Requirements met — NIST, CIS & OWASP (incl. LLM) mapping
Security and GRC reviewers ask which requirements Confidential AI Network meets and how they line up with NIST, CIS, and OWASP (web and LLM).
Quick orientation
| NIST | U.S. standards body. CSF 2.0 organizes outcomes (Govern → Recover); SP 800-53 Rev. 5 lists detailed baseline controls for system security plans. |
| CIS | Prioritized Critical Security Controls (practical safeguards) plus hardening Benchmarks. Current download: Controls v8.1; browse the 18 controls. |
| OWASP | Application-security risk lists. Top 10:2021 for web/API; LLM Top 10 (2025) for GenAI apps. |
The canonical matrix is:
SECURITY_CONTROLS_NIST_CIS_MAPPING.md
It covers eighteen requirements (identity, least privilege, network, encryption, confidential compute, provenance, SIEM, IaC, DR, privacy hooks, contract governance, OWASP web / LLM) with clickable links into:
- NIST Cybersecurity Framework 2.0 (CSF Reference Tool · CPRT category / outcome IDs)
- NIST SP 800-53 Rev. 5 (CPRT control catalog)
- CIS Controls v8.1 (18-control list · v8 overview)
- OWASP Top 10:2021 (A01–A10 — how addressed in app + edge)
- OWASP LLM Top 10 (2025) (LLM01–LLM10 — train / infer / Open-GMASE gates)
- Evidence pointers into multi-cloud patterns, IAM, SIEM, product tour, and lifecycle docs
This post is orientation only — the markdown file is the source of truth. It is a control crosswalk, not a claim of SOC 2 / ISO 27001 / FedRAMP / OWASP certification for a specific tenancy.