2024ReviewedOpen access
OWASP LLM AI Security & Governance Checklist
OWASP Foundation, Sandy Dunn, Jackie McGuire
OWASP GenAI Security Project
Abstract
Practical checklist for organizations deploying LLMs covering security, governance, legal, and regulatory considerations with actionable steps.
Categories
#checklist#governance#deployment
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM02Sensitive Information Disclosure
- LLM03Supply Chain
- LLM04Data and Model Poisoning
- LLM05Improper Output Handling
- LLM06Excessive Agency
- LLM07System Prompt Leakage
- LLM08Vector and Embedding Weaknesses
- LLM09Misinformation
- LLM10Unbounded Consumption
NIST AI Risk Management Framework
- GOVERNGovern
Cite
@techreport{owasp2024owaspa,
title = {{OWASP LLM AI Security \& Governance Checklist}},
author = {{OWASP Foundation} and Sandy Dunn and Jackie McGuire},
year = {2024},
institution = {OWASP GenAI Security Project},
url = {https://genai.owasp.org/resource/llm-applications-cybersecurity-and-governance-checklist-english/}
}