TIER 2 · CLOUD AI SECURITY FRAMEWORK

CSA AI Security to AITBM Mapping

Connects CSA MAESTRO and AICM controls to AITBM test selection and deployment evidence.

How to use this crosswalk

External requirements, controls, threats, and practices identify evidence to collect or tests to run. Only measured evidence from the assessed deployment determines AITBM rubric placements, IVP, ORP, ACI, MVT findings, and ERS.

Mapping content last verified 2026-08-13. No endorsement by the external framework owner is implied.

CSA AI Security

Cloud AI security framework (threat model + controls)

CSA AI Security (MAESTRO + AI Controls Matrix) · Cloud Security Alliance (CSA)

CSA supplies cloud-specific AI security through MAESTRO's seven-layer threat model and AICM v1.1's 247 control objectives across 18 domains. This crosswalk routes CSA evidence into AITBM's IVP, current Aa/As/Cp/Rf operational dimensions, and ACI. A CSA threat, control, domain, or maturity level never has an inherent ERS value or fixed ERS reduction.

MAESTRO Layer / AICM Domain Primary AITBM Sub-Metrics Evidence use / Notes
L1 Foundation ModelsRo-1Ro-4Pr-1Pr-2Tr-4Model-level attack paths and provenance evidence
L2 Data OperationsRo-4Pr-1Pr-3Pr-4Tr-3Training, retrieval, memory, data-flow, and SDG evidence
L3 Agent FrameworksCn-1Cn-2Cn-3Cn-5Cn-6Tool authority, identity, execution, and action-gating evidence; also informs Aa
L4 Deployment & InfrastructureCn-1Cn-2Cn-4Pr-2Exposure informs As; dependencies feed graph-derived Cp; recovery evidence informs Rf
L5 Evaluation & ObservabilityTr-2Tr-3Supports ACI Ec, Tf, C_monitor, and C_behavior when effectiveness is verified
L6 Security & ComplianceCn-1Cn-5Cn-6Tr-3Policies and records can support IVP, ACI, and Rf; no retired controls-maturity dimension
L7 Agent EcosystemCn-1Cn-2Cn-5Cn-6Ro-3External-agent identity, authority, behavioral, As, and SDG evidence

Key findings

  • All seven MAESTRO layers and all 18 current AICM domains are routed; this is not a claim that all 247 AICM control objectives have identical targets or have been individually crosswalked.
  • Multi-tenancy, shared services, and agent marketplaces affect As and the System Dependency Graph; they do not set a generic ERS or Cp value.
  • AICM control objectives can route AITBM evidence only when the assessed deployment demonstrates the applicable rubric criterion and test method.
  • AISMM maturity levels provide organizational context and are not converted into IVP, ORP, ACI, or ERS values.

CSA AI Security reference →