The OWASP GenAI Security Project's catalog names the most critical vulnerability classes in LLM applications — from Prompt Injection (LLM01:2025) through Sensitive Information Disclosure (LLM02) and Supply Chain (LLM03) to Excessive Agency (LLM06). Six of the ten risks directly concern data security. Development and AppSec teams use the list as a testing and requirements perspective when building and testing LLM systems.
AI Security Frameworks at a Glance
OWASP, MITRE ATLAS, and NIST AI RMF look at AI security from three different perspectives. An overview of what each framework stands for — and how, in combination, they form a viable protection concept.
3frameworks together cover the entire AI lifecycle
6of the ten Top 10 risks directly concern data security
4core functions in the NIST AI RMF: GOVERN, MAP, MEASURE, MANAGE
4steps for a practical start: Assess, Test, Govern, Protect
Classic security approaches only go so far with LLM-based systems: prompts, context data, data pipelines, and agentic logic become risk points in their own right, and non-deterministic model behavior eludes static analysis and signatures. Three frameworks have become established points of reference — each with its own perspective: the OWASP GenAI Security Project's Top 10 for LLM Applications provides the testing and requirements perspective for development and security teams, MITRE ATLAS catalogs the tactics and techniques of real-world attackers, and the NIST AI RMF structures overarching risk management. Together they cover the entire AI lifecycle — from secure building through adversarial testing to governance. This interplay also matters from a regulatory standpoint: the EU AI Act, NIS2, DORA, and the GDPR require demonstrable security measures for AI systems.
The Essentials at a Glance
Six topic blocks — tap to expand.
Three frameworks, three perspectives
What each framework stands for — tap a tab.
- The OWASP GenAI Security Project's catalog names the most critical vulnerability classes in LLM applications.
- Six of the ten risks directly concern data security.
- Development and AppSec teams use the list as a testing and requirements perspective when building and testing LLM systems.
Prompt Injection (LLM01:2025)Sensitive Information Disclosure (LLM02)Supply Chain (LLM03)Excessive Agency (LLM06)
- Catalogs real-world attack tactics and techniques against AI systems — analogous to the ATT&CK matrix.
- Consistently takes the attacker's perspective.
- The foundation for red and purple teaming against AI systems.
ReconnaissanceResource DevelopmentExfiltrationAML.T0051ATT&CK
- Structures risk management across the entire AI lifecycle along the four core functions.
- Addresses trustworthiness and governance, aimed at CISOs and risk management.
- A framework in which technical findings are translated into policies, processes, and responsibilities.
GOVERNMAPMEASUREMANAGETrustworthiness
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
OWASP LLM/GenAI Security Solutions Reference Guide Q2/Q3'25
Vendor-neutral mapping of open-source and commercial security solutions to the Top 10 risks along the LLMOps lifecycle phases from Scoping/Planning to Govern.
LLM and Gen AI Security Solution Landscape Guide — Cheat Sheet Series Q1 2025
Compact overview of the LLM/GenAI security solutions landscape, including the LLM and Gen AI App SecOps Framework.
AI Security Solutions Landscape for Agentic AI (Q3 2025)
Maps DevOps and SecOps tasks as well as solutions to the phases of the agentic AI lifecycle from Scope & Plan to Govern; updated quarterly.
Related Services
From framework to implementation
VamiSec supports you with AI and LLM pentests along the OWASP Top 10 and MITRE ATLAS, and with consulting on building your AI governance based on the NIST AI RMF. Schedule a no-obligation initial consultation.