Method, concepts and terminology
Why MAESTRO exists
Section titled “Why MAESTRO exists”Traditional threat methods remain useful, but agentic AI adds risks they do not always model explicitly: autonomous decision-making, goal manipulation, adversarial machine learning, non-deterministic behaviour, agent-to-agent interaction, self-learning, tool use and cascading effects across models, data, infrastructure and business ecosystems.
MAESTRO supplements, rather than invalidates, methods such as STRIDE, PASTA, LINDDUN, OCTAVE, Trike and VAST. It provides an AI-agent-specific reference architecture and threat landscape.
Canonical principles
Section titled “Canonical principles”The CSA method is based on:
- Extended security categories: retain traditional cybersecurity concerns while adding AI-specific attack and failure modes.
- Multi-agent and environment focus: include peer agents, people, tools, suppliers, registries, markets and the physical or digital environment.
- Layered security: examine every architectural layer and the dependencies between them.
- AI-specific threats: model adversarial ML, data poisoning, model extraction, autonomy and goal-related risk.
- Risk-based prioritisation: use likelihood and impact in the system’s actual context.
- Continuous monitoring and adaptation: update the threat model as systems and adversaries change.
Threat, vulnerability, risk and control
Section titled “Threat, vulnerability, risk and control”| Term | Meaning in a MAESTRO assessment |
|---|---|
| Asset | Something of value: model, dataset, identity, tool, decision, service, reputation or safety outcome |
| Threat | A canonical type of harmful event, attack or failure |
| Threat actor | A malicious user, insider, supplier, compromised agent, peer agent or automated process |
| Vulnerability | A weakness or missing condition that makes the threat feasible |
| Attack path | The sequence from entry point through trust transitions to harm |
| Control | A preventive, detective, responsive or recovery measure that breaks or constrains the path |
| Inherent risk | Risk before considering the effectiveness of current controls |
| Residual risk | Risk remaining after evidenced controls are considered |
| Finding | A documented control weakness, failed test, exception or unacceptable exposure |
| Treatment | Avoid, reduce, transfer, accept or monitor the risk under authorised governance |
A threat is not a control failure by itself. A vulnerability is not the same as business impact. A control existing on paper does not establish that the threat is well managed.
Canonical versus Gamut-authored material
Section titled “Canonical versus Gamut-authored material”The following are canonical CSA concepts:
- The MAESTRO name and purpose.
- Seven-layer architecture.
- Layer descriptions.
- 50 layer-specific threat names.
- Five cross-layer threat names.
- Eight architecture patterns.
- Six-step workflow.
- Likelihood-and-impact risk approach.
Gamut adds operational assessment machinery:
- Stable IDs such as
MAE-L2-05. - System-scoped storage.
- Detailed unique assessor playbooks.
- Evidence, testing and findings panels.
- A defined five-band risk matrix.
- Reporting and cross-framework links.
- Structured AI assistance.
Gamut-authored guidance makes the CSA method assessable; it should not be represented as additional CSA text or CSA endorsement.
Labels on the screen
Section titled “Labels on the screen”| Label | Meaning |
|---|---|
| Layer 1–7 | The canonical architectural area in which a threat originates |
| Cross-layer / X | A threat path spanning two or more layers |
| Vertical | Layer 6 applies across the full architecture |
| Threats assessed | Both likelihood and impact have been recorded for that number of threats |
| Low / Moderate / Elevated / High / Critical | Derived risk severity; higher is worse |
| Highest threat risk | Maximum severity among scored threats in that section or system |
| Workspace | Assessment is not tied to one registered AI system |
| Assessing system | The selected registered system whose MAESTRO bucket is active |
| AI-assisted assessment | Model-generated advisory output grounded in validated assessment context |
| Human approval required | Suggestions do not become approved assessment conclusions automatically |
Applicability
Section titled “Applicability”A canonical threat is applicable when the required asset, interface, actor or pathway exists or is reasonably foreseeable. Applicability can be:
- Applicable: the required path exists.
- Potentially applicable: it may exist, but architecture or ownership is incomplete.
- Not applicable: the required asset or pathway demonstrably does not exist.
- Insufficient information: the assessor cannot make a defensible decision.
Do not score an unexamined threat as Low. If it is not applicable, record the architectural reason. If information is missing, leave it unscored and request the missing information.
Defence-in-depth view
Section titled “Defence-in-depth view”For each threat, consider independent controls at several points:
- Prevent initial access or manipulation.
- Validate identity, provenance and authorisation.
- Constrain privileges, tools and reachable assets.
- Detect abnormal behaviour or integrity loss.
- Stop or isolate the affected component.
- Revoke credentials and delegated authority.
- Roll back data, configuration, models or agent state.
- Recover service and preserve forensic evidence.
Controls that share the same dependency or enforcement point may fail together and should not be counted as independent layers of defence.
What “aligned” means
Section titled “What “aligned” means”A MAESTRO-aligned Gamut assessment should:
- Use the canonical layer ordering and threat names.
- Include the cross-layer threats.
- Begin with system decomposition.
- Tailor threats to the real architecture.
- Assess likelihood and impact.
- Plan mitigations.
- Implement and monitor them continuously.
- Preserve provenance and framework attribution.
Alignment does not mean every canonical threat must receive a numeric score. It means every threat is considered and applicable threats are assessed rigorously.
Relationship to other Gamut frameworks
Section titled “Relationship to other Gamut frameworks”| Framework | Primary question |
|---|---|
| MAESTRO | What can attack, misuse or destabilise this system, and through which paths? |
| GTSAF | Which safeguards should be implemented, evidenced and tested? |
| ACRS | How much risk is created by dependency, autonomy, access and harm potential? |
| ATF | What trust controls and autonomy ceiling should govern the agent? |
MAESTRO identifies the attack paths. GTSAF provides a broad control baseline. ACRS supplies capability risk context. ATF governs agent trust and action authority.