OSAFIS

OSAFIS Relationship to Existing Frameworks

OSAFIS 2.0.0-draft.1 · Research proposal · 8 min read

On this page
  1. Resources and their distinct purposes
  2. Rules for mapping
  3. Historical LLM 2025 mapping
  4. Agentic 2026 mapping
  5. A worked mapping decision
  6. Coverage and novelty claims
  7. Maintenance

OSAFIS should interoperate with established AI security resources. Its proposed contribution is a contract-centred representation that connects a finding to analytical domains, actual system relationships and evidence. Whether that representation improves research or assessment practice is an empirical question. The existence of nine domains does not establish a coverage advantage, and an external resource need not adopt these domains to address a relevant threat.

This document distinguishes descriptions supported by external sources from OSAFIS mapping judgements. It records a source snapshot checked on 7 September 2026. Mappings below are provisional interpretations, not endorsements, certification crosswalks or proofs that the resources are equivalent.

Resources and their distinct purposes

NIST AI 100-2 E2025 provides adversarial machine-learning terminology organised around factors including learning methods, lifecycle stages and attacker goals, capabilities and knowledge. OSAFIS can retain these factors in a threat model while adding its proposed domain and contract assignments. The NIST publication does not validate the OSAFIS domain count or names. NIST adversarial machine learning taxonomy

NIST AI RMF supports voluntary management of risks associated with AI and considers effects on people, organisations and society. OSAFIS findings could supply evidence to a broader risk-management process, but completing a technical assessment does not demonstrate that all governance or trustworthiness responsibilities have been met. The NIST site reports work to revise AI RMF 1.0; citations should identify the version actually used. NIST AI Risk Management Framework

MITRE ATLAS is a knowledge base of adversarial tactics, techniques and case studies targeting AI. Its data also includes mitigations and typed relationships. OSAFIS must therefore not claim that external resources provide no account of relationships or propagation. Where a technique genuinely matches a case, an ATLAS identifier can accompany the local contract analysis, with the relevant ATLAS content and format versions. No comprehensive technique-level ATLAS crosswalk is asserted in this edition. MITRE ATLAS data repository

OWASP provides risk descriptions, attack scenarios and mitigation guidance for LLM and agentic applications. The 2025 LLM list remains useful as a versioned historical reference, while OWASP's resource page identifies an LLM 2026 edition dated 3 August 2026. The agentic 2026 guide is dated December 2025. The year in a guide title is not necessarily its publication year. OWASP LLM 2025 list, OWASP LLM 2026 resource, OWASP agentic 2026 resource

OWASP also publishes an industry framework crosswalk. Its existence is relevant to positioning: interoperability and cross-framework mapping are established activities, not exclusive OSAFIS capabilities. The OSAFIS-specific mapping task is to justify how a concrete failed contract relates to a particular external entry. OWASP framework crosswalk

CVSS v4.0 communicates vulnerability characteristics and severity through a defined scoring specification and vector. Where applicable, a report may retain a CVSS assessment with its version and vector alongside OSAFIS fields. OSAFIS does not provide a validated conversion from domain numbers, property counts or evidence descriptors into a CVSS score or a universal AI risk score. FIRST CVSS v4.0 specification

Rules for mapping

A mapping relates a specific definition or finding to a specific source edition. Similar wording is insufficient. The assessor identifies the external concept, explains the shared mechanism or obligation, records the limits of the match, and cites the source. A resource that covers a broad risk may intersect several OSAFIS domains, depending on where the particular system violates a contract.

Mapping relationships should use one of five descriptions: equivalent under stated scope, narrower, broader, partial overlap, or related context. Equivalence is a strong claim and requires matching conditions and exclusions. A provisional overlap is normally sufficient for a research cross-reference. Each mapping also records whether it is reviewed, proposed, disputed or not assessed. A missing mapping means only that no justified mapping is recorded; it does not establish a gap in the external resource.

Domain assignments in the following tables are conditional examples. They neither classify every instance of the external category nor list all possible domains. An entry point in a domain does not establish a violation there. L9 requires a collective contract and coupling mechanism in addition to any broad consequence.

Historical LLM 2025 mapping

The following table deliberately uses the 2025 identifiers. It must not be read as a category-level mapping of the 2026 guide. The table's domain assignments and contract descriptions are OSAFIS interpretations; the source establishes the existence and scope of the external categories. OWASP LLM 2025 list

External IDPossible domainsContract question for a concrete case
LLM01:2025L5 and possibly L6 or L7Did lower-trust content obtain instructional authority or change the authorised task
LLM02:2025L1 L2 L3 L6 or L7Which component disclosed protected information, to whom, and across which boundary
LLM03:2025L1 L2 or L3 with D3Which supplied artifact or dependency escaped its provenance or integrity controls
LLM04:2025L3 and L1Did corrupted information affect learning, or did an unauthorised model change persist
LLM05:2025L2 or L7Did a consumer interpret model output as executable authority without the required validation
LLM06:2025L7 with D1Could available capabilities exceed the task, resource or approval scope
LLM07:2025L1 L2 or L5Was a protected secret disclosed, and was secrecy incorrectly used as an enforcement boundary
LLM08:2025L3 and possibly L2 or L6Were retrieval isolation, provenance or state ownership violated
LLM09:2025L3 L5 or L8Which evidence, interpretation or presentation obligation failed; was the result a security issue or a quality error
LLM10:2025L1 L2 L7 or L9Which computation, quota, action budget or collective stability contract failed

The source treatment of prompt injection includes cross-modal cases. Accordingly, OSAFIS should not claim that image-borne attacks are absent from OWASP simply because an external list does not contain an entry called perception. Within OSAFIS, an image can be observed correctly while its text is improperly promoted to instruction in L5. An inaccurate estimate of the environment would instead require evidence for L4. OWASP prompt injection guidance

Agentic 2026 mapping

The identifiers in this table refer to the December 2025 publication of the agentic 2026 guide. The proposed domain relationships require case-level review. They do not imply that OWASP has accepted the OSAFIS model. OWASP agentic guide

External IDPossible domainsContract question for a concrete case
ASI01L5 and possibly L7Did external influence replace the authorised objective or corrupt its operational plan
ASI02L7 and possibly L2Were tool choice, parameters, sequencing or permitted effects improperly constrained
ASI03L2 L6 or L7 with D1Was identity, scope or delegated authority incorrectly inherited or applied
ASI04L1 L2 L3 or L7 with D3Which supplied agent, tool, model or descriptor failed its supply or adoption contract
ASI05L2 or L7Which execution boundary admitted unintended code or an unapproved command
ASI06L6 or L5Was retained state corrupted, or was transient context selected or interpreted improperly
ASI07L2 L5 or L7Did transport authenticity, message authority or actual delegation fail
ASI08L9 where justifiedWhich coupling or containment defect amplified the failure beyond local behaviour
ASI09L8 with D1Did the interaction undermine informed authorisation or justified human reliance
ASI10Case dependentWhich observable contract was violated; what evidence distinguishes malicious influence from autonomous malfunction

A worked mapping decision

Consider an illustrative, unexecuted case in which a retrieval assistant reads a document containing a request to change the user's task. The document is an entry point associated with L3. Its retrieval may satisfy the data-access contract, so L3 is not automatically a failed domain. If the interpreter treats the document as an authorised instruction, the hypothesised failure is L5 and P04 Instruction Integrity. If the objective changes, P09 Objective Integrity may also apply, provided the assessment independently specifies that obligation.

A provisional external mapping to LLM01:2025 is reasonable for the instruction manipulation. An agentic goal-redirection scenario may also overlap ASI01 in the specified 2026 guide. The two links describe related scopes; they do not create two independent vulnerabilities. The report should state the adversary's ability to place the document, the source of legitimate authority, the observable task change, and any untested downstream action. This example demonstrates the proposed mapping procedure, not a validated result.

Coverage and novelty claims

An external resource's scope must be assessed from its definitions, supporting guidance and examples. Comparing organisations such as OWASP, MITRE and NIST as though each had one fixed checklist produces misleading conclusions. A binary coverage matrix is particularly weak when a check mark means only that a topic is mentioned and a blank means only that a preferred name is absent.

A useful comparison selects a bounded case set, a defined task and a fixed version of each resource. It evaluates outcomes such as consistent contract identification, propagation reconstruction, missed obligations and analyst effort. Reviewers should disclose training differences and access to supporting material. This design can support a limited finding about utility. It cannot establish that OSAFIS covers every AI threat or is the first framework of its kind.

The current crosswalk is a scoped mapping proposal. Detailed migration of the LLM 2026 categories, a technique-level ATLAS mapping and a control-level standards mapping require separate source review. The resource-level references above acknowledge their relevance without representing unperformed work as complete. No certification or legal compliance conclusion follows from this document.

Maintenance

Each mapping record preserves the external publisher, title, identifier, edition, source URL, access date, local contract, mapping relationship, rationale, reviewer status and limitations. Revisions should identify whether the external definition changed or the local interpretation changed. Older mappings remain available for historical findings. Updating a website date without reviewing the source is not a mapping revision.

The release process should check referenced sources and any announced replacement edition, then update affected mapping records under Versioning and Identifiers. External content rights remain with their owners. OSAFIS links and interprets these resources without implying endorsement or copying their full guidance into the specification.

Word document · Markdown source · Open in the interactive site