Discussion about this post

User's avatar
Brian Martin, MD's avatar

BLUF: The paper proposes an implementation guidance and control taxonomy; but I wouldn’t describe it as an assurance framework. TRL-6/7 as implementation guidance/control taxonomy, TRL-8 only after independent control mapping and red-team validation.

The proposed approach should be mapped against NIST SP 800-207, CISA ZTMM, NIST AI RMF, OWASP Agentic AI guidance, MITRE ATLAS/ATT&CK, and FedRAMP High before being used in government-facing materials. And legal/compliance claims should be independently validated.

1 more comment...

No posts

Ready for more?