The AI IT Security Audit(TM) (Paperback)
Lingua: inglese
Editore: Srj Consulting & Services Publishing, 2026
Serie: Libro 5 di 6 - The Operating Discipline for AI Library™
- Brossura
- Nuovo

Da: Grand Eagle Retail, Bensenville, IL, U.S.A.Grand Eagle Retail
Venditore AbeBooks dal 12 ottobre 2005
Condizione: Nuovo
EUR 39,01
Quantità: 1 disponibili
Aggiungi al carrelloDescrizione dell’articolo da parte del venditore
Paperback. You built a real security program. Patch cycles on schedule, zero trust implemented correctly, incident response tested under pressure. Then AI agents, MCP servers, embedded vendor features, and autonomous tools walked into your environment faster than your operating model could absorb them. That is not a failure of effort. It is a failure of speed. Now a question is forming, from a regulator, an audit committee, an insurer, or an enterprise customer expanding its security questionnaire: can you prove your AI exposure is known, controlled, and governed? Every dashboard shows green, and none of them are lying. Every control functions. But none of those tools were built to watch what AI agents do inside your environment, because they were designed before AI agents entered it at scale. This is the Green Dashboard Fallacy. It is not a detection failure, it is an assumption failure. The greatest AI security risk facing your organization is not that you are undefended. It is that leadership believes the existing program is already watching. The audit produces six artifacts built to survive outside scrutiny: an AI exposure map across the six CISO domains, a non-human identity inventory and agent boundary matrix, a tested AI Red Button procedure, an AI vendor tier map and data flow map, a regulatory crosswalk, and a four-page board pack. These are not concepts to understand. They are documents to hand over. Three instruments carry the method. The Visibility Triangle sorts every gap into visible, suspected, or undetectable. The Six-Domain Operating View structures the work across governance, security operations, architecture, application security, third-party risk, and data protection. The Defensible AI Security Baseline sets a dated, scored standard across seven areas with a named owner for each, which turns a one-time audit into a program. Seven binding frameworks run underneath: NIST AI RMF, ISO/IEC 42001, the OWASP LLM and Agentic Top 10, OWASP AIVSS, MITRE ATLAS, HITRUST AI, and Google SAIF. The thesis is stated plainly. AI agents must be audited as privileged, non-human actors inside your control environment. Once an agent can retrieve data, invoke tools, write records, or trigger workflows, it is an operational actor with an identity, a privilege scope, and a blast radius. No products are recommended and the book does not end in a pitch. Volume V of The Operating Discipline for AI Library, and the opening volume of Pillar II, AI Risk Governance and Security. The timeline belongs to whoever moves first. Every dashboard is green, and none of them were built to watch your AI. A CISO audit method that produces six artifacts, a scored baseline, and a four-page board pack: proof your AI exposure is known, controlled, and governed. This item is printed on demand. Shipping may be from multiple locations in the US or from the UK, depending on stock availability.…
Codice articolo 9798996940226
- Titolo
- The AI IT Security Audit(TM) (Paperback)
- Autore
- Stephen R. Jordan
- Editore
- Srj Consulting & Services Publishing
- Anno di pubblicazione
- 2026
- Condizione
- new
- Rilegatura
- Paperback
- Lingua
- inglese
- ISBN 13
- 9798996940226
- Serie
- Libro 5 di 6: The Operating Discipline for AI Library™
Every dashboard shows green. Every control functions. And you still cannot prove what your AI is doing.
You built a real security program. Patch cycles that run on schedule. Zero trust that took two years to implement correctly. Incident response playbooks tested under pressure. Then, somewhere in the last eighteen months, AI agents, MCP servers, embedded vendor features, and autonomous tools walked into your environment faster than your operating model could absorb them. That is not a failure of effort. It is a failure of speed.
Now a question is forming. It comes from a regulator, an audit committee, an insurer, or an enterprise customer expanding its security questionnaire. It always means the same thing: can you prove your AI exposure is known, controlled, and governed? Evidence, documented, dated, scored, and defensible, is something else entirely. This book closes that gap.
THE GREEN DASHBOARD FALLACYNone of your dashboards are lying. The problem is structural: they were all designed before AI agents entered your environment at scale. The fallacy is not a detection failure. It is an assumption failure. The greatest AI security risk facing your organization is not that you are undefended. It is that leadership believes the existing program is already watching.
WHAT YOU PRODUCESix artifacts built to survive a regulator, an insurer, an auditor, an enterprise customer, or your own audit committee:
- An AI exposure map across the six CISO domains
- A non-human identity inventory and agent boundary matrix
- A tested AI Red Button procedure
- An AI vendor tier map and data flow map
- A regulatory crosswalk maintained as a document instead of a fire drill
- A four-page board pack assembled from work you have already done
These are not concepts to understand. They are documents to hand over.
THE METHODThree instruments carry the audit. The Visibility Triangle sorts every gap into visible, suspected, or undetectable, and the zone determines the response. The Six-Domain Operating View structures the work across governance, security operations, architecture, application security, third-party risk, and data protection. The Defensible AI Security Baseline sets a dated, scored standard across seven areas with a named owner for each, which turns a one-time audit into a program.
Seven binding frameworks run underneath: NIST AI RMF, ISO/IEC 42001, the OWASP LLM and Agentic Top 10, OWASP AIVSS, MITRE ATLAS, HITRUST AI, and Google SAIF. They are cited only where they actually bind, never as a compliance tour.
The engineering thesis is stated plainly. AI agents must be audited as privileged, non-human actors inside your control environment. Once an agent can retrieve data, invoke tools, write records, or trigger workflows, it is an operational actor with an identity, a privilege scope, and a blast radius. Your access review was built for human identities with enumerable behavior. It was not built for this.
Every domain chapter closes the same way: the Board Question your leadership must answer, the Evidence Required to answer it, the Common Failure Pattern that breaks the answer, and a 30-Day Move with a named output, a named owner, and a completion condition.
There is no vendor agenda here. No products are recommended. Its only job is to help you produce evidence that survives whoever asks the question first.
Volume V of The Operating Discipline for AI Library, and the opening volume of Pillar II, AI Risk Governance and Security. It extends Volumes I through IV and stands on its own. The executive who finishes this book walks into the next board meeting holding proof, not promises.
"Riassunto" può appartenere a un’altra edizione di questo titolo.
Grand Eagle Retail
Bensenville, IL, U.S.A.
Venditore AbeBooks dal 12 ottobre 2005
Tariffe di spedizione nazionale per U.S.A.
| Articolo | Da 6 a 14 giorni lavorativi | Da 6 a 16 giorni lavorativi |
|---|---|---|
| Primo articolo | EUR 0,00 | EUR 0,00 |
Metodi di pagamento
Informazioni sull’azienda del venditore
APOLLO ONLINE CORP.
605 Geddes Street
Wilmington, DE U.S.A. 19805
Condizioni di vendita
We guarantee the condition of every book as it¿s described on the Abebooks web sites. If you¿ve changed
your mind about a book that you¿ve ordered, please use the Ask bookseller a question link to contact us
and we¿ll respond within 2 business days.
Books ship from California and Michigan.
Diritto di recesso
Se sei un consumatore puoi recedere dal contratto in conformità con quanto segue. Per Consumatore si intende qualsiasi persona fisica che agisce per scopi estranei alla propria attività commerciale, imprenditoriale, artigianale o professionale.
Informazioni sul diritto di recesso
Diritto legale di recesso
Hai il diritto di recedere dal presente contratto entro 14 giorni senza fornire alcuna motivazione.
Il periodo di recesso scade dopo 14 giorni dal giorno in cui tu o una terza parte, diversa dal vettore e da te indicata, acquisisce il possesso fisico dell'ultimo bene o dell'ultimo lotto o pezzo.
Per esercitare il diritto di recesso, compila e invia elettronicamente una dichiarazione esplicita sul nostro sito Web, alla voce “I miei acquisti” nella sezione “Mio account”. Ti comunicheremo senza indugio una conferma di ricezione di tale recesso su un supporto durevole (ad es. via e-mail).
Per rispettare il termine di recesso, è sufficiente inviare la comunicazione relativa all'esercizio del diritto di recesso prima della scadenza del periodo di recesso stesso.
Effetti del recesso
In caso di recesso dal presente contratto, ti rimborseremo tutti i pagamenti ricevuti, compresi i costi di spedizione (ad eccezione dei costi supplementari derivanti dalla tua eventuale scelta di un tipo di spedizione diverso dal tipo meno costoso di consegna standard da noi offerto).
Potremo effettuare una detrazione dal rimborso per la perdita di valore dei beni forniti, qualora tale perdita sia il risultato di una manipolazione non necessaria da parte tua.
Eseguiremo il rimborso senza indebito ritardo e non oltre 14 giorni dal giorno in cui saremo informati della tua decisione di recedere dal presente contratto.
Il rimborso sarà effettuato utilizzando lo stesso mezzo di pagamento da te usato per la transazione iniziale, salvo che tu non abbia espressamente concordato altrimenti; in ogni caso, non dovrai sostenere alcun costo quale conseguenza di tale rimborso.
Possiamo trattenere il rimborso finché non avremo ricevuto i beni oppure finché non avrai fornito la prova di averli rispediti, a seconda di quale condizione si verifichi per prima.
Dovrai rispedire i beni o consegnarli a Grand Eagle Retail, Bensenville, Illinois, U.S.A., senza indebito ritardo e, in ogni caso, entro 14 giorni dal giorno in cui ci hai comunicato la tua volontà di recedere dal presente contratto. Il termine è rispettato se rispedisci i beni prima della scadenza del periodo di 14 giorni. I costi diretti della restituzione dei beni saranno a tuo carico. Sei responsabile solo della diminuzione del valore dei beni risultante da una manipolazione diversa da quella necessaria per stabilire la natura, le caratteristiche e il funzionamento dei beni stessi.
Eccezioni al diritto di recesso
Il diritto di recesso non si applica a:
- La fornitura di giornali, periodici o riviste ad eccezione dei contratti di abbonamento; e
- La fornitura di contenuto digitale non fornito su un supporto materiale (ad es. su un CD o DVD), se al momento dell'invio dell'ordine hai accettato l'inizio dell'esecuzione e hai riconosciuto che non avresti potuto recedere una volta iniziata l'esecuzione.
Condizioni di spedizione
Orders usually ship within 2 business days. All books within the US ship free of charge. Delivery is 4-14 business days anywhere in the United States.
Books ship from California and Michigan.
If your book order is heavy or oversized, we may contact you to let you know extra shipping is required.