sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

On this page

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

RiskMandate — OWASP, as a graph

A semantic graph of OWASP: the foundation, its AI and agent projects, the standards and tools an agent deployment touches, the items of eleven lists by title, and the relationships OWASP states between them, joined to the risk model behind the business cases.

Source: https://riskmandate.ai/owasp-graph.html↗


Every OWASP document has its own ontology. Here they are joined.

OWASP is a foundation of projects, each project a set of documents or tools, each document a list of numbered items with its own vocabulary, and each of those pointing at the others and at frameworks outside. This page is that structure as one graph you can zoom through, from the foundation to a single item, with every relationship taken from OWASP’s own pages. Then it joins the graph to the risk model the rest of this section runs on.

Read: OWASP’s own pages, 24 September 2026. Items are titles only. Levels are the live project pages’, and disputed ones are marked.

The data: graph.json↗, offered to OWASP to take, correct and keep. The bridge to our model is our reading, not OWASP’s.

Five levels, one graph.

The fractal part is that each level has the same shape as the one above it: a thing, its parts, and the edges to other things. A reader can stop at any level and still be holding something whole.

OWASP itself.

How this page groups the projects.

Each with its level, type and date.

The numbered entries of 11 lists.

Stated by OWASP, including 14 frameworks outside it.

The GenAI Security Project

The umbrella project for generative AI and agent security, renamed from the LLM Top 10 project on 26 March 2025, with its own initiatives and documents. The project is Flagship on its live page.

OWASP Top 10 for LLM Applications 2025 ↗

Ten risk categories for applications built on large language models.

OWASP Top 10 for LLM Applications 2026 ↗

The edition that replaces 2025, ranked by community vote and incident data, with a different order.

OWASP Top 10 for Agentic Applications for 2026 ↗

Ten risk categories for agents that plan and act.

Agentic AI – Threats and Mitigations ↗

The detailed agent threat taxonomy the Agentic Top 10 relies on.

Securing Agentic Applications Guide 1.0 ↗

Guidance for building and deploying agent applications.

Multi-Agentic System Threat Modeling Guide v1.0 ↗

The threat taxonomy applied to systems of several agents.

State of Agentic AI Security and Governance 2.01 ↗

An overview of frameworks and regulation for agents.

Agent Name Service (ANS) v1.0 ↗

A proposed scheme for naming and discovering agents.

Agent Control Standard (ACS) ↗

Standard hooks for inspecting and controlling agents at runtime, donated to the project.

A Practical Guide for Secure MCP Server Development ↗

Guidance for people who build MCP servers.

Cheat Sheet: Securely Using Third-Party MCP Servers 1.0 ↗

Guidance for people who use MCP servers written by others.

GenAI Red Teaming Guide ↗

A method for adversarial testing of generative AI systems.

Vendor Evaluation Criteria for AI Red Teaming Providers and Tooling v1.0 ↗

Questions to ask red-teaming vendors.

LLM Applications Cybersecurity and Governance Checklist v1.1 ↗

A checklist for leaders adopting large language models.

AI Security Solutions Landscape for Agentic AI, Q2 2026 ↗

A quarterly map of tools by lifecycle stage, for agents.

AI Security Solutions Landscape for LLM and GenAI Apps, Q2 2026 ↗

The same map, for LLM applications.

Solutions Landscape for AI and Agentic Red Teaming, Q2 2026 ↗

The same map, for red-teaming tools.

GenAI Data Security Risks and Mitigations 2026 v1.0 ↗

Data-layer risks for generative AI systems.

GenAI Security Industry Framework Crosswalk ↗

Maps the project's risks to controls in outside frameworks.

AIUC-1 Crosswalk of the Agentic Top 10 ↗

A two-way mapping between AIUC-1 and the Agentic Top 10.

Threat Defense COMPASS 1.0 ↗

A worksheet method for prioritising AI threats.

GenAI Incident Response Guide 1.0 ↗

Incident response for generative AI systems.

OWASP AIBOM Generator ↗

A tool that writes AI bills of materials in CycloneDX format.

FinBot Agentic AI CTF ↗

A deliberately vulnerable agent application for training.

Other OWASP AI projects

AI and agent projects that sit beside the GenAI Security Project, each its own OWASP project.

OWASP AI Exchange ↗

Reference guidance on AI threats and controls, continuously updated.

OWASP AI Testing Guide ↗

A method and test cases for testing AI systems; v1, 26 November 2025.

OWASP AI Vulnerability Scoring System (AIVSS) ↗

A scoring method, starting with agent risks; v0.8.

OWASP AI Security Verification Standard (AISVS) ↗

Testable security requirements for AI systems; 1.0, June 2026.

OWASP Machine Learning Security Top Ten ↗

Ten risk categories for machine-learning systems; the 2023 list, marked in draft.

OWASP MCP Top 10 ↗

Ten risk categories for MCP systems; a 2025 beta, next release announced for October 2026.

OWASP Non-Human Identities Top 10 ↗

Ten risk categories for machine identities: keys, tokens, service accounts; 2025 edition.

OWASP Agentic Skills Top 10 ↗

Ten risk categories for agent skills, the layer that carries out an agent's actions; in public review.

OWASP AIBOM ↗

Inventories of the parts of an AI system.

Standards, lists and guides an agent deployment touches

OWASP work that predates agents but applies to the systems they run in and call.

OWASP ASVS ↗

Security requirements for web applications; 5.0.0, May 2025.

OWASP SAMM ↗

A maturity model for software security programmes; v2.0.

OWASP Top 10: 2025 ↗

Ten web application risk categories; the 2025 edition.

OWASP API Security Top 10 ↗

Ten API risk categories; the 2023 edition.

CycloneDX (ECMA-424) ↗

A bill-of-materials standard with a machine-learning variant; specification 1.7.

Software Component Verification Standard ↗

Supply-chain verification controls; 1.0.

Top 10 CI/CD Security Risks ↗

Ten build-pipeline risk categories.

Kubernetes Top Ten ↗

Ten Kubernetes risk categories; the 2025 list.

Cheat Sheet Series ↗

Short guides, one topic each.

Threat Modeling Project ↗

The entry point for OWASP's threat-modelling guidance, including agentic threat modelling.

Tools

Software an organisation can run, several with a business case on this site.

Threat Dragon ↗

Threat models as data-flow diagrams.

pytm ↗

Threat models written as Python code.

Coraza Web Application Firewall ↗

A web application firewall engine.

Core Rule Set (CRS) ↗

Detection rules for web application firewalls.

Dependency-Track ↗

Tracks component risk from bills of materials.

Dependency-Check ↗

Finds known vulnerable dependencies.

DefectDojo ↗

Collects and manages security findings.

Juice Shop ↗

A deliberately vulnerable web application for training.

WrongSecrets ↗

Secrets-management training exercises.

The frameworks OWASP maps to, titles only.

MITRE ATLAS

MITRE ATT&CK

MITRE CWE

NIST AI RMF (AI 100-1)

NIST AI 600-1

CSA AI Controls Matrix

ISO/IEC 42001

ISO/IEC 27090

EU AI Act

AIUC-1

Google SAIF

NIST AML taxonomy

CSA MAESTRO

ZAP (left OWASP, 1 August 2023)

The Agentic Top 10, joined to the register.

For each item, the answers in our model that bound it, the risks those answers establish, and the open-source cases on this site that change those answers. This is our reading, stated as ours. Three items touch nothing in the model; that is a finding about the model, and it says where the model has to grow.

Published unresolved, for the projects to settle.

A graph OWASP does not have yet, offered to OWASP.

The lead is closely involved with OWASP, and the intent is to offer this graph, and in time the Agent Behaviour Policy format, to OWASP rather than keep them here. Until then the data is published so anybody can take it, and it changes with a date when a project corrects it.

An item names a risk. A behaviour policy says whether yours has it.

The Top 10s say what can go wrong with agents in general. What goes wrong with yours depends on what it can reach, which is what a behaviour policy writes down, and which projects change it, which is what the business cases compute.