AICM AtlasCSA AI Controls Matrix
Browse

Controls

Filter by domain, threat, lifecycle phase, architecture layer, control type, or mapping gap.

173 matchesclear
ID
Domain
Title
Type
Threats
DSP-12
DSPData Security and Privacy Lifecycle Management
Limitation of Purpose in Personal Data Processing
Cloud & AI Related
IAPISCLoGSDD
DSP-13
DSPData Security and Privacy Lifecycle Management
Personal Data Sub-processing
Cloud & AI Related
IAPISCLoGSDD
DSP-14
DSPData Security and Privacy Lifecycle Management
Disclosure of Data Sub-processors
Cloud & AI Related
IAPISCSDD
DSP-15
DSPData Security and Privacy Lifecycle Management
Limitation of Production Data Use
Cloud & AI Related
IAPISCLoGSDD
DSP-16
DSPData Security and Privacy Lifecycle Management
Data Retention and Deletion
Cloud & AI Related
IAPISCLoGSDD+1
DSP-17
DSPData Security and Privacy Lifecycle Management
Sensitive Data Protection
Cloud & AI Related
IAPISCLoGSDD+1
DSP-18
DSPData Security and Privacy Lifecycle Management
Disclosure Notification
Cloud & AI Related
IAPISCLoGSDD
DSP-19
DSPData Security and Privacy Lifecycle Management
Data Location
Cloud & AI Related
ISCLoGSDDMSF
DSP-20
DSPData Security and Privacy Lifecycle Management
Data Provenance and Transparency
Cloud & AI Related
DPIAPISCLoG+2
DSP-21
DSPData Security and Privacy Lifecycle Management
Data Poisoning Prevention & Detection
AI-Specific
DPISCLoGMSF
DSP-22
DSPData Security and Privacy Lifecycle Management
Privacy Enhancing Technologies
AI-Specific
IAPISCLoGSDD
DSP-23
DSPData Security and Privacy Lifecycle Management
Data Integrity Check
AI-Specific
DPISCLoGMM+1
DSP-24
DSPData Security and Privacy Lifecycle Management
Data Differentiation and Relevance
AI-Specific
DPLoGMSF
GRC-01
GRCGovernance, Risk and Compliance
Governance Program Policy and Procedures
Cloud & AI Related
ISCLoGSDD
GRC-02
GRCGovernance, Risk and Compliance
Risk Management Program
Cloud & AI Related
ISCLoGSDD
GRC-03
GRCGovernance, Risk and Compliance
Organizational Policy Reviews
Cloud & AI Related
ISCLoGSDD
GRC-04
GRCGovernance, Risk and Compliance
Policy Exception Process
Cloud & AI Related
ISCLoGSDD
GRC-05
GRCGovernance, Risk and Compliance
Information Security Program
Cloud & AI Related
ISCLoGSDD
GRC-06
GRCGovernance, Risk and Compliance
Governance Responsibility Model
Cloud & AI Related
ISCLoGSDD
GRC-07
GRCGovernance, Risk and Compliance
Information System Regulatory Mapping
Cloud & AI Related
LoGSDD
GRC-08
GRCGovernance, Risk and Compliance
Special Interest Groups
Cloud & AI Related
GRC-09
GRCGovernance, Risk and Compliance
Acceptable Use of the AI Service
AI-Specific
DoSIAPISCSDD+1
GRC-10
GRCGovernance, Risk and Compliance
AI Impact Assessment
AI-Specific
IAPISCLoGSDD+1
GRC-11
GRCGovernance, Risk and Compliance
Bias and Fairness Assessment
AI-Specific
ISCLoGSDD
GRC-12
GRCGovernance, Risk and Compliance
Ethics Committee
AI-Specific
LoGSDD
GRC-13
GRCGovernance, Risk and Compliance
Explainability Requirement
AI-Specific
DPIAPISCLoG+3
GRC-14
GRCGovernance, Risk and Compliance
Explainability Evaluation
AI-Specific
DPIAPISCLoG+3
GRC-15
GRCGovernance, Risk and Compliance
Human supervision
AI-Specific
DoSMMMTSDD+1
IAM-01
IAMIdentity & Access Management
Identity and Access Management Policy and Procedures
Cloud & AI Related
DoSIAPISCLoG+3
IAM-02
IAMIdentity & Access Management
Strong Password Policy and Procedures
Cloud & AI Related
DoSIAPISCLoG+2
IAM-03
IAMIdentity & Access Management
Identity Inventory
Cloud & AI Related
DoSIAPISCLoG+2
IAM-04
IAMIdentity & Access Management
Separation of Duties
Cloud & AI Related
DPIAPISCLoG+3
IAM-05
IAMIdentity & Access Management
Least Privilege
Cloud & AI Related
DPIAPISCLoG+3
IAM-06
IAMIdentity & Access Management
User Access Provisioning
Cloud & AI Related
DPIAPISCLoG+3
IAM-07
IAMIdentity & Access Management
User Access Changes and Revocation
Cloud & AI Related
DPIAPISCLoG+3
IAM-08
IAMIdentity & Access Management
User Access Review
Cloud & AI Related
DPIAPISCLoG+3
IAM-09
IAMIdentity & Access Management
Segregation of Privileged Access Roles
Cloud & AI Related
DPIAPISCLoG+3
IAM-10
IAMIdentity & Access Management
Management of Privileged Access Roles
Cloud & AI Related
DPIAPISCLoG+3
IAM-11
IAMIdentity & Access Management
Customers' Approval for Agreed Privileged Access Roles
Cloud & AI Related
DPIAPISCLoG+3
IAM-12
IAMIdentity & Access Management
Safeguard Logs Integrity
Cloud & AI Related
DPIAPISCLoG+4
IAM-13
IAMIdentity & Access Management
Uniquely Identifiable Users
Cloud & AI Related
DPDoSIAPISC+3
IAM-14
IAMIdentity & Access Management
Strong Authentication
Cloud & AI Related
DoSIAPISCLoG+2
IAM-15
IAMIdentity & Access Management
Passwords and Secrets Management
Cloud & AI Related
DoSIAPISCLoG+2
IAM-16
IAMIdentity & Access Management
Authorization Mechanisms
Cloud & AI Related
DoSIAPISCLoG+3
IAM-17
IAMIdentity & Access Management
Knowledge Access Control - Need to Know
Cloud & AI Related
IAPISCLoGMT+2
IAM-18
IAMIdentity & Access Management
Output Modification and Special Authorization
AI-Specific
DPIAPISCLoG+3
IAM-19
IAMIdentity & Access Management
Agent Access Restriction
Cloud & AI Related
DoSIAPISCLoG+3
IPY-01
IPYInteroperability & Portability
Interoperability and Portability Policy and Procedures
Cloud & AI Related
IAPLoGSDD
IPY-03
IPYInteroperability & Portability
Secure Interoperability and Portability Management
Cloud & AI Related
DPIAPLoGSDD
I&S-05
I&SInfrastructure Security
Production and Non-Production Environments
Cloud & AI Related
LoGSDDMSF
51100 of 173