AI Agent Security Control Library
28 controls across 8 domains for securing agentic AI in production

Version 2.0 August 2026 28 Controls | 8 Domains Free with Attribution

The operational companion to our Agentic AI Secure Deployment Framework: a full control library mapped to NIST CSF 2.0, ISO 27001:2022, CSA CCM v4, PCI DSS 4.0, and CIS Controls v8.1. Built for security teams that need audit-ready control statements, not slideware.

Three Gates Control Index Deployment Phases Downloads

Quickstart: Three Gates

Answer these about any agent already in production. A no is a gap today.

Gate 1

Can you disable this agent in under 30 seconds, without an engineer?

AI-ASC-25: Instant Kill Switch

Gate 2

Can you list every system, dataset, and tool the agent can reach right now?

AI-ASC-08: Documented Permission Inventory

Gate 3

Can you reconstruct why the agent made a specific decision last Tuesday?

AI-ASC-16: Forensic Reconstruction Capability

Three Tiers

1

Foundational

Required before first production deployment. The controls that stop the worst outcomes.

2

Core

Required for sustained production operation, within 90 days of deployment.

3

Maturity

Detection and analytics for a managed agent program as it matures.

Control Index

Full control statements, implementation guidance, risk narratives, and framework mappings are in the download package.

ID Control Domain Tier
AI-ASC-01 Network Segmentation for Agent Runtime Isolation and Boundary Protection Tier 1
AI-ASC-02 Credential Isolation and Vaulting Isolation and Boundary Protection Tier 1
AI-ASC-03 API Gateway Mediation Isolation and Boundary Protection Tier 1
AI-ASC-04 Resource Quota Enforcement Isolation and Boundary Protection Tier 2
AI-ASC-05 Process and Container Isolation Isolation and Boundary Protection Tier 2
AI-ASC-06 Least Privilege Agent Identity Authentication and Authorization Tier 1
AI-ASC-07 Non-Human Identity Registration Authentication and Authorization Tier 1
AI-ASC-08 Documented Permission Inventory Authentication and Authorization Tier 2
AI-ASC-09 Credential Rotation and Expiry Authentication and Authorization Tier 2
AI-ASC-10 Schema Validation on All Inputs Input Validation and Data Integrity Tier 1
AI-ASC-11 Data Source Integrity Verification Input Validation and Data Integrity Tier 2
AI-ASC-12 Prompt Injection Prevention Input Validation and Data Integrity Tier 1
AI-ASC-13 Input Anomaly Detection Input Validation and Data Integrity Tier 3
AI-ASC-14 Comprehensive Decision Logging Decision Logging and Audit Tier 1
AI-ASC-15 Immutable Audit Trail Decision Logging and Audit Tier 2
AI-ASC-16 Forensic Reconstruction Capability Decision Logging and Audit Tier 2
AI-ASC-17 Confidence and Uncertainty Capture Decision Logging and Audit Tier 3
AI-ASC-18 Graceful Degradation on Failure Failure Handling and Escalation Tier 1
AI-ASC-19 Defined Escalation Thresholds Failure Handling and Escalation Tier 1
AI-ASC-20 Human Response Service Level Failure Handling and Escalation Tier 2
AI-ASC-21 Rollback and State Recovery Failure Handling and Escalation Tier 2
AI-ASC-22 Behavioral Baseline and Analytics Monitoring and Detection Tier 2
AI-ASC-23 Output Validation and Hallucination Detection Monitoring and Detection Tier 2
AI-ASC-24 Agent Health Heartbeat Monitoring and Detection Tier 3
AI-ASC-25 Instant Kill Switch Incident Response and Kill Switch Tier 1
AI-ASC-26 Agent Incident Response Playbook Incident Response and Kill Switch Tier 2
AI-ASC-27 Model, Prompt, and Tool Version Control Governance and Change Management Tier 2
AI-ASC-28 Periodic Agent Risk Review Governance and Change Management Tier 2

Phased Deployment Model

Autonomy is earned in stages. A material change to model, prompt, tools, or permissions returns the agent to the prior phase for a minimum of 14 days.

1

Observation Only

Agent detects and recommends. Humans execute every action. Exit: 30 days, zero unexplained recommendations.

2

Low-Risk Automation

Agent handles enrichment, triage, and reversible actions. Exit: 30 days, escalation rate stable or declining.

3

Bounded Decisions

Agent executes within defined thresholds; above threshold escalates. Exit: 30 days, zero unapproved breaches.

4

Expanded Autonomy

Thresholds widened based on demonstrated performance after 30 consecutive clean days in Phase 3.

Download the Package

Free to use, adapt, and redistribute with attribution to Olympus Cyber. Pick the format that fits your workflow.

Control Library Document

The full library as a formatted document: every control statement, implementation guidance, risk narrative, and framework mapping.

Download PDF

Assessment Workbook

Self-assessment spreadsheet with scoring, dashboard, framework crosswalk, and deployment phase tracker. Start here if you are evaluating an agent today.

Download XLSX

Importing into a GRC platform? Machine-readable versions for direct import into your control management tooling.

Implementing It?

The library tells you what good looks like. We help you get there. Olympus Cyber runs agent architecture reviews, adversarial testing, and control implementation as part of executive resilience engagements.
🚨 Emergency IR