Quantifying AI Security Coverage: A Metric-Based Evaluation Across Five Governance Frameworks

As artificial intelligence (AI) systems are increasingly integrated into more systems, there is a requirement to extend cyber and information security risk management into AI security. AI security refers to the technical and governance mechanisms that protect AI systems from external threats. A gap analysis of AI security coverage was conducted across five AI risk frameworks: National Institute of Standards and Technology's (NIST) AI Risk Management Framework (RMF), the European Union (EU) AI Act, Microsoft's Guide for Securing the AI-Powered Enterprise (GSAIPE), International Standards Organisation (ISO)/IEC 42001, and the United Kingdom's National Cyber Security Centre (NCSC) AI Security Guidelines. We define a Normalised Coverage-Depth Score (CDS) metric to systematically compare controls recommended by each framework and which risk factors they address. We perform qualitative assessment on two case studies: prompt injection and model evasion. We combine these insights to build on existing AI risk management scholarship and propose targeted recommendations for addressing AI security risk assessment and strategic prioritisation.

Paper

Full text

PDF

Quantifying AI Security Coverage: A Metric-Based Evaluation Across Five Governance Frameworks

Semantic Scholar · 2025

Abstract

As artificial intelligence (AI) systems are increasingly integrated into more systems, there is a requirement to extend cyber and information security risk management into AI security. AI security refers to the technical and governance mechanisms that protect AI systems from external threats. A gap analysis of AI security coverage was conducted across five AI risk frameworks: National Institute of Standards and Technology's (NIST) AI Risk Management Framework (RMF), the European Union (EU) AI Act, Microsoft's Guide for Securing the AI-Powered Enterprise (GSAIPE), International Standards Organisation (ISO)/IEC 42001, and the United Kingdom's National Cyber Security Centre (NCSC) AI Security Guidelines. We define a Normalised Coverage-Depth Score (CDS) metric to systematically compare controls recommended by each framework and which risk factors they address. We perform qualitative assessment on two case studies: prompt injection and model evasion. We combine these insights to build on existing AI risk management scholarship and propose targeted recommendations for addressing AI security risk assessment and strategic prioritisation.

Similar papers

© 2026 NYSGPT2525 LLC