Skip to content

Reference and glossary

ItemValue
SourceCloud Security Alliance article, 6 February 2025
Lead authorKen Huang
Gamut catalogueCSA-2025-02-06-v1
Layers7
Layer threats50
Cross-layer threats5
Total threats55
Architecture patterns8
Workflow steps6
Risk formulaLikelihood × impact
IDNameThreats
L1Foundation Models7
L2Data Operations5
L3Agent Frameworks6
L4Deployment & Infrastructure6
L5Evaluation & Observability6
L6Security & Compliance7
L7Agent Ecosystem13
XCross-Layer Threats5
  • MAE-L1-01: first threat in Layer 1.
  • MAE-L7-13: thirteenth threat in Layer 7.
  • MAE-X-05: fifth cross-layer threat.
  • #L and #I are internal persisted score suffixes for likelihood and impact.
12345
RareUnlikelyPossibleLikelyAlmost certain
12345
NegligibleMinorModerateMajorSevere
ProductSeverityLabel
1–41Low
5–92Moderate
10–143Elevated
15–194High
20–255Critical

Higher is worse.

  1. Single-Agent Pattern.
  2. Multi-Agent Pattern.
  3. Unconstrained Conversational Autonomy.
  4. Task-Oriented Agent Pattern.
  5. Hierarchical Agent Pattern.
  6. Distributed Agent Ecosystem.
  7. Human-in-the-Loop Collaboration.
  8. Self-Learning and Adaptive Agents.
  1. System Decomposition.
  2. Layer-Specific Threat Modeling.
  3. Cross-Layer Threat Identification.
  4. Risk Assessment.
  5. Mitigation Planning.
  6. Implementation and Monitoring.

Agent ecosystem The network of agents, users, tools, suppliers, registries, marketplaces and business applications within which an agent operates.

Applicability Whether the assets and pathways required for a canonical threat exist in the selected system.

Attack path The sequence from actor or failure through entry point, weakness and trust transitions to harm.

Canonical threat A threat name and layer placement from the CSA MAESTRO catalogue.

Cross-layer threat A threat that exploits relationships between two or more architectural layers.

Defence in depth Multiple independent preventive, detective, response and recovery controls across a threat path.

Evidence An artefact or operating record supporting a claim about architecture or control operation.

Finding A recorded weakness, exception, failed test or unacceptable risk condition.

Highest threat risk The maximum severity among scored threats in the relevant section or system.

Inherent risk Risk before credit is given for current controls.

Layer A functional area of the agentic architecture used to organise threat analysis.

Residual risk Risk remaining after evidenced and effective controls are considered.

Risk severity The Low-to-Critical band derived from likelihood × impact.

System decomposition The description of components, capabilities, goals, constraints, interactions and trust boundaries.

Threat scenario The canonical threat tailored to a real actor, path, asset and consequence in the selected system.

Treatment The governed decision to avoid, reduce, transfer, accept or monitor risk.

Vertical layer Layer 6, Security & Compliance, which applies across the rest of the architecture.

Workspace roll-up Portfolio summary across registered systems; not a substitute for a system-level assessment.

Zero trust The principle that identity, device, workload, agent, data and action claims are continuously verified and constrained by least privilege.

No. Low is a risk conclusion from likelihood and impact. It is not a control-maturity score.

Every threat must be considered. Applicable threats need assessment. Demonstrably non-applicable threats should record the architectural reason rather than receive an artificial Low score.

To prevent material exposure from being diluted by averaging.

No. It is a dedicated section for attack chains spanning the seven layers.

Is Security & Compliance Layer 5 or Layer 6?

Section titled “Is Security & Compliance Layer 5 or Layer 6?”

In the canonical catalogue implemented by Gamut, Layer 5 is Evaluation & Observability and Layer 6 is Security & Compliance, with Layer 6 treated as vertical.

No. MAESTRO models threats; GTSAF assesses safeguards. They complement each other.

No. Human approval is required for applicability, scores, testing, evidence and risk decisions.

No. Framework, role, model, quota and workspace entitlements are enforced separately.

Does a completed assessment prove CSA certification?

Section titled “Does a completed assessment prove CSA certification?”

No. Gamut provides a CSA-aligned workflow and is not CSA-endorsed.