ai-governance
15 resources across 1 kinds
References
- Open ↗[un]prompted 2026 slide archivedual-uselicence
Community GitHub archive of 49 slide decks from [un]prompted 2026, the AI Security Practitioner Conference (March 3-4, San Francisco), spanning AI governance, agent security, offensive AI and agent evaluation; no licence stated.
- Open ↗
Slide deck from the SANS AI Cybersecurity Summit 2025 by Rob van der Veer of the Software Improvement Group, framing six ways AI security differs from standard security plus the AI-specific threats and controls it names.
- Open ↗
Cloud Security Alliance maturity model for an enterprise AI security program: 12 categories across three domains, five CMM levels and 120 KPI control objectives mapped to the AI Controls Matrix, plus a spreadsheet and poster.
- Open ↗
Vendor blog post from BeyondScale Technologies setting out a five-level AI security maturity model mapped to NIST AI RMF tiers and OWASP LLM Top 10 entries, with a five-question self-assessment and a per-level action plan.
- Open ↗
Serialized AI governance field guide from Moriah Hara's CISO Next Gen: 12 monthly chapters pairing a board briefing with a team playbook, five metrics and a 30/90/365-day roadmap; 2 of 12 published, chapter 1 Varonis-sponsored.
- Open ↗
Free Substack essay by Ron Fybish (CYBER WOW) setting out a five-stage AI security maturity model, a CISO/CIO/Chief-AI-Officer ownership split, layered shadow-AI discovery and a four-slide board report, with five diagrams.
- Open ↗
12-slide AI governance deck by Ragini Ramalingam, Director of Enterprise Security at Snowflake: a cross-functional steering committee, four visibility pathways, Enabled/Gated GenAI features, six coding-agent guardrails.
- Open ↗
Seven-slide [un]prompted 2026 deck in which Billy Norwood, CISO of FFF Enterprises, proposes a three-body risk-tiered AI governance structure and lists the stricter intake, policy and control measures he says are needed.
- Open ↗
Guide from the OWASP GenAI Security Project on standing up an AI security Center of Excellence: 11 per-function responsibility tables, five example objective/KPI sets and a four-phase 12-month rollout, aimed at CISOs.
- Open ↗
Preliminary-draft NIST Community Profile giving all 106 CSF 2.0 Subcategories a proposed priority under three focus areas — securing AI components, AI-enabled defense, thwarting AI attacks — and AI considerations where any exist.
- Open ↗
OWASP's SAMM-derived maturity model for AI programs: eight domains of three practices, each scored 0-3 with partial "+" levels via yes/no worksheets, plus a free Excel toolkit; for benchmarking and planning AI governance.
- Open ↗Own AI Securely: The SANS Secure AI Blueprintlicenceopt-in
16-page paper by Rob T. Lee of SANS Institute setting out the three-track Secure AI Blueprint — Protect AI, Utilize AI, Govern AI — on the six Critical AI Security Guidelines control categories; free SANS login to download.
- Open ↗
RSAC 2025 deck by Ian Brelinsky (OpenAI) and Josiah Hagen (Trend Micro) summarising CoSAI's four workstreams - AI supply chain, preparing defenders, risk governance, agentic AI - and mapping ten job roles to existing frameworks.
- Open ↗
Chris Cochran's SANS Institute eBook defining a three-pillar (Protect/Utilize/Govern) AI security maturity model with five stages, 0-5 evidence-based scoring and two cap rules; a free SANS account is required to download.
- Open ↗
Conference deck by LTC Chase Hasbrouck of U.S. Army Cyber Command on Army and DoD AI adoption in three phases, 2023 research previews to 2026 enterprise agreements, with a cost-per-query table for one 20-page log-analysis task.