Seven AI security frameworks exist. The incidents keep happening in the seams between them. AISIF is a five-layer architecture that integrates them — with two open instruments: assess your programme's maturity, and gate every AI system before it ships.
FREE · VERSIONED · CC BY 4.0 · MAPS TO ISO 27001 / NIST AI RMF / ISO 42001 / OWASP / ATLAS / CSA AICM
// tap a layer — each question is asked verbatim by the assessment instruments below
Illustrative case studies show AI-specific failures that traditional frameworks miss. The disclosed record shows the inverse: conventional failures that AI-specific frameworks miss — amplified by AI-scale data gravity.
How long it took outside researchers to find an AI provider's unauthenticated database — over one million log lines of plaintext chat history and API secrets on public ports. No ATLAS technique. No OWASP category. ISO 27001 fundamentals would have prevented it.
CASE STUDY D · DEEPSEEK · JAN 2025Data-platform tenants compromised with infostealer-harvested customer credentials — some stolen years earlier, never rotated, no MFA. The technique is ATT&CK Valid Accounts, not ATLAS. A control that is available but unmandated is, for risk purposes, absent.
CASE STUDY E · SNOWFLAKE CAMPAIGN · 2024The frameworks exist. The incidents keep happening in the seams between them.
The same five-layer architecture drives both instruments — released openly, with provisional scoring pending practitioner validation.
How mature is our AI security programme?
rule: a qualified answer is a No — evidence, not intent
May this system go live?
rule: Planned does not count — a gate separates implemented from intended
Three illustrative composites and two empirical analyses of disclosed incidents — each in a structured card format: attack vector, layers implicated, failure mode, mitigation, standards activated.
Reactive and person-dependent. Cannot pass the five floor questions.
Floor met: inventory, governance body, live accountability, identity trust, AI observability.
Architecture substantively in place; findings reach governance on a schedule.
The feedback loop has authority; posture evolves continuously, per estate.
Report the per-layer profile, not an average — high capability in one layer can coexist with Ad Hoc indicators in another. Your weakest layer is your programme's real level.
Versioned drafts with provisional scoring. Use them, break them, and tell us what the thresholds should be — anonymised practitioner results are the validation path. Every download asks for your email once — it's how we send updated versions and invite you into the validation cohort. One email unlocks the entire toolkit.
The full framework: architecture, control domains, standards crosswalks, maturity model, case studies A–E, and both instruments as appendices.
Download the white paper →EMAIL REQUIRED · JOINS THE VALIDATION COHORTThe 26-question instrument with rationale and maturity linkage for every question, assessment instructions, and the provisional scoring note.
Download the instrument →EMAIL REQUIRED · JOINS THE VALIDATION COHORTFormula-driven workbook: metadata capture, one tab per layer, per-estate answers, and a dashboard computing floor status and indicative levels.
Download the workbook →EMAIL REQUIRED · JOINS THE VALIDATION COHORTThe deployment gate: system profile and risk tier, 30 control checks with evidence columns, recommendation logic, and the governance sign-off block.
Download the workbook →EMAIL REQUIRED · JOINS THE VALIDATION COHORTFull analysis of the January 2025 ClickHouse exposure: layer tables, control crosswalk, maturity indicators, mitigations, and sources.
Download Case Study D →EMAIL REQUIRED · JOINS THE VALIDATION COHORTFull analysis of the 2024 identity campaign: the shared-responsibility failure, per-estate maturity argument, and the ATT&CK-not-ATLAS finding.
Download Case Study E →EMAIL REQUIRED · JOINS THE VALIDATION COHORT24 slides with speaker notes: the architecture, the empirical cases, and both instruments. Reuse internally for briefings.
Download the deck →EMAIL REQUIRED · JOINS THE VALIDATION COHORTThe SecTor edition of the same talk. The three-actions slide doubles as a 30-60-90 day starting plan.
Download the deck →EMAIL REQUIRED · JOINS THE VALIDATION COHORTLICENSED CC BY 4.0 — FREE TO USE, SHARE, AND ADAPT WITH ATTRIBUTION · creativecommons.org/licenses/by/4.0
The maturity thresholds, floor questions, and gate criteria are labelled provisional for a reason: they are hypotheses awaiting practitioner data. If you run either assessment, sharing anonymised results — even just your per-layer profile and sector — directly shapes the next version.
AISIF is maintained by Ola Lawal, a Canadian Cyber Security Professional based in Calgary, Alberta, Canada.
Enter your email to download. One submission unlocks every item in the toolkit. We'll use it only to send updated versions and, if you opt in below, to invite you to share anonymised results for threshold validation.