AI security dimension

Governance.

AI policy, accountable owner, inventory, framework alignment.

The six dimensions
Questions
5 in the adaptive tree
Frameworks
NIST AI RMF, ISO 42001, LLM06
Moves
The Program axis of the Posture Quadrant
Why it matters

Why governance matters

Governance is the foundation of every AI security program. The Govern function in NIST AI RMF and clauses 4 through 6 of ISO 42001 both prioritize the same things: a written AI policy, a named accountable executive, an inventory of AI systems, and documented framework alignment. Without governance, every other dimension drifts. Engineering teams adopt AI tools faster than security can review them, vendors get onboarded without contracts, and shadow AI grows without discovery. The check opens on governance: where AI stands with leadership decides which questions follow, and every governance question cites its NIST AI RMF or ISO 42001 source.

In the check

What the check asks about governance

The check asks up to five questions in total, chosen by your earlier answers, so a path may meet one of these or none. Each carries a weight from 0 to 3 and cites its source.

QuestionCitationAnswers
Which of these best describes AI in your organization today?Where AI stands with leadership decides which questions matter next. NIST AI RMF GOVERN-1.1, MAP-1.1
  • +0No sanctioned AI in use yet, and no policy
  • +1People use AI tools, and there is no approved policy or named owner
  • +2An approved policy and a named owner exist, and controls are uneven
  • +3Policy, owner, and inventory are in place and controls are audited
Is anyone evaluating or piloting AI tools right now, even informally?Pilots without a policy are how unsanctioned use begins. NIST AI RMF GOVERN-1.5
  • +1Not that we know of
  • +0Yes, informally in a few teams
  • +2Yes, under a documented pilot with an owner
Is there a named executive accountable for AI risk, even without a policy yet?Naming an owner matters even before a policy exists. ISO 42001 clause 5.3
  • +0No one
  • +1Someone informally, not signed off
  • +3Yes, named and accountable
Do you know which AI coding agents and assistants are running on staff machines, and what they can reach?Agents on developer machines can read files, sign in to applications and run commands. Knowing what is installed and what it can reach is the first control. OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1
  • +0No idea what is running
  • +1We know the tools, not what they can reach
  • +2Inventory, plus rules for what each agent may access
Do you know which AI coding agents and assistants run on staff machines, what they can reach, and how MCP servers and Skills are vetted before install?Agents on developer machines read files, sign in to applications and run commands, and their plug-ins ship as packages. Inventory and vetting are the controls that stop a quiet blast radius. OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1
  • +0No inventory, developers decide
  • +1We know the tools, not what they can reach
  • +3Inventory, an allow list for agents and plug-ins, and an approval step
Score yourself

See where governance lands on your chart.

Five questions, about three minutes, and your dot lands on the Posture Quadrant. Your stage and the move that takes you forward arrive by email or in a live conversation with a CWS engineer.