05 — frameworks & standards

MITRE ATLAS

ATT&CK for machine learning: a knowledge base of adversary tactics and techniques against AI systems, grounded in real incidents and published research, organised the same way security teams already organise threat intelligence. It is the natural place to map an attack family to a technique id when reporting to a SOC that thinks in ATT&CK terms.

Related terms

  • Red teaming Testing & measurement

    Adversarial testing that tries to make a system fail, rather than confirming it works. For AI systems it spans manual probing, curated attack corpora, and…

  • OWASP LLM Top 10 Frameworks & standards

    OWASP's list of the ten most critical risks in applications built on large language models — LLM01 Prompt Injection, LLM02 Sensitive Information…

Frameworks & standards

What auditors, buyers and regulators reference. See the compliance crosswalk for the control-by-control mapping.

MITRE ATLAS is term 4 of 8 in this part of the glossary.

Get started free Full glossary → How we test → Community agent on GitHub ↗

This page is one entry from the agentic AI security glossary, which defines 60 terms in the same style. Where a term belongs to a published taxonomy or standard — the HackAgent attack families, the OWASP lists, AMTSO's guidelines, MITRE ATLAS, ISO/IEC 42001, the NIST AI RMF, the EU AI Act — the authoritative wording is the source document's, not ours, and specifics should be verified there. "Lethal trifecta" is Simon Willison's term. OWASP® is a trademark of the OWASP Foundation; ATT&CK® and ATLAS™ are trademarks of The MITRE Corporation. Naming a framework here is description, not a claim of certification or endorsement.

glick.run — AGPL-3.0