Appendices

Appendix C: External Standards Mapping

Working draft

This page renders the current aws2 working draft. It is not a released standard, certification program, compliance framework, legal analysis, endorsement, or public conformance claim.

This appendix provides a compact source-by-source mapping baseline derived from the detailed source-first and family-first crosswalk notes maintained in references/crosswalk/aws2-crosswalk.md and references/crosswalk/aws2-crosswalk-family-view.md. It is informative in this working draft. It is not a normative crosswalk, legal analysis, certification basis, conformance claim, or statement of equivalence to any external source.

Source-specific rows preserve the access dates, mapping postures, evidence angles, and claim limits from the crosswalk baseline at a compact level. A future released profile may expand these rows into requirement-level mappings only after mapping governance, claim-review rules, and release criteria exist.

External sourceAccess date and status signalaws2 families mapped in this baselinePostures representedEvidence angle summaryClaim limit
EU AI Act official sourcesAccessed 2026-05-28; official European Commission and AI Act Service Desk pages used for role-sensitive, risk-based obligationsAWS2-SCP, AWS2-DEL, AWS2-RUN, AWS2-GOV, AWS2-LOG, AWS2-VAL, AWS2-CTX, AWS2-SEC, AWS2-SRCcandidate control; supports evidence forscoped system records, authority matrix, guardrail tests, retained logs, oversight records, disclosure workflow evidence, supplier due-diligence notessupports selected governance, oversight, transparency, logging, and due-diligence evidence only; no legal compliance, high-risk classification, conformity assessment, GDPR, biometric-lawfulness, or GPAI-provider compliance claim
CSA AARMAccessed 2026-05-28; CSA page says AARM v1.0 is published with Core and Extended conformance review structureAWS2-RUN, AWS2-LOGcandidate control; supports evidence forruntime policy exports, step-up approval records, denied-action logs, action receipts, policy-decision logsmaps to AARM-style runtime controls only where a real runtime implements and preserves those artifacts; no AARM conformance claim
OWASP AISVSAccessed 2026-05-28; OWASP incubator project, public docs show Version 0.1AWS2-SRC, AWS2-CTX, AWS2-DEL, AWS2-WSB, AWS2-RUN, AWS2-SEC, AWS2-LOG, AWS2-VAL, AWS2-GOVcandidate control; supports evidence forsource records, version pins, context-boundary tests, identity and approval records, sandbox tests, entitlement tests, interaction metadata, adversarial testing, oversight policystrong testable-control input, but incubator v0.1 does not prove AISVS conformance, organizational accountability, runtime enforcement completeness, or full safety
AIUC-1Accessed 2026-05-28; commercial AI-agent security, safety, and reliability scheme with latest public release on 2026-04-15 and next listed release on 2026-07-15AWS2-SRC, AWS2-LOG, AWS2-GOV, AWS2-DEL, AWS2-RUN, AWS2-WSB, AWS2-SEC, AWS2-VALcandidate control; supports evidence for; advisory inputagent identity records, agent cards, permission matrices, MCP and tool allowlists, runtime policy configuration, deployment architecture, DLP evidence, human-review and testing packetsuseful certification-style comparator and evidence signal, but no AIUC-1 certificate equivalence, privacy/legal sufficiency, AARM equivalence, or proof of complete safety
CCSS, AISVS, and AIUC-1 comparisonAccessed 2026-05-28 in Agent planning notes; structural comparison of assurance models, levels, evidence, audits, and certification claimsAWS2-VALadvisory inputtest plans, validation summaries, recurring review cadencestructural analogy only; not a direct control mapping or certification model for aws2
OWASP Agentic Skills Top 10Accessed 2026-05-28; OWASP incubator project with active-development and 2026-edition signalsAWS2-SCP, AWS2-WSB, AWS2-SRC, AWS2-SEC, AWS2-VAL, AWS2-GOVcandidate control; supports evidence forskill inventory, owner map, installation approvals, sandbox configuration, permission manifests, scan reports, incident-response procedureshigh-value skill-layer input, but emerging guidance rather than a mature assurance standard; no proof of full workspace boundary, endpoint hardening, or absence of leakage
OWASP AIVSSAccessed 2026-05-28; latest public release is v0.8 scoring methodologyAWS2-VAL, AWS2-GOVadvisory input; supports evidence forvulnerability score records, assessment reports, severity rationale, exception decisions, remediation backlogscoring can support prioritization and governance evidence, but it does not implement preventive controls or provide standalone governance or certification
CSA AI Controls MatrixAccessed 2026-05-28; released 2025-07-09 and updated 2025-10-30 with AI-CAIQ, implementation guidance, auditing guidance, and mappingsAWS2-SCP, AWS2-RUN, AWS2-VAL, AWS2-GOVcandidate control; supports evidence for; advisory inputscoped AI-CAIQ responses, role assignments, control-applicability notes, governance maps, audit-guideline notessupports enterprise AI control mapping and assessment preparation, but remains broader than agentic workspace security and does not imply STAR for AI or third-party attestation
CSA MAESTROAccessed 2026-05-28; CSA describes MAESTRO as a layer-by-layer Agentic AI threat-modeling frameworkAWS2-SCP, AWS2-DEL, AWS2-WSB, AWS2-SRC, AWS2-CTX, AWS2-LOG, AWS2-VAL, AWS2-GOVcandidate control; advisory inputlayer-scoped threat models, architecture maps, identity abuse cases, deployment threat models, RAG and context-risk tests, observability reviews, change-review recordsthreat-modeling and design input only where no specific control exists; not a control catalogue, scoring method, certification, or evidence of enforcement
NIST AI RMF 1.0Accessed 2026-05-28; voluntary framework released 2023-01-26 around GOVERN, MAP, MEASURE, and MANAGEAWS2-SCP, AWS2-DEL, AWS2-SRC, AWS2-VAL, AWS2-GOVcandidate control; supports evidence for; advisory inputintended-use statements, impact maps, owner matrices, supplier inventories, measurement plans, risk policies, exception registersstrong governance and risk-management input, but not an agentic-workspace-specific conformance standard or runtime identity-enforcement proof
NIST AI 600-1Accessed 2026-05-28; 2024 Generative AI Profile for AI RMF with risk-management actions across harm categoriesAWS2-SCP, AWS2-CTX, AWS2-SEC, AWS2-SRC, AWS2-LOG, AWS2-VAL, AWS2-GOVcandidate control; supports evidence forgenerative-AI risk profiles, data-flow maps, component inventories, privacy and misuse tests, incident records, provenance records, evaluation reportsuseful generative-AI risk-profile input, but does not decide workspace boundaries, prove leakage controls, or define aws2-specific agentic-workspace tests
ISO/IEC 42001Accessed 2026-05-28; ISO lists ISO/IEC 42001:2023 as published Edition 1 for an Artificial Intelligence Management SystemAWS2-SCP, AWS2-DEL, AWS2-LOG, AWS2-VAL, AWS2-GOVcandidate control; supports evidence forAIMS scope statements, AI system inventories, policy-owner matrices, management-system records, risk-treatment plans, management review notesmanagement-system mapping only; no ISO/IEC 42001 certification claim without an actual accredited certification path
ISO/IEC 23894Accessed 2026-05-28; ISO lists ISO/IEC 23894:2023 as published Edition 1 AI risk-management guidanceAWS2-SCP, AWS2-SEC, AWS2-CTX, AWS2-VAL, AWS2-GOVcandidate control; supports evidence for; advisory inputAI risk registers, context assumptions, risk assessments, data and activity maps, treatment decisions, review cadence, risk acceptance recordspublic ISO pages expose only high-level metadata and descriptions; no detailed control or certifiable management-system claim is made from this mapping
Five Eyes guidance on careful adoption of agentic AI servicesAccessed 2026-05-28; joint guidance first published 2026-05-01 by ASD ACSC, CISA, NSA, Cyber Centre, NCSC-NZ, and NCSC-UKAWS2-SCP, AWS2-DEL, AWS2-RUN, AWS2-WSB, AWS2-SRC, AWS2-CTX, AWS2-SEC, AWS2-LOG, AWS2-VAL, AWS2-GOVcandidate control; supports evidence forcomponent inventories, delegation matrices, JIT credential records, approval gates, rollout and rollback records, context-boundary tests, logs, red-team summaries, adoption gatesstrong practical guidance for agentic AI adoption, but not a conformance test suite, legal requirement, certification, or proof that all prompt-injection, exposure, retention, or endpoint risks are solved
MITRE ATLASAccessed 2026-05-28; living knowledge base of AI-enabled adversary tactics, techniques, mitigations, and case studiesAWS2-SCP, AWS2-DEL, AWS2-RUN, AWS2-SRC, AWS2-CTX, AWS2-SEC, AWS2-LOG, AWS2-VAL, AWS2-GOVcandidate control; supports evidence for; advisory inputATLAS coverage maps, identity threat models, tool-call abuse tests, provenance checks, prompt and context-poisoning tests, secret scanning, detection mapping, red-team cases, prioritized remediationthreat taxonomy and scenario-design input only; not a control catalogue, required log format, audit method, assurance-level model, or substitute for management-system and legal obligations

Context-only sources from section 10.3 that are not represented with source-specific rows above are intentionally excluded from this appendix until specific family-level mapping rows are added and reviewed. The current context-only sources are the CryptoCurrency Security Standard, OWASP Agentic AI Threats and Mitigations, and the NIST AI Agent Standards Initiative.

Claim limit:

  • This appendix is a compact informative mapping baseline. It is not a complete crosswalk, legal analysis, certification basis, audit method, standards-body endorsement, or equivalence claim.