Appendix D. Key Sources and Recommended Reading
Tables D.1–D.4 list the key sources, frameworks, guides, and research that informed the development of this guide. The tables are organized by topic to make it easy to find sources relevant to your needs.
This appendix not only provides the key sources used to develop this guide; it is designed to provide “read also” material for users who want to go deeper into specific areas of AI security. Each table highlights foundational works, emerging research, and widely cited sources that can help security teams, researchers, and policymakers adapt and extend the guidance provided in this guide.
Use this appendix to
- explore the methodologies and frameworks that shaped our recommendations
- dive into case studies and technical analyses of threats, vulnerabilities, and mitigations
- access standards, benchmarks, and guidelines for implementing risk-based security approaches
- stay informed about the evolving literature on AI security and governance.
Table D.1. AI Security Frameworks and Standards
| Source | Description |
|---|---|
| Anthropic, “Frontier Model Security” | Best practices for protecting advanced models, from weight security to safe deployment |
| Booth et al., Secure Software Development Practices for Generative AI and Dual-Use Foundation Models (NIST SP 800-218A) | Secure development lifecycle guidance for generative and dual-use AI |
| Cloud Security Alliance, “Agentic AI Identity and Access Management” | Identity and access management practices for multi-agent AI ecosystems |
| Cloud Security Alliance, “AI Controls Matrix” | Security and compliance control framework for AI systems |
| Cloud Security Alliance, “Secure Agentic System Design” | Security-by-design principles for agent-based AI systems |
| Cortegaca, Malhotra, and Abdol-Hamid, “Threat Modeling Your Generative AI Workload to Evaluate Security Risk” | Practical guidance for risk-assessing and securing Amazon Web Services (AWS)–based AI workloads |
| European Union Agency for Cybersecurity, Multilayer Framework for Good Cybersecurity Practices for AI | Layered approach to securing AI implementations within Europe |
| German Federal Office for Information Security, “Artificial Intelligence” | German guidelines for secure, trustworthy AI development and deployment |
| German Federal Office for Information Security, Generative AI Models | Analysis of generative AI risks and enterprise mitigations |
| Huang, “Agentic AI Threat Modeling Framework” | AI threat modeling framework for agentic environments |
| IBM, “Artificial Intelligence (AI) Cybersecurity” | Strategies and tools for enterprise-level AI system security |
| International Organization for Standardization (ISO), Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements (ISO/IEC 27001) | Foundational standard for security management systems applicable to AI infrastructure |
| ISO, “ISO/IEC JTC 1/SC 42: Artificial Intelligence” | Technical standards for AI lifecycle management and security |
| ISO, Risk Management—Guidelines (ISO/IEC 31000:2018) | Global risk management principles adaptable to AI projects and operations |
| Marshall et al., “Threat Modeling AI/ML Systems and Dependencies” | Tools and guidance for AI/ML threat modeling during design and deployment |
| Microsoft, “Secure AI” | Framework and guidance for securing AI deployments in Azure environments |
| Ministry of Japan, Group of 7, and European Union, “Hiroshima Process International Guiding Principles for Organizations Developing Advanced AI System” | Global principles emphasizing safety, accountability, and responsible AI |
| MITRE Corporation, “MITRE ATLAS” | Comprehensive taxonomy of AI threats, vulnerabilities, and mitigations |
| National Institute of Standards and Technology (NIST), “AI Risk Management Framework” | U.S. risk-based framework for managing AI security and trustworthiness |
| NIST, Security and Privacy Controls for Information Systems and Organizations | Security and privacy controls for information systems adapted to AI |
| NSA et al., Guidelines for Secure AI System Development | Joint guidance on secure, scalable AI development practices |
| OWASP, “AI Security and Privacy Guide” | Community-driven practical guide for AI security and privacy |
| OWASP, Multi-Agentic System Threat Modelling Guide | Threat modeling methodology for multi-agent AI systems |
Table D.2. Threats, Vulnerabilities, and Risk Research
| Source | Description |
|---|---|
| Center for AI Safety, “An Overview of Catastrophic AI Risks” | High-level overview of catastrophic and existential risks from advanced AI |
| Nevo et al., Securing AI Model Weights | Analysis of risks and controls for safeguarding high-value model weights |
| OWASP, Agentic AI—Threats and Mitigations | Current knowledge and mitigation guidance for agentic AI threats |
| Shepardson et al., “A Taxonomy of ML Attacks” | Foundational taxonomy categorizing adversarial AI threats |
Table D.3. Specialized Guidance and Case Studies
| Source | Description |
|---|---|
| Anthropic, “Developing Nuclear Safeguards for AI Through Public-Private Partnership” | Exploration of AI’s intersections with nuclear safeguards and risk |
| Chaudhry and Klein, Chemical & Biological Weapons and Artificial Intelligence | Policy-focused analysis of chemical and biological AI misuse risks |
| Executive Office of the President, United States Government Policy for Oversight of Dual Use Research of Concern and Pathogens with Enhanced Pandemic Potential | U.S. federal guidance on managing dual-use research of concern |
| Hattoh et al., “Can Large Language Models Design Biological Weapons?” | Research showing misuse potential of biodesign AI systems |
| National Nuclear Security Administration, “Artificial Intelligence for National Security” | Case studies of AI use in mission-critical, high-security environments |
| NIST, Updated Guidelines for Managing Misuse Risk for Dual-Use Foundation Models (NIST AI 800-1) | Guidance for identifying and mitigating risks in dual-use AI models |
| Sandia National Laboratories, “Artificial Intelligence at Sandia” | Insights into integrating secure AI in sensitive government environments |
| Urbina et al., “Dual Use of Artificial-Intelligence-Powered Drug Discovery” | Analysis of dual-use implications of AI-driven drug discovery |
Table D.4. Risk Management and Governance
| Source | Description |
|---|---|
| Barrett et al., Benchmark Early and Red Team Often | Recommendations for iterative evaluation and testing during AI development |
| Structured approach for assessing dual-use risks in foundation models | |
| Cybersecurity & Infrastructure Security Agency, “Secure by Design” | Principles for embedding security into AI from inception |
| Cybersecurity & Infrastructure Security Agency, AI Data Security | Guidance for protecting sensitive data in AI systems |
| Frontier Model Forum, “Foundational Security Practices” | Shared security standards for advanced AI models and infrastructure |
| Global AI Governance Observatory, “AGILE Index” | Benchmarking tool for national AI governance readiness |
| NCSC, “Machine Learning Principles” | Best practices for secure and resilient ML development |
| NCSC, “Risk Management” | Broad risk assessment and management principles for AI |
| Organisation for Economic Co-operation and Development and Global Partnership on Artificial Intelligence, “Policies, Data and Analysis for Trustworthy Artificial Intelligence” | Overview of global tools and benchmarks for assessing trustworthy AI |
| Organisation for Economic Co-operation and Development, “AI Principles” | Global principles for transparent, accountable, and trustworthy AI |
| Palo Alto Networks, “AI Governance for AI-Powered Applications” | Enterprise guidance for operationalizing AI governance |
| United Nations Educational, Scientific and Cultural Organization (UNESCO), Recommendation on the Ethics of Artificial Intelligence | Global ethical framework for the design and governance of AI systems |
| University of California, Berkeley, Responsible Use of Generative AI | University framework for responsible development and usage of generative AI |