Governance
Outcome: A named owner and explicit mission, prohibited actions and risk tolerance.
Evidence: Role record, approval trail, policy and use-case boundary.
Control baseline / defensive assurance
The Delx Security baseline turns agentic risk into 20 observable outcomes across ownership, authority, tools, context, secrets, evidence and recovery. It is a risk-based starting point — not a universal checklist, certification or guarantee.
An AI agent security control is useful when it states an outcome an owner can observe and a reviewer can verify. Begin with who owns the system, who can act, what tools and destinations it can reach, what context can become durable policy, and how an operator stops and recovers it. Then select only the controls that break the credible attack paths for the system's impact and maximum authority.
Outcome: A named owner and explicit mission, prohibited actions and risk tolerance.
Evidence: Role record, approval trail, policy and use-case boundary.
Outcome: Models, agents, tools, data, memory and suppliers are inventoried; identities are attributable, narrow and revocable, including delegated chains.
Evidence: Architecture, asset catalog, auth logs, policies, denial tests and delegation traces.
Outcome: Typed tool contracts, action-time approval and allowlisted egress protect provenance, memory integrity and policy from untrusted context.
Evidence: Schemas, negative tests, approval event, egress policy, retrieval trace, rollback proof and adversarial test record.
Outcome: Secrets are scoped and redacted; application controls are selected deliberately; code, models, prompts, skills and dependencies have provenance.
Evidence: Vault and log inspection, requirement matrix, tests, lockfile, attestations and review record.
Outcome: Decisions and side effects are attributable, with actionable signals for abuse, drift and anomalous authority.
Evidence: Immutable event trail, alert exercise and response log.
Outcome: Operators can pause or revoke safely, recover state, evidence and authority consistently, and recheck critical controls after change.
Evidence: Kill-switch and restore exercises, runbook, CI gate and production probe.
Make every actor attributable, least-privileged and independently revocable, including hand-offs between agents and services.
Type inputs, expose side effects, require approval at action time for high-impact effects and constrain destinations.
Keep retrieved content and instructions distinguishable; authenticate durable writes and resist context that tries to redefine authority.
Record decisions and side effects, detect drift, prove a pause and revocation path, and rehearse consistent restoration.
The baseline uses the public vocabulary of NIST CSF 2.0, NIST AI RMF, NIST SSDF 1.1, OWASP Top 10 for Agentic Applications, OWASP ASVS 5.0, MITRE ATLAS and CISA Secure by Design. The mapping helps teams find evidence; it does not copy a framework into a score or claim certification.
A policy, diagram or static setting is intent. Assurance requires a trace, test, exercise or other evidence that the deployed system behaves within the stated boundary.
They are observable security outcomes for an agentic system: accountable ownership, attributable identity, bounded authority, safe tool and egress behavior, trustworthy context and memory, protected secrets, evidence, recovery and continuous verification.
Version 1.0 has 20 control outcomes grouped across governance, inventory and authority, actions and context, secrets and supply chain, audit and detection, and stop, recovery and verification. It is a risk-based starting point, not a universal checklist.
No. Delx Security uses NIST, OWASP, MITRE ATLAS and CISA publications as a shared vocabulary for evidence and threat paths. The baseline does not certify a system, prove legal compliance or guarantee future security.
Start with ownership and scope, attributable least-privilege identity, delegated authority, typed tool contracts, action-time approval, constrained egress, secret handling, attributable audit, a stop path and recovery. Choose the smallest set that breaks the credible attack paths for the system's impact and authority.
Threat modeling maps credible abuse paths and consequences. The baseline names minimum outcomes and evidence to test along those paths. A bounded security review then verifies authorized behavior and records limitations instead of treating a completed checklist as proof.