Agentic Risk & Autonomous System Security
Domain purpose
Controls and requirements
D3-CTL-01Least Agency Enforcement
Limit agent tool access and action scopes to prevent catastrophic autonomous actions.
D3-CTL-02Inter-Agent Communication Security
Authenticate and encrypt all agent-to-agent messaging to prevent internal compromise.
D3-CTL-03Agentic Prompt Chaining Detection
Detect distributed attacks leveraging multiple agents/turns to bypass controls.
D3-CTL-04Embodied Ai Safety Controls
Secure physical-world AI interfaces (robots, drones, IoT) from sensor spoofing and unsafe commands.
D3-CTL-05Multi-Agent Trust Chain Attestation
Cryptographically verify agent identity, permissions, and trust relationships.
D3-CTL-06Persistent Memory Exfiltration Prevention
Protect cross-session user data stored in vector stores or agent memory.
D3-CTL-07Secure Memory Lifecycle Management
Ensure secure creation, rotation, and cryptographic deletion of AI memory stores.
Implementation use
Determine applicability using the framework scope and system context. Implementation should be proportionate to risk and supported by evidence sufficient to validate the intended outcome.