t a verdict on whether you belong in this field. It&#8217;s a measurement, and this time you aren&#8217;t starting from a blank page. You have the report. Read it, respect the timeline, and go take it back.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3llA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3llA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png 424w, https://substackcdn.com/image/fetch/$s_!3llA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png 848w, https://substackcdn.com/image/fetch/$s_!3llA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png 1272w, https://substackcdn.com/image/fetch/$s_!3llA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3llA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png" width="1456" height="1515" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1515,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:734400,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/206338114?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3llA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png 424w, https://substackcdn.com/image/fetch/$s_!3llA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png 848w, https://substackcdn.com/image/fetch/$s_!3llA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png 1272w, https://substackcdn.com/image/fetch/$s_!3llA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83213c3e-fd97-4162-b10a-2b66e83ec46d_1774x1846.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why People Fail the CISSP]]></title><description><![CDATA[The CISSP has a reputation as one of the hardest and most respected security exams, and it earns that reputation.]]></description><link>https://blog.balancedsec.com/p/why-people-fail-the-cissp</link><guid isPermaLink="false">https://blog.balancedsec.com/p/why-people-fail-the-cissp</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 03 Jul 2026 13:03:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NLr_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The CISSP has a reputation as one of the hardest and most respected security exams, and it earns that reputation. It&#8217;s broad, it&#8217;s written to catch the overconfident, and it runs on a format built to keep you off balance. Nobody publishes an official pass rate, but enough capable, experienced people fall short on the first attempt that the question is worth taking seriously: why?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NLr_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NLr_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png 424w, https://substackcdn.com/image/fetch/$s_!NLr_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png 848w, https://substackcdn.com/image/fetch/$s_!NLr_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png 1272w, https://substackcdn.com/image/fetch/$s_!NLr_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NLr_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png" width="1456" height="761" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:761,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:140143,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/204733309?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NLr_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png 424w, https://substackcdn.com/image/fetch/$s_!NLr_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png 848w, https://substackcdn.com/image/fetch/$s_!NLr_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png 1272w, https://substackcdn.com/image/fetch/$s_!NLr_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c7a491-34e0-493e-99f2-254ae3dd1df0_2000x1046.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Many people fail for the same short list of reasons, and almost none of them stem from not &#8220;knowing enough about security.&#8221; They come down to your prep, your in-exam thought process, and how you handle the pressure. That&#8217;s a gift because predictable mistakes are avoidable. Knowing the traps before you sit down is one of the biggest advantages you can bring into the exam room. Here are the most common reasons people fail, and how to beat them.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Six traps, and how to beat each one</h2><h3>1. The technical trap</h3><p>This is the big one, and it can catch even the strongest candidates. Experienced practitioners want to answer questions from, well, their experience. If much of that experience is &#8220;hands-on,&#8221; it can very well mean applying a technician&#8217;s lens to the questions. You really know your stuff, and you&#8217;ve been doing it for a hot minute. You see a problem, and your instinct is to reach for the hands-on fix: block the port, patch the service, contain the threat.</p><p>But the CISSP isn&#8217;t testing that instinct. The exam wants you to view risk, governance, and security from an organizational perspective. The technical fix may disregard the root problem, and we need to treat the organization holistically. We&#8217;re striving for a balance between driving security to reduce organizational risk and not standing in the way of goal achievement. And it can be a tricky stance to take. We want to view security programmatically, thinking like a CISO or a senior risk advisor. Answering questions from that higher-level policy, governance, and organizational risk perspective. People fail because they pick the technically perfect option over the one that fits how a business actually makes security decisions. The better you are at the technical job, the more likely this is to trip you up, because your instincts are well-trained for the work and misaligned for the test.</p><p>There&#8217;s a second version of this trap that&#8217;s easy to miss. Years on the job build habits, and some of those habits quietly disagree with the standardized answer the exam wants. If your shop handles something a certain way, that doesn&#8217;t make it the CISSP-correct way. Passing means being willing to set aside how it&#8217;s done at your desk and answer the way the Common Body of Knowledge defines it. Experience is an asset here, right up until it argues with the exam.</p><p><strong>How to beat it: think like the CEO or owner.</strong> When you read a scenario, separate the business problem from the technical symptom before you look at the answers. A few habits keep you on the right side of it:</p><ul><li><p><strong>Risk and policy first.</strong> Look for the answer that establishes governance, reviews the business case, or runs a risk assessment before deploying a technical control.</p></li><li><p><strong>Pick the answer that covers the most ground.</strong> When several options are technically correct, choose the one that protects the organization&#8217;s overall risk posture rather than the narrow fix.</p></li><li><p><strong>Human life wins, every time.</strong> In any physical security, business continuity, or disaster recovery scenario, personnel safety comes before equipment, money, and data.</p></li><li><p><strong>Be able to explain it.</strong> A security manager has to justify decisions to people who don&#8217;t live in security. Some questions test whether you can pick the answer a non-technical executive or board would understand and back, not just the one that&#8217;s technically sharpest.</p></li></ul><p>Then read the question like a lawyer. A law degree is, of course, not required, but put on your &#8220;attorney hat&#8221; and read carefully and purposely:</p><ul><li><p><strong>Find the qualifier.</strong> Words like MOST, BEST, FIRST, PRIMARY, and NOT change the whole question. They tell you whether it wants your first action (usually an assessment or a policy step) or the ultimate goal (reducing risk). Remember that there are also processes that work best when followed in a particular sequence (I&#8217;m looking at you, Incident Response).</p></li><li><p><strong>Read it twice.</strong> Once for the scenario and to catch the qualifier, once to strip away the noise and find the actual problem. Try to read the question without looking at the potential answers.</p></li><li><p><strong>Eliminate hard.</strong> Two of the four options can usually go fast. Cut the answer that jumps to a technical fix when the question asks what to do first, because the first step is almost always to assess, analyze, or get management&#8217;s buy-in. Cut absolutes (always, never, eliminate all risk), since security manages risk rather than erasing it. Cut a control that costs more than the asset is worth. And cut the option that treats the symptom instead of the root cause. What&#8217;s left is usually a real 50/50, and now you&#8217;re choosing between two answers instead of four.</p></li></ul><p>Rehearse this with scenario-based questions until the business-first answer no longer feels unnatural.</p><h3>2. Cramming and memorizing</h3><p>Plenty of candidates treat the CISSP like a vocabulary quiz. They memorize definitions, ciphers, port numbers, and checklists, then walk in and find almost none of it being asked directly.</p><p>The questions are likely situational. You may not be asked to define a preventive control, but you will likely be handed a messy scenario and asked which control type fits the budget and the value of the asset in front of you. Experience and cross-domain reasoning help you navigate these beyond mere memorization.</p><p><strong>How to beat it: study for understanding, not recall.</strong></p><ul><li><p><strong>Learn how concepts connect,</strong> not definitions in isolation. If you can explain why a control exists and when you&#8217;d choose it, the scenario questions will seem a lot more natural.</p></li><li><p><strong>Practice on scenarios, not just flashcards.</strong> Work questions that hand you a situation and make you choose.</p></li><li><p><strong>Active learning over silent reading.</strong> Teaching a concept to someone else, mind-mapping a domain, or working through it in a study group exposes the gaps that rereading may miss.</p></li><li><p><strong>Real examples, not just definitions.</strong> Read about ways AI is failing and succeeding, real examples of actual breaches, and case studies. It helps tie concepts together.</p></li></ul><h3>3. Studying without an anchor</h3><p>This one is about structure. You can study a lot and still walk in underprepared, because volume is not the same as a plan. Without a spine for your prep, an anchor to measure new material against, and a clear sense of how you learn best, the hours may not yield the retention or substantive coverage you need. It can be difficult to judge whether you&#8217;re covering the right material, in enough depth, at the right pace.</p><p>Going wide can be a good thing, and if you have the time, do it. Breadth builds perspective, and perspective is what lets you notice when a resource is off-base or out of step with the exam. Breadth becomes a problem only when there&#8217;s no baseline to judge it against, because without an anchor, five slightly different explanations turn into noise instead of a fuller picture. </p><p><strong>How to beat it: anchor first, then go wide on purpose.</strong></p><ul><li><p><strong>Build a small core, then read around it.</strong> Anchor on one trusted primary text (the official ISC2 CISSP Study Guide, or OSG, is the common baseline) and one solid question bank (the Official Practice Tests, or OPT, its companion, with around 1,300 questions). That core is your spine, and everything else supplements it.</p></li><li><p><strong>Map everything to the exam outline.</strong> Use <a href="https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline">ISC2&#8217;s official CISSP exam outline</a> as your checklist for what&#8217;s in scope, so you can place each new resource against it and study the test that actually exists.</p></li><li><p><strong>Go wide for perspective.</strong> With an anchor in place, more viewpoints can help, however, the exam is already wide, so judge the best use of your time accordingly. A second guide for the concepts that won&#8217;t click, a video series for framing and priority. Being widely read is what gives you the judgment to spot a resource that&#8217;s off.</p></li><li><p><strong>Match the format to how you learn.</strong> Some people internalize by reading and writing concepts out. Others are best reinforced with audio or video. Figure out your own modalities and weight your stack toward them, because the best resource is the one that is easy to actually absorb.</p></li><li><p><strong>Cross-check against the authority, not against each other.</strong> When two sources disagree, the exam outline and official materials are the tiebreaker.</p></li></ul><h3>4. CAT panic and bad pacing</h3><p>The English CISSP uses Computerized Adaptive Testing. You get between 100 and 150 questions within a three-hour window, and the difficulty is likely to increase as you answer correctly.</p><p>That last part can feel like a trap. As the questions get harder, candidates assume they&#8217;re failing, when a hard question can mean the opposite. Panic can make it harder to answer questions you would otherwise be able to reason through, creating a sense of urgency and leading to second-guessing, and ultimately running out of clock.</p><p><strong>How to beat it: work with the format, not against it.</strong></p><ul><li><p><strong>Reframe the hard stretch.</strong> When the questions get brutal, that&#8217;s often a sign you&#8217;re doing well. Expect it, and don&#8217;t read difficulty as failure.</p></li><li><p><strong>It&#8217;s one-way.</strong> The format serves your next question based on your last answer, so you can&#8217;t skip or go back. Make a decisive, educated choice on every item and move on.</p></li><li><p><strong>Hold a pace.</strong> Aim for roughly 50 questions an hour, and glance at the clock every 20 to 25 questions. That&#8217;s enough to stay on track without feeding the panic.</p></li><li><p><strong>Expect the unknown.</strong> You will hit topics you never studied. That&#8217;s normal. Stay calm, fall back on core principles you&#8217;ve learned, cut the distractors, and pick the most organizationally sound answer.</p></li></ul><h3>5. Leaning on your strong domains</h3><p>Most of us live in one or two corners of security at work, say cyberthreat response, or identity and access management, and we get comfortable there. Candidates can lean on that real-world experience and neglect the domains they touch less often. The exam covers all eight, so a lopsided prep produces a lopsided score, and the weak domains drag the whole thing down.</p><p>There&#8217;s a subtler version of this. The domains aren&#8217;t islands, and some of the hardest questions live where they overlap, like identity feeding a business continuity plan or cryptography showing up inside a network design.</p><p><strong>How to beat it: study all eight, and target the weak ones.</strong></p><ul><li><p><strong>Find your weak domains and pour time there.</strong> Use the practice tests from your stack for diagnostics. Treat every miss as a signal about where to study next, then spend your hours on the uncomfortable domains, not the comfortable ones.</p></li><li><p><strong>Study the seams.</strong> Deliberately work the places where the domains overlap, since that&#8217;s where the hardest questions live.</p></li><li><p><strong>Bring every domain to a baseline,</strong> even the ones you think you own.</p></li></ul><h3>6. The language tax</h3><p>The CISSP is as much an English reading test as a security test, and that&#8217;s a real headwind if English isn&#8217;t your first language. The jargon is dense, the vocabulary is heavy, and plenty of questions turn on a subtle distinction between two words. Every item you have to translate in your head costs time and focus you can&#8217;t spare. The exam is offered in only a handful of languages (English, Chinese, German, Japanese, Korean, and Spanish), so for most non-native speakers, English is the only option.</p><p><strong>How to beat it: prepare for the language, not just the material.</strong></p><ul><li><p><strong>Immerse in English.</strong> Do your prep in English rather than translating from your first language, so exam-day reading feels familiar.</p></li><li><p><strong>Practice on English questions.</strong> Get used to how the exam phrases things, including the qualifiers that carry the whole question.</p></li><li><p><strong>Build vocabulary alongside the content.</strong> Keep a running list of the terms and turns of phrase that slow you down.</p></li></ul><p>None of this is a wall. People clear it every year with prep aimed squarely at the language, not just the material.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ly2n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ly2n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png 424w, https://substackcdn.com/image/fetch/$s_!ly2n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png 848w, https://substackcdn.com/image/fetch/$s_!ly2n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!ly2n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ly2n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png" width="1456" height="845" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:845,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:241067,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/204733309?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ly2n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png 424w, https://substackcdn.com/image/fetch/$s_!ly2n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png 848w, https://substackcdn.com/image/fetch/$s_!ly2n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!ly2n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90df6a2e-74fd-4d04-afc2-4fb760dd6a6b_2480x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The resources I&#8217;ve built</h2><p>Everything above works with any good materials. Here&#8217;s how mine fit -- one is free for good, one is free for now.</p><p><strong>Always free: the BalancedSec <a href="https://github.com/jefferywmoore/CISSP-Study-Resources">GitHub study notes</a>.</strong> My notes condense the OSG and are organized domain by domain along ISC2&#8217;s exam outline, so they double as the spine and a distilled version of the primary text. No signup, no cost, and they stay that way. Readers have told me the notes were the backbone of their prep, and there are <a href="https://www.balancedsec.com/cissp/what-people-are-saying">testimonials on balancedsec.com</a> if you want to see what people got out of them. If you use nothing else of mine, use these.</p><p><strong>Free for now: <a href="https://academy.balancedsec.com/">BalancedSec Academy (founding beta)</a>.</strong> It runs CAT-style practice exams to surface your weak domains, builds a study plan that adapts to them and your exam date, drills the owner/manager mindset through scenario questions, and includes my book, <em>CISSP: A Balanced Approach,</em> in-app (organized along the same outline). It&#8217;s in founding beta right now, so it&#8217;s free while that lasts. Use it if it helps, or stick with the free notes.</p><p>Passing the CISSP has never been about being the smartest person in the room. It comes down to studying your weak spots, learning to think like the owner/manager the exam is written for, and keeping your composure when it pushes back. All of that is learnable, and you now have a map of exactly what to practice. Trust your preparation, believe you can do this, and the exam becomes a challenge you&#8217;re ready for instead of one waiting to surprise you. Knowing where the traps are is your advantage: go use it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The AI Paradigm Shift: Running It in the Wild (CISSP Domains 4, 5, 6 & 7)]]></title><description><![CDATA[Part 1 of this series was about governance and risk: who&#8217;s accountable for an AI system and how you decide what could go wrong.]]></description><link>https://blog.balancedsec.com/p/the-ai-paradigm-shift-running-it</link><guid isPermaLink="false">https://blog.balancedsec.com/p/the-ai-paradigm-shift-running-it</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 26 Jun 2026 13:03:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!z9fk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z9fk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z9fk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!z9fk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!z9fk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!z9fk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z9fk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5996194,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/203448543?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z9fk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!z9fk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!z9fk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!z9fk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff137d6ec-7dc4-4c56-a25d-d85273d51908_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><a href="https://blog.balancedsec.com/p/the-ai-paradigm-shift-governance?r=1k08iw">Part 1</a> of this series was about governance and risk: who&#8217;s accountable for an AI system and how you decide what could go wrong. <a href="https://blog.balancedsec.com/p/the-ai-paradigm-shift-asset-security?r=1k08iw">Part 2</a> was about the data: how to classify and protect the information a model learns from. <a href="https://blog.balancedsec.com/p/the-ai-paradigm-shift-architecture?r=1k08iw">Part 3</a> was about the build: the architecture and pipelines that turn that data into a finished model. Every part so far has been about getting a model ready. None of them touched what happens once you switch it on.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>That&#8217;s where part 4 picks up. The model is now live, taking real traffic from real people, sitting behind APIs and inside your network. That changes the attack surface, and four CISSP domains answer the change: network security (Domain 4), identity (Domain 5), testing (Domain 6), and security operations (Domain 7).</p><p>You don&#8217;t need to be an ML engineer to follow this. The goal, as in the earlier parts, is to recognize a new category of risk and determine which kind of control addresses it. Most of these controls are ones you already know. They just point at something new.</p><h2>Network Security and Endpoint Protection (Domain 4)</h2><p>A live AI system talks to many things: APIs, cloud services, and clusters of GPUs that provide the actual compute. Every one of those connections is a door. Two of them lead somewhere you don&#8217;t want an attacker to go.</p><h3>Model Extraction: Stealing the Model Through the Front Door</h3><p>Imagine someone who can&#8217;t see your recipe but is allowed to taste the dish as many times as they want. Taste it enough, vary the orders enough, and eventually they can reproduce it at home. That is model extraction. The API is the tasting spoon.</p><p>In a model extraction attack, someone repeatedly queries your public endpoint, observing which inputs produce which outputs. Each answer tells them a little more about where the model draws its lines. Given enough queries, they can train their own local copy that behaves like yours. They walk away with your intellectual property without ever touching your database. This isn&#8217;t theoretical: researchers extracted production models from BigML and Amazon&#8217;s ML service with near-perfect fidelity using only the public prediction API (<a href="https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/tramer">Tram&#232;r et al., USENIX Security 2016</a>), and the technique is now cataloged as <a href="https://atlas.mitre.org/techniques/AML.T0024">Exfiltration via AI Inference API (AML.T0024)</a> in MITRE ATLAS.</p><p>You don&#8217;t need the math to get the point. The more queries an attacker can fire at your endpoint, the better their copy gets. If nothing caps the number of queries, nothing caps the quality of the clone. So the fix is simple: limit how many queries any one caller can send, and you limit how good a copy they can build. That&#8217;s what rate-limiting does, and it&#8217;s the main defense here.</p><h3>The Controls</h3><p>Protecting a model endpoint is mostly familiar network security pointed at a new target.</p><ul><li><p><strong>TLS 1.3 with mutual authentication (mTLS).</strong> Encrypt everything in transit, and use mTLS (both sides prove who they are with certificates, no passwords) for internal calls between your application services and the AI engines behind them.</p></li><li><p><strong>Micro-segmentation.</strong> Put the GPU clusters in their own Virtual Private Clouds, block direct inbound traffic, and force every query through an authenticated API gateway. This is the same network segmentation from Domain 4 you already know, pointed at compute instead of subnets.</p></li><li><p><strong>Rate-limiting and query baselining.</strong> Set a normal range for how a human interacts with the endpoint. When something blows past that range, the way an extraction attack has to, block it automatically. This is the direct counter to the model-theft problem above.</p></li></ul><h2>Identity and Access Management (Domain 5)</h2><p>Access control in an AI environment splits the same way it always has. Authentication asks, &#8220;Are you who you say you are?&#8221; Authorization asks, &#8220;Are you allowed to touch this model or this dataset?&#8221; The twist is that more and more of the things asking for access aren&#8217;t people.</p><h3>Least Privilege, Need-to-Know, and Just-in-Time Access</h3><p>The old principles still hold. They just apply to model weights and training jobs now.</p><ul><li><p><strong>Lock down the model registry.</strong> Treat read, write, and modify rights on model weights like you&#8217;d treat write access to production code, because that&#8217;s what they are. Only your automated build tools should be able to promote a model. People shouldn&#8217;t be editing neural parameters by hand any more than they&#8217;d hand-edit a production binary.</p></li><li><p><strong>Just-in-time retraining access.</strong> Don&#8217;t hand engineers a standing permission to retrain. Make them request it when they need it, and revoke it automatically when the job finishes. This is the same just-in-time privilege you&#8217;d use for admin access, applied to the training pipeline.</p></li></ul><h3>Identity for Autonomous Agents</h3><p>Here&#8217;s where the familiar model starts to crack. AI workflows are moving toward autonomous agents: software that queries databases, calls APIs, and takes actions on an employee&#8217;s behalf without a human in the loop for each step. User-based identity wasn&#8217;t built for that.</p><ul><li><p><strong>Give every agent its own identity.</strong> Each autonomous agent needs a unique cryptographic machine identity (a service account or OAuth client credentials of its own). Without it, you can&#8217;t prove which agent did what, and non-repudiation falls apart the moment something goes wrong.<a href="https://www.bankinfosecurity.asia/blogs/zero-trust-for-age-autonomous-ai-agents-part-2-p-4040">[5]</a></p></li><li><p><strong>Use ABAC, not just RBAC.</strong> Role-Based Access Control checks who you are, like a badge at a door. Attribute-Based Access Control checks who you are <em>and</em> what you&#8217;re doing, what you&#8217;re touching, where the request came from, and how risky it looks right now, all before it says yes (<a href="https://csrc.nist.gov/pubs/sp/800/162/upd2/final">NIST SP 800-162</a> is the canonical definition). For an agent whose job changes minute to minute, the badge alone isn&#8217;t enough.</p></li></ul><h2>Security Assessment and Testing (Domain 6)</h2><p>Your existing tools have a blind spot here. A vulnerability scanner reads code. A static analyzer reads code. Neither one can tell you that your model will happily ignore its own safety rules when a user phrases the request the right way. There&#8217;s no buggy line of code to find. The weakness lies in how the model handles language, so the only way to catch it is to deliberately attack it with words.</p><h3>The AI Red Teaming Program</h3><p>AI red teaming is testing a live model the way an attacker would, hunting for inputs that cause it to misbehave or reveal what it shouldn&#8217;t. According to a <a href="https://www.nist.gov/news-events/news/2026/06/nist-mathematical-proof-supports-transition-continuous-monitor-and-update">recent NIST post</a>, you can&#8217;t lock a model down once and walk away. NIST senior scientist Apostol Vassilev published a 2026 proof that no finite set of guardrails is universally robust against adversarial prompts, and his takeaway, in a sentence, is the case for red teaming: &#8220;You have to commit to a constant search for weaknesses and stay ahead of attackers.&#8221; It&#8217;s an offensive mindset aimed at a system that traditional testing treats as a black box.</p><p>Red teaming goes after three main things. <em>Model hijacking</em> is taking control of how the model behaves, bending its outputs, or repurposing it for something it was never meant to do. <em>Model extraction</em>, the theft attack from Domain 4 above, reverse-engineers the model itself. <em>Prompt injection</em> abuses the input channel to override the system prompt and the rules baked into it. A good program probes for all three.</p><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/6ol1i/1/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b6d99eba-c452-4830-b690-006ba4225cc4_1220x738.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6adc37b-a4a4-45a5-b5e7-25fc55632fcf_1220x738.png&quot;,&quot;height&quot;:375,&quot;title&quot;:&quot;Created with Datawrapper&quot;,&quot;description&quot;:&quot;&quot;,&quot;belowTheFold&quot;:true}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/6ol1i/1/" width="730" height="375" frameborder="0" scrolling="no" loading="lazy"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><p>Run it as a real program, not a one-off. AI red-teaming is one of the testing methodologies that NIST formally recommends in the Measure function of its <a href="https://www.nist.gov/itl/ai-risk-management-framework">Generative AI Profile (NIST AI 600-1)</a>, which also provides the Govern/Map/Measure/Manage structure for handling what you find. Document those findings in a central risk register and fix things in the order that business impact dictates, not the order you found them in.</p><h2>Security Operations (Domain 7)</h2><p>Your SOC can&#8217;t defend what it can&#8217;t see, and a live AI system generates a kind of traffic the SOC has never had to watch before: prompts going in, generated responses coming out, agents acting on their own. Domain 7 is about getting eyes on it all.</p><h3>The Defensive Tooling Got an Upgrade Too</h3><p>The same AI that opened new attack surfaces is now built into the tools that defend them. In four categories of security tooling, AI was once an optional add-on. Now it comes built in, and it&#8217;s worth knowing what each one does:</p><ul><li><p><strong>SIEM</strong> aggregates and correlates logs. The AI layer spots anomalies across event streams and reduces alert fatigue by separating real signals from the noise.</p></li><li><p><strong>SOAR</strong> automates the response once a threat is detected. Agentic AI is what&#8217;s driving it now: systems that take defined actions without waiting for a human to push the button.</p></li><li><p><strong>XDR</strong> ties detection together across endpoints, networks, clouds, and apps. The AI connects dots across data sources that no human could correlate by hand at that volume.</p></li><li><p><strong>UEBA</strong> monitors behavior and flags deviations from a baseline for users and service accounts alike. It catches the slow compromise that never trips a single alarm, the drift that signature-based detection sleeps right through.</p></li></ul><p>These extend your existing Domain 7 controls; they don&#8217;t replace them. For the exam, know what each one does and where AI augments the analyst rather than replaces their judgment. UEBA is the answer worth memorizing: it&#8217;s the canonical &#8220;anomaly over time&#8221; pick when a scenario rules out signature-based detection.</p><h3>Watching What Goes Out: Continuous Monitoring and DLP</h3><p>The everyday risk here isn&#8217;t an attacker. It&#8217;s a well-meaning employee pasting source code or customer PII into a public chatbot. This already happened at Samsung: within weeks of allowing ChatGPT, engineers leaked semiconductor source code and internal meeting notes into it three separate times, and the company banned the tool outright (<a href="https://www.techradar.com/news/samsung-workers-leaked-company-secrets-by-using-chatgpt">TechRadar, 2023</a>).</p><ul><li><p><strong>Inline DLP and CASB.</strong> Put Data Loss Prevention gateways and Cloud Access Security Brokers (a CASB sits between your users and the cloud service, inspecting what crosses) in line with outbound prompts. When sensitive strings show up, a credit card number, an internal code header, the payload gets blocked or tokenized before it leaves the building.</p></li><li><p><strong>Semantic logging.</strong> Normal logs record events: who logged in, what ran. AI auditing needs more than that. Record the actual prompt strings and the model&#8217;s responses, then run automated analysis over them to flag data leakage, social engineering, or an attack in progress. You&#8217;re logging meaning, not just events.</p></li></ul><h3>Watching the Model Itself: Model Drift</h3><p>Even with no attacker anywhere near it, an AI model gets worse over time. Picture a guard dog trained on last year&#8217;s burglars. The burglars changed their methods. The dog didn&#8217;t. On paper, it&#8217;s the same deterrent. On the street, they are less effective. That&#8217;s model drift: production data slowly stops looking like the training data, and accuracy bleeds away. A threat-detection model trained on old attack patterns gets weaker every time attackers change their tactics.</p><p>For Domain 7, drift is a continuous-monitoring problem with three parts:</p><ul><li><p><strong>Detection.</strong> Compare live performance against your baseline numbers (accuracy, precision, recall, false-positive rate). A statistically real drop triggers a look.</p></li><li><p><strong>Indicators.</strong> Shifts in the input feature distribution, a sudden change in the confidence-score histogram, rising false positives, and outputs drifting away from ground truth (when you have it) all point the same way.</p></li><li><p><strong>Response.</strong> Decide your retraining trigger in advance. Some teams retrain on a schedule, others when drift crosses a threshold. Either works, as long as it&#8217;s a written playbook and not a judgment call made in a panic.</p></li></ul><p>Drift is the quiet sibling of data poisoning. Poisoning corrupts the model on purpose. Drift happens because the world moved on. Both give you wrong answers, both need monitoring, and both live in the Domain 7 playbook.</p><h3>When It Breaks: Incident Response</h3><p>Your IR plan needs a few AI-specific moves.</p><ul><li><p><strong>Model quarantine.</strong> Write the playbook for isolating a model you think has been poisoned. The moment it&#8217;s suspect, pull the container offline and route inference to a clean cold-standby copy. Treat it like isolating any other compromised host, just faster, because the model keeps answering until you stop it.</p></li><li><p><strong>Automated guardrails.</strong> Put rule-based limits around the inference API that act as a circuit breaker. When an output looks wrong in shape or content, the guardrail catches it before it ever reaches the user.</p></li></ul><h2>The Part That Stays Human: Context and Critique</h2><p>There&#8217;s one risk in this whole series that no control in any domain can fix for you. AI is taking over the routine middle of knowledge work, the everyday analysis that used to be how people built their expertise in the first place. As it takes that work over, people stop checking its output. And when you stop checking the machine&#8217;s work, you slowly stop understanding it. The skill hollows out from the inside. This isn&#8217;t a hunch. Human-factors research has documented &#8220;automation complacency&#8221; for years: when a system is usually right, people stop scrutinizing it, miss its failures, and the effect hits experts as well as novices and doesn&#8217;t wash out with practice (<a href="https://journals.sagepub.com/doi/10.1177/0018720810376055">Parasuraman &amp; Manzey, </a><em><a href="https://journals.sagepub.com/doi/10.1177/0018720810376055">Human Factors</a></em><a href="https://journals.sagepub.com/doi/10.1177/0018720810376055">, 2010</a>).</p><p>That&#8217;s a security problem, not just a career one. A tool can&#8217;t be held accountable in a courtroom or an audit. You can. So the human has to stay in the loop on purpose, through a discipline we can call the Context and Critique Rule. It adds a little friction back in, on purpose, in three steps:</p><ul><li><p><strong>Evidence.</strong> Treat every AI output as raw, unverified data. Not an answer yet.</p></li><li><p><strong>Cognition.</strong> Check it against what you actually know: the business rules, the compliance lines, the security frameworks in your head.</p></li><li><p><strong>Discernment.</strong> Take the &#8220;Human Pause.&#8221; Stop, think, and decide. Because the liability falls on you no matter what the model says, you sign off on accuracy and security before anything moves forward.</p></li></ul><p>The shift this series has been building toward is from doing the work to directing it. As a professional, you&#8217;re more valuable the better you understand and orchestrate these systems. The technology is a tool. It isn&#8217;t a teammate, and it can&#8217;t carry the blame when something breaks.</p><h2>Pulling the Series Together</h2><p>Across four parts, the throughline has been the same: AI doesn&#8217;t get its own CISSP domain, it lands in all of them, and the controls you already know mostly still apply once you see where they point. To put it in one map:</p><ol><li><p><strong>Secure the pipeline (Domain 3).</strong> Isolated, multi-tier MLOps architecture with cryptographic checks on datasets and model weights.</p></li><li><p><strong>Protect the weights in use (Domain 3 &amp; 8).</strong> Confidential Computing enclaves and polyinstantiation (separate, isolated copies so one tenant can never read another&#8217;s data) to keep model weights safe while they&#8217;re running.</p></li><li><p><strong>Lock the interfaces (Domain 4).</strong> TLS 1.3, VPC micro-segmentation, and rate-limiting against model extraction.</p></li><li><p><strong>Tighten access (Domain 5).</strong> Least privilege and need-to-know on the registries and training jobs, with ABAC for anything autonomous.</p></li><li><p><strong>Verify continuously (Domain 6 &amp; 7).</strong> A real AI red teaming program alongside semantic monitoring, inline DLP, and automated output guardrails.</p></li><li><p><strong>Keep the human in charge.</strong> The Context and Critique Rule and the Human Pause, on every team.</p></li></ol><p>Get the first five right, and you&#8217;ve got a defensible AI security posture. Get the sixth right, and you&#8217;ve got people who can still tell when the first five have failed. That last one is the whole point. Every other control in this series protects the system. This one protects your ability to know whether the system is lying to you.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The AI Paradigm Shift: Architecture, Pipelines, and Secure Development in CISSP Domains 3 & 8]]></title><description><![CDATA[The Cyber Leader - Balanced Security is a reader-supported publication.]]></description><link>https://blog.balancedsec.com/p/the-ai-paradigm-shift-architecture</link><guid isPermaLink="false">https://blog.balancedsec.com/p/the-ai-paradigm-shift-architecture</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 19 Jun 2026 13:03:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EnYx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EnYx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EnYx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png 424w, https://substackcdn.com/image/fetch/$s_!EnYx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png 848w, https://substackcdn.com/image/fetch/$s_!EnYx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png 1272w, https://substackcdn.com/image/fetch/$s_!EnYx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EnYx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53fde8d0-af78-451a-803f-8152af999091_2048x1124.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3548882,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/202493613?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EnYx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png 424w, https://substackcdn.com/image/fetch/$s_!EnYx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png 848w, https://substackcdn.com/image/fetch/$s_!EnYx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png 1272w, https://substackcdn.com/image/fetch/$s_!EnYx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53fde8d0-af78-451a-803f-8152af999091_2048x1124.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Introduction</h2><p><a href="https://blog.balancedsec.com/p/the-ai-paradigm-shift-asset-security?r=1k08iw">Part 2</a> was about the assets: naming them, classifying them, protecting them. This article is about the machinery that produces and runs them, and it sits in two CISSP domains. Domain 3 (Security Architecture and Engineering) is where you design how a model gets built so it can&#8217;t be quietly corrupted. Domain 8 (Software Development Security) is where you keep the software, external components, and model files themselves from being used to carry an attack into production.</p><p>You don&#8217;t need to be a developer to follow this. The goal is to recognize a new category of risk and know which kind of control answers it. Here&#8217;s why it&#8217;s new: these attacks don&#8217;t trip the tools you already run. A firewall doesn&#8217;t catch a tampered training record. A vulnerability scanner doesn&#8217;t flag an input that looks perfectly normal but makes the model misbehave. And a model file you download can run hidden commands on your system the moment a program opens it. Ordinary security reviews miss all three, which is why they must be built into the architecture and the build.</p><p>A quick definition carried over from Part 2 that we&#8217;ll lean on: a model&#8217;s <strong>weights</strong> are the numbers it learned during training. They are the model&#8217;s &#8220;brain,&#8221; and the file that holds them is the asset everything below is trying to protect or abuse.</p><h2>Building the model safely (Domain 3)</h2><p>Ordinary software is predictable. The same input gives the same output every time. A model is different. It is built by feeding it large amounts of data and letting it learn patterns, so whatever goes into that training quietly shapes how it behaves later. That one fact, a model is only as trustworthy as the data and the process that produced it, is the heart of Domain 3 for AI.</p><p>Think of building a model as an assembly line with a few stages: collect the data, clean it, train the model, test it, and release it. The security goal is to keep those stages separate and under control so that a problem at one stage can&#8217;t slip downstream unnoticed. The controls map to things a CISSP already knows:</p><ul><li><p><strong>Keep data collection walled off from training.</strong> The systems that pull in external data reside on their own network segment, so untrusted material never sits alongside the model being built. This is network segmentation applied to the assembly line.</p></li><li><p><strong>Check data before it is used.</strong> Incoming data is validated against what you expect, and anything malformed or out of place is rejected rather than trained on. This is input validation.</p></li><li><p><strong>Lock down the finished models.</strong> Store completed models where they can&#8217;t be quietly swapped or altered, and digitally sign each one so you can prove you&#8217;re running the version you approved. This is integrity and change control.</p></li></ul><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/BlFFN/3/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68939480-2f14-46ab-9319-37b951efe4f3_1220x742.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dca837d1-8c63-4821-b1a7-cae9b918a66c_1220x742.png&quot;,&quot;height&quot;:327,&quot;title&quot;:&quot;Created with Datawrapper&quot;,&quot;description&quot;:&quot;&quot;,&quot;belowTheFold&quot;:true}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/BlFFN/3/" width="730" height="327" frameborder="0" scrolling="no" loading="lazy"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><p>If you want the authoritative catalog of how these attacks actually play out, <a href="https://blog.balancedsec.com/p/mitre-atlas-the-ai-threat-framework?r=1k08iw">MITRE ATLAS</a> is the one to know. It documents real-world attacks on AI systems and is the AI counterpart to the MITRE ATT&amp;CK framework your SOC analysts already use.</p><h2>Attacks that target the model, not the network</h2><p>The next two attacks don&#8217;t break in through a port or a credential. They corrupt how the model learns, or they manipulate what it sees when it runs, and both slip past firewalls and signature-based detection because there is nothing obviously malicious to catch.</p><h3>Poisoning: corrupting what the model learns</h3><p>Poisoning is tampering with the data a model is trained on. An attacker slips bad records into the training data so the model learns the wrong lesson. The most concerning version is a <strong>backdoor</strong>: with a small number of planted examples, the model behaves normally almost all the time but flips to an attacker-chosen behavior whenever a specific secret trigger appears in the input.</p><p>This is not just an image-recognition problem. Many organizations take a ready-made model and adjust it on their own examples (this is &#8220;fine-tuning,&#8221; from Part 2). If that example data is poisoned, the trigger goes in with it. Systems that answer questions by first looking up your internal documents, often called retrieval-augmented generation, have their own version: poison the documents being searched, and you change the model&#8217;s answers without ever touching the model.</p><p>The defenses are about provenance (knowing where data came from) and inspection:</p><ul><li><p><strong>Chain of custody for training data.</strong> Track and verify where every batch of data came from. &#8220;We scraped it from the web&#8221; is not provenance.</p></li><li><p><strong>Screening before use.</strong> Statistical checks flag records that look nothing like the rest of the set, so they can be pulled before training.</p></li><li><p><strong>Trimming influence.</strong> Periodically remove records that carry an outsized effect on the model, which limits what a small poisoned batch can do.</p></li></ul><h3>Evasion: fooling the model at the moment it runs</h3><p>Evasion happens when the system is live. The attacker crafts an input that looks ordinary to a person but pushes the model to the wrong answer. The classic example is a stop sign with a few carefully placed stickers that a self-driving car&#8217;s vision system reads as &#8220;Speed Limit 45,&#8221; a real safety failure.</p><p>For the language models most organizations are adopting, this same idea has a name you&#8217;ve already met: <strong>prompt injection</strong>. A cleverly worded input that doesn&#8217;t look like an attack talks the model into ignoring its instructions, and it sits high on the <a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/">OWASP Top 10 for LLM Applications</a> (LLM01 in the core list). <a href="https://blog.balancedsec.com/p/the-ai-paradigm-shift-governance?r=1k08iw">Part 1</a> introduced it as a concept. In Domain 3, it becomes an architecture problem: you have to assume some inputs are hostile and design the system so that a model that gets fooled can&#8217;t do much damage.</p><p>The defenses sit on both sides of the model:</p><ul><li><p><strong>Screen inputs and outputs.</strong> Treat every prompt as untrusted, and check the model&#8217;s responses before anything acts on them. Open-source guardrail tools (such as Protect AI&#8217;s <a href="https://github.com/protectai/llm-guard">llm-guard</a>) do exactly this, watching for injection attempts, leaked secrets, and unsafe output.</p></li><li><p><strong>Train it to resist.</strong> Deliberately train the model on tricky and manipulated inputs so it holds up better against them.</p></li><li><p><strong>Limit the blast radius.</strong> The fewer systems and permissions the model can reach, the less a successful trick is worth. Part 4 returns to this.</p></li></ul><p>For the full map of these threats and their controls, the <a href="https://owaspai.org/docs/ai_security_overview/">OWASP AI Exchange</a> is the deeper reference.</p><h2>Securing the software and the model files (Domain 8)</h2><p>Domain 8 is where AI development meets the software supply-chain security you already know, with one twist that surprises people: an AI model file can be a program in disguise.</p><h3>When a model file is really a program</h3><p>You&#8217;d reasonably assume a saved model is just data, a big set of numbers. The catch is that the industry&#8217;s most common method for saving models (Python&#8217;s Pickle serialization (.pkl or .pt) allows arbitrary code to be tucked inside the file. When the wrong tool opens it, those instructions run automatically on your computer. So a model downloaded from a public sharing site can carry an attack, and loading it is like running a program handed to you by a stranger.</p><p>Three controls address this:</p><ul><li><p><strong>Scan a model before you open it.</strong> Tools such as Protect AI&#8217;s <a href="https://github.com/protectai/modelscan">ModelScan</a> and <a href="https://protectai.com/guardian">Guardian</a> inspect a model file for hidden malicious instructions before any program loads it.</p></li><li><p><strong>Prefer the safer file format.</strong> A newer format called <code>safetensors</code> stores only the numbers and has no way to carry instructions, so it can&#8217;t run anything when opened. Favor it over the older formats.</p></li><li><p><strong>Only accept models from sources you trust,</strong> confirmed by a valid digital signature, the same way you&#8217;d treat any other software you bring into the environment.</p></li></ul><h3>Know what&#8217;s in your software (supply chain)</h3><p>AI applications are built on large toolkits and pre-trained models created by others, and any of those outside components can be a way in. The control is the one you already apply to software: keep an inventory. A <strong>Software Bill of Materials (SBOM)</strong> lists every component you depend on. Extend that idea to AI by tracking the models and datasets too, sometimes called an AI Bill of Materials, and scan those dependencies continuously for known weaknesses.</p><h3>Run a new model as if it can&#8217;t be trusted</h3><p>Until a downloaded model has been scanned and cleared, treat it like untrusted software. Run it in an isolated container with the least access it needs, so even a malicious model can&#8217;t reach the rest of the system. And while the model&#8217;s weights are loaded in memory and used, protect them with the hardware-based enclaves described in Part 2 (Confidential Computing), which keep the data readable only within a protected boundary.</p><h3>Keep tenants apart (polyinstantiation)</h3><p>When a single model or data store serves multiple customers or classification levels, a lower-privilege user can sometimes infer sensitive details about another user from the shared state. <strong>Polyinstantiation</strong> is the classic Domain 3 database control: it involves creating multiple versions of the same data object based on classification levels. In AI, this means giving different classification levels or tenants their own distinct instances of models or data stores, ensuring a lower-privilege user cannot infer sensitive training data from a shared model state.</p><h2>In the next article</h2><p>The pipeline is built, and the model is defended. Part 4 moves to running it in production: Domains 4 through 7, where network controls, identity and access for both people and machine accounts, red-team testing, and day-to-day security operations keep the deployed system in check, and where the AI-powered tools in your own SOC start working for you.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The AI Paradigm Shift: Asset Security and Where AI Meets Your Data in CISSP Domain 2]]></title><description><![CDATA[Intro The first article in this series covered Domain 1: governance, policy, and the risk structures that decide who&#8217;s accountable for AI.]]></description><link>https://blog.balancedsec.com/p/the-ai-paradigm-shift-asset-security</link><guid isPermaLink="false">https://blog.balancedsec.com/p/the-ai-paradigm-shift-asset-security</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 12 Jun 2026 13:02:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!deeb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!deeb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!deeb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!deeb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!deeb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!deeb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!deeb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20835,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/201651867?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!deeb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!deeb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!deeb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!deeb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edb5d2-169a-4db6-a32e-636ec9bc54de_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Intro</h2><p>The first article in this series covered Domain 1: governance, policy, and the risk structures that decide who&#8217;s accountable for AI. That&#8217;s the part where you write the rules. Domain 2 is where the rules meet the assets.</p><p>Asset Security is about the things you actually own. You can&#8217;t protect an asset you haven&#8217;t named; you can&#8217;t apply the right control until you know how sensitive it is, and you can&#8217;t claim it&#8217;s destroyed unless you can prove it. AI doesn&#8217;t change that logic. It changes the inventory. Training datasets, prompt histories, fine-tuning inputs, and model weights are now corporate assets that carry real value and real exposure, and likely postdate many asset registers. Fine-tuning inputs are the proprietary examples a company supplies to adapt a pre-trained model to its own work, the tagged support transcripts or annotated documents that teach a general model a specific domain.</p><p>ISC2&#8217;s <em>Exam Guidance for Artificial Intelligence</em> (April 2, 2026) points in the same direction. The guidance maps AI security into the existing eight domains, and for Domain 2, that means extending the asset-security work you already do to this new inventory. Part 1 walked through the mapping. (See <a href="https://blog.balancedsec.com/p/ai-security-for-the-cissp-whats-changed">AI Security for the CISSP: What&#8217;s Changed</a>.)</p><p>Here&#8217;s the shift in one line.</p><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/6GzvZ/1/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e7dfc94-4af8-43cf-95bc-e5b6a7603f46_1220x562.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3b26d21-b69b-44fe-ac84-dd8a24c43868_1220x632.png&quot;,&quot;height&quot;:288,&quot;title&quot;:&quot;Shift Summary&quot;,&quot;description&quot;:&quot;&quot;,&quot;belowTheFold&quot;:false}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/6GzvZ/1/" width="730" height="288" frameborder="0" scrolling="no"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><h2>Classifying AI Assets</h2><p>You can&#8217;t protect what you can&#8217;t see. Classic asset security grew up around structured databases, physical media, and discrete files, things with an obvious shape and an obvious owner. AI assets break that mold, and the value sits in unexpected places.</p><p>Foundation models are commoditizing fast. Capable base models are cheap or free to get, many with downloadable (open) weights, so the base model itself is rarely where a company&#8217;s advantage lives. That advantage sits in the data you fed the model and the resulting weights. If a competitor walks off with your refined training set or your final model weights, the damage is immediate, because they get the full benefit of your work without paying to build it.</p><p>That leads to the rule to anchor on, whether you&#8217;re studying or doing the work: classify AI assets by the impact of their compromise, not by their file format or where they happen to sit. A 4 GB weights file and a spreadsheet look the same to a storage system. They&#8217;re nowhere close in value.</p><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/tVqk3/1/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a5f9bd7d-0219-4435-b22a-bc68e32045ec_1220x1026.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff1d56c6-d34a-4069-ad30-c71e87c1e7f5_1220x1026.png&quot;,&quot;height&quot;:519,&quot;title&quot;:&quot;Created with Datawrapper&quot;,&quot;description&quot;:&quot;&quot;,&quot;belowTheFold&quot;:true}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/tVqk3/1/" width="730" height="519" frameborder="0" scrolling="no" loading="lazy"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><p>One complication: AI assets are hard to value precisely. A model&#8217;s capabilities can emerge during training in ways the team didn&#8217;t plan for, so a standard benchmark won&#8217;t always tell you what the thing is really worth, or what you&#8217;d actually lose. When the value is fuzzy, classify for the downside. Ask what a competitor or a regulator could do with the asset if it walked, and price the protection against that.</p><h2>Who Owns What: Data Roles in an AI Pipeline</h2><p>Most asset-security failures in AI aren&#8217;t exotic. They come from blurred roles. In a machine learning pipeline, the people who own the data, the people who run the infrastructure, and the systems that process the records all start to overlap, and accountability quietly evaporates. Keeping these roles straight matters as much in production as it does in study.</p><ul><li><p><strong>Data Owner.</strong> A senior leader, accountable for the asset. The Owner sets the classification, approves access, and authorizes any corporate data going into a training pipeline. Accountability stops here and can&#8217;t be handed off to a technician.</p></li><li><p><strong>Data Custodian.</strong> The technical role that implements what the Owner approved: backups, encryption keys, access lists, the hosting environment.</p></li><li><p><strong>Data Controller.</strong> A privacy role under GDPR. The Controller decides the purpose and lawful basis for processing personal data and makes sure training inputs comply with privacy law.</p></li><li><p><strong>Data Processor.</strong> Processes personal data only on the Controller&#8217;s instructions. A third-party AI summarization or translation API is the textbook example.</p></li><li><p><strong>Data Subject.</strong> The person whose data is being processed or trained on.</p></li><li><p><strong>User.</strong> The employee who actually operates the system to get work done.</p></li></ul><p>It almost always plays out the same way. A data scientist or DBA, acting as a Custodian, uploads a corporate dataset to a public AI service to get a quick result, and nobody cleared it with the Owner. Outside the company&#8217;s control, that service might store the data, keep it indefinitely, or train its models on it, and any of those outcomes leaks intellectual property and creates third-party privacy risk. Only the Owner has the authority to accept that risk, and a Custodian who makes the call alone has broken the asset-security policy. The GDPR definitions of <a href="https://www.edpb.europa.eu/system/files/2023-10/EDPB_guidelines_202007_controllerprocessor_final_en.pdf">controller and processor</a> exist to keep exactly that line from blurring.</p><p>The fix is administrative, not technical. Separation of duties so the engineers who train models can&#8217;t also push them to production or rewrite access controls. Job rotation and mandatory vacations so quiet tampering, poisoned data, or unauthorized parameter changes have a chance to surface.</p><h2>Protecting Data in Three States</h2><p>Every asset lives in one of three states, and each one needs a different control. Apply the wrong one, and you either leave a hole or break the system.</p>
      <p>
          <a href="https://blog.balancedsec.com/p/the-ai-paradigm-shift-asset-security">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Start Here: AI Security, CISSP, and Building Security Capability]]></title><description><![CDATA[Welcome.]]></description><link>https://blog.balancedsec.com/p/start-here-ai-security-cissp-and</link><guid isPermaLink="false">https://blog.balancedsec.com/p/start-here-ai-security-cissp-and</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Sun, 07 Jun 2026 23:14:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oDGi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome.</p><p>I&#8217;m Jeff Moore, a security practitioner, educator, and builder. Over the last 25+ years, I&#8217;ve worked across technology and security leadership roles, and today I write about security architecture, AI security, risk management, certification preparation, and the practical realities of defending modern systems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oDGi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oDGi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!oDGi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!oDGi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!oDGi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oDGi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29360,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/200928417?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oDGi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!oDGi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!oDGi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!oDGi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d520e5e-36d3-4bc3-a06e-583cc0af59c9_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>People typically subscribe for one of three reasons:</p><h2><strong>Path 1: You&#8217;re Studying for CISSP</strong></h2><p>If you&#8217;re preparing for the CISSP exam, start here.</p><p>You&#8217;ll find content on:</p><ul><li><p>CISSP study strategies</p></li><li><p>Domain-specific guidance</p></li><li><p>Practice questions and exam preparation</p></li><li><p>Security architecture fundamentals</p></li><li><p>Common mistakes candidates make</p></li></ul><p>Recommended reading:</p><ul><li><p><a href="https://blog.balancedsec.com/p/how-difficult-is-the-cissp-exam?r=1k08iw">How difficult is the CISSP exam?</a></p></li><li><p><a href="https://blog.balancedsec.com/p/strategy-guide-for-answering-difficult?r=1k08iw">Strategy Guide for Answering Difficult Questions</a></p></li><li><p><a href="https://blog.balancedsec.com/p/ai-security-for-the-cissp-whats-changed?r=1k08iw">AI Security for the CISSP: What&#8217;s Changed and How to Prepare</a></p></li><li><p><a href="https://blog.balancedsec.com/p/cissp-cbk-explainer?r=1k08iw">CISSP CBK Explainer</a></p></li><li><p><a href="https://blog.balancedsec.com/p/security-control-frameworks-explained?r=1k08iw">Security Control Frameworks Explained</a></p></li></ul><h2><strong>Path 2: You&#8217;re Already a Security Professional</strong></h2><p>Many readers already hold certifications and work in security, engineering, architecture, governance, risk, compliance, or leadership roles.</p><p>Topics include:</p><ul><li><p>Security architecture and governance in the age of AI</p></li><li><p>Cloud security</p></li><li><p>Risk management</p></li><li><p>Security leadership</p></li><li><p>AppSec and  development</p></li><li><p>Security Credentials</p></li></ul><p>Recommended reading:</p><ul><li><p><a href="https://blog.balancedsec.com/p/strap-in-with-harness-engineering">Strap In (with harness engineering)</a></p></li><li><p><a href="https://blog.balancedsec.com/p/mitre-atlas-the-ai-threat-framework">MITRE ATLAS: The AI Threat Framework Every Security Leader Needs to Know</a></p></li><li><p><a href="https://blog.balancedsec.com/p/isacas-aaism-the-first-ai-security">ISACA&#8217;s AAISM: The First AI Security Management Certification, Examined</a></p></li><li><p><a href="https://blog.balancedsec.com/p/the-cissp-holders-guide-to-ai-security">The CISSP Holder&#8217;s Guide to AI Security Credentials</a></p></li><li><p><a href="https://blog.balancedsec.com/p/original-inside-the-nist-ai-risk">Inside the NIST AI Risk Management Framework</a></p><p></p></li></ul><h2><strong>Path 3: You&#8217;re Exploring Security</strong></h2><p>AI is rapidly changing how organizations build, operate, and defend systems.</p><p>Here you&#8217;ll find content covering:</p><ul><li><p>Overviews of specific security topics, including governance and risk management</p></li><li><p>Security &amp; risk management frameworks</p></li><li><p>Security implications of AI adoption (including AI-driven dev, supply chain, and model security)</p></li></ul><p>Recommended reading:</p><ul><li><p><a href="https://blog.balancedsec.com/p/guide-to-security-governance?r=1k08iw">Guide to Security Governance</a></p></li><li><p><a href="https://blog.balancedsec.com/p/nist-ai-rmf-or-iso-42001?r=1k08iw">NIST AI RMF or ISO 42001?</a></p></li><li><p><a href="https://blog.balancedsec.com/p/six-things-adversaries-are-doing">Six Things Adversaries Are Doing With AI</a></p></li><li><p><a href="https://blog.balancedsec.com/p/original-inside-the-nist-ai-risk?r=1k08iw">Inside the NIST AI Risk Management Framework</a></p></li><li><p><a href="https://blog.balancedsec.com/p/exploring-claude-code-and-ai-driven?r=1k08iw">Exploring Claude Code and AI-Driven Development</a></p></li></ul><h2><strong>What I&#8217;m Building</strong></h2><p>In addition to writing, I&#8217;m currently building the Academy, an AI-powered learning platform for CISSP candidates and security professionals.</p><p>As founding members, participants receive access to my new CISSP book, available exclusively on the platform as an interactive learning experience.</p><p>You&#8217;ll also receive 30 days of Pro access and an opportunity to help shape the platform through direct feedback.</p><p>If that sounds interesting, learn more <a href="https://academy.balancedsec.com/">here</a>.</p><h2><strong>Say Hello</strong></h2><p>One thing I enjoy most about this platform is meeting other people in the field.</p><p>Hit reply and tell me:</p><ul><li><p>What brought you here</p></li><li><p>What you do</p></li><li><p>What you&#8217;re working on</p></li><li><p>What you&#8217;d like to learn next</p></li></ul><p>I read every response.</p>]]></content:encoded></item><item><title><![CDATA[The AI Paradigm Shift: Governance, Risk, and the CISSP Domain 1]]></title><description><![CDATA[For decades, information security worked on a simple assumption: software is deterministic.]]></description><link>https://blog.balancedsec.com/p/the-ai-paradigm-shift-governance</link><guid isPermaLink="false">https://blog.balancedsec.com/p/the-ai-paradigm-shift-governance</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 05 Jun 2026 13:01:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!THs6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!THs6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!THs6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!THs6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!THs6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!THs6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!THs6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:52341,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/200687450?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!THs6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!THs6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!THs6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!THs6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83a807b-cfd0-4988-9ebf-507af1a74c6b_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>For decades, information security worked on a simple assumption: software is deterministic. Input parameter A into system B, and you&#8217;ll get result C every time, bounded by the strict logic a programmer wrote. Security controls (whether static code analysis, input validation, or access control matrices) were built around that predictability.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Artificial intelligence breaks that assumption.</p><p>Generative AI and autonomous agent architectures move enterprise systems into probabilistic, non-deterministic, and increasingly autonomous territory. ISC2 acknowledged this on April 2, 2026 by publishing <em>Exam Guidance for Artificial Intelligence</em>, which maps AI security topics across the eight existing CISSP domains. (For more on that guidance, see <a href="https://blog.balancedsec.com/p/ai-security-for-the-cissp-whats-changed">AI Security for the CISSP: What&#8217;s Changed</a>.)</p><p>This article, the first in a series, covers the Domain 1 material: foundational concepts, governance frameworks, and the administrative controls a CISSP candidate needs.</p><h2>Concept Coverage</h2><p>To evaluate AI risk on the exam (or in practice), you need the vocabulary. Questions may test whether you can place a specific risk at the right point in the system lifecycle.</p><h3>What is Generative AI?</h3><p>Generative AI or Gen AI is ubiquitous and you&#8217;ve probably been using many associated services for a couple of years. Gen AI refers to AI systems that create new content (text, images, code, audio) rather than just analyze existing data. Examples span many aspects of our digital lives: text (Claude, ChatGPT, Gemini), images (DALL-E, Stable Diffusion), video (Sora, Runway), music (Suno), voice synthesis (ElevenLabs), and code (Cursor). When a vendor says their platform is &#8220;powered by GenAI,&#8221; they mean it produces output, not just classifies or scores inputs.</p><h3>What is an AI Model?</h3><p>An AI model is a mathematical structure trained on a dataset to recognize patterns, make predictions, or generate outputs, without being explicitly programmed with step-by-step rules. After training, the model is the brain of the AI system. It holds everything the system &#8220;learned&#8221; as numbers (the weights and biases) that determine how it responds to any new input.</p><p>While traditional software uses code written by human developers to process inputs (<code>Input &#8594; Rules &#8594; Output</code>), an AI model uses statistical weights and biases derived from training data to produce its output (<code>Input &#8594; Statistical Weights &#8594; Output</code>).</p><h3>What is a Large Language Model (LLM)?</h3><p>A Large Language Model (LLM) is a specialized subset of generative AI built on a deep neural network architecture (specifically the Transformer architecture) that uses &#8220;self-attention&#8221; mechanisms to model relationships between words in a sequence.</p><p>LLMs are trained on internet-scale text to understand, summarize, translate, predict, and generate &#8220;human-like&#8221; language. The training data is measured in <em>tokens</em>: a token is what the model treats as a unit of text, usually a word or a piece of a word. Modern LLMs are trained on trillions of them.</p><h3>What is a Prompt?</h3><p>A prompt is everything you (or the system) hand to the AI on a single request. That includes the user&#8217;s question, any instructions the application has added behind the scenes, and any documents or chat history the model is pulling in. It&#8217;s also the only entry point an attacker has, which is the entire basis of prompt injection (see below).</p><h3>Training vs. Inference: The AI Lifecycle</h3><p>You need to distinguish the two operational phases of an AI model&#8217;s life:</p><ul><li><p><strong>Training</strong> is how the model gets built. The system shows the algorithm a big dataset over and over, and each pass nudges the weights and biases until the model gives the &#8220;right&#8221; answer often enough to ship. The dataset used is the <em>training data</em>, and if it&#8217;s biased, missing important cases, or just bad, the model can never outperform what it was shown.</p></li><li><p><strong>Inference</strong> is what the model does once it&#8217;s running. Every time someone asks a chatbot a question or a fraud detector scores a transaction, that&#8217;s inference: one run of the trained model. Almost everything a CISSP encounters in the enterprise is inference. Training is a much heavier, much rarer event.</p></li></ul><p>Each phase has a different attack surface and calls for different controls.</p><p><strong>The Training Phase (Development Lifecycle):</strong></p><ul><li><p>The Process<strong>:</strong> The algorithm is exposed to a training dataset and adjusts its internal parameters (weights and biases) until it can perform its target task.</p></li><li><p>Secure SDLC Focus<strong>:</strong> A sensitive supply-chain and development phase. The priority is the integrity of the training dataset.</p></li><li><p>Primary Threat<strong>:</strong> <em>Data poisoning</em>. If an attacker injects malicious or biased records into the training pool, they can permanently alter the model&#8217;s behavior or implant hidden backdoors.</p></li></ul><p><strong>The Inference Phase (Production Operations):</strong></p><ul><li><p>The Process<strong>:</strong> The trained model runs in production (API endpoint, web application, autonomous agent) and processes live inputs.</p></li><li><p>Operational Security Focus<strong>:</strong> The priority is validating inputs and sanitizing outputs.</p></li><li><p>Primary Threat<strong>:</strong> Prompt injection and model hijacking, where attackers manipulate live runtime inputs to execute unauthorized commands or bypass safety boundaries. Simon Willison <a href="https://simonwillison.net/2022/Sep/12/prompt-injection/">coined the term &#8220;prompt injection&#8221; in September 2022</a>. The Samsung ChatGPT IP-leak incident in April 2023 was its first widely-reported corporate consequence.</p></li></ul><h2>Why It&#8217;s Hard to Secure</h2><p>AI systems introduce three architectural properties that legacy security frameworks can&#8217;t fully manage:</p><h3>Non-Determinism</h3><p>Generative AI models don&#8217;t produce identical outputs for identical inputs. LLMs are the clearest example: each next token is picked from a probability distribution, so the same prompt can produce two slightly different answers on two different calls. Image, music, and video models work the same way. Traditional security testing depends on reproducibility: find a bug, baseline behavior, confirm a fix. <em>Non-determinism</em> breaks all three.</p><h3>The Black-Box Problem</h3><p>A trained neural network has millions or billions of internal parameters. Decisions emerge from those parameters all at once. There&#8217;s no sequence of if-then rules a human can follow. When a model denies a credit application or flags a transaction as fraud, no one can point to the specific reason. The model just produces an output.</p><p>In terms of the CISSP, that hits <em>Traceability</em>: the ability to verify, audit, and recreate why an action was taken. After an incident, reconstructing what the AI &#8220;saw&#8221; and &#8220;decided&#8221; requires specialized logging of the inputs that went in (prompts, retrieved documents, prior context) plus the outputs and confidence scores that came back. Without that logging, you can&#8217;t answer what every regulator, auditor, and exec will ask after an AI incident: &#8220;Why did it do that?&#8221;</p><h3>Hallucinations</h3><p>A <em>hallucination</em> is when a generative model confidently produces false information that looks plausible. The model generates output based on statistical patterns in its training data. There&#8217;s no internal step that checks whether that output is true. So it can invent names, citations, statistics, or quotes that don&#8217;t exist.</p><p>The CISSP implication is direct. AI outputs are unverified data. The professional who acts on them is the one who answers for it, in court and in the boardroom.</p><h2>Frameworks and Regulation</h2><p>Governments and standards bodies are still catching up to AI. Domain 1 expects you to know how the major frameworks fit into a compliance posture.</p><h3>Standardized Security Frameworks</h3><p><strong><a href="https://blog.balancedsec.com/p/original-inside-the-nist-ai-risk">NIST AI Risk Management Framework (AI RMF 1.0)</a></strong> is the most cited voluntary framework for structuring an AI security program. It organizes work into four core functions:</p><ul><li><p><strong>Govern:</strong> Establish a culture of risk management, policies, and organizational alignment.</p></li><li><p><strong>Map:</strong> Contextualize the AI system, identify boundaries, and map specific risks.</p></li><li><p><strong>Measure:</strong> Quantify, analyze, and track identified risks through empirical testing.</p></li><li><p><strong>Manage:</strong> Allocate resources to respond to mapped and measured risks dynamically.</p></li></ul><p>These aren&#8217;t sequential steps. Govern sits across the whole framework as the policy and accountability layer, while Map, Measure, and Manage form a continuous feedback loop on top of it. In practice, Govern is also the function organizations may underinvest in the most.</p><p>The 40-page framework gives you the principles. The companion NIST AI RMF Playbook is where the operational guidance lives. If you&#8217;re implementing rather than briefing, you need both. NIST has also published a Generative AI Profile (NIST AI 600-1) that applies the four functions to GenAI-specific risks like hallucinations, data exposure, and misuse.</p><p><strong><a href="https://www.iso.org/standard/81230.html">ISO/IEC 42001</a> (Artificial Intelligence Management System)</strong> is the certifiable counterpart to the NIST framework: a third-party-auditable management system that adds an outward-facing AI System Impact Assessment (consequences for external individuals and groups) on top of an ISO 27001-style structure. It also aligns with EU AI Act compliance expectations, which makes it the more useful choice for companies with European exposure. The <a href="https://blog.balancedsec.com/p/nist-ai-rmf-or-iso-42001">most common pattern</a> is to deploy NIST first to build taxonomy and lifecycle discipline, then layer ISO 42001 on top for external attestation. The common failure mode is starting both at once and finishing neither.</p><h3>Global AI Regulation</h3><p>CISSPs don&#8217;t need to be lawyers, but you do need to understand regulatory risk. The most prominent example is the <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj">EU AI Act</a>, which classifies AI systems by risk tier:</p><ul><li><p><strong>Unacceptable Risk:</strong> Systems that threaten human safety or rights (e.g., government social scoring) are banned outright.</p></li><li><p><strong>High Risk:</strong> Systems used in critical infrastructure, medical devices, or employment. These require pre-market assessments, logging, and human-in-the-loop oversight.</p></li><li><p><strong>Limited Risk (Specific Transparency):</strong> Chatbots, deepfakes. Users have to be told they&#8217;re interacting with AI.</p></li><li><p><strong>Minimal/No Risk:</strong> Spam filters, video games. No additional regulatory intervention required.</p></li></ul><p>The Act reaches beyond the EU. <a href="https://artificialintelligenceact.eu/article/2/">Article 2</a> says it applies to anyone selling an AI system into the EU, anyone using one inside the EU, and any company anywhere whose AI outputs end up being used in the EU. If you have European customers, you&#8217;re in scope no matter where you&#8217;re headquartered.</p><h2>Data, Bias, and Ethics</h2><p>AI security still depends on the CIA triad, but integrity grows to include Data Quality and AI Ethics.</p><h3>Data Quality (Garbage In, Garbage Out)</h3><p>If the training dataset is poisoned, incomplete, or fundamentally skewed, the model&#8217;s outputs will be flawed, and the integrity of every downstream corporate decision goes with them. Security leaders need to vet data pipelines for accuracy, representativeness, and absence of tampering.</p><h3>AI Ethics &amp; Societal Adaptation</h3><p>Ethics on the CISSP exam comes back to the <a href="https://www.isc2.org/Ethics">ISC2 Code of Ethics</a> (act honorably, protect society). In an AI context, that translates to:</p><ul><li><p><strong>Fairness:</strong> Algorithmic decisions shouldn&#8217;t exhibit systemic bias against protected groups.</p></li><li><p><strong>Transparency:</strong> Stakeholders should be able to understand how a model reaches its conclusions.</p></li><li><p><strong>Human Oversight:</strong> Critical actions, especially those affecting livelihoods, physical safety, or financial assets, need human validation rather than fully automated execution.</p></li></ul><h3>The Disinformation Suite: Deepfakes and Automated Misinformation</h3><p>Two non-technical AI threats sit squarely in Domain 1&#8217;s governance and societal-adaptation area. Deepfakes (AI-generated voice, image, or video impersonations) are now used in executive-targeting fraud and social engineering, blurring the line between identity verification and content verification. Automated misinformation campaigns use generative AI to produce false content at industrial scale and distribution speed, complicating brand defense, election integrity, and customer trust. Both call for governance responses (executive verification protocols, public-communications playbooks, third-party content-authenticity standards) rather than purely technical ones, which is why they belong in a Domain 1 risk conversation, not a firewall ruleset.</p><h2>Building the Program</h2><p>How do you turn the regulatory and architectural concepts into something operational? Start with administrative and organizational changes.</p><h3>The Chief AI Officer (CAIO) or &#8220;AI Czar&#8221;</h3><p>When organizations adopt AI at scale, a leadership gap often opens between the CISO (security) and the CDO/CIO (data and enablement). Enter the Chief AI Officer.</p><p>The CAIO aligns AI strategy with business goals, manages AI-specific compliance, and coordinates with the CISO on security architecture. If you don&#8217;t have a CAIO, a formal AI Governance Board (legal, compliance, engineering, security) fills the void.</p><h3>The AI Acceptable Use Policy (AUP)</h3><p>Before buying expensive security tools, set clear guidelines. An AI AUP should explicitly define:</p><ul><li><p><strong>Approved Platforms:</strong> Distinguish approved enterprise-tier AI platforms (which guarantee data privacy) from public, consumer-grade tools (which may ingest user prompts for training).</p></li><li><p><strong>Classification Constraints:</strong> Restrict sensitive intellectual property, source code, and PII from being submitted to unauthorized external LLMs.</p></li><li><p><strong>Code Review Requirements:</strong> Any software written with AI coding tools goes through standard SAST/DAST security reviews before deployment.</p></li></ul><h3>Verify then Trust</h3><p>For AI, every input (prompt) sent to a model needs sanitization to prevent prompt injection, and every output coming back gets treated as untrusted, hostile data. You can&#8217;t assume the model will always return benign, safe, or accurate content. The pattern echoes Zero Trust&#8217;s &#8220;never trust, always verify,&#8221; applied to LLM I/O. The <a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/">OWASP LLM Top 10 (LLM01: Prompt Injection)</a> is the canonical taxonomy.</p><h3>Cost-Benefit Analysis</h3><p>AI deployments have real resource overhead. Beyond software subscriptions, deep learning needs GPU compute and storage at scale. A formal cost-benefit analysis weighs efficiency gains against the costs of implementation, continuous monitoring, model retraining, and new compliance liabilities.</p><h2>Adapting Your Existing Program</h2><p>Your existing Domain 1 risk management processes also need to adapt to AI-related assets:</p><ul><li><p><strong>Asset Inventory:</strong> Build a registry of AI models, training datasets, fine-tuning pipelines, and vector databases. Treat them as critical enterprise assets.</p></li><li><p><strong>Risk Register Integration:</strong> Document new threat profiles (prompt injection, training data poisoning, model inversion, and AI-augmented attacks like automated phishing and vulnerability discovery at scale) and assign risk owners.</p></li><li><p><strong>Third-Party Risk Management (TPRM):</strong> When evaluating SaaS vendors, audit AI usage. Do they use customer data to train their models? Are their LLM dependencies hosted in secure environments?</p></li></ul><h2>In the Next Article...</h2><p>With governance and policy in place, the next article moves to Domain 2 (Asset Security): how to classify, protect, and dispose of the data pipelines, model weights, and compute assets that drive AI in the enterprise.</p><div><hr></div><p>I&#8217;m building a CISSP prep platform centered on the idea that the exam tests your judgment and application of concepts, not rote memorization. It includes an adaptive CAT practice-exam engine, concept-coverage analytics, question-by-question scoring, exam-readiness tracking, mindset pattern analysis, weak-area drills, a custom study planner built around your schedule and requirements, my integrated book, and spaced repetition. It&#8217;s in limited beta. To request an invite (free extended Pro access in exchange for your feedback), join the <a href="https://academy.balancedsec.com/signup">waitlist</a> at academy.balancedsec.com, and I&#8217;ll send invites on a rolling basis.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Compute Tax on Free Trials]]></title><description><![CDATA[Opt-In, Opt-Out, and the Free-Trail Economics of AI-Native Apps]]></description><link>https://blog.balancedsec.com/p/the-compute-tax-on-free-trials</link><guid isPermaLink="false">https://blog.balancedsec.com/p/the-compute-tax-on-free-trials</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 29 May 2026 13:03:47 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f510c933-4da0-4b84-bbd7-195f63a503c9_1200x627.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For two decades, the SaaS playbook on free trials was simple: the marginal cost of letting one more person try the product was effectively zero. Bandwidth was cheap, database reads were cheap, and a trial signup that never converted cost the business almost nothing. Generous free trials were basically free to give away.</p><p>AI-native platforms have broken that math. Every prompt sent to a frontier model, every retrieval-augmented query, every personalized explanation routes through a metered inference call. The marginal cost per trial signup is no longer near zero. It&#8217;s measurable, often material, and almost always non-recoverable when the user doesn&#8217;t convert. The economics of free trials need a fresh look.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I&#8217;m working through this decision right now for a <a href="https://academy.balancedsec.com/">CISSP exam prep platform</a> I&#8217;m building. The product combines a large proprietary practice-question bank, an adaptive CAT engine, an in-app full-text version of my book <em>CISSP: A Balanced Approach</em>, and AI features that lean heavily on premium models: a personalized in-context coach, mindset pattern analysis, and dynamic answer rationales that go beyond what I&#8217;ve written. Every one of those AI features costs real money per use. Free-trial design has become a three-way decision: marketing reach, security exposure, and unit economics.</p><p>Here is my reasoning through that decision and the security trade-offs each option carries.</p><h2>Opt-In vs. Opt-Out</h2><p>The first fork is whether to require a credit card before someone gets to use the product. Opt-in (no card required) is frictionless and historically draws a larger top-of-funnel. Opt-out (requiring a card upfront) reduces sign-up volume but serves as a self-qualification gate. <a href="https://chartmogul.com/reports/saas-conversion-report/">ChartMogul&#8217;s January 2026 </a><em><a href="https://chartmogul.com/reports/saas-conversion-report/">SaaS Conversion Report</a></em>, based on 200 B2B software products, puts hard numbers on the trade-off. Per 1,000 website visitors, an opt-in trial typically produces about 45 signups and 3.6 paying customers. An opt-out trial produces about 35 signups and 10.5 paying customers. So opt-in pulls roughly 30% more signups, but opt-out produces nearly 3x the paying customers. Stated as trial-to-paid conversion, no-credit-card trials sit in the 4-6% range, and credit-card-required trials sit around 30%, more than 5x higher.</p><p>For a conventional SaaS product, that&#8217;s a marketing decision. For an AI-native product, it&#8217;s also a threat-model decision because each model targets a different adversary class.</p><p><strong>The opt-in failure mode is automated trial farming.</strong> With no financial identity at the door, attackers can use headless browser scripts (Puppeteer, Playwright), temporary inbox generators, and residential proxy networks (Bright Data, Oxylabs) to bypass standard IP-based rate limits. Once inside, two attacks run in parallel: (1) walking your REST endpoints to dump proprietary content like a test bank or curated explanations, and (2) hammering the most expensive AI features to drain inference credits for personal use, resale, or training a copycat model. The cost falls on you as non-recoverable compute.</p><p><strong>The opt-out failure mode is payment fraud.</strong> Putting a card form at the top of the funnel attracts a different adversary: carders running stolen-card dumps against your checkout endpoint to validate live numbers, and abusers feeding single-use virtual cards (privacy.com, Revolut) that pass a $0 authorization and then go dead before the first real charge. The cost includes processor review fees, chargeback exposure, and merchant-account standing.</p><p>For my platform, I&#8217;m landing on <em>opt-out</em> for three reasons:</p><ol><li><p><strong>The compute exposure on opt-in is asymmetric.</strong> A single determined adversary with a residential proxy pool can extract thousands of dollars in inference cost in a weekend. Recovering it is not realistic. Recovering payment-fraud losses, by contrast, is a workflow that processors already run for me.</p></li><li><p><strong>Self-qualification matters more when seats are expensive to serve.</strong> A ~30% conversion rate on a smaller pool of higher-intent users is a better fit for a product where every active trial user is burning real money in tokens.</p></li><li><p><strong>It lets me push off device fingerprinting.</strong> This is the part nobody talks about. If I went opt-in, I&#8217;d need a custom abuse stack from day one: device fingerprinting, behavioral signals, residential-ASN detection, link-graph clustering. With opt-out, the identity boundary moves to the financial system, which is the part of the internet where identity already costs something to fake.</p></li></ol><h2>How the Posture Slims: Shifting Identity to the Financial Layer</h2><p>The core idea: in opt-in, you build a &#8220;proxy identity&#8221; yourself because emails are free and unlimited. In opt-out, you outsource identity to the card network, where supply is constrained, fraud is regulated, and the processors already operate a global tracking layer.</p><p>That outsourcing works regardless of which processor you pick. Stripe is what I&#8217;m using, but the same architectural pattern applies to Adyen, Braintree, Chargebee, Paddle, or any modern PSP with a managed checkout flow and a fraud product. What you get for free, in rough order of value:</p><p><strong>1. Card fingerprinting across the processor&#8217;s network.</strong> Modern processors see the same card across many merchants. <a href="https://www.pymnts.com/news/fintech-investments/2026/stripe-reaches-record-valuation-global-volume-hits-2-trillion-dollars/">Stripe alone processed $1.9 trillion</a> in transaction volume in 2025, and reports that<a href="https://stripe.com/radar"> 90% of the cards used on its network have been seen more than once</a> across different merchants. Adyen and Braintree have comparable cross-merchant signals on a smaller scale. A card with a history of trial-abuse showing up at other merchants will get flagged before it ever creates an account on your platform.</p><p><strong>2. Built-in trial-abuse models.</strong> Most processors now ship a free-trial-abuse product as a one-click feature rather than a custom build. Stripe Radar&#8217;s Free Trial Abuse Prevention, launched in 2025, claims 90% accuracy at flagging signups likely to violate trial terms. In its first two months across four high-growth AI businesses, Stripe blocked over <a href="https://stripe.com/blog/how-stripe-radar-helps-prevent-free-trial-abuse">550,000 high-risk trials</a> and reported $4.4M in prevented downstream compute losses. Other processors offer analogous features under different names. The point is that the processor&#8217;s centralized view of card and bank identification number (BIN) behavior is doing work that you&#8217;d otherwise have to build in-house.</p><p><strong>3. Lightweight pre-checkout gating.</strong> A few cheap filters in front of checkout keep the customer database clean and stop low-effort scripts before they reach the payment layer:</p><ul><li><p><strong>Disposable email blocks.</strong> Server-side validation against a maintained list of throwaway domains. Free or low-cost APIs (NinjaPear, DeBounce, AbstractAPI) handle this.</p></li><li><p><strong>Email alias and syntax checks.</strong> Block +alias spamming and obvious typos at the form level.</p></li><li><p><strong>A bot challenge at signup.</strong> Cloudflare Turnstile, hCaptcha, or Google reCAPTCHA. Low friction for humans, high friction for scripts.</p></li></ul><p>With this combination, an abuser has to spend real capital on unique, valid credit cards to automate signups. The economics of attacking the platform invert. The custom device-fingerprinting stack you&#8217;d need for opt-in becomes unnecessary on day one.</p><h2>The New Threat Landscape: Payment-Layer Vulnerabilities</h2><p>The opt-out posture, however, is slimmer, but not threat-free. Three vectors carry over from the broader card payments ecosystem, regardless of which processor you choose. The mitigations are processor-agnostic in concept, and I&#8217;ll note how they look in Stripe specifically since that&#8217;s what I&#8217;m implementing.</p><h3>1. Card Testing</h3><p>A public card form is a target for <em>card testing</em>: criminals with stolen-card dumps fire $0.50 to $1.00 validation charges to find live numbers. Modern processors detect and block most of these, but two costs are still yours:</p><ul><li><p><strong>Review fees on the paid fraud tier.</strong> Stripe&#8217;s Radar for Fraud Teams add-on costs 7&#162; per screened transaction (reduced to $.02 if you&#8217;re on Stripe&#8217;s standard processing pricing). An overnight botnet of 15,000 attempts can saddle a Fraud Teams subscriber with anywhere from $300 to $1,050 in review fees, depending on tier, even though none of the charges went through. Adyen and Braintree&#8217;s enterprise risk products follow the same per-transaction pricing model.</p></li><li><p><strong>Auth-rate damage.</strong> A flood of declines hurts your acceptance-rate signal at the network.</p></li></ul><p><strong>Mitigation, in general:</strong> rate-limit your payment endpoints at the network layer (Cloudflare, your WAF, or your edge proxy), and put a bot challenge in front of checkout so high-velocity scripts can&#8217;t reach the processor&#8217;s backend at all. Stripe Checkout also ships its own managed CAPTCHA, which kicks in dynamically when Stripe&#8217;s models detect card-testing patterns.</p><h3>2. Single-Use Virtual Card Drain</h3><p>The more sophisticated abuser doesn&#8217;t use stolen cards. They use legitimate single-use virtual cards from services such as Privacy.com or Revolut.</p><ul><li><p><strong>The loophole.</strong> A trial signup runs a $0 authorization, which the virtual card passes. The abuser then closes the card. When the first real charge fires at the end of the trial, it&#8217;s declined. The attacker has now extracted the full trial period of premium AI usage for free.</p></li><li><p><strong>The detection signal.</strong> Virtual and prepaid cards have identifiable BIN ranges. Most processors can flag them.</p></li></ul><p><strong>Mitigation, in general:</strong> if this pattern shows up in your data, write a rule against prepaid and known-virtual BINs. In Stripe, this is a custom rule in Radar for Fraud Teams. Other processors expose similar BIN targeting via their rule engines. The cost is that some legitimate users (people who genuinely prefer virtual cards for privacy) get blocked, so you can choose whether to enable this on day one, or only once the data shows it&#8217;s a real problem.</p><h3>3. Friendly Fraud and Card-Network Monitoring</h3><p>The leading cause of opt-out chargebacks is <em>friendly fraud</em>: a real user signs up, forgets to cancel, sees the charge on their statement, and disputes with their bank instead of asking you for a refund. The threshold of concern is the dispute rate.</p><ul><li><p><strong>Industry standard threshold.</strong> <a href="https://docs.stripe.com/disputes/measuring">Above 0.75% dispute rate</a>, you&#8217;re under processor scrutiny. Above 1%, you risk being placed in Visa&#8217;s monitoring program. Stripe explicitly recommends staying below 0.75% to avoid being escalated.</p></li><li><p><strong>Card-network programs.</strong> Both card networks run monitoring programs that can ultimately terminate your processing relationship if dispute activity stays elevated. <a href="https://corporate.visa.com/content/dam/VCOM/corporate/visa-perspectives/security-and-trust/documents/visa-acquirer-monitoring-program-fact-sheet-2025.pdf">Visa&#8217;s Acquirer Monitoring Program (VAMP)</a> replaced the older VDMP and VFMP programs, with enforcement live since October 1, 2025. <a href="https://cside.com/blog/mastercard-scam-merchant-monitoring-2026">Mastercard&#8217;s Scam Merchant Monitoring Program (SMMP)</a> takes full effect on July 24, 2026, with confirmed scam activity resulting in immediate termination of Mastercard and Maestro processing.</p></li></ul><p><strong>Mitigation, in general:</strong> make the trial reminder and cancellation flow nearly impossible to misuse against you. An email 3 days before the charge clearly stating the upcoming amount, plus a one-click cancellation in the user dashboard, converts most would-be disputers into either renewals or clean cancellations. In Stripe specifically, the <code>customer.subscription.trial_will_end</code> webhook is the trigger point. Other processors expose equivalent events.</p><h2>TL;DR</h2><p>The marginal-cost economics of AI-native platforms make the free-trial decision a security- and unit-economics decision, not just a marketing one. Opt-in trials draw a larger top-of-funnel but expose you to compute exfiltration via automated farming. Opt-out trials draw a smaller, higher-intent funnel and shift your residual risk into the payment layer, where the processor&#8217;s global fraud signal does most of the work you&#8217;d otherwise build in-house.</p><p>For an AI-native product where each active trial user burns real tokens, the opt-out posture plus pre-checkout gating (disposable email blocks, a bot challenge, and a clean cancellation flow) is the architecture I&#8217;m going with. You don&#8217;t get an enterprise-grade anti-abuse stack out of it, but you get most of the way there for a fraction of the engineering cost, and you keep your focus on the product instead of fighting botnets.</p><p></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-ysh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-ysh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png 424w, https://substackcdn.com/image/fetch/$s_!-ysh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png 848w, https://substackcdn.com/image/fetch/$s_!-ysh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png 1272w, https://substackcdn.com/image/fetch/$s_!-ysh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-ysh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png" width="1100" height="2600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2600,&quot;width&quot;:1100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:275114,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/199541610?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-ysh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png 424w, https://substackcdn.com/image/fetch/$s_!-ysh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png 848w, https://substackcdn.com/image/fetch/$s_!-ysh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png 1272w, https://substackcdn.com/image/fetch/$s_!-ysh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91fd703e-8a2c-46e1-b7cf-6402d8ee577f_1100x2600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Strap In (with Harness Engineering)]]></title><description><![CDATA[Creating a Security Boundary for Autonomous AI Agents]]></description><link>https://blog.balancedsec.com/p/strap-in-with-harness-engineering</link><guid isPermaLink="false">https://blog.balancedsec.com/p/strap-in-with-harness-engineering</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 22 May 2026 13:02:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BDrE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BDrE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BDrE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png 424w, https://substackcdn.com/image/fetch/$s_!BDrE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png 848w, https://substackcdn.com/image/fetch/$s_!BDrE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png 1272w, https://substackcdn.com/image/fetch/$s_!BDrE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BDrE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png" width="1456" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c493257-5374-4122-b4ff-479db9819689_1854x662.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:117773,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/198604018?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BDrE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png 424w, https://substackcdn.com/image/fetch/$s_!BDrE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png 848w, https://substackcdn.com/image/fetch/$s_!BDrE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png 1272w, https://substackcdn.com/image/fetch/$s_!BDrE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c493257-5374-4122-b4ff-479db9819689_1854x662.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As organizations rush to harness and deploy autonomous AI agents for software development, security professionals face a daunting challenge: how do we secure a system that relies on probabilistic reasoning rather than deterministic code?</p><p>We&#8217;re all looking for ways to bring some secure sanity to this new development paradigm. I started my AI-assisted development experimentation way back in the early days (last year) by spinning up Claude directly in a cloned repo on my development machine (please don&#8217;t do that). As we&#8217;ll see below, giving an agent that much unfettered access can lead to unfortunate outcomes. Put simply, an agent should never run directly on a developer&#8217;s bare-metal machine with full filesystem access, or even broad local access. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><blockquote><p>The best approach is isolation.</p></blockquote><p>That&#8217;s why I wanted to write this article. For CISSP holders and cybersecurity leaders, securing AI dev tools means moving past &#8220;prompt engineering&#8221; (asking AI to be good) and instead thinking in terms of Harness Engineering.</p><p>This short guide provides an overview of what harness engineering is, why it represents an important security boundary for AI agents, and how you can lead an assessment to protect your organization.</p><h2><strong>What is &#8220;Harness Engineering&#8221;?</strong></h2><p>The term harness engineering, <a href="https://mitchellh.com/writing/my-ai-adoption-journey">coined by Mitchell Hashimoto</a> in early 2026, <a href="https://madplay.github.io/en/post/harness-engineering">refers</a> to &#8220;designing the environment, specifying intent clearly, and building the feedback loops that allow agents to autonomously build and maintain software.&#8221; You could generalize this as defining how modern autonomous systems must be structured:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Xt3D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Xt3D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png 424w, https://substackcdn.com/image/fetch/$s_!Xt3D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png 848w, https://substackcdn.com/image/fetch/$s_!Xt3D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png 1272w, https://substackcdn.com/image/fetch/$s_!Xt3D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Xt3D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png" width="1390" height="154" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ace4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:154,&quot;width&quot;:1390,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Xt3D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png 424w, https://substackcdn.com/image/fetch/$s_!Xt3D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png 848w, https://substackcdn.com/image/fetch/$s_!Xt3D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png 1272w, https://substackcdn.com/image/fetch/$s_!Xt3D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Face4dbf1-3b85-4f27-8251-2f4588b3cac9_1390x154.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><ul><li><p><strong>The Model is the &#8220;Brain&#8221;:</strong> An LLM (like Claude or GPT) provides the raw reasoning, language processing, and statistical inference. However, in isolation, a model can&#8217;t interact with the world.</p></li><li><p><strong>The Harness is the &#8220;Hands, Eyes, and Guardrails&#8221;:</strong> the deterministic software infrastructure that wraps around the model. It manages the memory modules, tool registries, database/API connectors, execution loops, and safety checkpoints.</p></li></ul><p>For security professionals, harness engineering encompasses the discipline of designing the control systems that govern how an AI agent perceives its environment, selects actions, and validates its outputs.</p><p>Harness components generally fall into two classic control-theory categories:</p><ol><li><p><strong>Guides (Feedforward Controls):</strong> Active constraints that direct the agent <em>before</em> it acts. Examples include system prompts, constraint documents, and organizational boundaries (such as a CLAUDE.md or AGENTS.md file).</p></li><li><p><strong>Sensors (Feedback Controls):</strong> Mechanisms that observe and validate the agent&#8217;s behavior <em>after</em> it acts. Examples include real-time validation loops, output parsers, and automated evaluation suites.</p></li></ol><h2><strong>Why the Harness is a Better Security Boundary</strong></h2><p>Early implementations of AI assistants relied on &#8220;prompt guardrails&#8221; (e.g., <em>&#8220;Do not delete files&#8221;</em> or <em>&#8220;Never disclose system keys&#8221;</em>). However, prompts are mere suggestions to a probabilistic model. Under complex multi-step reasoning, context dilution, or adversarial inputs, these prompt-based walls reliably collapse.</p><p>And of course, you know this: You wouldn&#8217;t secure a database with just a comment like &#8216;please don&#8217;t drop tables.&#8217; <a href="https://cobusgreyling.medium.com/claude-code-hooks-f5a4a8b0e53c">You&#8217;d write a permission system</a>. </p><blockquote><p>The harness is that permission system.</p></blockquote><p>Without a secure harness, your organization is exposed to severe, agent-specific risks:</p><ul><li><p><strong>Excessive Autonomy and Tool Abuse:</strong> An agent might exploit overly permissive tools to execute high-impact actions without human-in-the-loop validation.</p></li><li><p><strong>Indirect Prompt Injection:</strong> A malicious payload hidden in an external data source (like a customer PDF, a PR comment, or a web page) can hijack the agent&#8217;s reasoning loop. If the agent has a privileged toolset, this injection instantly escalates to remote code execution.</p></li><li><p><strong>Malicious Repository Configurations:</strong> In tools like Claude Code, repository configuration files (which historically were passive metadata) now control active execution paths. Disclosures such as&nbsp;<a href="https://github.com/anthropics/claude-code/security/advisories/GHSA-4fgq-fpq9-mr3g">CVE-2025-59536</a>&nbsp;and&nbsp;<a href="https://github.com/anthropics/claude-code/security/advisories/GHSA-jh7p-qr78-84p7">CVE-2026-21852</a>&nbsp;demonstrated that simply opening or cloning an untrusted project could enable a rogue configuration to execute arbitrary code or steal API credentials.</p></li></ul><h2><strong>How to Conduct an AI Agent Harness Assessment</strong></h2><p>To help your engineering teams transition from risky &#8220;vibe coding&#8221; to a more hardened, compliant deployment, you can lead a security assessment of their AI agent harness.</p><blockquote><p>This structured assessment methodology maps the bleeding-edge AI risks back to traditional CISSP domains.</p></blockquote><h3><strong>Step 1: Map the Trust Boundaries (Asset Security &amp; Architecture)</strong></h3><p>Before evaluating code, you need to map the data flows. Treat the AI agent as a highly privileged, non-human identity.</p><ul><li><p><strong>Inventory Entry Points:</strong> Where does the agent ingest data? (e.g., User prompts, API responses, RAG databases, and/or external URLs).</p></li><li><p><strong>Define Trust Zones:</strong> Where does the trusted system end and untrusted data begin? Remember: any data retrieved by the agent (including tool outputs) must be treated as untrusted input.</p></li><li><p><strong>Identify Secrets:</strong> Ensure the agent&#8217;s harness doesn&#8217;t have direct access to raw SSH keys, cloud credentials, or long-lived API tokens. Instead, verify it uses scoped, short-lived tokens injected at runtime (typically implemented using OAuth 2.0).</p></li></ul><h3><strong>Step 2: Threat Modeling</strong></h3><p>While the classical Microsoft STRIDE framework is great for static applications, autonomous agents break the idea that software has fixed, predictable roles. We previously explored several threat modeling frameworks, including&nbsp;<a href="https://blog.balancedsec.com/p/mitre-atlas-the-ai-threat-framework">MITRE ATLAS</a>, and used&nbsp;<a href="https://blog.balancedsec.com/p/after-atlas-why-maestro-is-the-threat">MAESTRO alongside ATLAS</a>. </p><p>Instead of fixed roles, Agents simultaneously behave as users, services, and data pipelines. For the purposes of this discussion, let&#8217;s conduct a threat modeling session using STRIDE+A, where &#8220;A&#8221; stands for AI Agent-Specific Attacks:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4Dtf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4Dtf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png 424w, https://substackcdn.com/image/fetch/$s_!4Dtf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png 848w, https://substackcdn.com/image/fetch/$s_!4Dtf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!4Dtf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4Dtf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png" width="1258" height="1596" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1596,&quot;width&quot;:1258,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:373387,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/198604018?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4Dtf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png 424w, https://substackcdn.com/image/fetch/$s_!4Dtf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png 848w, https://substackcdn.com/image/fetch/$s_!4Dtf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!4Dtf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5faa1fb7-799a-4dcb-8fa2-c8079921015a_1258x1596.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>Step 3: Audit Tool Permissions &amp; Sandboxing (Identity &amp; Access Management)</strong></h3><p>Evaluate the physical boundaries of the agent&#8217;s <a href="https://www.truefoundry.com/blog/claude-code-sandboxing">execution environment</a>.</p><ul><li><p><strong>Isolate the Host:</strong> As I mentioned at the top, the agent should never run directly on a developer&#8217;s bare-metal machine with full filesystem access. It must run inside an ephemeral container (such as a DevContainer), a microVM, or a remote sandbox.</p></li><li><p><strong>Enforce Least Privilege:</strong> <a href="https://medium.com/@haberlah/configure-claude-code-to-power-your-agent-team-90c8d3bca392">Does the agent have &#8220;wildcard&#8221; access</a> (e.g., Bash(*))? Scrutinize and <a href="https://inventivehq.com/knowledge-base/claude/how-to-manage-permissions-and-sandboxing">restrict allowed commands</a>.</p></li><li><p><strong>Network Egress:</strong> Is network traffic wide open? Establish a strict network proxy with an allowlist limited to required endpoints (like the LLM provider and specific package registries) to prevent data exfiltration.</p></li></ul><h3><strong>Step 4: Assess the Guides and Sensors (Security Assessment &amp; Testing)</strong></h3><p>Review how the engineering team is instructing and observing the model.</p><ul><li><p><strong>Feedforward Check:</strong> Review system instructions and constraint files (e.g., AGENTS.md or CLAUDE.md). Are they under version control? Are they concise (ideally under 150 lines) to avoid context bloat?</p></li><li><p><strong>Feedback Check:</strong> Does the harness use deterministic validation loops? If the agent edits code, does a <a href="https://code.claude.com/docs/en/hooks-guide">PostToolUse hook</a> automatically run tests and linters before committing?</p></li><li><p><strong>Human-in-the-Loop Gates:</strong> Ensure that destructive, financial, or externally visible actions (like pushing to production or deploying code) require explicit, independent human authorization.</p></li></ul><h3><strong>Step 5: Implement Continuous Automated Scanning (Security Operations)</strong></h3><p>Unfortunately, we can&#8217;t treat this assessment as a one-time gate. The threat landscape of Model Context Protocol (MCP) servers and agent skills is evolving daily.</p><ul><li><p><strong>Static Configuration Auditing:</strong> Integrate tools like AgentShield (<a href="https://github.com/affaan-m/agentshield">ecc-agentshield</a>) into your team&#8217;s local environments or CI/CD pipelines. These scanners continuously look for hardcoded secrets, overly permissive tool definitions, and risky MCP server configurations before code is committed.</p></li><li><p><strong>Behavioral Regression Testing:</strong> Introduce frameworks like the <a href="https://github.com/OWASP/Agent-Security-Regression-Harness">OWASP Agent Security Regression Harness</a>. This allows security teams to run executable security regression scenarios against the agentic application, verifying that prompt or model updates do not introduce new security failures or allow goal hijacking.</p></li></ul><p>What are you using to keep your development environment secure?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CEfA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CEfA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png 424w, https://substackcdn.com/image/fetch/$s_!CEfA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png 848w, https://substackcdn.com/image/fetch/$s_!CEfA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png 1272w, https://substackcdn.com/image/fetch/$s_!CEfA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CEfA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png" width="1456" height="1895" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1895,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:468429,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/198604018?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CEfA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png 424w, https://substackcdn.com/image/fetch/$s_!CEfA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png 848w, https://substackcdn.com/image/fetch/$s_!CEfA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png 1272w, https://substackcdn.com/image/fetch/$s_!CEfA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a0638bb-9ee3-4e2f-adff-6075d2ff4885_2160x2811.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Six Things Adversaries Are Doing With AI]]></title><description><![CDATA[Inside Google's Q2 threat report. What MITRE ATLAS covers, and where it doesn't]]></description><link>https://blog.balancedsec.com/p/six-things-adversaries-are-doing</link><guid isPermaLink="false">https://blog.balancedsec.com/p/six-things-adversaries-are-doing</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 15 May 2026 13:01:28 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/dc847c36-be7c-46fb-8034-e1828c5fa048_2400x1350.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For the first time, Google&#8217;s Threat Intelligence Group (GTIG) has identified a threat actor using a zero-day exploit they believe was developed with AI. A criminal group used a large language model to write a working exploit script that bypassed two-factor authentication in a popular open-source admin tool. The group was preparing to use the exploit in a mass-attack campaign when Google identified it and worked with the vendor to disclose and patch the flaw.</p><p>The structural signatures that gave GTIG confidence in the assessment are telling: the exploit script contained a hallucinated CVSS score in its docstrings (the in-code comments left by the developer), a textbook Python format characteristic of AI-generated code, down to extra code that prints the terminal output in color. These are small stylistic tells that a human exploit developer wouldn&#8217;t bother with.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>That&#8217;s the headline finding from GTIG&#8217;s <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">Q2 2026 AI Threat Tracker</a>, published May 11. The TLDR version: adversaries have moved beyond basic experimentation to industrial-scale use of generative AI, and they&#8217;re doing several different things with it. Google is calling out specific groups by name, including state-sponsored clusters from China and North Korea, financially motivated cybercrime crews like TeamPCP, and Russia-linked operators targeting Ukraine. Each one uses AI at a specific phase of the attack lifecycle. </p><p>Below, I walk through what they&#8217;re doing and where it lands, mapping each use to the part of the kill chain a CISSP holder already operates against.</p><p>Here&#8217;s a quick tour.</p><h2>Researching their targets</h2><p>Before the attack comes the homework. Adversaries are using large language models to map out their victims. They generate detailed organizational hierarchies for departments such as finance and HR, identify which third-party vendors a target enterprise relies on, and even fingerprint the specific make and model of the computer a high-value executive uses. In one documented case, a threat actor asked an AI model to identify a target&#8217;s laptop from photographs.</p><p>Two China-linked actors stand out. The cluster GTIG tracks as UNC2814 prompts Google&#8217;s Gemini to act as a &#8220;senior security auditor&#8221; or &#8220;C/C++ binary security expert&#8221; before asking it to analyze the firmware of embedded devices like TP-Link routers. A separate China-linked group used a <a href="https://github.com/0x4m4/hexstrike-ai/">public agentic framework called Hexstrike</a>, combined with a knowledge-graph memory system, to maintain persistent state on a target&#8217;s attack surface and pivot autonomously between reconnaissance tools.</p><p>The shared pattern: AI as a research force multiplier. Tasks that used to take a human analyst hours of OSINT can now happen at machine speed.</p><h2>Developing new exploits</h2><p>The identified zero-day matters for what it reveals about how AI changes vulnerability research. The 2FA bypass came from a hardcoded trust assumption in the developer&#8217;s authentication logic. It&#8217;s a high-level semantic flaw that fuzzers and static analyzers routinely miss. AI models, reading the developer&#8217;s intent across the codebase, increasingly find them.</p><h2>Writing stealthier malware</h2><p>AI also appears inside the malware itself. Sometimes it&#8217;s used to hide the malicious code. Sometimes it&#8217;s used to operate it in real time.</p><p>Two Russia-linked malware families, CANFAIL and LONGSTREAM, target Ukrainian organizations and contain LLM-generated decoy code. LONGSTREAM checks the system&#8217;s daylight saving status 32 times in a row, for no operational reason except to make the malicious file look like routine administrative work.</p><p>And then there is PROMPTSPY. The Android backdoor sends the device&#8217;s current screen layout to Google&#8217;s Gemini API and asks the model where to tap next. The model returns coordinates. The malware taps. ESET first identified the malware. GTIG extended the analysis to describe what they call the first widely-reported example of an AI service driving real-time malware behavior in the wild.</p><h2>Industrializing account abuse</h2><p>AI providers cap usage. Attackers don&#8217;t want to be capped. So they industrialized account abuse.</p><p>Two China-linked clusters, UNC6201 and UNC5673, run automated registration pipelines that bypass CAPTCHA and SMS verification to create premium accounts at scale. Middleware aggregators such as Claude-Relay-Service and CLIProxyAPI allow attackers to pool API keys from Gemini, Claude, and OpenAI accounts via a single OpenAI-compatible interface. Anti-detect browsers mask the fingerprints. The whole ecosystem looks professionalized. GTIG documents five tool categories with named examples for each.</p><h2>Manufacturing scale</h2><p>The same scaling impulse shows up in influence operations. The pro-Russia campaign Operation Overload used suspected AI voice cloning to make real journalists appear to say things they never said, splicing the synthetic audio into manipulated video to lend credibility to false narratives. Russia, Iran, China, and Saudi Arabia are all using AI to produce political content at volume, though most of the breakthrough capability claims for these campaigns have not yet appeared in observed operations.</p><h2>Going after the AI supply chain</h2><p>The frontier models themselves are well-defended. So attackers are going after the connecting layers: the libraries, the package managers, the skill marketplaces, and the API gateways that AI systems depend on.</p><p>A cybercrime cluster known as TeamPCP (also tracked as UNC6780) compromised the GitHub repositories of LiteLLM, BerriAI, Trivy, and Checkmarx in late March 2026. They embedded a credential stealer called SANDCLOCK that extracted AWS keys and GitHub tokens from affected build environments. The stolen credentials were sold to ransomware and data-theft-extortion groups, turning a single supply chain compromise into multiple downstream payloads.</p><p>A parallel pattern hit the OpenClaw skill marketplace. Researchers found malicious packages distributed as legitimate skills, containing hidden routines that abused OpenClaw&#8217;s elevated system access to run unauthorized code. Both incidents are supply chain attacks specifically targeting the AI dependency layer.</p><h2>How does MITRE ATLAS help?</h2><p>All six behaviors above need names. Once a threat has a technique ID, you can record it in a risk register, assign an owner, select a control, and audit the result. MITRE ATLAS is the canonical vocabulary for AI-specific adversary tactics, the AI extension of MITRE ATT&amp;CK. <a href="https://blog.balancedsec.com/p/mitre-atlas-the-ai-threat-framework">I previously wrote a longer piece on ATLAS</a> for readers who want the deeper context.</p><p>A question worth asking follows: how well does ATLAS cover what GTIG just documented?</p><p>The answer is partial. Some of GTIG&#8217;s findings map cleanly to pre-existing ATLAS techniques. Several map to techniques MITRE added or updated in their early May  (v5.6.0) release. A handful have no direct ATLAS coverage, but the framework is responsive, and it&#8217;s still catching up.</p><h3>Already in the catalog</h3><p>Four of GTIG&#8217;s findings map to ATLAS techniques that predate the May update:</p><ul><li><p><strong>PROMPTSPY&#8217;s autonomous orchestration</strong> is fully covered. <a href="https://atlas.mitre.org/techniques/AML.T0040">AML.T0040</a> (AI Model Inference API Access), <a href="https://atlas.mitre.org/techniques/AML.T0103">AML.T0103</a> (Deploy AI Agent), <a href="https://atlas.mitre.org/techniques/AML.T0102">AML.T0102</a> (Generate Malicious Commands), and <a href="https://atlas.mitre.org/techniques/AML.T0053">AML.T0053</a> (AI Agent Tool Invocation) describe the architecture pattern PROMPTSPY uses.</p></li><li><p><strong>LLM account abuse and middleware proxies</strong> map to <a href="https://atlas.mitre.org/techniques/AML.T0008.005">AML.T0008.005</a> (AI Service Proxies), <a href="https://atlas.mitre.org/techniques/AML.T0021">AML.T0021</a> (Establish Accounts), and <a href="https://atlas.mitre.org/techniques/AML.T0016.002">AML.T0016.002</a> (Obtain Capabilities: Generative AI). These were added in earlier ATLAS releases.</p></li><li><p><strong>TeamPCP&#8217;s AI supply chain compromise</strong> maps to <a href="https://atlas.mitre.org/techniques/AML.T0010.001">AML.T0010.001</a> (AI Supply Chain Compromise: AI Software).</p></li><li><p><strong>Operation Overload&#8217;s voice-cloning campaign</strong> maps to <a href="https://atlas.mitre.org/techniques/AML.T0088">AML.T0088</a> (Generate Deepfakes), the technique GTIG used in their own appendix to attribute this finding. T0088 covers the synthesis of high-fidelity audio and video to impersonate authoritative figures.</p></li></ul><p>These map straight into a register today without waiting for anything new. </p><h3>Just added</h3><p>ATLAS Data v5.6.0 (<a href="https://atlas.mitre.org">atlas.mitre.org</a>, <a href="https://github.com/mitre-atlas/atlas-data/compare/v5.5.0...v5.6.0">view the diff</a>) added or updated four entries relevant to the behaviors above:</p><ul><li><p><strong>Deepfake-assisted phishing</strong> (<a href="https://atlas.mitre.org/techniques/AML.T0052.001">AML.T0052.001</a>, new) is a phishing-specific subtechnique that extends the pre-existing T0088 Generate Deepfakes. GTIG didn&#8217;t document a deepfake-phishing-specific incident in this report, but ATLAS's addition of this subtechnique signals the framework&#8217;s anticipation of voice cloning moving from influence operations into phishing pretexts (CEO fraud, executive impersonation).</p></li><li><p><strong>Code repository reconnaissance</strong> (<a href="https://atlas.mitre.org/techniques/AML.T0095.000">AML.T0095.000</a>, new subtechnique under the new parent <a href="https://atlas.mitre.org/techniques/AML.T0095">AML.T0095</a> Search Open Websites/Domains) covers the GTIG-documented use of public code repos for AI-related secrets and configuration discovery.</p></li><li><p><strong>LLM Jailbreak</strong> (<a href="https://atlas.mitre.org/techniques/AML.T0054">AML.T0054</a>, updated) now reflects persona-driven prompting patterns, including acting as a &#8220;senior security researcher&#8221; jailbreak that GTIG attributed to UNC2814.</p></li><li><p><strong>OpenClaw command-and-control case study</strong> (<a href="https://atlas.mitre.org/studies/AML.CS0051">AML.CS0051</a>, updated) formalizes the OpenClaw skill marketplace compromise pattern.</p></li></ul><p>The release timing: MITRE published v5.6.0 on May 4. GTIG published their threat report on May 11. The framework was updated in close parallel with the threat intelligence cycle. </p><h3>Not yet in the catalog</h3><p>Three GTIG findings have no dedicated ATLAS technique:</p><ul><li><p><strong>AI-developed zero-day exploits.</strong> The lead finding from the GTIG report, the criminal-actor 2FA bypass developed with AI assistance, doesn&#8217;t have a specific ATLAS technique. The closest is <a href="https://atlas.mitre.org/techniques/AML.T0017">AML.T0017</a> (Develop Capabilities), which is generic. There&#8217;s no &#8220;adversary uses AI to discover vulnerabilities in target systems&#8221; entry.</p></li><li><p><strong>AI-generated polymorphic malware code.</strong> The LLM-generated decoy code in CANFAIL and LONGSTREAM, including LONGSTREAM&#8217;s 32 daylight-saving checks, has no dedicated technique. ATLAS covers prompt-side obfuscation under <a href="https://atlas.mitre.org/techniques/AML.T0068">AML.T0068</a>, but adversary use of AI to generate malware code with camouflage logic isn&#8217;t named.</p></li><li><p><strong>Agentic frameworks as offensive tools.</strong> The PRC-nexus actor using Hexstrike with the Graphiti memory system for autonomous reconnaissance has no matching ATLAS entry. The framework covers adversaries' use of AI inference APIs and includes&nbsp;<a href="https://atlas.mitre.org/techniques/AML.T0103">AML.T0103</a>&nbsp;for deploying defender- or victim-owned agents, but offensive use of full agentic frameworks against victims remains a gap.</p></li></ul><p>The gap is ATLAS-specific. GTIG&#8217;s own appendix maps these findings to conventional <a href="https://attack.mitre.org/">MITRE ATT&amp;CK</a> techniques: <a href="https://attack.mitre.org/techniques/T1587/001/">T1587.001</a> (Develop Capabilities: Malware) for CANFAIL and LONGSTREAM, <a href="https://attack.mitre.org/techniques/T1587/004/">T1587.004</a> (Develop Capabilities: Exploits) for the AI-developed zero-day, <a href="https://attack.mitre.org/techniques/T1027/014/">T1027.014</a> (Polymorphic Code) for PROMPTFLUX, and <a href="https://attack.mitre.org/techniques/T1027/016/">T1027.016</a> (Junk Code Insertion) for the decoy code patterns. Traditional ATT&amp;CK covers the underlying behaviors. ATLAS hasn&#8217;t yet named them in AI-specific form.</p><p>The gap is informative. The biggest single GTIG finding (AI used to develop a real zero-day exploit) sits in the no-direct-mapping bucket. Frameworks update on incident-disclosure timelines, and it makes sense that the threat intelligence is ahead of the vocabulary.</p><h2>How to harness ATLAS</h2><p>Four things a CISSP-led security program can do this quarter with what&#8217;s in front of us:</p><p><strong>1. Map ATLAS technique IDs into your existing risk register.</strong><em> The directly-mapped findings are the easy lift. </em>Risk: AI dependency supply chain compromise. Threat: <a href="https://atlas.mitre.org/techniques/AML.T0010.001">AML.T0010.001</a>. Mitigation: <a href="https://atlas.mitre.org/mitigations/AML.M0023">AML.M0023</a> AI Bill of Materials and <a href="https://atlas.mitre.org/mitigations/AML.M0014">AML.M0014</a> Verify AI Artifacts. Owner: AppSec team. Same structural pattern your ATT&amp;CK-anchored entries already use, with ATLAS-formal mitigation IDs rather than generic supply chain practices.</p><p><strong>2. Add the v5.6.0 techniques where they apply.</strong> Deepfake-assisted phishing belongs in your security awareness training program now, not next year. The technique has a corresponding mitigation (<a href="https://atlas.mitre.org/mitigations/AML.M0034">AML.M0034</a> Deepfake Detection), and your tabletop exercises can use it as a scenario starter. Code repository reconnaissance fits into your secrets management and source control hygiene program.</p><p><strong>3. Document the gaps as monitoring needs.</strong> This is the part most risk registers will miss. For each GTIG finding that doesn&#8217;t have an ATLAS technique (AI-developed zero-days, AI-generated polymorphic malware, offensive agentic frameworks), the register entry should explicitly say <em>&#8220;no standard taxonomy entry; monitor framework releases for coverage.&#8221;</em> A risk register that names where the framework has gaps is stronger than one that pretends the gaps don&#8217;t exist.</p><p><strong>4. Track ATLAS releases.</strong> The framework moved from &#8220;no v5.6.0&#8221; to &#8220;four directly-relevant new entries&#8221; in less than a month after the underlying incidents became publicly known. Release tags live at <a href="https://github.com/mitre-atlas/atlas-data/releases">github.com/mitre-atlas/atlas-data/releases</a>. The canonical user-facing technique pages are at <a href="https://atlas.mitre.org">atlas.mitre.org</a>. Subscribing to release notifications is a one-time setup with ongoing value.</p><p>Six attacker behaviors, named groups behind each, and a framework that&#8217;s partially there. Your risk register needs both the techniques the framework has named and the gaps it hasn&#8217;t.</p><div><hr></div><p><em>Are you seeing any of these six behaviors already in your environment? Reply or drop it in the comments.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fbUt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fbUt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png 424w, https://substackcdn.com/image/fetch/$s_!fbUt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png 848w, https://substackcdn.com/image/fetch/$s_!fbUt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png 1272w, https://substackcdn.com/image/fetch/$s_!fbUt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fbUt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png" width="1456" height="4403" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4403,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:810674,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/197567165?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fbUt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png 424w, https://substackcdn.com/image/fetch/$s_!fbUt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png 848w, https://substackcdn.com/image/fetch/$s_!fbUt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png 1272w, https://substackcdn.com/image/fetch/$s_!fbUt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4077ac30-2184-4ce8-b044-4624f780c63e_1760x5322.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[NIST AI RMF or ISO 42001?]]></title><description><![CDATA[A CISSP-Holder's Guide to Choosing (or Sequencing)]]></description><link>https://blog.balancedsec.com/p/nist-ai-rmf-or-iso-42001</link><guid isPermaLink="false">https://blog.balancedsec.com/p/nist-ai-rmf-or-iso-42001</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 08 May 2026 13:03:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!K59B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K59B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K59B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!K59B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!K59B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!K59B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K59B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69178,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/196720788?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K59B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!K59B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!K59B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!K59B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8a90d2-61ac-49b8-92bd-33b9eefec2f9_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI governance has moved from voluntary guidance to enforceable obligation in less than two years. The <a href="https://artificialintelligenceact.eu/">EU AI Act</a> came into force on 1 August 2024. NIST released its AI Risk Management Framework (AI 100-1) in January 2023. ISO/IEC 42001, the first ISO standard for an AI management system, was published in December 2023.</p><p>For CISSP holders, the practical questions are how they fit together and what existing ISO 27001 work actually transfers. In this article, we dive into a comparison of NIST AI RMF and ISO/IEC 42001: how they differ, where they overlap, and which fits which use case.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>The two frameworks at a glance</h2><p><strong>NIST AI RMF (AI 100-1).</strong> Published January 2023 by the U.S. National Institute of Standards and Technology (NIST). Four core functions: <a href="https://blog.balancedsec.com/p/original-inside-the-nist-ai-risk">Govern, Map, Measure, and Manage</a>. Seven trustworthiness characteristics. Four implementation Tiers. The Playbook companion document elaborates on 72 subcategories with suggested actions. <a href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf">NIST AI 600-1</a> (July 2024) introduces a Generative AI Profile that includes 12 GAI-specific risks. Voluntary, non-certifiable, free to download.</p><p><strong><a href="https://www.iso.org/standard/42001">ISO/IEC 42001:2023</a>.</strong> The AI version of ISO 27001. Published December 2023, it follows the same management system pattern that any 27001-certified organization already operates: leadership commitment, risk assessment, controls, internal audit, management review, and continual improvement. Clauses 4 through 10 are identical in structure to those in ISO 27001 and use the standard ISO management system template (i.e., &#8220;Annex SL-conformant&#8221;) as do other ISO management system standards. What&#8217;s new is the AI-specific control catalog in Annex A: 38 reference controls covering AI policy, roles, resources, system impact assessment, lifecycle management, data, transparency, intended use, and third-party relationships. As with 27001, you produce a Statement of Applicability (SoA) that lists every control and provides a written justification for its inclusion or exclusion. Unlike NIST AI RMF, you can earn a certificate through an accredited third-party audit. Note that reading the standard requires purchasing a license from ISO.</p><p>The two were designed to be readable together. ISO 42001 clause 4.1 NOTE 1 explicitly cross-references NIST AI RMF for AI role types and lifecycle stages.</p><h2>What transfers from existing ISO 27001 work</h2><p>If you have experience with ISO 27001, that muscle memory does most of the work. The <a href="https://www.iso.org/the-iso-survey.html">ISO Survey 2024</a>, published by ISO/IAF CASCO in September 2025, reports 96,709 ISO 27001 certificates and 179,877 sites globally. ISO 27001 ranks fourth among all ISO management system standards by certificate volume, behind only ISO 9001, ISO 14001, and ISO 45001. At a 179,877-to-96,709 ratio of sites to certificates, the average certified organization runs 1.86 sites under one certificate scope.</p><p>What that engagement gives you:</p><ol><li><p><strong>The audit cadence is identical.</strong> Stage 1 documentation review, Stage 2 on-site assessment, annual surveillance audits in years one and two, full recertification in year three. ISO 27001 audit capability (internal audits per clause 9.2, certification body relationships, surveillance preparation) transfers the management-system half of ISO 42001. The AI-specific half (model risk, AI System Impact Assessment, and the new control catalog) is a separate competency that typically requires AI domain expertise, which can be sourced internally or from specialists.</p></li><li><p><strong>The Statement of Applicability is the document that gets audited.</strong> Both standards require it in the same form: a list of every Annex A control, justification for inclusion or exclusion, and management sign-off. ISO 42001 trades 27001&#8217;s 93 information security controls for 38 AI-specific ones. The document discipline transfers.</p></li><li><p><strong>CISSP Domain 1 already covers both.</strong> <a href="https://blog.balancedsec.com/p/ai-security-for-the-cissp-whats-changed">ISC2&#8217;s Exam Guidance for AI (April 2026)</a> cites NIST AI RMF and ISO 42001 as required compliance-tracking frameworks for AI governance professionals.</p></li><li><p><strong>Top management commitment, internal audit, management review, and corrective action.</strong> Same wording in 27001, 42001, and other ISO management system standards. If you&#8217;ve run any of them, you already know these clauses.</p></li><li><p><strong>A crosswalk already exists.</strong> NIST&#8217;s AI Resource Center hosts a <a href="https://airc.nist.gov/docs/NIST_AI_RMF_to_ISO_IEC_42001_Crosswalk.pdf">community-submitted 72-row crosswalk</a> pairing every NIST AI RMF subcategory with the relevant parts of ISO 42001. GOVERN maps to leadership and policy areas. MAP to context-setting and impact-assessment processes. MEASURE maps to monitoring and verification. MANAGE to management review and continual improvement. NIST hosts the crosswalk but doesn&#8217;t endorse it (the <a href="https://airc.nist.gov/airmf-resources/crosswalks/">crosswalk&#8217;s page</a> notes that inclusion doesn&#8217;t imply NIST endorsement of either framework&#8217;s coverage). Use it as a starting reference for your own verification work.</p></li></ol><p>That covers maybe 60% of the work. Here&#8217;s where the muscle memory breaks.</p><h2>What doesn&#8217;t transfer</h2><p><strong>NIST AI RMF asks for use-case-specific Profiles.</strong> An organization deploying both a recommendation engine and a clinical decision support system needs two different Profiles, not one. ISO 27001&#8217;s Statement of Applicability operates at the organizational level rather than on a per-use-case basis, so this is new ground for practitioners coming from ISO 27001.</p><p><strong>ISO 42001 has an outward-facing AI System Impact Assessment (clause 6.1.4) with no clean 27001 analog.</strong> Internal risk assessment looks at consequences for the organization. Impact assessment looks at consequences for individuals, groups, and societies external to it. The closest 27001 analog is supplier risk, but it isn&#8217;t the same shape.</p><p><strong>Annex A is leaner than 27001&#8217;s.</strong> 38 controls across 9 categories versus 27001&#8217;s 93. Lean by design, but it places more weight on the auditor's and implementer's judgment in the SoA. Two 42001-conformant organizations with identical risk profiles can end up with materially different control sets.</p><p><strong>A climate change clause.</strong> ISO 42001 clause 4.1 requires the organization to determine whether climate change is a relevant issue. Inherited from a harmonized update that flowed through 27001, 9001, and other ISO management system standards in 2023 and 2024. The energy footprint of large-model training and inference makes this a real audit-interpretation question, not a paper one.</p><p><strong>NIST has a dedicated Generative AI Profile (AI 600-1).</strong> ISO 42001 is a general-purpose standard. If your AI estate is mostly GenAI, AI 600-1&#8217;s 12 GAI-specific risks give you a more specific risk taxonomy than Annex A does.</p><h2>Which to lead with</h2><p><strong>Lead with NIST AI RMF when</strong> your audience is the engineering organization, your regulatory exposure is U.S.-centric, or you want internal risk discipline before external proof. NIST is free, easy to adopt as a taxonomy, and doesn&#8217;t require a relationship with an audit body.</p><p><strong>Lead with ISO 42001 when</strong> your audience includes procurement, customers, or regulators seeking third-party assurance. When your exposure is EU AI Act-adjacent. When you already have ISO 27001, 9001, or 14001 certified, the harmonized structure makes 42001 a meaningfully smaller delta than going greenfield. ISO 42001 is the path to a certificate. NIST AI RMF is the path to a self-attestation document.</p><p>The pattern teams might settle into is to implement NIST first to establish the taxonomy and lifecycle discipline, then layer ISO 42001 certification on top once the documentation work is complete. According to a Modulos vendor blog (April 2026), teams that go in this order find 42001 certification work substantially easier to land. Caveat worth flagging: Modulos sells an AI governance platform that supports both frameworks, so the framing is shaped by their product, but the structural claim still holds.</p><h2>What doesn&#8217;t map cleanly?</h2><p><strong>NIST AI RMF cannot be audited.</strong> Self-attestation only. If a customer asks for proof, you have your documentation, not a certificate, and of course, ISO 42001 is the path to that certificate.</p><p><strong>Both frameworks predate widespread agentic AI deployment, but their structure was built to flex.</strong> NIST AI 100-1 is January 2023. ISO 42001 is December 2023. Neither directly names the agent stack (multi-agent systems, persistent memory, tool-using agents). In practice, organizations map agentic behaviors onto existing requirements rather than waiting for explicit agent text. ISO 42001&#8217;s risk assessment (clause 6.1.2) and AI system impact assessment (clause 6.1.4) evaluate the degree of autonomy and identify agent-specific risks like prompt injection. Annex A.9 (Use of AI systems) covers responsible-use processes, including human-oversight controls for high-risk agentic workflows. A.6.2.8 (AI system recording of event logs) becomes the audit trail for agent reasoning. A.6.2.6 (AI system operation and monitoring) becomes the drift-detection discipline. Extension frameworks like CSA MAESTRO and the OWASP Agentic Top 10 add technical depth on agent-specific threats, but the management system architecture for governing them is already in 42001.</p><p><strong>The decommissioning gap is the clearest difference.</strong> NIST AI RMF treats the safe retirement of AI systems as a separate step. ISO 42001 doesn&#8217;t have a dedicated decommissioning control. End-of-life gets folded into broader operation and monitoring work. If you run AI systems where retirement has real consequences (regulated industries, customer-facing deployments, and expensive trained models), you&#8217;ll need to build your own decommissioning process beyond what Annex A asks for.</p><p><strong>BS ISO/IEC 42006:2025 is the AI audit qualification standard.</strong> Published by BSI in July 2025. When selecting a certification body for ISO 42001, ask whether their auditors are qualified under 42006. For CISSPs considering an AI audit as a career path, this is the named qualification track.</p><h2>Monday morning</h2><p>If you have an existing ISO 27001 SoA template, pull it. Sit down with the ISO 42001 Annex A controls list. For each of the 38 controls, note &#8220;we do this already / we partially do this / we don&#8217;t do this.&#8221; That 30-minute paper exercise becomes the foundation for an eventual real SoA.</p><p>If you don&#8217;t have a 27001 SoA in your toolkit, start with NIST AI RMF. Read the four functions. Run a one-page self-assessment of where your organization sits on the four Tiers. Two hours of work that helps create a defensible baseline.</p><p>A common implementation failure is starting both frameworks at once and finishing neither. Pick one to lead with, document the decision, and revisit in six months.</p><p>Your CISSP doesn&#8217;t make you an AI governance expert. It makes you the person whose existing risk discipline transfers fastest to the new problem. The frameworks are different. The job is the same.</p><div><hr></div><h2>Sources</h2><p><strong>Primary standards and frameworks</strong></p><ul><li><p>ISO/IEC 42001:2023, <em>Information technology, Artificial intelligence, Management system</em>. ISO/IEC JTC 1 / SC 42, December 2023. <a href="https://www.iso.org/standard/42001">https://www.iso.org/standard/42001</a></p></li><li><p>ISO/IEC 27001:2022, <em>Information security, cybersecurity and privacy protection, Information security management systems, Requirements</em>. ISO/IEC JTC 1 / SC 27, October 2022. <a href="https://www.iso.org/standard/27001">https://www.iso.org/standard/27001</a></p></li><li><p>ISO/IEC 27006:2015 (and revisions), <em>Requirements for bodies providing audit and certification of information security management systems</em>. ISO/IEC JTC 1 / SC 27. <a href="https://www.iso.org/standard/27006">https://www.iso.org/standard/27006</a></p></li><li><p>ISO/IEC 42006:2025, <em>Information technology, Artificial intelligence, Requirements for bodies providing audit and certification of artificial intelligence management systems</em>. ISO/IEC JTC 1 / SC 42, published September 4, 2025. <a href="https://www.iso.org/standard/42006">https://www.iso.org/standard/42006</a>. National adoption available as BS ISO/IEC 42006:2025 via BSI: <a href="https://knowledge.bsigroup.com/products/information-technology-artificial-intelligence-requirements-for-bodies-providing-audit-and-certification-of-artificial-intelligence-management-systems">https://knowledge.bsigroup.com/products/information-technology-artificial-intelligence-requirements-for-bodies-providing-audit-and-certification-of-artificial-intelligence-management-systems</a></p></li><li><p>NIST AI 100-1, <em>Artificial Intelligence Risk Management Framework (AI RMF 1.0)</em>. National Institute of Standards and Technology, January 26, 2023. <a href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf">https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf</a></p></li><li><p>NIST AI RMF Playbook (companion to AI 100-1, 72 subcategories with suggested actions). <a href="https://airc.nist.gov/AI_RMF_Knowledge_Base/Playbook">https://airc.nist.gov/AI_RMF_Knowledge_Base/Playbook</a></p></li><li><p>NIST AI 600-1, <em>Generative AI Profile</em>. NIST, July 2024. <a href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf">https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf</a></p></li><li><p>EU AI Act, Regulation (EU) 2024/1689. Entered into force 1 August 2024. </p></li></ul><p>https://artificialintelligenceact.eu/</p><p><strong>Survey and reference data</strong></p><ul><li><p>ISO/IAF CASCO, <em>The ISO Survey of Management System Standard Certifications, 2024, Explanatory Note</em>. September 2025. <a href="https://iafcertsearch.org/services/iso-survey">https://iafcertsearch.org/services/iso-survey</a></p></li><li><p>ISC2 Cybersecurity Workforce Study (2025) and Exam Guidance for AI (April 2, 2026), via ISC2 Insights. <a href="https://www.isc2.org/research">https://www.isc2.org/research</a></p></li></ul><p><strong>Secondary commentary (with vendor caveats)</strong></p><ul><li><p>Modulos, <em>NIST AI Risk Management Framework: the engineering spec for AI risk</em>. Vendor blog, April 17, 2026. (Modulos sells an AI governance platform supporting both frameworks, and the framing reflects that.)</p></li><li><p><em>NIST AI RMF to ISO/IEC FDIS 42001 AI Management system Crosswalk</em>. Community-submitted, hosted on NIST AI Resource Center. PDF: <a href="https://airc.nist.gov/docs/NIST_AI_RMF_to_ISO_IEC_42001_Crosswalk.pdf">https://airc.nist.gov/docs/NIST_AI_RMF_to_ISO_IEC_42001_Crosswalk.pdf</a>. Listed on the AIRC crosswalks page: <a href="https://airc.nist.gov/airmf-resources/crosswalks/">https://airc.nist.gov/airmf-resources/crosswalks/</a>. NIST hosts but does not endorse the crosswalk. FDIS-stage clause references predate the December 2023 ISO/IEC 42001:2023 publication.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[NIST AI RMF: Govern, Map, Measure, Manage Explained]]></title><description><![CDATA[The NIST AI Risk Management Framework is the US government's recommendation for organizations seeking a structured approach to AI risk.]]></description><link>https://blog.balancedsec.com/p/original-inside-the-nist-ai-risk</link><guid isPermaLink="false">https://blog.balancedsec.com/p/original-inside-the-nist-ai-risk</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 01 May 2026 13:03:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9Oyr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The <a href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf">NIST AI Risk Management Framework</a> is the US government's recommendation for organizations seeking a structured approach to AI risk. It was published in January 2023, mandated by the National AI Initiative Act of 2020, and developed through a public consultation process that ran through early 2023.</p><p>The framework is voluntary and non-certifiable. Nobody can audit you against it, and you can self-claim alignment, which is where&nbsp;<a href="http://iso.org/standard/81230.html">ISO 42001</a>&nbsp;comes in as the certifiable counterpart. What RMF gives you is a shared vocabulary. </p><p>NIST also publishes a companion document called the <a href="https://airc.nist.gov/airmf-resources/playbook/">AI RMF Playbook</a>. The framework itself is about 40 pages of principles. The Playbook runs over 140 pages of suggested actions, transparency questions, and reference resources for each piece of the framework. If you only read the framework, you get the abstractions, while most of the operational guidance is in the Playbook.</p><p>This article walks through the four functions at the heart of the framework, using Playbook content to sharpen what each function actually requires.</p><p></p><h2>The four functions at a glance</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9Oyr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9Oyr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!9Oyr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!9Oyr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!9Oyr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9Oyr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5183828,&quot;alt&quot;:&quot;Diagram of the four core functions of the NIST AI RMF 1.0, GOVERN, MAP, MEASURE, and MANAGE, with the sub-activities of each.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/196022341?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram of the four core functions of the NIST AI RMF 1.0, GOVERN, MAP, MEASURE, and MANAGE, with the sub-activities of each." title="Diagram of the four core functions of the NIST AI RMF 1.0, GOVERN, MAP, MEASURE, and MANAGE, with the sub-activities of each." srcset="https://substackcdn.com/image/fetch/$s_!9Oyr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!9Oyr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!9Oyr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!9Oyr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e12c36-edab-4989-baf1-34cba19e2dd1_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The NIST AI RMF organizes everything around four functions: GOVERN, MAP, MEASURE, and MANAGE. They aren&#8217;t sequential steps. They&#8217;re roles in a system that runs continuously.</p><p>GOVERN sits across the whole framework. It&#8217;s the organizational foundation: policies, accountability, culture, and oversight that make the other three functions possible. MAP, MEASURE, and MANAGE, then run in a loop. MAP establishes the context for understanding a specific AI system. MEASURE tests it against the trustworthiness characteristics NIST defines. MANAGE turns those measurements into prioritization decisions, kill-switch procedures, and disclosures to affected parties. The outputs of all three feed back into GOVERN, which uses them to update policies, roles, and culture over time. The framework is iterative, not linear.</p><p>Here is what each function covers:</p><ul><li><p><strong>GOVERN (cross-cutting).</strong> Cultivates a risk-aware culture. Key elements: policies and processes, accountability, workforce diversity, organizational culture, engagement with AI actors, and third-party and supply-chain oversight.</p></li><li><p><strong>MAP (framing).</strong> Establishes context and identifies risks before they can be measured. Key elements: context, system categorization, capabilities and goals, risk and benefit mapping, and impact characterization.</p></li><li><p><strong>MEASURE (analysis).</strong> Analyzes and monitors AI risks. Key elements: methods and metrics, evaluation of trustworthy characteristics, risk tracking, and efficacy feedback.</p></li><li><p><strong>MANAGE (response).</strong> Prioritizes and responds to what MAP and MEASURE surface. Key elements: prioritization and response, benefit and impact strategies, third-party management, and risk treatment and communication.</p></li></ul><h2>GOVERN</h2><p>GOVERN is where the framework starts and where most organizations underinvest. It&#8217;s the function that establishes who&#8217;s responsible for what, what risks the organization is willing to take, how AI work fits into existing accountability structures, and how culture supports raising concerns rather than burying them.</p><p>Two concrete examples make GOVERN tangible. First, NIST requires you to maintain an inventory of your AI systems, with a named individual or team responsible for keeping it up to date. This is the AI equivalent of a CMDB (Configuration Management Database). Right now, most teams don&#8217;t have one, but I don&#8217;t think the reason is laziness. Employees are provisioning AI agents through personal accounts and unmonitored API integrations faster than any central registry can keep up. When you connect an AI agent to Google Drive or Slack via MCP, the OAuth prompt goes to the individual employee. The result is direct app-to-app access that bypasses the corporate identity provider entirely, leaving the security team with no visibility into what was authorized or by whom. You can&#8217;t manage what you haven&#8217;t cataloged, and you can&#8217;t catalog what was provisioned without you.</p><p>Second, NIST requires a written policy for the safe decommissioning of AI systems before you deploy them. The Playbook lists what those policies must address: user and community concerns; business continuity and financial risks; upstream and downstream system dependencies; regulatory requirements, such as data retention; future legal or forensic investigations; reputational risk; and migration to a replacement system. NIST treats decommissioning as a governance decision. Engineering executes the policy.</p><p>Governance gaps here invalidate downstream measurements. If you don&#8217;t know what you&#8217;re running, you can&#8217;t understand/measure/secure it.</p><h2>MAP</h2><p>MAP is about context. Before you measure an AI system&#8217;s performance or risk, you have to understand what it&#8217;s supposed to do, who&#8217;s affected by it, where it operates, and what the organization considers an acceptable level of risk for that deployment.</p><p>The most operationally important piece of MAP is risk tolerance. NIST requires you to determine and document organizational risk tolerances before deployment. The Playbook makes this concrete by requiring maximum allowable risk thresholds above which the system won&#8217;t be deployed (or will need to be decommissioned), with explicit criteria established in advance. Production AI deployments that don&#8217;t have this end up making risk decisions after the fact, when problems surface, rather than before, when the criteria can be set without pressure.</p><p>MAP also begins the stakeholder picture. NIST names &#8220;affected communities&#8221; (i.e., people who will be impacted by the system but don&#8217;t use it directly) as required participants in establishing system context (MAP 1.6) and in evaluating benefits and costs (MAP 3.1, MAP 3.2). The operational consultation work happens later, in MEASURE.</p><p>If GOVERN is the substrate, MAP is the framing. You can&#8217;t measure what you haven&#8217;t framed.</p><h2>MEASURE</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JFk0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JFk0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png 424w, https://substackcdn.com/image/fetch/$s_!JFk0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png 848w, https://substackcdn.com/image/fetch/$s_!JFk0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png 1272w, https://substackcdn.com/image/fetch/$s_!JFk0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JFk0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png" width="1200" height="775" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:775,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:124073,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/196022341?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JFk0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png 424w, https://substackcdn.com/image/fetch/$s_!JFk0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png 848w, https://substackcdn.com/image/fetch/$s_!JFk0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png 1272w, https://substackcdn.com/image/fetch/$s_!JFk0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79493a06-b468-4e30-a16e-95aedc29a7a0_1200x775.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>MEASURE is the largest function in the framework and the most technically detailed. It evaluates an AI system against seven trustworthiness characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.</p><p>The seven sound abstract until you read what they require. Take &#8220;secure and resilient.&#8221; Traditional cybersecurity controls aren&#8217;t enough for AI. The Playbook names specific operational metrics such as &#8220;time-to-bypass&#8221; (how long it takes a determined attacker to defeat the system&#8217;s safeguards), red-team exercise frequency, and anomalous event rates. For per-vulnerability severity scoring, <a href="https://aivss.owasp.org/">OWASP&#8217;s AIVSS</a> extends CVSS v4.0 with an agentic uplift model that handles prompt injection and model jailbreaks. NIST&#8217;s contribution in MEASURE 2.7 is the operational test-and-measurement side, which AIVSS doesn&#8217;t cover.</p><p>MEASURE also distinguishes between transparency, explainability, and interpretability. They sound similar and get used interchangeably, but they mean different things. Transparency is what happened (visible outputs and audit trails). Explainability is how the model reached a decision. Interpretability is whether the explanation actually means something to the person reading it. A model can be technically explainable to a data scientist while being completely uninterpretable to the loan applicant whose application it just denied.</p><p>MEASURE is also where NIST widens the stakeholder picture from MAP. The Playbook is specific about where this shows up. Fairness metrics for MEASURE 2.11 are to be developed &#8220;in collaboration with affected communities.&#8221; MEASURE 3.3 requires feedback processes for impacted communities to report problems and unexpected behaviors. These are people affected by the system who don&#8217;t use it directly, such as loan applicants under an automated underwriting model or job candidates screened by a resume parser. </p><p>This is where most of the technical AI risk work lives.</p><h2>MANAGE</h2><p>MANAGE is where measurements become organizational action. Two requirements stand out.</p><p>First, NIST requires established procedures for superseding, disengaging, or deactivating AI systems that demonstrate performance or outcomes inconsistent with their intended use. This is the <em>kill switch</em>. The Playbook requires you to identify the incident thresholds that trigger deactivation, plan for redundant systems to ensure continuity when the AI is offline, and review the procedures regularly. This is likely another production AI deployment area that&#8217;s deficient for many companies.</p><p>Second, NIST requires a database of reported errors, near-misses, incidents, and negative impacts, with date reported, impact assessment, and responses. Plus a separate database of system changes, with rationale, test procedures, and version history. This is the AI equivalent of a vulnerability tracker and a change log. Industry references already exist for what these look like at scale: the <a href="http://avidml.org">AI Vulnerability Database</a> catalogs failures across the AI ecosystem, and <a href="https://blog.balancedsec.com/p/mitre-atlas-the-ai-threat-framework">MITRE ATLAS</a> maps the adversarial TTPs that incidents are likely to fall under.</p><p>MANAGE is where the framework meets production reality, and where the Playbook&#8217;s content gets the most operationally specific.</p><h3>Is there a NIST AI RMF 2.0 or a 2026 version?</h3><p>Short answer: no. As of 2026, AI RMF 1.0 (NIST AI 100-1, January 2023) is still the current core framework. NIST has said the framework is being revised, but no 2.0 has been released.</p><p>What confuses a search is that NIST extends the framework through Profiles, not new version numbers. The <a href="https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence">Generative AI Profile (NIST AI 600-1, July 2024)</a> applies the four functions to generative AI risk, and that is the document most people mean when they ask about a &#8220;2024 version.&#8221; <a href="https://www.nist.gov/programs-projects/concept-note-ai-rmf-profile-trustworthy-ai-critical-infrastructure">A Trustworthy AI in Critical Infrastructure Profile</a> followed as a concept note in April 2026. So if you see &#8220;2023,&#8221; &#8220;2026,&#8221; or &#8220;1.0&#8221; attached to the same four functions, they all point back to the same core document, and the functions themselves have not changed.</p><h2>How to use this if you&#8217;re leading an AI initiative</h2><p>Read NIST AI RMF as an engineering spec, not a compliance document. Voluntary and non-certifiable looks like a weakness if you&#8217;re looking for something to audit against. It looks different if you&#8217;re looking for a complete public taxonomy of AI risk work, which is what RMF actually is. The depth is hard to recreate in private, which is why US financial regulators have built directly on it. </p><p>The&nbsp;<a href="https://cyberriskinstitute.org/artificial-intelligence-risk-management/">Financial Services AI RMF</a>, released by the Cyber Risk Institute in February 2026 and backed by the US Treasury and over 100 financial institutions, layers 230 control objectives onto NIST&#8217;s structure.</p><p>Practically, the framework is most useful as a structural vocabulary for cross-team conversations. It gives you a way to ask &#8220;what&#8217;s our documented risk tolerance for this deployment&#8221; or &#8220;do we have a decommissioning policy&#8221; without having to re-explain what an &#8220;AI risk&#8221; even means.</p><p>It&#8217;s not a checklist. The implementation tiers are directional rather than scored, and there is no audit procedure to certify which tier you&#8217;re at.</p><p>The Playbook is where value compounds, but you don&#8217;t have to read 140 pages cover to cover. Pull from it when you have a specific decision to make, like setting up an incident database or defining a kill-switch procedure. The framework points you at the question. The Playbook helps you build the answer.</p><p>One piece of practitioner advice worth ending on. The framework presents GOVERN first, but experienced implementers often suggest starting with MAP instead. Governance written without a current inventory governs imaginary systems. Run a discovery sprint first. Inventory the AI you&#8217;re already running, including the SaaS features that quietly added AI and the agents operating under employee credentials. Then write the GOVERN layer with specific reference to what you found. Your decision-rights matrix is a different document when &#8220;Slack now ships an AI summarizer that twelve of our teams use&#8221; is in the inventory.</p><p>Both documents are at <a href="https://www.nist.gov/itl/ai-risk-management-framework">nist.gov/itl/ai-risk-management-framework</a>.</p><h3>Frequently asked questions</h3><p><strong>What are the four functions of the NIST AI RMF?</strong><br>Govern, Map, Measure, and Manage. Govern is cross-cutting, and the other three run in rough lifecycle order.</p><p><strong>Is the NIST AI RMF mandatory?</strong><br>No. It is voluntary, non-certifiable, and not sector-specific. It carries weight in US regulatory and procurement settings because of NIST&#8217;s authority, the same way the NIST Cybersecurity Framework became a de facto standard.</p><p><strong>What is the difference between NIST AI RMF and ISO 42001?</strong><br>NIST AI RMF is a voluntary framework for how to manage AI risk. ISO/IEC 42001 is a certifiable management system you can be audited against. Many teams use NIST for the risk taxonomy, then map to ISO 42001.</p><p><strong>Does Govern come first?</strong><br>It is listed first because it is cross-cutting, but many practitioners start with Map so governance reflects a real inventory of AI systems.</p><p><strong>Is there a NIST AI RMF for generative AI?</strong><br>Yes. The Generative AI Profile (NIST AI 600-1, July 2024) applies the four functions to generative AI risk.</p>]]></content:encoded></item><item><title><![CDATA[AI Security for the CISSP: What’s Changed and How to Prepare]]></title><description><![CDATA[On April 2, 2026, ISC2 published the Exam Guidance for Artificial Intelligence, a 25-page document that maps how AI security concepts are woven into each of its nine certification exams.]]></description><link>https://blog.balancedsec.com/p/ai-security-for-the-cissp-whats-changed</link><guid isPermaLink="false">https://blog.balancedsec.com/p/ai-security-for-the-cissp-whats-changed</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 24 Apr 2026 13:03:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nkqm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On April 2, 2026, ISC2 published the <em><a href="https://www.isc2.org/Insights/2026/04/ISC2-Publishes-Exam-Guidance-AI">Exam Guidance for Artificial Intelligence</a></em>, a 25-page document that maps how AI security concepts are woven into each of its nine certification exams. If you&#8217;re studying for the CISSP (or maintaining your certification through CPEs), this document provides some insights into the way AI security is incorporated into the CISSP.</p><p>The <a href="https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline">CISSP exam outline,</a>&nbsp;which has been in effect since April 15, 2024, already includes some AI-specific references in several domain objectives. ISC2 didn&#8217;t bolt on a new &#8220;AI Security&#8221; domain. Instead, they distributed AI concepts throughout the existing structure, as they&#8217;ve always handled emerging technology. The difference this time is scale because AI touches every domain, and the Exam Guidance makes that explicit.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Here&#8217;s my take on what changed, and what you need to know.</p><h2>The Dual Pattern</h2><p>Across all eight CISSP domains, AI shows up in two ways:</p><ol><li><p><strong>AI as a system that needs to be secured.</strong> Protecting models, training data, and AI infrastructure from attack: think data poisoning, prompt injection, adversarial inputs, and model theft.</p></li><li><p><strong>AI as a tool you use for defense.</strong> SIEM/SOAR automation, behavioral analytics, anomaly detection, and AI-powered vulnerability scanning.</p></li></ol><p>Understanding which one is being asked will help you reason through unfamiliar scenarios on the exam.</p><h2>What&#8217;s New in Each Domain</h2><p>Here are some AI-related concepts from each domain that I think are the most likely to feel new or foreign to CISSP candidates.</p><h3>Domain 1: Security and Risk Management</h3><p><strong>The new concept: AI supply chain risk.</strong></p><p>You already know third-party risk management. The AI version asks the same governance questions, but about different things. Where does the training data come from? What model is your vendor using, and who trained it? What happens when the model is updated and its behavior changes? CISSPs are now expected to assess AI service providers with the same rigor applied to any critical vendor. The questions are different (data provenance, bias documentation, model transparency), but the framework is the one you already know from Domain 1.</p><h3>Domain 2: Asset Security</h3><p><strong>The new concept: AI-specific asset classification.</strong></p><p>Training datasets, pre-trained models, and model weights are now assets that need to be classified and protected. A pre-trained model is intellectual property. A training dataset may contain PII that triggers privacy mandates. Model weights are a theft target. If your organization&#8217;s data classification scheme doesn&#8217;t account for these asset types, it has a gap.</p><h3>Domain 3: Security Architecture and Engineering</h3><p><strong>The new concept: Prompt injection as an architectural concern.</strong></p><p>This is the domain where the technical specifics of AI attacks intersect with traditional security architecture. Prompt injection is the AI equivalent of SQL injection: untrusted input that manipulates the system&#8217;s behavior. But the defense isn&#8217;t just input validation. It includes architectural decisions about model isolation, output verification, and Explainable AI (XAI), which is the ability to audit why a model produced a specific output. ISC2 frames XAI as a security architecture requirement, not just a nice-to-have.</p><h3>Domain 4: Communication and Network Security</h3><p><strong>The new concept: Network segmentation for AI workloads.</strong></p><p>AI training clusters generate traffic patterns distinct from those of standard enterprise applications and pose unique lateral movement risks. The exam outline now expects CISSPs to understand micro-segmentation and Zero Trust Architecture as applied to AI environments. The goal is the same as always (prevent lateral movement from a compromised interface), but the specific architecture for isolating AI training environments from production networks is new territory.</p><h3>Domain 5: Identity and Access Management</h3><p><strong>The new concept: Non-Human Identity (NHI) governance.</strong></p><p>This one is significant. The CISSP now covers managing identities for AI agents and automated service accounts. That means understanding how to apply the Principle of Least Privilege to a system that might try to escalate its own permissions during learning or execution. It also means understanding the dual problem: you&#8217;re securing the AI&#8217;s identity (what credentials it has, who owns them, and whether it can escalate) while also using AI to make IAM more resilient (behavioral biometrics, adaptive authentication, anomaly detection in login patterns).</p><p>But credential controls alone don&#8217;t solve the problem. As <a href="https://www.linkedin.com/posts/resilientcyber_theres-a-dangerous-assumption-gaining-traction-ugcPost-7452329750947246080-DF78?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAA5wDgBdpFuaomSU0ve-kF8UXFlJvShH8E">Chris Hughes points out</a>, agents don&#8217;t just exist as identities. They use identities to take action. An agent manipulated at runtime through prompt injection or a poisoned tool response will request access through valid paths, receive a properly scoped token, and act exactly as policy allows. Every identity control passes. The breach still happens. The threat model has shifted from &#8220;who holds the key&#8221; to &#8220;who is influencing the decision,&#8221; and static permission models weren&#8217;t designed to answer the latter.</p><p>For context on why this matters: a <a href="https://cloudsecurityalliance.org/press-releases/2026/01/27/79-of-it-pros-feel-ill-equipped-to-prevent-attacks-via-nhi-csa-oasis-survey-finds">2025 CSA survey</a> of 383 security professionals found that only 8% were highly confident their legacy IAM tools could handle AI and NHI risks. Only 22% had formal policies for creating or removing AI identities. Making this more than a hypothetical gap.</p><h3>Domain 6: Security Assessment and Testing</h3><p><strong>The new concept: Red teaming for AI systems.</strong></p><p>Traditional penetration testing looks for software bugs and misconfigurations. AI red teaming tests different things: model robustness against evasion attacks, susceptibility to training data extraction, and &#8220;logic flaws&#8221; in the model&#8217;s output that an adversary could exploit. The Exam Guidance makes clear that CISSPs should understand these as distinct assessment methodologies, not just variations of traditional pen testing.</p><h3>Domain 7: Security Operations</h3><p><strong>The new concept: Model drift as a security operations concern.</strong></p><p>Model drift is what happens when an AI model&#8217;s performance degrades over time. Data scientists have always cared about this. What&#8217;s new is ISC2 framing it as a security operations problem. A model that&#8217;s drifting might be degrading naturally or under adversarial influence. SOC teams need to monitor AI systems as production assets, watching for drift as a potential indicator of compromise rather than just a performance issue.</p><h3>Domain 8: Software Development Security</h3><p><strong>The new concept: AI-generated code risks.</strong></p><p>As organizations adopt AI-generated code to an ever-larger degree, the CISSP is emphasizing the role of security in understanding specific risks. Hallucinated dependencies, where AI references packages that don&#8217;t exist (and an attacker creates a malicious package with that name). Insecure defaults in generated code. Leaked training data in code suggestions. And the AI/ML supply chain: the security of the ML libraries and frameworks your software depends on.</p><h2>How to Prepare</h2><p>If you&#8217;re studying for the CISSP right now, here&#8217;s some practical advice.</p><p><strong>Don&#8217;t panic about depth.</strong> The CISSP is a management-level certification. You don&#8217;t need to know how to build a prompt injection defense, but you need to understand that prompt injection exists, that it&#8217;s an architectural concern, and that the defense involves input validation, model isolation, and output verification. As with other topics, you need to know <em>what</em> and <em>why</em>, not <em>how to implement</em>.</p><p><strong>Distinguish the guidance from the outline.</strong> The Exam Guidance doesn&#8217;t always separate &#8220;the exam outline says this&#8221; from &#8220;here&#8217;s how to think about this in an AI context.&#8221; When it claims the outline integrates AI into shared responsibility models for cloud-based AI services, it&#8217;s most likely reading an AI lens onto an existing objective that already covers shared responsibility generally. The exam outline is the authoritative source for what&#8217;s explicitly tested. Read the Exam Guidance as an interpretive layer. It shows you how existing CISSP concepts apply to AI scenarios, rather than a guarantee that every domain now has standalone AI questions. To know what&#8217;s on the exam, check the outline. To understand how to think about it, read the guidance.</p><p><strong>Learn the vocabulary.</strong> Several AI concepts show up across multiple domains. If you understand these terms, you can reason through scenarios even if the specific question is unfamiliar:</p><ul><li><p><strong>Data poisoning:</strong> Corrupting training data to manipulate model behavior</p></li><li><p><strong>Model drift:</strong> Degradation of model performance over time (natural or adversarial)</p></li><li><p><strong>Prompt injection:</strong> Untrusted input that changes an AI system&#8217;s intended behavior</p></li><li><p><strong>Adversarial attacks:</strong> Inputs specifically crafted to cause model misclassification</p></li><li><p><strong>Non-Human Identity (NHI):</strong> Credentials used by AI agents and automated systems</p></li><li><p><strong>Explainable AI (XAI):</strong> The ability to understand and audit AI decision-making</p></li><li><p><strong>Shadow AI:</strong> Unauthorized use of public AI tools by employees</p></li></ul><p><strong>Map AI to frameworks you already know.</strong> The ISC2 Exam Guidance references several frameworks that connect AI security to traditional CISSP material:</p><ul><li><p><strong>NIST AI RMF (AI 100-1):</strong> The voluntary US framework for AI risk management. Four functions: Govern, Map, Measure, and Manage. This maps directly to Domain 1&#8217;s risk management concepts. If you understand NIST RMF, the structure is familiar.</p></li><li><p><strong>ISO/IEC 42001:</strong> The certifiable AI management system standard. Think of it as ISO 27001 for AI. If you understand the ISO 27001 PDCA cycle, you understand the structure of 42001.</p></li><li><p><strong>OWASP Top 10 for LLMs:</strong> The authoritative vulnerability taxonomy for LLM applications. Prompt injection is #1. If you know the traditional OWASP Top 10, this is the AI equivalent.</p></li></ul><p><strong>Use the dual pattern as a study filter.</strong> When you encounter an AI topic, ask yourself: Is this about securing an AI system or about using AI for defense? That distinction will help you orient quickly to exam questions.</p><p><strong>Read the Exam Guidance itself.</strong> It&#8217;s 25 pages, free, and directly from ISC2. The CISSP section is pages 8 through 10. It won&#8217;t tell you exactly what the exam will ask, but it tells you what ISC2 considers testable. That&#8217;s as close to a study guide as you&#8217;ll get from the source.</p><h2>The Bigger Picture</h2><p>ISC2 folded AI into every existing credential because that&#8217;s how AI works in practice. It isn&#8217;t a separate discipline. It changes how you manage risk, classify assets, design architecture, manage identities, test systems, run a SOC, and secure software.</p><p>The CISSP has always been about breadth. Knowing enough about every domain to make good security decisions. AI extends that expectation.</p><p>If you&#8217;re a current CISSP holder, <a href="https://blog.balancedsec.com/p/you-passed-the-cissp-heres-how-to">this is CPE territory</a>. Pick a framework (NIST AI RMF is a good starting point), learn the vocabulary, and start mapping AI risks to the domains you already understand. While the assets and threats may be different, the governance structure you&#8217;ve learned still applies.</p><p>ISC2 has built out a dedicated learning track for CISSP holders who want to go deeper. The <strong><a href="https://www.isc2.org/professional-development/certificates/build-ai-strategy">ISC2 AI Security Certificate</a></strong> is <a href="https://blog.balancedsec.com/i/190555750/the-credential-options">a standalone credential</a> covering AI attack recognition and mitigation, AI security framework comparisons, and strategies for balancing AI tools with human decision-making (essentially the layer above what the base CISSP AI integration requires). For something more targeted, the&nbsp;<strong><a href="https://www.isc2.org/landing/ai-security-skills#AI%20Express%20Courses">AI Security Express Courses</a></strong>&nbsp;cover specific topics like Generative AI, Secure Development, and AI Integration and Monitoring in a shorter format. If you have five or more years of experience and want to work through the strategic picture with peers, ISC2 also runs in-person and virtual <strong><a href="https://www.isc2.org/landing/ai-security-skills#AI%20Workshops">Securing AI Workshops</a></strong> designed for mid- and senior-level practitioners. The data support doing something: according to ISC2&#8217;s 2025 Cybersecurity Workforce Study, <a href="https://www.isc2.org/Insights/2026/03/how-can-cissps-learn-ai-security-skills">70% of CISSPs are already pursuing additional AI qualifications</a>. The professionals who close this gap now will be the ones asked to lead the governance conversations in their organizations.</p><p>If you&#8217;re a candidate, the governance frameworks you&#8217;re studying are the foundation for AI security. The risk management processes, classification schemes, access control principles, and assessment methodologies all apply. What&#8217;s new is the threat surface inside each one: the poisoning vectors, the non-deterministic outputs, the identity challenges that come with autonomous agents. The Exam Guidance information gives you a map of what to learn.</p><p>The structure you&#8217;ve studied is the starting point.</p><div><hr></div><p><em>CISSP relevance: All 8 domains. Domain 1 (AI governance, supply chain risk), Domain 2 (AI asset classification), Domain 3 (prompt injection, XAI), Domain 4 (AI network segmentation), Domain 5 (NHI governance), Domain 6 (AI red teaming), Domain 7 (model drift monitoring), Domain 8 (AI-generated code risks).</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nkqm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nkqm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png 424w, https://substackcdn.com/image/fetch/$s_!nkqm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png 848w, https://substackcdn.com/image/fetch/$s_!nkqm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!nkqm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nkqm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png" width="816" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:816,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113007,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/194949102?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nkqm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png 424w, https://substackcdn.com/image/fetch/$s_!nkqm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png 848w, https://substackcdn.com/image/fetch/$s_!nkqm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!nkqm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ef76cfb-329a-4cbd-83c9-69a2df8fdb49_816x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.balancedsec.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Cyber Leader - Balanced Security is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[A Security Guide for Building Agentic AI Applications]]></title><description><![CDATA[I&#8217;ve recently been spending time reading about agentic AI security frameworks such as MITRE ATLAS, MAESTRO, and the OWASP Agentic Top 10 to better understand how to build agentic systems more securely.]]></description><link>https://blog.balancedsec.com/p/a-security-guide-for-building-agentic</link><guid isPermaLink="false">https://blog.balancedsec.com/p/a-security-guide-for-building-agentic</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 17 Apr 2026 13:03:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!l_vj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6195d141-fbf4-433e-b86a-9b05860f1276_1938x1245.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve recently been spending time reading about agentic AI security frameworks such as MITRE ATLAS, MAESTRO, and the OWASP Agentic Top 10 to better understand how to build agentic systems more securely.</p><p>There are two specific guides that help answer that question more directly. The first is the <a href="https://genai.owasp.org">OWASP Securing Agentic Applications Guide</a> (80 pages, July 2025), an engineering manual from the same team behind the Agentic Top 10. The second is Casaba Security&#8217;s <a href="https://www.casaba.com/agentic-ai-security-guide/">Agentic AI Security Guide</a> (v1.2, April 2026), written by a penetration testing firm based on findings from actual engagements.</p><p>Between the two, you get both the framework and the field report. Here&#8217;s what I think matters, organized around the risks that show up in practice and the architectural decisions that address them.</p><h3>A useful starting point</h3><p>Before getting into specifics, one concept from the OWASP guide is worth mentioning first. The guide decomposes &#8220;an agent&#8221; into six Key Components (KC1 through KC6): the language model (KC1), orchestration and control flow (KC2), reasoning and planning (KC3), memory (KC4), tool integration (KC5), and the operational environment (KC6). Each has its own attack surface, and the risks below target specific components. This matters because you can&#8217;t secure a system you haven&#8217;t decomposed. I&#8217;m betting that teams mapping their agent to these six components will find gaps in KC4 (memory) and KC6 (operational environment), the components that existing threat models don&#8217;t cover well.</p><h2>Untrusted Data Reaching the Control Plane</h2><p>The risk that underlies almost everything else in agentic security is indirect prompt injection, what the research community calls XPIA. Most people think of prompt injection as a user typing something malicious into a chat box. The indirect version is harder to spot. The injection comes from the data the agent processes, not from the user: documents in RAG indices, tool outputs, emails, web pages, API responses, CRM records. Anywhere the agent reads untrusted data, an attacker can plant instructions.</p><p>Casaba breaks XPIA into four attack surfaces. Perception-layer injection hides instructions in content the agent ingests, but humans can&#8217;t see (e.g., CSS display: none, HTML comments, aria-label attributes). Research shows these alter agent outputs in <a href="https://arxiv.org/abs/2509.05831">15-29% of tested cases</a>. Instead of injecting explicit commands, the attacker fills the source content with confident, authoritative language that leans in a particular direction. The agent isn&#8217;t being told what to say. But when most of what it reads carries the same framing, its synthesis reflects that framing. There&#8217;s no payload to detect because the attack is in the aggregate rather than in any single document. </p><p>Memory and learning attacks corrupt stored context, so the compromise persists across sessions. Action-layer attacks embed explicit instruction sequences in external resources that, when ingested, override safety alignment.</p><p><strong>The architectural response: separate the data plane from the control plane.</strong> This is the single most important design decision. The OWASP guide highlights <a href="https://arxiv.org/abs/2503.18813">Google&#8217;s CaMeL</a> as the cleanest conceptual model. A privileged LLM receives only trusted inputs and generates control flow (which tools to call, in what order). A quarantined LLM processes untrusted data (web content, email bodies, retrieved documents) and has no access to tools. Prompt injection in a retrieved document hits the quarantined LLM, which can&#8217;t invoke tools. The injection has nowhere to go. CaMeL also isolates memory: the quarantined LLM&#8217;s context doesn&#8217;t leak into the privileged LLM&#8217;s memory, which prevents poisoned data from influencing future control flow decisions.</p><p>CaMeL remains a research architecture. A <a href="https://arxiv.org/abs/2505.22852">follow-up paper</a> (May 2025) adds prompt screening, tiered-risk access, and output auditing, but no production deployments have been published. What is shipping in production is the underlying principle: external enforcement layers that sit between the agent and its tools. <a href="https://www.globenewswire.com/news-release/2026/03/23/3260474/0/en/Check-Point-Launches-AI-Defense-Plane-to-Secure-the-Agentic-Enterprise-at-Scale.html">Check Points</a>, <a href="https://zenity.io/platform/ai-observability">Zenity&#8217;s runtime agent monitor</a>, <a href="https://github.com/lasso-security/mcp-gateway">Lasso Security&#8217;s MCP Gateway</a>, and <a href="https://airia.com/managing-ai-risk-first-third-party-agents/">Airia&#8217;s model-agnostic control plane </a>all enforce the same boundary: untrusted content can&#8217;t directly trigger tool invocations. They do it through runtime policy engines and gateways rather than a second LLM, but the design principle is identical.</p><p><strong>What to watch for:</strong> Any workflow where an agent retrieves or processes content from sources outside your direct control. Email summarizers, web research agents, document analyzers, RAG-based assistants. All are at high risk for XPIA.</p>
      <p>
          <a href="https://blog.balancedsec.com/p/a-security-guide-for-building-agentic">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Combining MAESTRO and ATLAS For AI Threat Modeling]]></title><description><![CDATA[My previous article covered MITRE ATLAS at some depth: what it is, why it matters, and how the maturity filter (Feasible, Demonstrated, Realized) makes it a practical prioritization tool rather than just a theoretical catalog.]]></description><link>https://blog.balancedsec.com/p/after-atlas-why-maestro-is-the-threat</link><guid isPermaLink="false">https://blog.balancedsec.com/p/after-atlas-why-maestro-is-the-threat</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 10 Apr 2026 13:03:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UMXh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>My <a href="https://blog.balancedsec.com/p/mitre-atlas-the-ai-threat-framework">previous article</a> covered <a href="https://atlas.mitre.org/">MITRE ATLAS</a> at some depth: what it is, why it matters, and how the maturity filter (Feasible, Demonstrated, Realized) makes it a practical prioritization tool rather than just a theoretical catalog. If you haven&#8217;t read it, the short version is that ATLAS gives security teams a structured vocabulary for AI-targeted attacks, grounded in what adversaries have actually done. Fifty of its 167 techniques have been confirmed or &#8220;Realized&#8221; (another 121 are rated but unconfirmed; 46 remain unrated). That&#8217;s the part worth holding onto with this article.</p><p>Because here&#8217;s what ATLAS doesn&#8217;t cover: it can&#8217;t tell you how an attack might unfold in a system you&#8217;re building or defending right now, especially if that system involves autonomous agents with persistent memory, tool access, and the ability to spawn sub-agents. For a traditional web application, a retrospective TTP catalog is usually enough. The architecture is stable, and past patterns predict future ones with reasonable accuracy. Agentic AI doesn&#8217;t behave that way. An autonomous agent that can browse the web, call external APIs, write files, and delegate tasks to other agents creates an attack surface that&#8217;s still generating its first wave of documented incidents. The ATLAS case study record hasn&#8217;t caught up with what&#8217;s already in production.</p><p>That&#8217;s where MAESTRO comes in.</p><h2>What MAESTRO Is and What Problem It&#8217;s Actually Solving</h2><p>MAESTRO (Multi-Agent Environment, Security, Threat, Risk, and Outcome) was <a href="https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro">published in February 2025 by Ken Huang</a>, co-chair of the CSA AI Safety Working Group. The framework&#8217;s central premise is that traditional threat modeling approaches weren&#8217;t designed for systems that make autonomous decisions, adapt behavior over time, and coordinate with other agents across trust boundaries.</p><p>That&#8217;s not a provocative claim. STRIDE models systems as static data flows between defined components (relying on Data Flow Diagrams to visualize a system at a specific point in time). PASTA&#8217;s attack simulation model assumes the system being analyzed has deterministic, bounded behavior, with no mechanism to represent a system that autonomously modifies its own goals or behavior at runtime. </p><p>Neither has a mechanism to address threats arising from goal misalignment, autonomous decision-making, or multi-agent collusion. A <a href="https://arxiv.org/abs/2508.10043">peer-reviewed 2025 study</a> (Zambare, Thanikella, and Liu at Texas Tech University) reviewed existing frameworks and directly confirmed the gap, noting that STRIDE &#8220;does not model emergent behavior, cognitive reasoning of AI agents very well.&#8221; The OWASP Agentic Security Initiative <a href="https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/">reached the same conclusion</a>, ultimately endorsing MAESTRO as a comprehensive extension of STRIDE for handling Agentic AI.</p><p>MAESTRO&#8217;s answer is a seven-layer reference architecture, each with its own mapped threat categories: Foundation Models (L1), Data Operations (L2), Agent Frameworks (L3), Deployment and Infrastructure (L4), Evaluation and Observability (L5), Security and Compliance as a vertical layer that cuts across all others (L6), and Agent Ecosystem (L7).</p><p>What that structure forces, and what classical frameworks don&#8217;t, is cross-layer analysis. Take a <a href="https://docs.langchain.com/oss/python/langchain/rag">LangChain-based agent with RAG</a> access. STRIDE treats it as a system with data flows. MAESTRO requires you to analyze it at L2 (the vector database is a poisoning surface), L3 (the framework itself is a supply chain risk), and L7 (the agent faces tool manipulation and identity attacks in the ecosystem it operates in). In other words, STRIDE asks, &#8220;Can someone tamper with the data moving through this system?&#8221; MAESTRO asks, &#8220;Can someone corrupt what the AI knows, compromise the tools it was built with, and manipulate who it trusts in the world it operates in,&#8221; and treats each of those as a separate, distinct problem requiring separate analysis.</p><p>Each layer carries its own threat categories, and a compromise in one doesn&#8217;t stay contained. <a href="https://arxiv.org/abs/2508.10043">Researchers at Texas Tech confirmed this empirically</a>: poisoning a single memory file in L2 caused measurable performance degradation in L4 and L5 without altering any system logic. In essence, someone edited a JSON file, inserting fake high-severity attack entries that the agent reads. The agent didn&#8217;t break, but it degraded silently. The attack entered at L2 (data operations &#8212; the memory file). It affected L3 (the tuning module changed its behavior). That caused resource exhaustion at L4 (infrastructure) and degraded observability at L5 (the monitoring system itself became less responsive). One layer&#8217;s compromise propagated through three others without directly touching any of them. STRIDE would model the JSON file as a data integrity issue at one point in the system. It wouldn&#8217;t predict that corrupting the file would degrade the monitoring infrastructure two layers away. </p><p>The striking fact is that a single JSON file with no code access caused an autonomous security agent to silently misjudge its environment and waste resources defending against nonexistent threats, while potentially missing those that did exist. </p><p>That&#8217;s the kind of threat STRIDE doesn&#8217;t surface. MAESTRO does.</p><h2>Where the Real Threats Live</h2><p>Not all seven layers carry equal risk. Three of them deserve immediate attention.</p><p>L2 (Data Operations) is where the most operationally mature threat activity currently resides. <a href="https://atlas.mitre.org/tactics/AML.TA0003">ATLAS&#8217;s Resource Development tactic</a> shows 9 of 13 rated techniques are &#8220;Realized&#8221;, meaning adversaries have already industrialized data poisoning against retrieval systems. Any organization running a production RAG pipeline should treat L2 threat modeling as urgent, and the Texas Tech cascade described above began here, with a single poisoned file.</p><p>L7 (Agent Ecosystem) is where agentic AI diverges most sharply from everything that came before. Agent impersonation, tool squatting, rug pull attacks against MCP integrations, and compromised discovery registries, none of which have classical equivalents. SesameOp (<a href="https://atlas.mitre.org/studies/AML.CS0042">ATLAS case study AML.CS0042</a>) confirmed adversaries are already using legitimate AI service APIs as covert C2 channels. That&#8217;s a fully &#8220;Realized&#8221; L7 attack chain. What makes L7 defense especially difficult is the governance baseline organizations are actually starting from. A <a href="https://cloudsecurityalliance.org/press-releases/2026/01/27/79-of-it-pros-feel-ill-equipped-to-prevent-attacks-via-nhi-csa-oasis-survey-finds">2025 CSA survey</a> of 383 IT and security professionals found that 51% have no clear ownership of AI identities, and over 16% don&#8217;t track when new AI credentials are created. MAESTRO&#8217;s L7 threat categories assume someone is watching the identity layer. Most organizations aren&#8217;t.</p><p>L1 (Foundation Models) receives less operational attention, but two threat classes are particularly relevant for compliance-sensitive environments. Backdoor attacks embed hidden triggers in fine-tuned models that remain dormant until a specific input activates them. Membership inference attacks let an adversary determine whether specific records were used in training. That&#8217;s a direct HIPAA or GDPR exposure for any organization fine-tuning on sensitive data.</p><h2>Using ATLAS and MAESTRO Together</h2><p>The two frameworks solve different parts of the same problem. MAESTRO generates a systematic threat list from the architecture up. ATLAS tells you which items on that list adversaries have confirmed in the wild. </p><p>The workflow that combines them is straightforward. Take each layer of your system and ask: what could go wrong here? That&#8217;s the MAESTRO step. Then check ATLAS for each threat you&#8217;ve identified: has anyone actually done this? If a technique is tagged &#8220;Realized,&#8221; it moves to the top of your risk register. If it&#8217;s &#8220;Demonstrated&#8221; or &#8220;Feasible,&#8221; it still matters, but it&#8217;s not yet confirmed in the wild. The <a href="https://cloudsecurityalliance.org/artifacts/agentic-ai-red-teaming-guide">CSA Agentic Red Teaming Guide</a> then provides concrete test procedures you can run against each layer to validate whether your system is actually exposed.</p><p>The Texas Tech study is the clearest argument for why you need both. The L2-to-L4/L5 cascade, the researchers confirmed, had no corresponding &#8220;Realized&#8221; ATLAS technique at the time of publication. MAESTRO predicted the attack class. ATLAS didn&#8217;t have the incident. That&#8217;s exactly where the combined methodology earns its keep.</p><p>One honest caveat: <a href="https://blog.balancedsec.com/i/192897012/the-maturity-slider-a-practical-prioritization-tool">46 of ATLAS&#8217;s 167 native techniques are unrated</a> (as of this writing), and most are newer agentic additions. The &#8220;Realized&#8221; filter works well for L2 and L4 threats. For L7, it&#8217;s less discriminating. Treat more L7 items as &#8220;Demonstrated&#8221; rather than &#8220;Realized&#8221; until the incident record catches up.</p><h2>What This Pairing Doesn&#8217;t Solve</h2><p>MAESTRO doesn&#8217;t yet have a formal specification. No versioning, no conformance testing, no defined scoring methodology that I could find. <a href="https://arxiv.org/abs/2603.23801">The AgentRFC framework from Dartmouth and Palo Alto Networks</a> produced companion security principles with formal conformance language. MAESTRO doesn&#8217;t operate at that level of rigor, and practitioners building repeatable assessment processes will hit that ceiling.</p><p>Both frameworks share a documented scope gap. <a href="https://atlas.mitre.org/resources/ai-security-101">ATLAS explicitly excludes malicious use of AI against non-AI targets</a>, and MAESTRO follows the same boundary. AI-enhanced phishing, AI-automated vulnerability discovery, and deepfake-assisted social engineering aren&#8217;t covered. If your threat model needs to include those vectors, you&#8217;re working outside both frameworks.</p><p>There&#8217;s also no native scoring engine. <a href="https://aivss.owasp.org/">OWASP&#8217;s Agentic Vulnerability Scoring System</a> needs to be applied separately for quantitative prioritization.</p><p>And the constraint that no framework resolves: the CSA NHI survey found only 8% of organizations are highly confident their legacy IAM can handle AI and NHI risks, and 24% take more than 24 hours to revoke a compromised credential after an exposure event. A rigorous threat model is only as useful as the organization&#8217;s ability to act on it. Closing that operational gap is a separate, harder problem.</p><h2>Where to Start</h2><p>The combined methodology reduces to three questions applied to any AI system your organization operates.</p><p>1. What does your AI system actually touch? Map your system against MAESTRO&#8217;s seven layers. In practice, this means listing: which foundation model you use (L1), what data sources feed it and where they&#8217;re stored (L2), which framework or platform it&#8217;s built on (L3), where it runs and who manages that infrastructure (L4), how you monitor its behavior and measure its performance (L5), and what external tools, APIs, or other agents it can access (L7). Many teams will discover layers they haven&#8217;t thought about as attack surfaces, particularly L2 (the data the AI trusts) and L7 (the tools and services it connects to).</p><p> 2. Which of those layers have confirmed attacks in the wild? Cross-reference your layer map against ATLAS. Start with L2: nine of thirteen techniques in ATLAS&#8217;s Resource Development tactic are &#8220;Realized,&#8221; meaning adversaries have demonstrated them in real incidents. If your AI system ingests external data &#8212; retrieval-augmented generation, fine-tuning on user data, or any pipeline that feeds information to the model &#8212; that&#8217;s your most evidence-backed risk. Any layer where ATLAS shows &#8220;Realized&#8221; techniques goes to the top of your risk register.</p><p> 3. Can you actually detect and respond if something goes wrong? This is where most organizations hit the real gap. MAESTRO&#8217;s L5 (Evaluation and Observability) asks whether your monitoring can detect a compromised AI agent, not just whether the system is up, but whether it&#8217;s making trustworthy decisions. And the governance question is unavoidable: the CSA NHI survey found 51% of organizations have no clear ownership of AI identities. If no one owns the AI identity layer, your threat model describes a problem that nobody is accountable for fixing. </p><p>For CISSP holders, questions 1 and 2 fall under Domain 1 (Security and Risk Management). Question 3 spans Domain 8 (Software Development Security) for the monitoring and testing controls, and Domain 1 again for the governance structure. The CSA Agentic Red Teaming Guide provides executable test procedures for each MAESTRO layer once you&#8217;ve completed the mapping.</p><p>Assign ownership first. Then model the threats.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UMXh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UMXh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png 424w, https://substackcdn.com/image/fetch/$s_!UMXh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png 848w, https://substackcdn.com/image/fetch/$s_!UMXh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png 1272w, https://substackcdn.com/image/fetch/$s_!UMXh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UMXh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png" width="1456" height="1594" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98405223-634b-4704-a225-02054a0206f2_3064x3354.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1594,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:611092,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/193506702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UMXh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png 424w, https://substackcdn.com/image/fetch/$s_!UMXh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png 848w, https://substackcdn.com/image/fetch/$s_!UMXh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png 1272w, https://substackcdn.com/image/fetch/$s_!UMXh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98405223-634b-4704-a225-02054a0206f2_3064x3354.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[MITRE ATLAS: The AI Threat Framework Every Security Leader Needs to Know ]]></title><description><![CDATA[In March 2016, Microsoft launched Tay, a Twitter-based chatbot designed to learn from conversations with users and respond in kind.]]></description><link>https://blog.balancedsec.com/p/mitre-atlas-the-ai-threat-framework</link><guid isPermaLink="false">https://blog.balancedsec.com/p/mitre-atlas-the-ai-threat-framework</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 03 Apr 2026 13:03:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AHMS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In March 2016, Microsoft launched Tay, a Twitter-based chatbot designed to learn from conversations with users and respond in kind. Within 24 hours, some Twitter users began trolling it, tweeting, among other things, politically incorrect phrases and sending it inflammatory messages until it began producing them on its own. Microsoft pulled the plug the next day.</p><p>The attack wasn&#8217;t sophisticated in any traditional sense. No CVE was exploited. No credentials were stolen. No network was breached. It was simply provided inputs through the interface the system was designed to accept, and the model&#8217;s own learning mechanism turned those inputs into a weapon against itself. If you tried to map that attack to MITRE ATT&amp;CK at the time, you&#8217;d come up empty. The attack surface wasn&#8217;t an endpoint or a network. It was the model&#8217;s relationship with its training data.</p><p>That gap, the space between what ATT&amp;CK covers and what AI systems actually expose, is exactly what <a href="http://atlas.mitre.org">MITRE ATLAS</a> was built to fill.</p><p>ATLAS stands for Adversarial Threat Landscape for Artificial-Intelligence Systems. It&#8217;s a structured knowledge base of adversary tactics, techniques, and real-world case studies specifically targeting AI and machine learning systems. Think of it as ATT&amp;CK&#8217;s purpose-built extension into territory that traditional threat frameworks never modeled: data pipelines, model architectures, inference APIs, and training processes. As of today, ATLAS documents 16 tactics and 167 techniques across 57 case studies, with 35 mapped mitigations, and the framework is actively growing.</p><p></p><h2>Where This Started</h2><p>ATLAS began in late 2020 as a collaboration between MITRE and Microsoft, with twelve industry and academic partners, under the blunter name Adversarial ML Threat Matrix. The original repository still lives at <a href="https://github.com/mitre/advmlthreatmatrix">github.com/mitre/advmlthreatmatrix</a>.</p><p>The project was justified by a pattern of high-profile ML failures. Google&#8217;s image recognition system was fooled by adversarial stickers. Amazon&#8217;s Alexa was triggered by ultrasonic commands embedded in bird chirps. Tesla&#8217;s Autopilot was steered into oncoming traffic by three small road stickers, at roughly $0 cost and without exploiting any software vulnerability. And then there was Tay. Four incidents, four companies, four different attack mechanisms, united only by the fact that the target in each case was the AI system&#8217;s behavior, not its infrastructure. A survey of 28 organizations conducted around the same time found that 25 of them didn&#8217;t know how to secure their ML systems. Industry wasn&#8217;t behind on patches. It was behind on the vocabulary needed to think about the problem systematically.</p><p>MITRE&#8217;s AI Security 101 resource at <a href="https://atlas.mitre.org/resources/ai-security-101">atlas.mitre.org/resources/ai-security-101</a> frames why AI attacks require a different analytical lens through three dimensions:</p><ul><li><p><strong>AI Access Time</strong> refers to whether an attack occurs during training, when the model is still being shaped by data, or during inference, when it&#8217;s responding to live queries. </p></li><li><p><strong>AI Access Points</strong> covers whether the adversary reaches the model digitally via an API or physically by modifying real-world inputs, such as a sticker on a road sign or a sound pattern near a microphone. </p></li><li><p><strong>System Knowledge</strong> covers whether the adversary has white-box access to the model architecture and weights or operates in a black-box manner, probing only the inputs and outputs via an API. Most real-world attacks are black-box, and adversaries have learned to do significant damage without ever seeing model weights.</p></li></ul><p>These three dimensions explain why AI attacks don&#8217;t map cleanly onto ATT&amp;CK. An adversary targeting an ML system doesn&#8217;t necessarily need a foothold on a server. API access and a few thousand queries may be enough.</p><h2>How ATLAS Builds on ATT&amp;CK</h2><p>ATLAS was consciously modeled on ATT&amp;CK: the same tactic-technique matrix structure, the same case-study grounding, and the same community contribution model. Security teams already know how to use ATT&amp;CK, and ATLAS doesn&#8217;t ask them to learn a new mental model, just extend an existing one.</p><p><a href="https://attack.mitre.org/">ATT&amp;CK Enterprise</a> has 14 tactics. <a href="https://atlas.mitre.org/matrices/ATLAS">ATLAS</a> has 16. Most overlap directly and are adapted to describe how familiar attack phases look when the target is an AI system. Two new tactics have no ATT&amp;CK equivalent.</p><p><strong>AI Model Access</strong> covers how adversaries reach the target model itself, through an inference API, a stolen artifact, or an offline copy built through iterative querying. You can&#8217;t run AI-specific attacks without first getting to the model in some form, and traditional attack chains have no equivalent requirement. Every technique under this tactic is ATLAS-native.</p><p><strong>AI Attack Staging</strong> is the most technically distinctive column in the matrix. It describes the preparation phase unique to AI attacks: crafting adversarial data, building proxy models for offline testing, and verifying that an attack works before deploying it against production. An adversary poisoning a production model doesn&#8217;t just submit corrupted data and hope. They build a local approximation, test inputs against it, refine until the attack reliably produces the desired output, then execute. Like AI Model Access, every one of AI Attack Staging&#8217;s entries is ATLAS-native. No equivalent exists in ATT&amp;CK because this class of preparation didn&#8217;t exist as a documented threat category before AI systems became production infrastructure.</p><p>Beyond the 167 ATLAS-native techniques, the matrix incorporates 98 ATT&amp;CK-adapted techniques that MITRE doesn&#8217;t count in its headline figure. Those inherited techniques carry a clear signal: when traditional TTPs appear in AI system attacks, adversaries are usually targeting the underlying infrastructure, API keys, data servers, and GPU compute, rather than the model itself. ATLAS doesn&#8217;t pretend that the threat disappears just because the target system has a neural network.</p><h2>Sixteen Tactics and a Prioritization Tool</h2><p>The 16 ATLAS tactics run left to right in rough attack-progression order, which can be read in four groups, which I&#8217;ll call preparation, establishment, exploitation, and objectives.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://atlas.mitre.org/matrices/ATLAS" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AHMS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png 424w, https://substackcdn.com/image/fetch/$s_!AHMS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png 848w, https://substackcdn.com/image/fetch/$s_!AHMS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png 1272w, https://substackcdn.com/image/fetch/$s_!AHMS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AHMS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png" width="1456" height="544" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:544,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:672270,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://atlas.mitre.org/matrices/ATLAS&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/192897012?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AHMS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png 424w, https://substackcdn.com/image/fetch/$s_!AHMS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png 848w, https://substackcdn.com/image/fetch/$s_!AHMS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png 1272w, https://substackcdn.com/image/fetch/$s_!AHMS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304bd7b2-33f4-4cd3-bd2b-d5764eb5288b_3364x1256.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>Preparation</strong> covers Reconnaissance, Resource Development, Initial Access, and AI Model Access. Reconnaissance in an AI attack might mean querying a public API to map model behavior or scraping job postings to identify what ML frameworks a target uses. <a href="https://atlas.mitre.org/tactics/AML.TA0003">Resource Development</a> covers building attack inputs, including poisoned datasets, crafted prompt libraries, and hallucinated entities published to contaminate retrieval systems. <a href="https://atlas.mitre.org/tactics/AML.TA0004">Initial Access</a> includes an AI supply chain compromise, prompt injection via public-facing applications, and phishing targeting engineers with access to the training infrastructure.</p><p><strong>Establishment</strong> covers Execution, Persistence, and Privilege Escalation. Persistence in an AI system looks different from traditional IT. An adversary might poison a RAG (Retrieval-Augmented Generation) knowledge base so that malicious content survives model updates. Or they embed a backdoor trigger in a fine-tuned model that stays dormant until a specific input activates it. For <a href="https://atlas.mitre.org/tactics/AML.TA0012">Privilege Escalation</a>, the two ATLAS-native techniques are AI Agent Tool Invocation and LLM Jailbreak. Both reflect the same underlying risk: an agentic AI system that can take actions on behalf of users becomes a potential bridge between a sandboxed AI environment and the resources beneath it.</p><p><strong>Exploitation</strong> covers Defense Evasion, Credential Access, Discovery, Lateral Movement, and Collection. <a href="https://atlas.mitre.org/tactics/AML.TA0007">Defense Evasion</a> is the most populated tactic in the matrix: 15 ATLAS-native techniques plus 26 ATT&amp;CK-adapted entries in that column, covering everything from AI supply chain reputation inflation to manipulating a user&#8217;s LLM chat history to cover attack traces.</p><p><strong>Objectives</strong> cover AI Attack Staging, Command and Control, Exfiltration, and Impact. <a href="https://atlas.mitre.org/tactics/AML.TA0010">Exfiltration</a> under ATLAS includes techniques specific to AI systems: extracting an LLM&#8217;s system prompt, inducing data leakage through crafted queries, or using model response rendering to exfiltrate information. <a href="https://atlas.mitre.org/tactics/AML.TA0011">Impact</a> includes Cost Harvesting and resource exhaustion attacks that inflate inference bills on a victim&#8217;s API account, alongside data destruction and service denial.</p><p>MITRE also publishes an <a href="https://atlas.mitre.org/knowledge-graph">ATLAS Knowledge Graph</a> that's worth bookmarking alongside the matrix. Where the matrix shows tactics and techniques in column-row format, the graph shows the relationships between them: how a technique connects to its mitigations, which case studies demonstrate it in practice, and how tactics link to one another across an attack chain. You can filter by entity type to focus on tactics and techniques or mitigations; search by ID when working with specific techniques; and enter focus mode on any node to expand its immediate network. For threat modeling, it's a faster way to answer "what mitigates this specific technique" than to navigate the matrix column by column. The graph was added in Website v4.12.0, alongside the Data v5.5.0 update in March 2026, and reflects the same 167 techniques, 35 mitigations, and 57 case studies cited throughout this article.</p><h3>The Maturity Slider: A Practical Prioritization Tool</h3><p>The live matrix includes a filter that deserves more attention than it typically gets. The maturity slider lets you filter techniques by evidence level across three tiers. <em>Feasible</em> means the technique works in a research setting. <em>Demonstrated</em> means it&#8217;s been proven in a red-team exercise or against a realistic AI system. <em>Realized</em> means a threat actor has used it in a confirmed real-world incident.</p><p>Of 167 ATLAS-native techniques, 121 carry a maturity rating. The remaining 46, mostly newer agentic AI additions, haven&#8217;t been assessed yet. Of the 121 rated techniques, 50 appear in the <em>Realized</em> tier.</p><p>Fifty techniques confirmed in actual threat-actor operations against AI systems. This isn&#8217;t theoretical anymore.</p><p>The distribution is instructive. <a href="https://atlas.mitre.org/tactics/AML.TA0003">Resource Development</a> has 9 of 13 rated techniques <em>Realized</em>, indicating that adversaries are actively building poisoned datasets, hallucinated entities, and compromised models as part of their operational tradecraft. <a href="https://atlas.mitre.org/tactics/AML.TA0001">AI Attack Staging</a> has 4 <em>Realized</em> out of 6, a high ratio for a tactic that describes specialized preparation work. <a href="https://atlas.mitre.org/tactics/AML.TA0008">Discovery</a> and <a href="https://atlas.mitre.org/tactics/AML.TA0013">Credential Access</a> each show only 1 <em>Realized</em> technique despite having 9 and 6 rated, respectively, suggesting that the reconnaissance and credential-theft phases of AI attacks remain more theoretical than operational in documented incidents. That gap is worth noting when prioritizing defensive investments.</p><p>The <em>Realized</em> filter is a built-in prioritization shortcut. With 167 techniques in the full matrix, knowing which 50 are confirmed adversary behavior gives you a defensible, evidence-based starting point for threat modeling.</p><h3>What the Case Studies Tell Us</h3><p>ATLAS launched with 13 case studies drawn from real incidents. Four that hold up well as illustrations: <a href="https://atlas.mitre.org/studies/AML.CS0002">VirusTotal Poisoning</a>, where adversaries submitted adversarial samples to corrupt a shared malware detection service; <a href="https://atlas.mitre.org/studies/AML.CS0003">Bypassing Cylance's AI Malware Detector</a>, where researchers studied the product's public API behavior to craft evasion inputs; <a href="https://atlas.mitre.org/studies/AML.CS0009">Tay poisoning</a>; and <a href="https://atlas.mitre.org/studies/AML.CS0007">GPT-2 model replication</a> through iterative API querying. The <a href="https://atlas.mitre.org/studies">full case study library</a> now documents 57 incidents and exercises. Two recent additions stand out. The <a href="https://atlas.mitre.org/studies/AML.CS0033">iProov deepfake case</a> documents adversaries using face-swap tools and virtual camera injection to defeat <a href="https://en.wikipedia.org/wiki/Liveness_test">liveness detection</a> in banking KYC (Know Your Customer) systems. <a href="https://atlas.mitre.org/studies/AML.CS0042">SesameOp</a> documents adversaries turning a legitimate AI service API into a covert command-and-control channel, hiding malicious traffic inside normal AI workflow activity.</p><p>Each case study is labeled either &#8220;Incident&#8221; for confirmed real-world attacks or &#8220;Exercise&#8221; for red-team and research demonstrations. That distinction is visible on each case study page and is worth checking before treating any entry as evidence of active adversarial use. Not all 57 carry equal operational weight, but the labeled distinction makes it straightforward to tell them apart.</p><p></p><h2>What This Means for CISSP Holders</h2><p>ATLAS isn&#8217;t just for ML engineers. Two domains make it directly relevant to security leaders.</p><p><strong>Domain 1, Security and Risk Management.</strong> Most risk registers in use today don&#8217;t include entries for AI Attack Staging, Functional Extraction, or Inversion Attacks. ATLAS gives practitioners the vocabulary to translate &#8220;our AI system might be vulnerable&#8221; into specific, structured threat scenarios that map to controls and drive prioritized remediation.</p><p><strong>Domain 8, Software Development Security.</strong> On the ATLAS&nbsp;<a href="https://atlas.mitre.org/mitigations">mitigations page</a>, each of the 35 mitigations is tagged to the phase of AI development it applies to, from initial data collection through model deployment and ongoing monitoring. If you've spent time mapping security controls to software development phases, this is the same idea applied to AI systems. It tells the team building or buying an AI system, where in the process, each defense needs to go, not just what the defense is.</p><p>On the regulatory side, the <a href="http://ai-act-service-desk.ec.europa.eu">EU AI Act's obligations</a> for general-purpose AI models became <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act">active in August 2025</a>, with the broader high-risk AI system framework following in August 2026. For the largest frontier <a href="https://artificialintelligenceact.eu/high-level-summary/">GPAI models</a> (those deemed to carry systemic risk), <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-55">Article 55 of the Act</a> already requires providers to conduct and document adversarial testing. For organizations deploying high-risk AI systems, the compliance deadline arrives in August 2026.</p><p>For ecosystem fit: ATLAS works alongside other frameworks rather than replacing them. Pair it with the <a href="https://airc.nist.gov/airmf-resources/airmf/5-sec-core/">NIST AI RMF's Measure function</a> for risk quantification, the <a href="https://genai.owasp.org/llm-top-10/">OWASP LLM Top 10</a> for application-level vulnerability coverage, and <a href="https://www.iso.org/standard/42001">ISO/IEC 42001</a> for governance structure. ATLAS covers the adversarial tactics and techniques layer, which is what attackers actually do, a piece that the others largely leave undefined.</p><p>Two limitations worth naming. First, ATLAS is still catching up to agentic AI. The late 2025 and early 2026 updates added significant new coverage of AI agent techniques, but <em>Realized</em> technique counts in that area remain low. The framework is reacting to, not predicting, how attackers use autonomous AI systems. Second, ATLAS <a href="https://atlas.mitre.org/resources/ai-security-101">explicitly does not yet cover</a> what MITRE calls "Malicious Use of AI," meaning AI as a weapon rather than as a target. AI-enhanced phishing, AI-powered reconnaissance, AI-automated attack development against conventional infrastructure: none of that fits the current TTP structure, and MITRE says so directly. The framework tells you how to defend your AI systems. It doesn&#8217;t yet systematically address how AI is changing attacks against your non-AI systems.</p><p>ATLAS is the shared language AI security has needed. The framework at <a href="https://atlas.mitre.org">atlas.mitre.org</a> is free, open, and actively maintained. The only barrier to using it is not knowing it exists.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!v6hC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v6hC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png 424w, https://substackcdn.com/image/fetch/$s_!v6hC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png 848w, https://substackcdn.com/image/fetch/$s_!v6hC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png 1272w, https://substackcdn.com/image/fetch/$s_!v6hC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v6hC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png" width="900" height="2606" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2606,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:300237,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/192897012?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!v6hC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png 424w, https://substackcdn.com/image/fetch/$s_!v6hC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png 848w, https://substackcdn.com/image/fetch/$s_!v6hC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png 1272w, https://substackcdn.com/image/fetch/$s_!v6hC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96eca03-b4a4-4f19-9c0b-2ed38e039d38_900x2606.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[ISACA’s AAISM: The First AI Security Management Certification, Examined]]></title><description><![CDATA[By The Cyber Leader | balancedsec.com]]></description><link>https://blog.balancedsec.com/p/isacas-aaism-the-first-ai-security</link><guid isPermaLink="false">https://blog.balancedsec.com/p/isacas-aaism-the-first-ai-security</guid><dc:creator><![CDATA[Jeffery Moore]]></dc:creator><pubDate>Fri, 20 Mar 2026 13:03:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XNfj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p><em>By The Cyber Leader | balancedsec.com</em></p><p>In August 2025, ISACA did something long overdue. They launched a certification built specifically for security managers who need to deal with AI. Not data scientists. Not ML engineers. Security managers.</p><p>The timing wasn&#8217;t subtle. Organizations were already deploying AI systems across their operations, and most had no one formally responsible for securing those deployments. ISC2&#8217;s <a href="https://www.isc2.org/Insights/2025/07/ISC2-Launches-AI-Certificate">2025 AI Adoption Survey</a> found that over one-third of surveyed cybersecurity professionals cited AI as the biggest skills shortfall on their teams, and 42% said they&#8217;re actively exploring or testing AI-focused security tools. ISACA&#8217;s response was the <a href="https://www.isaca.org/credentialing/aaism">Advanced in AI Security Management (AAISM)</a>: a credential designed to sit atop existing security management expertise and extend it into AI governance, risk, and technical controls.</p><p>I believe it&#8217;s the first certification that treats AI security as a management and leadership discipline rather than as a demonstration of technical knowledge. For CISSP or CISM holders, it&#8217;s the most directly relevant option on the market right now. But &#8220;first&#8221; doesn&#8217;t automatically mean &#8220;complete,&#8221; and the certification has limitations worth understanding before you charge the card.</p><h2>Who It&#8217;s For (And Who It Isn&#8217;t)</h2><p>The most important design decision ISACA made was the prerequisite. You can&#8217;t sit for the AAISM exam without an <a href="https://www.isaca.org/credentialing/aaism/get-aaism-certified">active CISM or CISSP certification</a>. Active. Not expired or in progress.</p><p>That single requirement tells you everything about the intended audience. AAISM isn&#8217;t trying to create AI security professionals from scratch. It&#8217;s trying to take experienced security managers who already think in terms of governance, risk tolerance, and program management, and give them the AI-specific knowledge they&#8217;re missing. In other words, the credential is additive, not foundational.</p><p>The target candidate is a security leader, GRC professional, or anyone accountable for enterprise AI risk, vendor oversight, or regulatory compliance around AI systems. If your organization isn&#8217;t working with AI, or if you&#8217;re in a purely hands-on technical role with no governance responsibilities, this may not be the right investment.</p><h2>The Exam: What You&#8217;re Walking Into</h2><p>The <a href="https://www.isaca.org/credentialing/aaism/aaism-exam-content-outline">AAISM exam</a> consists of 90 multiple-choice questions and lasts 2.5 hours, roughly 1 minute and 40 seconds per question. The passing score is 450 on ISACA&#8217;s 200&#8211;800 scaled scoring system. It&#8217;s computer-based and administered through PSI testing centers or via remote proctoring (available in most countries worldwide, with a few specific regional exceptions). Available in English and Spanish.</p><p>Cost: $459 for ISACA members, $599 for non-members, plus a one-time $50 application fee after passing. You get a 12-month eligibility window, up to three attempts at full price each, and can schedule up to 90 days in advance.</p><p>Maintenance is notably lighter than what you&#8217;re used to. AAISM requires just <a href="https://www.isaca.org/credentialing/aaism/maintain-aaism-certification">10 CPE hours per year (30 over three years)</a>, with an annual fee of $20 for members or $35 for non-members, due January 1st. Compare that to the CISSP&#8217;s 120 CPE credits over three years. You do need to keep your qualifying CISM or CISSP active throughout. One practical note for CISSP holders: your CISSP fee is due on your certification anniversary, but the AAISM fee is due January 1st. Different calendars. Worth noting now.</p><h2>The Three Domains</h2><h3>Domain 1: AI Governance and Program Management (31%)</h3><p>This is where CISSP holders will feel the most solid footing. This domain covers the creation, implementation, and maintenance of ethical and secure AI systems. Per the <a href="https://www.isaca.org/credentialing/aaism/aaism-exam-content-outline">AAISM exam content outline</a>, it covers stakeholder engagement, industry frameworks and regulatory requirements; AI-related policies and procedures; AI asset and data lifecycle management; security program development; and business continuity/incident response as they apply to AI systems.</p><p>If you&#8217;ve spent time in CISSP Domain 1 (Security and Risk Management), the concepts are structurally familiar. What&#8217;s new is the application layer. AI asset classification doesn&#8217;t work the same way as traditional IT asset management. A trained model isn&#8217;t a server. The regulatory frameworks (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001) are ones you probably haven&#8217;t had to operationalize before.</p><h3>Domain 2: AI Risk Management (31%)</h3><p>This domain covers AI risk assessment, thresholds, and treatment; threat and vulnerability management; and AI vendor and supply chain management. It tests your ability to assess both the risks and opportunities that come with enterprise AI adoption.</p><p>The vendor and supply chain piece deserves extra attention. Multiple exam prep providers flag third-party AI risk as one of the most heavily tested areas, and the one candidates consistently underestimate. My research suggests that the AAISM exam treats AI as a supply chain problem. The questions test whether you can evaluate the risk posture of cloud AI providers, SaaS vendors running AI-powered automation, and managed model services where you don&#8217;t control the training data or model architecture.</p><h3>Domain 3: AI Technologies and Controls (38%)</h3><p>The largest domain by weight, and where most CISSP holders will need the most study time. It covers AI security architecture and design; the AI lifecycle (model selection, training, validation); data management controls; privacy/ethical/trust/safety controls; and security controls and monitoring.</p><p>The AI lifecycle subtopics are where I think the CISSP foundation stretches thinnest. Model selection, training pipelines, and validation processes are not in the CISSP CBK. You don&#8217;t need to become an ML engineer, but you do need to understand how models are built, what can go wrong at each phase, and what controls are appropriate.</p><p>The privacy, ethics, and trust component is a differentiator. This is where AAISM goes beyond traditional security into the realm of responsible AI, covering bias detection, fairness in automated decision-making, and transparency requirements. The EU AI Act&#8217;s risk classification system explicitly requires these controls for high-risk systems, and organizations in regulated industries need people who understand how to implement them.</p><h2>Prep Materials and Study Strategy</h2><p>ISACA offers several <a href="https://www.isaca.org/credentialing/aaism">official prep resources</a>: the AAISM Official Review Manual (<a href="https://www.amazon.com/ISACA-AAISM-Official-Review-Manual/dp/B0FPZZ6WMT">digital and print</a>), an online review course ($449 for members / $549 for non-members), and a 200+-question QAE database with a 12-month subscription. As with other exams, there may be a members-only study group on ISACA Engage, but I haven&#8217;t found a public link yet.</p><p>The review manual ($105 for non-members, $89 for members) is available either as a hardcopy book delivered to your physical address or as a platform-locked ebook accessible only through the platform's browser-based interface. Note that you can <a href="https://support.isaca.org/s/article/How-can-I-read-my-eBook-on-ISACA-s-browser-based-eBook-platform-when-I-am-not-connected-to-the-internet">save all or a part of your eBook in your browser's cache for offline reading</a>, but you&#8217;ll need to activate the feature before you need it.</p><p>Third-party options are still limited. Destination Certification offers a <a href="https://destcert.com/aaism/online-bootcamp/">3-day online bootcamp</a>. <a href="https://trainingcamp.com/training/isaca-aaism-boot-camp/">Training Camp</a> offers a 3-day in-person bootcamp with a claimed 94% pass rate and a voucher. While the cost of the bootcamp is not explicitly listed as a single public price on their main landing page, similar advanced ISACA boot camps generally run $2,500 to $3,000. </p><p>Because the cert launched less than a year ago, don&#8217;t expect the depth of community study guides, YouTube walkthroughs, or Reddit threads that exist for CISSP or CISM. Supplementing with the <a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/">OWASP Top 10 for LLMs</a>, <a href="https://atlas.mitre.org/">MITRE ATLAS</a>, and the <a href="https://www.nist.gov/artificial-intelligence">NIST AI RMF</a> will give you practical grounding in the frameworks referenced in the exam.</p><p>Returning to third-party risk, consider using the NIST framework to assess how to verify that a third-party vendor (such as a cloud AI provider) is meeting its own safety claims, a frequent theme in the AAISM's managerial reasoning questions.</p><p>One study tip that comes up repeatedly: the questions are scenario-based and rarely black-and-white. You&#8217;re choosing the least risky option, not the perfect one. If you&#8217;ve been through the CISSP, you know the feeling. From what I&#8217;ve read, the &#8220;ISACA mindset&#8221; leans heavily toward governance-first thinking.</p><h2>The Bottom Line</h2><p>The AAISM is one of the strongest governance-path AI security credentials currently available for experienced security managers. The prerequisite keeps the quality bar high, the domain coverage is relevant, and the maintenance burden is light. Every hour you spend studying counts toward your CISSP renewal as Group A credit.</p><p>But it won&#8217;t teach you hands-on model security testing (look at <a href="https://www.practical-devsecops.com/certified-ai-security-professional/">Practical DevSecOps&#8217; CAISP</a> for that). It doesn&#8217;t go deep on agentic AI security, arguably the fastest-moving threat vector right now. The third-party study ecosystem is immature. And because the certification is less than a year old, its market recognition is still building.</p><p>For CISSP holders: from what I have gathered, your Domain 1 knowledge maps strongly to AAISM Domains 1 and 2. Domain 3 (38% of the exam) is where you&#8217;ll need to put in real study time. Budget accordingly. If AI governance is in your job description today, or will be in the next 18 months, the AAISM is worth serious consideration. The window to be early is still open.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XNfj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XNfj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png 424w, https://substackcdn.com/image/fetch/$s_!XNfj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png 848w, https://substackcdn.com/image/fetch/$s_!XNfj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png 1272w, https://substackcdn.com/image/fetch/$s_!XNfj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XNfj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png" width="1080" height="1276" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1276,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:172831,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.balancedsec.com/i/191315120?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XNfj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png 424w, https://substackcdn.com/image/fetch/$s_!XNfj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png 848w, https://substackcdn.com/image/fetch/$s_!XNfj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png 1272w, https://substackcdn.com/image/fetch/$s_!XNfj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9b6c243-7dfe-41c1-b394-72e687d6eb73_1080x1276.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p>]]></content:encoded></item></channel></rss>