Standards Crosswalk
The ten domains mapped to OWASP ASI 2026, NIST AI RMF, ISO/IEC 42001 and the EU AI Act.
| This framework | OWASP ASI 20261 | NIST AI RMF14 | ISO/IEC 4200115 | Other |
|---|---|---|---|---|
| DISC — Discovery | ASI10 | MAP 1, MAP 3 | Annex A — AI system inventory | CSA AICM v1.1; OWASP ACS Agent Bill of Materials27 |
| AUTH — Identity | ASI03, ASI07 | GOVERN 2, MANAGE 2 | Annex A — roles and responsibilities | NCCoE agent identity concept paper16; OWASP NHI Top 1017 |
| CRED — Credentials | ASI03 | MANAGE 2 | Annex A — operational controls | OWASP NHI Top 10; SPIFFE32 |
| ISO — Isolation & Egress | ASI05 | MANAGE 2, MEASURE 2 | Annex A — technical controls | CIS Benchmarks18; MITRE ATLAS |
| TOOL — Tool Authorization | ASI02, ASI07, ASI08 | GOVERN 1, MANAGE 4 | Annex A — operational controls | MCP OAuth 2.1 (Linux Foundation / AAIF); OWASP Agent Control Standard27 |
| DATA — Data & Memory | ASI01, ASI06 | MAP 2, MEASURE 2 | Annex A — data management | OWASP LLM Top 1019 |
| SUP — Supply Chain | ASI04 | GOVERN 6, MAP 4 | Annex A — third-party management | SLSA20; SSDF21; MITRE ATLAS; OWASP third-party MCP guide30; CSA Agentic MCP Best Practices31 |
| OBS — Detection | ASI08, ASI10 | MEASURE 3, MEASURE 4 | Annex A — monitoring | MITRE ATLAS; OpenTelemetry GenAI conventions29; OWASP Agent Observability Standard28; OCSF |
| RESP — IR & Forensics | ASI08, ASI10 | MANAGE 4 | Annex A — incident management | NIST SP 800-6122 |
| GOV — Governance | ASI09 | GOVERN (all) | Clauses 4–10 | EU AI Act Arts. 9, 14, 15, 17, 26 |
| RET — Decommissioning | ASI03, ASI10 | MANAGE 2, MANAGE 3 | Annex A — AI system lifecycle | OWASP NHI Top 10; ISO/IEC 27001 A.8 |
Regulatory notes. The EU AI Act’s obligations around risk management (Art. 9), human oversight (Art. 14), accuracy and robustness including cybersecurity (Art. 15), quality management (Art. 17), and deployer obligations (Art. 26) apply where agentic systems fall within high-risk classifications.23 Sector regimes—DORA for EU financial services,24 HIPAA, PCI DSS, SEC cyber disclosure—impose additional requirements that were drafted without agents in contemplation; assume the regulator’s position will be that existing obligations apply unchanged until stated otherwise. Where an agent acts on regulated data or systems, document the mapping explicitly rather than waiting for guidance. Standards work specific to agents is in flight—NIST’s Center for AI Standards and Innovation opened an AI Agent Standards Initiative in February 202625 and the NCCoE has published a concept paper on agent identity and authorization16—but neither is a reason to defer the controls in Section 6, none of which any eventual standard is likely to contradict.
References cited in this section
19 of 32 · numbering matches the PDF
- 1"OWASP Top 10 for Agentic Applications 2026 (ASI01–ASI10)," OWASP GenAI Security Project, December 9, 2025.genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai ↗
- 14Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, National Institute of Standards and Technology, January 2023.www.nist.gov/itl/ai-risk-management-framework ↗
- 15ISO/IEC 42001:2023 — Information Technology, Artificial Intelligence, Management System, International Organization for Standardization, December 2023. †www.iso.org/standard/42001 ↗
- 27Agent Control Standard (ACS), OWASP GenAI Security Project, unveiled September 1, 2026 (runtime agent governance: guardian-agent enforcement points, OpenTelemetry and OCSF observability, and an Agent Bill of Materials expressed in CycloneDX, SWID, or SPDX).genai.owasp.org/2026/09/01/owasp-genai-security-project-unveils-2026-top-10-for-llm-applications-new-agent-control-standard-and-sponsors-as-community-tops-30000-members ↗
- 16"Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization," draft concept paper, National Cybersecurity Center of Excellence, NIST, February 5, 2026.www.nccoe.nist.gov/projects/software-and-ai-agent-identity-and-authorization ↗
- 17"OWASP Non-Human Identities Top 10," OWASP Foundation.owasp.org/www-project-non-human-identities-top-10 ↗
- 32Secure Production Identity Framework for Everyone (SPIFFE), Cloud Native Computing Foundation.spiffe.io ↗
- 18CIS Benchmarks, Center for Internet Security.www.cisecurity.org/cis-benchmarks ↗
- 19"OWASP Top 10 for LLM Applications 2026," OWASP GenAI Security Project, August 3, 2026.genai.owasp.org/resource/owasp-genai-llm-top-10-2026 ↗
- 20Supply-chain Levels for Software Artifacts (SLSA), Open Source Security Foundation.slsa.dev ↗
- 21Secure Software Development Framework (SSDF) Version 1.1, NIST SP 800-218, National Institute of Standards and Technology, February 2022.csrc.nist.gov/pubs/sp/800/218/final ↗
- 30"Practical Guide for Securely Using Third-Party MCP Servers," OWASP GenAI Security Project. †genai.owasp.org/resources ↗
- 31"Agentic MCP Security Best Practices v1," Cloud Security Alliance, August 2026. †cloudsecurityalliance.org/research/artifacts ↗
- 29"Semantic Conventions for Generative AI Systems," OpenTelemetry (gen_ai.* namespace at Development stability; agent, workflow, tool, and model spans).opentelemetry.io/docs/specs/semconv/gen-ai ↗
- 28Agent Observability Standard (AOS), OWASP GenAI Security Project. †aos.owasp.org ↗
- 22Computer Security Incident Handling Guide, NIST SP 800-61, National Institute of Standards and Technology. †csrc.nist.gov/pubs/sp/800/61 ↗
- 23Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal of the European Union, June 13, 2024.eur-lex.europa.eu/eli/reg/2024/1689/oj ↗
- 24Regulation (EU) 2022/2554 (Digital Operational Resilience Act), Official Journal of the European Union, December 14, 2022.eur-lex.europa.eu/eli/reg/2022/2554/oj ↗
- 25"AI Agent Standards Initiative," Center for AI Standards and Innovation, National Institute of Standards and Technology, launched February 17, 2026.www.nist.gov/artificial-intelligence/ai-agent-standards-initiative ↗