Every dashboard shows green. Every control functions. And you still cannot prove what your AI is doing.
You built a real security program. Patch cycles that run on schedule. Zero trust that took two years to implement correctly. Incident response playbooks tested under pressure. Then, somewhere in the last eighteen months, AI agents, MCP servers, embedded vendor features, and autonomous tools walked into your environment faster than your operating model could absorb them. That is not a failure of effort. It is a failure of speed.
Now a question is forming. It comes from a regulator, an audit committee, an insurer, or an enterprise customer expanding its security questionnaire. It always means the same thing: can you prove your AI exposure is known, controlled, and governed? Evidence, documented, dated, scored, and defensible, is something else entirely. This book closes that gap.
THE GREEN DASHBOARD FALLACYNone of your dashboards are lying. The problem is structural: they were all designed before AI agents entered your environment at scale. The fallacy is not a detection failure. It is an assumption failure. The greatest AI security risk facing your organization is not that you are undefended. It is that leadership believes the existing program is already watching.
WHAT YOU PRODUCESix artifacts built to survive a regulator, an insurer, an auditor, an enterprise customer, or your own audit committee:
These are not concepts to understand. They are documents to hand over.
THE METHODThree instruments carry the audit. The Visibility Triangle sorts every gap into visible, suspected, or undetectable, and the zone determines the response. The Six-Domain Operating View structures the work across governance, security operations, architecture, application security, third-party risk, and data protection. The Defensible AI Security Baseline sets a dated, scored standard across seven areas with a named owner for each, which turns a one-time audit into a program.
Seven binding frameworks run underneath: NIST AI RMF, ISO/IEC 42001, the OWASP LLM and Agentic Top 10, OWASP AIVSS, MITRE ATLAS, HITRUST AI, and Google SAIF. They are cited only where they actually bind, never as a compliance tour.
The engineering thesis is stated plainly. AI agents must be audited as privileged, non-human actors inside your control environment. Once an agent can retrieve data, invoke tools, write records, or trigger workflows, it is an operational actor with an identity, a privilege scope, and a blast radius. Your access review was built for human identities with enumerable behavior. It was not built for this.
Every domain chapter closes the same way: the Board Question your leadership must answer, the Evidence Required to answer it, the Common Failure Pattern that breaks the answer, and a 30-Day Move with a named output, a named owner, and a completion condition.
There is no vendor agenda here. No products are recommended. Its only job is to help you produce evidence that survives whoever asks the question first.
Volume V of The Operating Discipline for AI Library, and the opening volume of Pillar II, AI Risk Governance and Security. It extends Volumes I through IV and stands on its own. The executive who finishes this book walks into the next board meeting holding proof, not promises.
Die Inhaltsangabe kann sich auf eine andere Ausgabe dieses Titels beziehen.
Anbieter: PBShop.store UK, Fairford, GLOS, Vereinigtes Königreich
PAP. Zustand: New. New Book. Shipped from UK. Established seller since 2000. Artikel-Nr. L2-9798996940226
Anzahl: Mehr als 20 verfügbar