Appendix C. Security Control Sources

This appendix documents the sources used in the development of the security control tables presented in this guide. Table C.1 maps the individual security controls to the authoritative publications, standards, frameworks, and industry guidance from which they were derived or informed.

Table C.1. AI Security Controls and Source References

Control Identifier Control Name Source
API1:2023 Broken Object Level Authorization OWASP, “API1:2023 Broken Object Level Authorization.”
API2:2023 Broken Authentication OWASP, “API2:2023 Broken Authentication.”
API3:2023 Broken Object Property Level Authorization OWASP, “API3:2023 Broken Object Property Level Authorization.”
API4:2023 Unrestricted Resource Consumption OWASP, “API4:2023 Unrestricted Resource Consumption.”
API5:2023 Broken Function Level Authorization OWASP, “API5:2023 Broken Function Level Authorization.”
API6:2023 Unrestricted Access to Sensitive Business Flows OWASP, “API6:2023 Unrestricted Access to Sensitive Business Flows.”
API7:2023 Server Side Request Forgery OWASP, “API7:2023 Server Side Request Forgery.”
API8:2023 Security Misconfiguration OWASP, “API8:2023 Security Misconfiguration.”
API9:2023 Improper Inventory Management OWASP, “API9:2023 Improper Inventory Management.”
API10:2023 Unsafe Consumption of APIs OWASP, “API10:2023 Unsafe Consumption of APIs.”
LLM03:2023 Inadequate Sandboxing OWASP, “LLM03:2023: Inadequate Sandboxing
LLM01 Prompt Injection OWASP, “LLM01 Prompt Injection.”
LLM02 Insecure Output Handling OWASP, “LLM02 Insecure Output Handling.”
LLM03 Training Data Poisoning OWASP, “LLM03 Training Data Poisoning.”
LLM04 Model Denial of Service OWASP, “LLM04 Model Denial of Service.”
LLM05 Supply Chain Vulnerabilities OWASP, “LLM05 Supply Chain Vulnerabilities.”
LLM06 Sensitive Information Disclosure OWASP, “LLM06 Sensitive Information Disclosure.”
LLM07 Insecure Plugin Design OWASP, “LLM07 Insecure Plugin Design.”
LLM08 Excessive Agency OWASP, “LLM08 Excessive Agency.”
LLM09 Overreliance OWASP, “LLM09 Overreliance.”
LLM10 Model Theft OWASP, “LLM10 Model Theft.”
LLM07:2025 System Prompt Leakage OWASP, “LLM07:2025 System Prompt Leakage
ML01 Input Manipulation Attack OWASP, “ML01:2023 Input Manipulation Attack.”
ML02 Data Poisoning Attack OWASP, “ML02:2023 Data Poisoning Attack.”
ML03 Model Inversion Attack OWASP, “ML03:2023 Model Inversion Attack.”
ML04 Membership Inference Attack OWASP, “ML04:2023 Membership Inference Attack.”
ML05 Model Stealing Attack OWASP, “ML05:2023 Model Theft.”
ML06 AI Supply Chain Attack OWASP, “ML06:2023 ML Supply Chain Attacks.”
ML07 Transfer Learning Attack OWASP, “ML07:2023 Transfer Learning Attack.”
ML08 Model Skewing OWASP, “ML08:2023 Model Skewing.”
ML09 Output Integrity Attack OWASP, “ML09:2023 Output Integrity Attack.”
ML10 Model Poisoning OWASP, “ML10:2023 Model Poisoning.”
BIML Input Manipulation; Data Manipulation; Model Manipulation; Input Extraction; Data Extraction; Model Extraction Shepardson et al., “A Taxonomy of ML Attacks.”