CSA, the Cloud Security Alliance, has published the AI Security Maturity Model (AISMM). This aims to help organizations assess, build, and improve their AI security programmes.
Aligning with common information security structures, processes, and responsibilities, the AISMM ‘provides a practical roadmap for advancing AI security maturity across the enterprise’.
The AISMM specifically focuses on operationalising an enterprise AI security programme, using domains that reflect real-world functions, including application security, incident response, and AI risk management.
Aligned with CSA research and the AI Controls Matrix (AICM), the AISMM identifies five key indicators of maturity:
- Initial
- Repeatable
- Defined
- Capable
- Efficient
The AISMM also addresses cross-functional concerns such as data privacy, regulatory compliance, provider risk evaluation, and AI deployment governance.






