The Cloud Security Alliance (CSA) has published a new framework, the Capabilities-Based Risk Assessment (CBRA) for AI systems. This is a structured, scalable approach to evaluating AI risk in enterprise environments.
CBRA evaluates AI through four core dimensions: System Criticality, Autonomy, Access Permissions, and Impact Radius. It uses these dimensions to calculate a composite risk profile. This enables organizations to align security controls with the true capabilities and potential consequences of each AI deployment, says CSA.
Mapped directly to the CSA’s AI Controls Matrix (AICM), CBRA helps enterprises apply proportional safeguards. Low-risk AI gets lightweight controls, medium-risk gets enhanced monitoring, and high-risk gets full-scale governance. The result is a consistent framework for risk-tiered oversight across industries.






