ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Overview. What to create, and how far each policy reaches
2
Where the policies land in the framework, what the build tiers actually mean, and a count taken live from the register.
3
4
THE FOUR PARTS OF THE NIST AI RISK FRAMEWORK, and where the policies land
5
GOVERNThis is where most of the policies live. It is the policies themselves, who is accountable for them, and how the organisation keeps an eye on third parties.
6
MAPUnderstanding the situation. The context the organisation works in, the assets worth protecting, the threats, and how a person keeps oversight of what an agent is doing.
7
MEASUREWatching and testing. Logging, monitoring, evaluation and the security and resilience work all sit here.
8
MANAGEActing on the risk. Treating it, limiting what an agent may do on its own, responding when something goes wrong, and retiring systems safely.
9
10
WHAT THE BUILD TIERS MEAN
11
Draft & client-testThis is the real deliverable, the part I would actually write in full and test on the sample organisation. Taken together these get a small organisation ready for Cyber Essentials and ISO 27001, and they cover the safe adoption of agents.
12
Starter packWorth writing as a reusable template, but not something I would expect to test with a client inside this piece of work. These are the heavier middle level controls and the more operational agent policies.
13
Map onlyKept only as the marker at the very top of the ladder. The top two security levels are beyond anything a small organisation realistically needs, or could build, so I have pointed at them rather than written them out.
14
15
COUNTS, taken live from the register
16
Build tierPolicies
17
Draft & client-test38
18
Starter pack8
19
Map only2
20
Total policies48
21
22
If there is one thing worth saying out loud, it is this. Because the policies line up across frameworks, a single piece of work produces evidence for Cyber Essentials, ISO 27001 and SOC 2 all at once, and the AI columns show those same controls also meeting the newer expectations around AI governance. That overlap is the whole efficiency argument, and for an organisation that is short on both time and money, it is the part that matters most.
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100