Appendix C. Security Control Sources
This appendix documents the sources used in the development of the security control tables presented in this guide. Table C.1 maps the individual security controls to the authoritative publications, standards, frameworks, and industry guidance from which they were derived or informed.
Table C.1. AI Security Controls and Source References
| Control Identifier | Control Name | Source |
|---|---|---|
| API1:2023 | Broken Object Level Authorization | OWASP, “API1:2023 Broken Object Level Authorization.” |
| API2:2023 | Broken Authentication | OWASP, “API2:2023 Broken Authentication.” |
| API3:2023 | Broken Object Property Level Authorization | OWASP, “API3:2023 Broken Object Property Level Authorization.” |
| API4:2023 | Unrestricted Resource Consumption | OWASP, “API4:2023 Unrestricted Resource Consumption.” |
| API5:2023 | Broken Function Level Authorization | OWASP, “API5:2023 Broken Function Level Authorization.” |
| API6:2023 | Unrestricted Access to Sensitive Business Flows | OWASP, “API6:2023 Unrestricted Access to Sensitive Business Flows.” |
| API7:2023 | Server Side Request Forgery | OWASP, “API7:2023 Server Side Request Forgery.” |
| API8:2023 | Security Misconfiguration | OWASP, “API8:2023 Security Misconfiguration.” |
| API9:2023 | Improper Inventory Management | OWASP, “API9:2023 Improper Inventory Management.” |
| API10:2023 | Unsafe Consumption of APIs | OWASP, “API10:2023 Unsafe Consumption of APIs.” |
| LLM03:2023 | Inadequate Sandboxing | OWASP, “LLM03:2023: Inadequate Sandboxing” |
| LLM01 | Prompt Injection | OWASP, “LLM01 Prompt Injection.” |
| LLM02 | Insecure Output Handling | OWASP, “LLM02 Insecure Output Handling.” |
| LLM03 | Training Data Poisoning | OWASP, “LLM03 Training Data Poisoning.” |
| LLM04 | Model Denial of Service | OWASP, “LLM04 Model Denial of Service.” |
| LLM05 | Supply Chain Vulnerabilities | OWASP, “LLM05 Supply Chain Vulnerabilities.” |
| LLM06 | Sensitive Information Disclosure | OWASP, “LLM06 Sensitive Information Disclosure.” |
| LLM07 | Insecure Plugin Design | OWASP, “LLM07 Insecure Plugin Design.” |
| LLM08 | Excessive Agency | OWASP, “LLM08 Excessive Agency.” |
| LLM09 | Overreliance | OWASP, “LLM09 Overreliance.” |
| LLM10 | Model Theft | OWASP, “LLM10 Model Theft.” |
| LLM07:2025 | System Prompt Leakage | OWASP, “LLM07:2025 System Prompt Leakage” |
| ML01 | Input Manipulation Attack | OWASP, “ML01:2023 Input Manipulation Attack.” |
| ML02 | Data Poisoning Attack | OWASP, “ML02:2023 Data Poisoning Attack.” |
| ML03 | Model Inversion Attack | OWASP, “ML03:2023 Model Inversion Attack.” |
| ML04 | Membership Inference Attack | OWASP, “ML04:2023 Membership Inference Attack.” |
| ML05 | Model Stealing Attack | OWASP, “ML05:2023 Model Theft.” |
| ML06 | AI Supply Chain Attack | OWASP, “ML06:2023 ML Supply Chain Attacks.” |
| ML07 | Transfer Learning Attack | OWASP, “ML07:2023 Transfer Learning Attack.” |
| ML08 | Model Skewing | OWASP, “ML08:2023 Model Skewing.” |
| ML09 | Output Integrity Attack | OWASP, “ML09:2023 Output Integrity Attack.” |
| ML10 | Model Poisoning | OWASP, “ML10:2023 Model Poisoning.” |
| BIML | Input Manipulation; Data Manipulation; Model Manipulation; Input Extraction; Data Extraction; Model Extraction | Shepardson et al., “A Taxonomy of ML Attacks.” |