Frameworks 7 frameworks
The frameworks behind the catalogue
The threat catalogue brings together 7 frameworks covering law, risk management and IT security. Explore their focus and how they help assess 52 threats. Each page explains the purpose and use of a framework, lists its sources and shows the documented mappings. The catalogue contains 486 mappings from 21 primary sources.
- EU AI Act European Union (EUR-Lex) The Union’s AI law: risk classes and the obligations attached to them for providers and deployers. EU legal act, binding · 1 document · 51 threats
- GDPR European Union (EUR-Lex), European Data Protection Board (EDPB) The Union’s data protection law: it applies to AI systems as it does to any other processing of personal data. EU legal act, binding · 2 documents · 8 threats
- NIST AI RMF National Institute of Standards and Technology (NIST) A framework for managing AI risk across the whole lifecycle, organised into the four functions Govern, Map, Measure and Manage. Voluntary framework · 3 documents · 47 threats
- OWASP LLM Top 10 OWASP Foundation The OWASP Top 10 describe key security risks in applications built on large language models and outline suitable mitigations. Practical overview of risks · 11 documents · 45 threats
- MITRE ATLAS MITRE Attacks on AI systems, organised by tactics and techniques as ATT&CK does for classic IT. Open knowledge base · 1 document · 44 threats
- BSI Bundesamt für Sicherheit in der Informationstechnik (BSI) The German cybersecurity authority on generative AI models: risks from use, misuse and attacks, each with mitigations. Guidance from a public authority · 1 document · 40 threats
- BIML Berryville Institute of Machine Learning (BIML) Architectural risk analyses that break an AI system into its components and name the risks per component and data flow. Research paper · 2 documents · 29 threats
This page does not reproduce the text of the standards. It states the identifier, title and location; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.