Security of AI with Bobby

Security of AI™

with Bobby  ·  AI Assurance Intelligence Navigator

security-of-ai.com NIST AI RMF · MITRE ATLAS · OWASP · PyRIT · Garak

AI Assurance Intelligence Navigator

49 assurance activities designed to produce evidence that your AI defenses are working as intended. Every entry asks a practical question: what evidence would support the assurance claim that this control is functioning under defined conditions? Three SOAI assessments per entry: Evidence Strength, Coverage, and Assurance Confidence.

NIST AI RMF NIST AI 100-2 MITRE ATLAS OWASP LLM Top 10 PyRIT / Garak ART / Foolbox Mapped to Vuln Navigator
▲ 1 — AI Risk Navigator → ▲ 2 — ATLAS Navigator → ▲ 3 — Vulnerability Navigator → ✓ 4 — Assurance Navigator
Independent educational tool. The SOAI AI Assurance Intelligence Navigator provides educational guidance on AI security testing and assurance activities. It is not affiliated with NIST, MITRE, OWASP, or any tool vendor mentioned. Tool references are for educational purposes — verify current versions, licensing, and applicability to your environment. Assurance activities should be adapted to your specific AI system context and risk profile. SOAI Evidence Strength, Coverage, and Assurance Confidence assessments, assurance claims, framework mappings, and testing recommendations represent Security of AI™ analysis unless explicitly identified as information obtained from an authoritative source. Passing an assurance activity provides evidence within defined test conditions and does not guarantee that an AI system is secure, safe, compliant, or free from residual risk.
About SOAI Assurance Scoring. These are Security of AI™ decision-support assessments, not NIST, MITRE, OWASP, or vendor scores. Evidence Strength represents the rigor and repeatability of evidence produced by the activity. Coverage represents the breadth of relevant attack surface addressed. SOAI Assurance Confidence combines Evidence Strength and Coverage on a 0–25 scale: (Evidence Strength × Coverage) ÷ 4. Scores are relative indicators and must be interpreted in the context of the specific AI system, mission, operating environment, and residual risk.
Frequency: ● Continuous ○ Periodic ◆ Event-Driven Show All
Model Data Application Agent Infrastructure Governance Operational Continuous monitoring Periodic testing Event-driven