Section 25 of 25 3 min read

Reference Sources

The standards, incident reports, and empirical studies this framework is built on.

Numbered in order of first appearance. Standards and regulatory instruments are cited to the issuing body; verify the current version and any superseding revision before relying on a specific clause. Figures drawn from vendor and analyst surveys are reported as published and have not been independently audited.

URLs were checked in September 2026. Entries marked † resolve to a publisher landing page rather than a verified deep link, because the document sits behind registration, is distributed as a periodically revised artifact, or had no stable permalink at the time of writing—confirm the specific edition before citing it externally.

  1. 1“OWASP Top 10 for Agentic Applications 2026 (ASI01–ASI10),” OWASP GenAI Security Project, December 9, 2025.
  2. 2MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems, MITRE Corporation.
  3. 3AI Controls Matrix (AICM) v1.1, Cloud Security Alliance (247 control objectives across 18 domains, with mappings to ISO/IEC 42001 and ISO/IEC 27001). †
  4. 4“OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation,” OpenAI, July 21, 2026.
  5. 5“Security Incident Disclosure — July 2026,” Hugging Face, July 16, 2026.
  6. 6Zhun Wang, Nico Schiller, Hongwei Li, et al., “ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?” arXiv:2605.11086, May 11, 2026.
  7. 7“The AI Agent Governance Gap: What CISOs Need Now,” Cloud Security Alliance Lab Space, April 2026, reporting the 2026 CISO AI Risk Report survey of 235 large-enterprise CISOs and CIOs.
  8. 8“Top Cybersecurity Trends 2026,” Gartner, April 28, 2026, as reported by the Cloud Security Alliance. †
  9. 9“AI Agents at Work 2026: Securing the Agentic Enterprise,” Okta, June 2, 2026. †
  10. 10“Top Cybersecurity Threats 2026,” Forrester Research, as reported in Cybersecurity Insiders, July 2026. †
  11. 11“2026 SANS State of Identity Threats & Defenses Survey,” SANS Institute, March 10, 2026. †
  12. 12“The Non-Human Identity Governance Vacuum: AI Agents and the Fastest-Growing Unmanaged Attack Surface,” Cloud Security Alliance Lab Space, May 20, 2026.
  13. 13“State of Identity Security 2026,” Sophos, May 12, 2026 (survey of 5,000 security leaders across 17 countries). †
  14. 14Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, National Institute of Standards and Technology, January 2023.
  15. 15ISO/IEC 42001:2023 — Information Technology, Artificial Intelligence, Management System, International Organization for Standardization, December 2023. †
  16. 16“Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization,” draft concept paper, National Cybersecurity Center of Excellence, NIST, February 5, 2026.
  17. 17“OWASP Non-Human Identities Top 10,” OWASP Foundation.
  18. 18CIS Benchmarks, Center for Internet Security.
  19. 19“OWASP Top 10 for LLM Applications 2026,” OWASP GenAI Security Project, August 3, 2026.
  20. 20Supply-chain Levels for Software Artifacts (SLSA), Open Source Security Foundation.
  21. 21Secure Software Development Framework (SSDF) Version 1.1, NIST SP 800-218, National Institute of Standards and Technology, February 2022.
  22. 22Computer Security Incident Handling Guide, NIST SP 800-61, National Institute of Standards and Technology. †
  23. 23Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal of the European Union, June 13, 2024.
  24. 24Regulation (EU) 2022/2554 (Digital Operational Resilience Act), Official Journal of the European Union, December 14, 2022.
  25. 25“AI Agent Standards Initiative,” Center for AI Standards and Innovation, National Institute of Standards and Technology, launched February 17, 2026.
  26. 26Model Context Protocol, Agentic AI Foundation, Linux Foundation, December 2025; authorization specification built on OAuth 2.1 with PKCE and Resource Indicators (RFC 8707).
  27. 27Agent Control Standard (ACS), OWASP GenAI Security Project, unveiled September 1, 2026 (runtime agent governance: guardian-agent enforcement points, OpenTelemetry and OCSF observability, and an Agent Bill of Materials expressed in CycloneDX, SWID, or SPDX).
  28. 28Agent Observability Standard (AOS), OWASP GenAI Security Project. †
  29. 29“Semantic Conventions for Generative AI Systems,” OpenTelemetry (gen_ai.* namespace at Development stability; agent, workflow, tool, and model spans).
  30. 30“Practical Guide for Securely Using Third-Party MCP Servers,” OWASP GenAI Security Project. †
  31. 31“Agentic MCP Security Best Practices v1,” Cloud Security Alliance, August 2026. †
  32. 32Secure Production Identity Framework for Everyone (SPIFFE), Cloud Native Computing Foundation.

Version 1.3. Published August 2026; updated September 2026. This framework is offered as practitioner guidance and does not constitute legal or regulatory advice. Verify all regulatory mappings against current obligations in your jurisdiction.

PDF