Skip to main content

Selective Reading Guide

Full-book reading is not required. Use the NIST AI RMF and GenAI Profile for risk structure, OWASP LLM guidance for application threats, NIST SSDF for development controls, and Building Secure and Reliable Systems for operational control design.

Required evidence

Submit versioned tests, system manifest, raw and summarized results, representative failures, a rejected alternative, named control owners, and residual-risk decision. Safety claims without adversarial evidence do not pass.

Oral defense

Demonstrate one failure, identify its first violated boundary, explain why layered controls limit impact, and execute the stop or escalation path.

Source backbone

Use NIST AI RMF, OWASP LLM Top 10, NIST SSDF, and Building Secure and Reliable Systems.