Skip to content

Reference

Mapping & scoring a finding

A finding is only as useful as the language you report it in - this is the one-pass workflow that turns “the agent emailed a customer record out” into an OWASP id, a MITRE ATLAS technique, a cross-framework control reference, and a defensible severity score.

You found something. Before it goes in a report, run it through five mapping steps and one scoring step. Every step points at the deep treatment elsewhere in the book; this page is the checklist that keeps them in order.

The mapping workflow - five steps

1. Name it in plain language

One sentence, mechanism-first, no framework jargon yet: “the agent acts on unverified tool output; no spotlighting, and the email tool is in scope.” This is the sentence every later tag hangs off, and the one a developer will actually read.

2. Tag the OWASP id (both lists where they apply)

  • OWASP LLM Top 10 2026 for the model-level risk: LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM03 Excessive Agency, LLM04 Supply Chain, LLM05 Data & Model Poisoning, LLM06 Unbounded Consumption, LLM07 Misinformation, LLM08 Hidden Context Exposure, LLM09 Vector & Embedding Weaknesses, LLM10 Improper Output Handling. (If you are carrying a 2025 crosswalk: System Prompt Leakage moved to LLM08:2026 Hidden Context Exposure, and LLM07:2026 is now Misinformation.)
  • OWASP Agentic (ASI) Top 10 for the agent-as-actor: ASI01 Agent Goal Hijack, ASI02 Tool Misuse, ASI03 Identity & Privilege Abuse, ASI04 Agentic Supply Chain, ASI05 Unexpected Code Execution, ASI06 Memory & Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation, ASI10 Rogue Agents.

The example above is LLM01 (injection) and ASI02 (tool misuse) - the model reads untrusted content, the agent acts on it.

3. Tag the MITRE ATLAS technique, with a case study as evidence

Cite the technique id AML.Txxxx (and sub-technique .xxx), plus the closest case study AML.CSxxxx as the incident-backed evidence, and a mitigation AML.Mxxxx for the fix. Take the id verbatim from atlas.mitre.org; if that page will not render, the machine-readable source of record is the mitre-atlas/atlas-data repo. The matrix is calendar-versioned on a monthly cadence, so the id set shifts - re-check before you cite.

For the example: AML.T0051.001 (LLM Prompt Injection: Indirect) and AML.T0053 (AI Agent Tool Invocation), evidenced by a relevant case study. For agentic findings, ATLAS 2026 added autonomous-agent techniques worth knowing by ID - AML.T0116 (Autonomous Reconnaissance), AML.T0117 (Autonomous Attack-Path Adaptation), AML.T0118 (Autonomous AI Agent Communication) and AML.T0124 (Autonomous Attack Orchestration), plus the sub-technique AML.T0017.001 (Autonomous Exploit Development).

4. Cross-map to every other framework in one step

You do not hand-map to NIST, ISO, and the EU AI Act separately. OWASP now publishes an official crosswalk: the GenAI Security Industry Framework Crosswalk (interactive at genai-security-project.github.io/crosswalk) maps the OWASP LLM Top 10, the Agentic (ASI) Top 10, and the Data-Security list across 25 frameworks, including MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, the EU AI Act, and OWASP ASVS. Look up your OWASP id there and read across.

For an evidence-graded OWASP-to-ATLAS view specifically, the community StingrAI crosswalk maps each ASI class to ATLAS case-study ids and grades them “incident-backed” versus “exercise-only.”

5. Read the native control from each framework

The book’s own hand-built per-finding table in VIII.1 · Frameworks & standards shows the native control at each altitude - the SAIF control, the NIST AI RMF subcategory, the ISO/IEC 42001 clause, and the EU AI Act article - and the “crosswalk drill” there is the same five steps in that chapter’s words. Use whichever framework the room speaks: report one finding as an MS-2.7 measure gap to the NIST-aligned team, an Annex A control gap to the ISO auditor, and an Article 15 robustness exposure to legal.

Scoring severity

A jailbroken chatbot and a jailbroken agent that can move money are not the same finding. AI severity has to reflect what the system can do, not just the technical flaw. Two numbers do that.

AIVSS - the agentic severity score

AIVSS (AI Vulnerability Scoring System) is an OWASP project (spec v0.8; v1.0 expected end of 2026). It starts from a CVSS v4.0 base, then adds an Agentic AI Risk Score (AARS) driven by ten agentic amplifiers - execution autonomy, external tool-control surface, natural-language interface, contextual awareness, behavioral non-determinism, opacity/reflexivity, persistent state, dynamic identity, multi-agent interaction, and self-modification - each scored 0.0 / 0.5 / 1.0, then applies a threat multiplier and a mitigation discount:

AIVSS - a CVSS base amplified by how agentic the system is
Risk Gap = 10 - CVSS_Base
AARS = Risk Gap x (Factor_Sum / 10) x Threat_Multiplier
AIVSS = (CVSS_Base + AARS) x Mitigation_Factor
Threat_Multiplier Actively attacked 1.00 | PoC 0.97 | Unreported 0.50
Mitigation_Factor None/Weak 1.00 | Partial 0.83 | Strong 0.67

The full worked example - an indirect-injection finding on a support agent scoring 6.59 / Medium - is in VIII.4 · ISO/IEC 42001, verification & maturity. Two things to get right: the mitigation term lowers the score, so claim it only with evidence the control holds; and AIVSS is pre-release, so re-derive against the current spec and its official calculator before a number goes in a client report.

Attack-success-rate - report it with an attempt budget

Severity also depends on how reliably the attack fires, and generation is stochastic, so a single proof-of-concept is not a severity. Report attack-success-rate (ASR) over N trials, under adaptive attack, disaggregated by impact - the full statistical discipline is in VI.4 · AI red-team playbook. The 2026 norm, set by the frontier labs’ system cards, is a multi-attempt curve: an attack that is single digits at one attempt can reach a majority by a hundred. A low single-shot number is not low severity if it climbs steeply, so always publish the budget (“63% at 100 attempts”), never a bare rate.

The finding record

Put the tags and the score into one row. The schema and the two-audience report template live in Templates & checklists; the fuller finding ontology (Actor, TTPs, System weakness, Downstream impact) is in VI.4 · AI red-team playbook.

One finding, fully mapped and scored
Finding: Support agent acts on unverified tool output; email tool in scope
OWASP: LLM01 Prompt Injection + ASI02 Tool Misuse
ATLAS: AML.T0051.001 (LLM Prompt Injection: indirect); evidence AML.CS<id>
Frameworks: via OWASP crosswalk -> NIST MS-2.7 / ISO 42001 Annex A / EU AI Act Art. 15
Severity: AIVSS 6.59 (Medium) - CVSS 6.0 base, agentic amplifiers, partial mitigation
ASR: 40% over 25 adaptive trials (exfil objective), single-turn
Fix: spotlight untrusted content; gate outbound actions; scope the email tool