The Center for Internet Security, Inc., Astrix Security, and Cequence Security have jointly announced the release of three new CIS Critical Security Controls Companion Guides designed to help enterprises secure rapidly evolving AI environments.
Co-authored by experts across all three organizations, the guides extend the CIS Critical Security Controls into AI systems where large language models (LLMs), autonomous agents, and Model Context Protocol (MCP) integrations introduce new and unique risks. Each guide focuses on a distinct layer of the AI ecosystem, offering targeted guidance aligned with how modern AI systems operate.
The three guides are:
- AI LLM Companion Guide: Provides guidance for securing large language models, including risks related to prompts, context handling, and exposure of sensitive information.
- AI Agent Companion Guide: Outlines controls for managing autonomous and semi-autonomous agents, focusing on safe tool execution, governed autonomy, and appropriate access to enterprise systems.
- MCP Companion Guide: Details protections for Model Context Protocol environments, emphasising secure tool access, management of non-human identities (NHIs), and auditable interactions across the protocol layer.






