Dedicated crosswalks
Each has its own canonical URL and explicit evidence boundary.
EVIDENCE CROSSWALKS
Sixteen external threat taxonomies, control standards, regulations, certification regimes, and maturity models mapped to AITBM evidence and test-selection targets. External frameworks never set an AITBM score by themselves.
Each has its own canonical URL and explicit evidence boundary.
The measurement substrate that external evidence may support.
Controls and compliance labels never carry a generic ERS delta.
Core threat, control, and certification references most directly connected to AITBM assessment.
Routes the released OWASP LLM risks to AITBM tests and evidence without assigning generic risk scores.
Maps agentic threats and the companion Top 10 to AITBM containment, robustness, privacy, and operational-risk evidence.
Shows how AISVS control-verification results can supply evidence for AITBM's 23 measured sub-metrics.
Uses released ATLAS tactics and techniques to select AITBM tests while keeping system scoring deployment-specific.
Relates AIUC-1 requirements to AITBM evidence, assurance, and operational-risk inputs without treating certification as a score.
Connects defensive techniques to the AITBM sub-metrics they may evidence when deployed effectiveness is measured.
Governance, regulatory, and cloud-security frameworks that broaden deployment and assurance evidence.
Maps GOVERN, MAP, MEASURE, and MANAGE activities to AITBM assessment evidence and decision outputs.
Relates management-system and impact-assessment evidence to AITBM scoring, governance, and assurance inputs.
Maps relevant legal obligations to evidence routes while making clear that AITBM is not a legal-compliance determination.
Connects CSA MAESTRO and AICM controls to AITBM test selection and deployment evidence.
Maturity, cyber-profile, defense, and prior-art frameworks that support specialized assessment needs.
Relates the Cyber AI Profile's outcomes to AITBM's measured properties, context, and evidence confidence.
Shows how maturity practices can support AITBM evidence without converting maturity levels directly into ERS.
Maps COMPASS practices to AITBM threat prioritization, evidence collection, and scoring inputs.
Uses defensive countermeasures to organize evidence routes while AITBM tests determine the actual score.
Explains where CVSS complements AITBM and why AI system risk still requires multidimensional and confidence-aware assessment.
Additional governance guidance with narrower but useful evidence relationships.