Skip to content
Search
paper2024ReviewedOpen access

OWASP LLM AI Security & Governance Checklist

OWASP Foundation, Sandy Dunn, Jackie McGuire

OWASP GenAI Security Project

Abstract

Practical checklist for organizations deploying LLMs covering security, governance, legal, and regulatory considerations with actionable steps.

Categories

#checklist#governance#deployment

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM02Sensitive Information Disclosure
  • LLM03Supply Chain
  • LLM04Data and Model Poisoning
  • LLM05Improper Output Handling
  • LLM06Excessive Agency
  • LLM07System Prompt Leakage
  • LLM08Vector and Embedding Weaknesses
  • LLM09Misinformation
  • LLM10Unbounded Consumption

Cite

@techreport{owasp2024owaspa,
  title = {{OWASP LLM AI Security \& Governance Checklist}},
  author = {{OWASP Foundation} and Sandy Dunn and Jackie McGuire},
  year = {2024},
  institution = {OWASP GenAI Security Project},
  url = {https://genai.owasp.org/resource/llm-applications-cybersecurity-and-governance-checklist-english/}
}