الانتقال إلى المحتوى
← AI security frameworks and red teaming

الدرس 6 من 9 · 8 دقيقة

CIS Controls applied to AI systems

Use CIS Controls v8.1 and the three AI companion guides CIS published in 2026 to check that baseline hygiene covers models, agents and their tool connections.

هذه الصفحة متاحة بالإنجليزية حاليًا.

The other three frameworks in this course are about AI. The CIS Critical Security Controls are about everything, and that is their value here. A prompt-injection finding is often only as damaging as the missing basics around it: an unlogged tool call, an over-privileged token, an unknown application. CIS Controls give you a plain checklist of those basics, and in 2026 CIS extended them to AI directly.

CIS Controls v8.1 in brief

CIS describes v8.1 as an iterative update to version 8. It was guided by three principles, context, coexistence (alignment with other security frameworks) and consistency (continuity for existing users), and it realigned the NIST Cybersecurity Framework mappings to CSF 2.0, added the Govern function from CSF 2.0, revised asset classes and clarified some safeguard descriptions. The 18 controls are:

  1. Inventory and Control of Enterprise Assets
  2. Inventory and Control of Software Assets
  3. Data Protection
  4. Secure Configuration of Enterprise Assets and Software
  5. Account Management
  6. Access Control Management
  7. Continuous Vulnerability Management
  8. Audit Log Management
  9. Email and Web Browser Protections
  10. Defenses against harmful software
  11. Data Recovery
  12. Network Infrastructure Management
  13. Network Monitoring and Defense
  14. Security Awareness and Skills Training
  15. Service Provider Management
  16. Application Software Security
  17. Incident Response Management
  18. Penetration Testing

The AI companion guides

On 20 April 2026, CIS announced three companion guides for CIS Controls v8.1, released with Astrix Security and Cequence Security. They cover large language models, AI agents and the Model Context Protocol (MCP). The press release describes them as extending the Controls into AI systems and adapting them to AI-driven architectures. So the answer to the common question, “is there CIS guidance for AI?”, is yes, and you should read the guide that matches your system:

Summaries follow CIS’s own descriptions on its pages.
GuideFocus (as CIS describes it)
AI and LLM Companion GuideText-centric generative AI across the lifecycle: training and fine-tuning, deployment, inference, monitoring and retirement
AI Agents Companion GuideThe agent layer where planning, reasoning, tool invocation and multi-step workflows occur; risks named include unauthorised actions, data leakage and unintended system changes
MCP Companion GuideSecure tool access, management of non-human identities, and auditable interactions across the protocol layer

The LLM guide’s central message is useful to memorise. Many existing safeguards apply directly: asset management, secure configuration, identity, logging, vulnerability management and supplier governance. But implementation must account for prompt injection, retrieval poisoning, over-permissioned tool integrations and provider-driven model updates. It also highlights controls that are new in emphasis: prompt and guardrail change control, context boundary enforcement, model and dataset provenance, and containment levers to respond quickly when AI-driven workflows behave unexpectedly. The agents guide says each section interprets relevant safeguards in the context of agent behaviour, showing where traditional controls still apply and where new patterns must be considered.

A mapping you can use in a review

The table below is this course’s own illustration of how the control families translate to AI. It works at the level of control names; the companion guides map to individual safeguards, so consult them for numbered detail.

CIS control (name)Question to ask about an AI system
1 and 2: Asset inventoriesDo we know every AI application, agent, model file, plugin and MCP server in use, including ones staff installed themselves?
3: Data ProtectionWhat data can reach prompts, retrieval indexes and logs, and who can read it?
4: Secure ConfigurationAre system prompts and guardrail settings under change control, like any other configuration?
5 and 6: Accounts and AccessDoes each agent have its own identity, with the minimum permissions for its task?
7: Vulnerability ManagementWho patches AI frameworks and libraries, and who tracks provider model updates that change behaviour?
8: Audit LogsDo logs record tool invocations, data access and the identity used?
13: Network Monitoring and DefenseCan we see and restrict where AI tools send data?
15: Service Provider ManagementHave we reviewed the model provider’s documentation and terms?
17: Incident ResponseCan we switch off a tool, revoke a credential or disable an agent quickly?
18: Penetration TestingHas the AI system been tested by someone trying to misuse it?

Control 18 is the entry point to the next lesson: red teaming is the AI-specific form of penetration testing. But it works best as the last check, after the earlier rows are answered. If you cannot list your agents (row 1) or tell what they did last night (row 8), a red team will mostly discover that.

أهم النقاط

  • CIS Controls v8.1 has 18 controls, and CIS published AI LLM, AI Agents and MCP companion guides on 20 April 2026.
  • Many existing safeguards (assets, configuration, identity, logging, vulnerability and supplier management) apply directly to AI, but must account for prompt injection, retrieval poisoning, over-permissioned tools and provider model updates.
  • New emphasis areas include prompt and guardrail change control, context boundaries, model and dataset provenance, and containment levers.
  • Use CIS controls as the baseline check before an AI red-team engagement, so testing finds new problems rather than missing basics.

اختبر نفسك

  1. 1. What did CIS publish on 20 April 2026?

    • CIS Controls v9
    • Three companion guides adapting CIS Controls v8.1 to LLMs, AI agents and MCP — صحيح.
    • A model certification scheme
    • A scoring scheme for AI models

    CIS, Astrix Security and Cequence Security released the AI LLM, AI Agent and MCP companion guides for CIS Controls v8.1.

  2. 2. According to CIS’s LLM guide, which is true of existing safeguards?

    • They are irrelevant to LLMs
    • Many apply directly, but implementation must account for AI-specific risks — صحيح.
    • Only Data Recovery applies
    • They apply only during model training

    The guide lists asset management, secure configuration, identity, logging, vulnerability management and supplier governance as applying directly, while stressing AI-specific risks.

  3. 3. Which CIS control is closest to AI red teaming?

    • Control 3 Data Protection
    • Control 14 Security Awareness and Skills Training
    • Control 18 Penetration Testing — صحيح.
    • Control 11 Data Recovery

    Red teaming an AI system is the AI-specific counterpart of penetration testing, which is CIS Control 18.

جرّبها مع FireAI

طبّق هذا الدرس عمليًا على جهاز Mac الخاص بك.

المصادر

طبّق ذلك على جهاز Mac الخاص بك

جرّب كل الميزات مجانًا لمدة 17 يومًا، دون بطاقة.

تنزيل لجهاز Mac التوثيق