Turn agent security controls into evidence buyers can use.

Oktsec connects runtime enforcement, workflow assessment, dependency intelligence and verifiable evidence to the frameworks security, risk and procurement teams already trust.

Review the mappings

One operating model, translated for every buyer.

Engineering sees enforceable controls. Security sees threat coverage. Risk and procurement see evidence connected to familiar requirements. The product remains the same; the language becomes easier to evaluate.

Framework mappings

Select a framework family or review the complete crosswalk.

Threat guidance

OWASP Top 10 for Agentic Applications

Connects Oktsec runtime enforcement, agent identity, supply-chain review and audit evidence to seven of the ten agentic risk categories.

Framework version
2026
Oktsec mapping
2026.08
Last reviewed
2026-08-19
Products
Control · Signal · Node · Aguara
Selected scopeASI01, ASI02, ASI03, ASI04, ASI05, ASI07 and ASI10Open official framework
ASI01 · Agent Goal HijackContent inspection, intent validation and multi-message escalationAguara · Node
Direct control

Combines threat detection with downstream authorization for defense in depth.

ASI02 · Tool Misuse and ExploitationTool allowlists, parameter constraints, rate limits and pre-execution policyControl · Node
Direct control

Protects agent actions routed through an Oktsec enforcement point.

ASI03 · Identity and Privilege AbuseCryptographic agent identity, ACLs, scoped delegation and default-deny policyControl · Node
Direct control

Adds agent-specific controls to the customer's identity and access-management program.

ASI04 · Agentic Supply Chain VulnerabilitiesDependency inspection, tool-definition pinning and drift detectionSignal · Node
Direct control

Covers the repositories, packages and tool definitions included in the approved workflow.

ASI05 · Unexpected Code ExecutionExecution-path assessment plus tool, path and destination constraintsAssessment · Control
Evidence support

Works alongside host isolation in the customer-controlled runtime.

ASI07 · Insecure Inter-Agent CommunicationSigned messages, agent ACLs, content controls and tamper-evident audit recordsControl · Node
Direct control

Establishes a governed path for agent-to-agent communication.

ASI10 · Rogue AgentsSuspension, anomaly signals, rate limits and evidence for investigationControl · Cloud
Evidence support

Connects runtime signals to the organization's monitoring and incident-response process.

Threat guidance

MITRE ATLAS

Relates observable agent actions and controls to adversary behaviors across tool invocation, prompt injection, credential access and AI supply-chain compromise.

Framework version
Living knowledge base · reviewed August 2026
Oktsec mapping
2026.08
Last reviewed
2026-08-19
Products
Assessment · Signal · Control · Aguara
Selected scopeSelected Agentic AI tactics and techniquesOpen official framework
Execution · AI Agent Tool InvocationExercise and constrain real tool-call paths before consequential actions runAssessment · Control
Direct control

Focuses coverage on observable, instrumented execution paths.

Execution · LLM Prompt InjectionDeterministic inspection and policy enforcement around downstream actionsAguara · Control
Evidence support

Pairs threat detection with authorization controls around the resulting action.

Initial Access · AI Supply Chain CompromiseInspect agent dependencies and identify changes in approved tool definitionsSignal · Node
Direct control

Uses dependency and tool metadata from the approved workflow.

Credential Access and ExfiltrationCredential-leak detection, egress policy and destination controlsAguara · Node
Direct control

Connects agent-specific controls to the customer's secrets lifecycle and vault.

AI risk and controls

NIST Artificial Intelligence Risk Management Framework

Turns workflow boundaries, testing, policy decisions and operating evidence into concrete inputs for an organization-wide AI risk program.

Framework version
1.0
Oktsec mapping
2026.08
Last reviewed
2026-08-19
Products
Assessment · Control · Cloud · Signal
Selected scopeGOVERN · MAP · MEASURE · MANAGEOpen official framework
GOVERN · Accountability and policyNamed workflow ownership, explicit authority and signed policy lifecycleControl · Cloud
Evidence support

Supplies operating evidence to the organization's governance roles and risk appetite.

MAP · Context and intended purposeDocument the workflow, action surfaces, dependencies and approved boundaryAssessment · Signal
Evidence support

Combines technical scope with customer-defined business impact and stakeholder context.

MEASURE · Test and evaluateExercise real execution paths and produce reproducible findings and remediationAssessment
Direct control

Evaluates the scoped agent workflow and its observable execution path.

MANAGE · Prioritize and monitor riskEnforce policy, review exceptions and preserve decision evidenceControl · Cloud
Evidence support

Provides the evidence used for customer risk acceptance and response decisions.

AI risk and controls

Cloud Security Alliance AI Controls Matrix

Links Oktsec controls and evidence to cloud AI control domains used for agent boundaries, identity, logging and threat management.

Framework version
v1.1
Oktsec mapping
2026.08
Last reviewed
2026-08-19
Products
Control · Cloud · Assessment · Signal
Selected scopeSelected controls across AIS, IAM, LOG and TVMOpen official framework
AIS · AI security boundariesDefine and enforce allowed tools, paths, parameters and destinationsControl · Node
Direct control

Adds an enforceable agent-action boundary to the customer's broader AI service architecture.

IAM · Agent access restrictionAgent identity, ACLs, scoped delegation and revocationControl · Node
Direct control

Extends enterprise IAM with identity and least-privilege controls purpose-built for agents.

LOG · Activity and decision evidenceHash-chained audit entries, policy versions and signed evidenceCloud · Node
Direct control

Feeds verifiable agent-action evidence into the customer's retention and enterprise logging strategy.

TVM · Testing and threat managementPurpose-built assessment harness and dependency intelligenceAssessment · Signal
Evidence support

Maps selected high-value technical objectives into the organization's broader AICM program.

AI risk and controls

AIUC-1 AI Agent Standard

Maps Oktsec capabilities to practical AIUC-1 requirements for agent permissions, MCP and A2A security, tool governance, third-party access and tamper-evident records.

Framework version
July 15, 2026 release
Oktsec mapping
2026.08
Last reviewed
2026-08-19
Products
Control · Assessment · Signal · Cloud · Node
Selected scopeSelected agent security and evidence requirementsOpen official framework
B006 · Prevent unauthorized AI agent actionsRuntime policy for tools, parameters, filesystem, network and credentialsControl · Node
Direct control

Provides the policy enforcement point for instrumented agent actions within the customer's runtime architecture.

A003 · Limit AI agent data accessScoped identity, permissions, delegation and access boundariesControl · Node
Direct control

Turns the customer's data classification and entitlements into enforceable agent boundaries.

D003 · Restrict unsafe tool callsTool authorization, schema drift detection and input/output inspectionControl · Node
Direct control

Applies to supported integrations and agent-action paths instrumented through Oktsec.

E009 · Monitor third-party accessDependency review, egress controls and auditable external-service accessSignal · Control
Evidence support

Supplies technical evidence for vendor due diligence, access review and third-party governance.

E015 · Log model and agent activityTamper-evident action records with identity, request, decision and policy versionCloud · Node
Direct control

Creates a verifiable record of the governed actions that matter to security and audit teams.

C002 · Conduct pre-deployment testingControlled workflow testing with reproducible findings, evidence and remediationAssessment
Evidence support

Produces technical evidence that can support an AIUC assessment with the selected auditor.

Management systems

ISO/IEC 42001 — Artificial intelligence management system

Provides technical controls and records that can support an organization operating an AI management system, from risk treatment to monitored operation.

Framework version
2023
Oktsec mapping
2026.08
Last reviewed
2026-08-19
Products
Assessment · Control · Cloud · Signal
Selected scopeTechnical evidence supporting an organizational AIMSOpen official framework
AI risk assessment and treatmentWorkflow-level attack-path testing, prioritized findings and remediationAssessment
Evidence support

Gives the organization's AIMS concrete workflow evidence for risk criteria and treatment decisions.

Operational planning and controlSigned policy, local enforcement and governed exceptionsControl · Cloud
Evidence support

Operationalizes the management system with agent-specific policy, enforcement and exception evidence.

Monitoring, measurement and evaluationEnvironment status, audit evidence and verifiable decision recordsCloud · Node
Evidence support

Provides measurable operating evidence for management review and conformity evaluation.

Third-party and system lifecycle riskDependency intelligence and change detection for agent componentsSignal
Evidence support

Adds agent dependency intelligence to supplier governance and lifecycle review.

Management systems

ISO/IEC 27001 — Information security management systems

Supports an ISMS with agent-specific access control, secure operation, supplier-risk inputs, logging and evidence for governed actions.

Framework version
2022
Oktsec mapping
2026.08
Last reviewed
2026-08-19
Products
Control · Cloud · Signal · Assessment
Selected scopeTechnical evidence supporting an organizational ISMSOpen official framework
Identity and access controlUnique agent identity, least-privilege policy, ACLs and revocationControl · Node
Evidence support

Oktsec complements the organization's identity lifecycle and access reviews.

Logging and monitoringTamper-evident action records and verifiable policy decisionsCloud · Node
Evidence support

Feeds agent-action evidence into enterprise retention, correlation and incident procedures.

Supplier and technology riskInspect MCP servers, skills, packages and workflow dependenciesSignal
Evidence support

Adds technical dependency intelligence to commercial due diligence and supplier governance.

Secure development and change controlAssess code-changing agents and require policy before privileged actionsAssessment · Control
Evidence support

Connects the customer's SDLC approval gates and segregation of duties to agent execution.

Built for due diligence and real operating evidence.

Every mapping names the framework version, the Oktsec capability, the product surface and the responsibility boundary. That gives buyers a useful starting point for technical review and gives teams a clear path to the evidence behind each claim.

Clear claim boundary

Mappings describe technical relevance and selected coverage. Formal certification, conformity and endorsement follow each framework owner's authorized process.

What buyers should know.

Does framework mapping mean certification?

No. A mapping shows how Oktsec controls and evidence relate to selected requirements or threat categories. Certification, conformity and audit opinions are issued only through the applicable standard owner or accredited assessment process.

How can a security team use these mappings?

Use them to connect one agent workflow to existing security, AI risk and procurement processes. Each mapping identifies the Oktsec capability, the evidence available and how it fits into the organization's control environment.

Are the mappings kept current?

Each published mapping records the framework version, the Oktsec mapping version and the last review date. Living frameworks are reviewed against a dated snapshot before updates are published.

Bring one agent workflow into the security review.

We will map its action boundary, controls and available evidence to the frameworks that matter to your organization.