Model.
Selection, version control, hallucination testing, retirement, theft prevention.
- Questions
- 2 in the adaptive tree
- Frameworks
- LLM03, NIST AI RMF, LLM04, MITRE ATLAS
- Moves
- The Controls axis of the Posture Quadrant
Why model matters
Model covers the lifecycle of the AI models themselves: how they are selected, tracked, evaluated, retired, and protected. The check asks about version tracking, retirement, and controls against theft and extraction for models you build or fine-tune. This dimension maps to OWASP LLM03 (Supply Chain), LLM04 (Data and Model Poisoning), and LLM09 (Misinformation), plus the Measure function of NIST AI RMF. Full weight on the model answers indicates engineering maturity around AI lifecycle management. Low weight means models are being deployed and updated without security review, hallucinations are not being tested for, and end-of-life is reactive rather than planned.
What the check asks about model
The check asks up to five questions in total, chosen by your earlier answers, so a path may meet one of these or none. Each carries a weight from 0 to 3 and cites its source.
| Question | Citation | Answers |
|---|---|---|
| Do you track which model versions are in use and have a way to retire one?Models change quickly. If you cannot retire one, you cannot manage its risk. | OWASP LLM03, NIST AI RMF MEASURE-2.7 |
|
| For models you build or fine-tune, are there controls against theft and extraction?This is the last dimension most mature programs leave open. | OWASP LLM04, MITRE ATLAS |
|
Frameworks cited on this dimension
Every question above cites its source. These are the frameworks behind model.
Supply Chain (LLM03)
Vulnerabilities or compromises in upstream training data, pre-trained models, third-party datasets, model marketplaces, or fine-tuning servi.
Read the guideNIST AI RMF in Operation
The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) defines four core functions for AI risk: Govern, Map, Measure, Ma.
Read the guideData and Model Poisoning (LLM04)
An attacker injects malicious data into training, fine-tuning, or RAG-corpus content to alter model behavior in their favor, often subtly an.
Read the guideMITRE ATLAS for AI Defenders
MITRE ATLAS (Adversarial Threat Landscape for AI Systems) is a knowledge base of tactics, techniques, and case studies for adversarial machi.
Read the guideSee where model lands on your chart.
Five questions, about three minutes, and your dot lands on the Posture Quadrant. Your stage and the move that takes you forward arrive by email or in a live conversation with a CWS engineer.