CSA AI Controls Matrix
The Cloud Security Alliance AI Controls Matrix is a vendor-neutral control framework for securely developing, providing, orchestrating, operating, and consuming cloud-based AI systems. Version 1.1 contains implementation and auditing guidance, an assessment questionnaire, and mappings to ISO/IEC 42001, ISO/IEC 27001, NIST AI RMF, and the EU AI Act.
Buyer question
“Which AI security and governance controls can a Legra deployment implement or evidence, and which remain the responsibility of model, cloud, application, and customer organizations?”
Legra fit
| Assessment area | Legra fit | Status |
|---|---|---|
| Governance, risk, and accountability | Policies, Use Case Trees, ownership, approvals, provenance, and control evidence can be represented and queried in governed workspaces. Organizational governance remains external. | Partial fit |
| Identity, access, and agent authority | Workspace membership, encryption, persona-bound Stories, scoped tools, task branches, and signed identities constrain access and agent actions. | Native fit |
| Data security and privacy | Encrypted workspaces, provenance, branch isolation, validation, classification metadata, and controlled sharing support protection across the knowledge lifecycle. | Native fit |
| Application and orchestration security | Story-defined operations, explicit tool surfaces, task hierarchy, transaction boundaries, validation, and human review address excessive agency and unsafe promotion. | Native fit |
| Logging, monitoring, and evidence | Tasks, Journal events, signed commits, validation reports, and provenance supply queryable evidence, while SIEM integration and organization-wide monitoring remain deployment concerns. | Partial fit |
| Model security and evaluation | Legra governs context and operations around models but does not itself train, host, red-team, benchmark, or certify every model used by an application. | External responsibility |
| Cloud and supply-chain assurance | Dependency metadata and provenance can identify services and artifacts, but cloud-provider controls, software supply-chain assurance, contracts, and third-party audits remain shared or external responsibilities. | External responsibility |
What Legra can say
The matrix is especially useful for Legra because it separates responsibilities among model providers, orchestrated-service providers, application providers, cloud providers, and AI customers. Legra may occupy different roles in different deployments, so each assessment must state the role being evaluated.
For the controls within Legra’s boundary:
- Agents can receive narrowly scoped knowledge and executable Stories instead of unrestricted database or infrastructure credentials.
- Writes can be isolated on task branches and reviewed before production merge.
- Policies, classifications, validation rules, and evidence can live beside the graph data they govern.
- Signed commits, task history, and events preserve who did what and why.
- Data custody, hosting, model inference, orchestration, and application authority can be assessed as separate trust boundaries.
Assessment boundary
AICM alignment is role- and deployment-specific. A Legra feature cannot satisfy controls owned by an organization’s management process, its model provider, its cloud provider, or its operational security program.
An assessment should select the applicable AICM role, identify the control owner, and link each claimed implementation to actual deployment evidence rather than treating this page as a blanket statement of conformity.