Skip to content

Method, concepts and terminology

Traditional threat methods remain useful, but agentic AI adds risks they do not always model explicitly: autonomous decision-making, goal manipulation, adversarial machine learning, non-deterministic behaviour, agent-to-agent interaction, self-learning, tool use and cascading effects across models, data, infrastructure and business ecosystems.

MAESTRO supplements, rather than invalidates, methods such as STRIDE, PASTA, LINDDUN, OCTAVE, Trike and VAST. It provides an AI-agent-specific reference architecture and threat landscape.

The CSA method is based on:

  • Extended security categories: retain traditional cybersecurity concerns while adding AI-specific attack and failure modes.
  • Multi-agent and environment focus: include peer agents, people, tools, suppliers, registries, markets and the physical or digital environment.
  • Layered security: examine every architectural layer and the dependencies between them.
  • AI-specific threats: model adversarial ML, data poisoning, model extraction, autonomy and goal-related risk.
  • Risk-based prioritisation: use likelihood and impact in the system’s actual context.
  • Continuous monitoring and adaptation: update the threat model as systems and adversaries change.
TermMeaning in a MAESTRO assessment
AssetSomething of value: model, dataset, identity, tool, decision, service, reputation or safety outcome
ThreatA canonical type of harmful event, attack or failure
Threat actorA malicious user, insider, supplier, compromised agent, peer agent or automated process
VulnerabilityA weakness or missing condition that makes the threat feasible
Attack pathThe sequence from entry point through trust transitions to harm
ControlA preventive, detective, responsive or recovery measure that breaks or constrains the path
Inherent riskRisk before considering the effectiveness of current controls
Residual riskRisk remaining after evidenced controls are considered
FindingA documented control weakness, failed test, exception or unacceptable exposure
TreatmentAvoid, reduce, transfer, accept or monitor the risk under authorised governance

A threat is not a control failure by itself. A vulnerability is not the same as business impact. A control existing on paper does not establish that the threat is well managed.

The following are canonical CSA concepts:

  • The MAESTRO name and purpose.
  • Seven-layer architecture.
  • Layer descriptions.
  • 50 layer-specific threat names.
  • Five cross-layer threat names.
  • Eight architecture patterns.
  • Six-step workflow.
  • Likelihood-and-impact risk approach.

Gamut adds operational assessment machinery:

  • Stable IDs such as MAE-L2-05.
  • System-scoped storage.
  • Detailed unique assessor playbooks.
  • Evidence, testing and findings panels.
  • A defined five-band risk matrix.
  • Reporting and cross-framework links.
  • Structured AI assistance.

Gamut-authored guidance makes the CSA method assessable; it should not be represented as additional CSA text or CSA endorsement.

LabelMeaning
Layer 1–7The canonical architectural area in which a threat originates
Cross-layer / XA threat path spanning two or more layers
VerticalLayer 6 applies across the full architecture
Threats assessedBoth likelihood and impact have been recorded for that number of threats
Low / Moderate / Elevated / High / CriticalDerived risk severity; higher is worse
Highest threat riskMaximum severity among scored threats in that section or system
WorkspaceAssessment is not tied to one registered AI system
Assessing systemThe selected registered system whose MAESTRO bucket is active
AI-assisted assessmentModel-generated advisory output grounded in validated assessment context
Human approval requiredSuggestions do not become approved assessment conclusions automatically

A canonical threat is applicable when the required asset, interface, actor or pathway exists or is reasonably foreseeable. Applicability can be:

  • Applicable: the required path exists.
  • Potentially applicable: it may exist, but architecture or ownership is incomplete.
  • Not applicable: the required asset or pathway demonstrably does not exist.
  • Insufficient information: the assessor cannot make a defensible decision.

Do not score an unexamined threat as Low. If it is not applicable, record the architectural reason. If information is missing, leave it unscored and request the missing information.

For each threat, consider independent controls at several points:

  1. Prevent initial access or manipulation.
  2. Validate identity, provenance and authorisation.
  3. Constrain privileges, tools and reachable assets.
  4. Detect abnormal behaviour or integrity loss.
  5. Stop or isolate the affected component.
  6. Revoke credentials and delegated authority.
  7. Roll back data, configuration, models or agent state.
  8. Recover service and preserve forensic evidence.

Controls that share the same dependency or enforcement point may fail together and should not be counted as independent layers of defence.

A MAESTRO-aligned Gamut assessment should:

  • Use the canonical layer ordering and threat names.
  • Include the cross-layer threats.
  • Begin with system decomposition.
  • Tailor threats to the real architecture.
  • Assess likelihood and impact.
  • Plan mitigations.
  • Implement and monitor them continuously.
  • Preserve provenance and framework attribution.

Alignment does not mean every canonical threat must receive a numeric score. It means every threat is considered and applicable threats are assessed rigorously.

FrameworkPrimary question
MAESTROWhat can attack, misuse or destabilise this system, and through which paths?
GTSAFWhich safeguards should be implemented, evidenced and tested?
ACRSHow much risk is created by dependency, autonomy, access and harm potential?
ATFWhat trust controls and autonomy ceiling should govern the agent?

MAESTRO identifies the attack paths. GTSAF provides a broad control baseline. ACRS supplies capability risk context. ATF governs agent trust and action authority.