Part I: System and threat modeling

A system map and a threat model give technical and management readers the same description of the system, its operators, attacker access, and possible harm.

An employee support assistant provides the running example. The organization operates identity, document, and policy services and may use an external or internal model. Mapping those components comes before adding attacker access, failure paths, controls, evidence, and remaining risk.

An illustrated organization contains an employee, identity, AI application, internal data, an optional internal model, policy check, business service, and evidence records. An external model sits in a provider boundary. Chapter 1 and Chapter 2 produce a reusable record, while later Parts remain outside the Part 1 boundary. Lower strips list measurements, risks, and evidence.
Figure 1: External users, supplier content, a model provider, network access, and attacker-controlled input surround the organization. Part 1 records the system and a bounded threat before later Parts develop specific protections. The measurement strip shows fields and units to record for the chosen system; it does not supply universal limits.

Chapters in this part

  • Mapping the AI system: A system map records the people, components, data, permissions, and evidence that a security decision about an AI assistant depends on.
  • Threat modeling and controls: A threat record connects an attacker’s access to a possible failure, the controls expected to prevent it, and the evidence needed to test them.