Infrastructure risk
3 controls address this domain.
- detective
AI-CTRL-008
AI System Logging and Monitoring
Ensure that AI systems produce logs sufficient to detect abuse, investigate incidents, demonstrate compliance, and reconstruct decisions, with logs protected from tampering and retained per regulatory requirements.
Logging & MonitoringISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +4v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-010
Model Versioning and Change Control
Ensure that every model promoted to production is uniquely versioned, traceable to its training data, evaluation results, and approval, and subject to controlled change-management with rollback capability.
Change ManagementISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +4v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-019
Agentic AI Tool Authorization Boundaries
Restrict agentic AI systems to least-privilege tool authorizations; enforce approval boundaries for high-impact actions; log and review all tool invocations; and prevent privilege escalation across multi-step or multi-agent workflows.
Inference & OutputISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01