Reference and glossary
Quick facts
Section titled “Quick facts”| Item | Value |
|---|---|
| Source | Cloud Security Alliance article, 6 February 2025 |
| Lead author | Ken Huang |
| Gamut catalogue | CSA-2025-02-06-v1 |
| Layers | 7 |
| Layer threats | 50 |
| Cross-layer threats | 5 |
| Total threats | 55 |
| Architecture patterns | 8 |
| Workflow steps | 6 |
| Risk formula | Likelihood × impact |
Layer counts
Section titled “Layer counts”| ID | Name | Threats |
|---|---|---|
| L1 | Foundation Models | 7 |
| L2 | Data Operations | 5 |
| L3 | Agent Frameworks | 6 |
| L4 | Deployment & Infrastructure | 6 |
| L5 | Evaluation & Observability | 6 |
| L6 | Security & Compliance | 7 |
| L7 | Agent Ecosystem | 13 |
| X | Cross-Layer Threats | 5 |
Identifier format
Section titled “Identifier format”MAE-L1-01: first threat in Layer 1.MAE-L7-13: thirteenth threat in Layer 7.MAE-X-05: fifth cross-layer threat.#Land#Iare internal persisted score suffixes for likelihood and impact.
Likelihood
Section titled “Likelihood”| 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|
| Rare | Unlikely | Possible | Likely | Almost certain |
Impact
Section titled “Impact”| 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|
| Negligible | Minor | Moderate | Major | Severe |
Risk bands
Section titled “Risk bands”| Product | Severity | Label |
|---|---|---|
| 1–4 | 1 | Low |
| 5–9 | 2 | Moderate |
| 10–14 | 3 | Elevated |
| 15–19 | 4 | High |
| 20–25 | 5 | Critical |
Higher is worse.
Architecture patterns
Section titled “Architecture patterns”- Single-Agent Pattern.
- Multi-Agent Pattern.
- Unconstrained Conversational Autonomy.
- Task-Oriented Agent Pattern.
- Hierarchical Agent Pattern.
- Distributed Agent Ecosystem.
- Human-in-the-Loop Collaboration.
- Self-Learning and Adaptive Agents.
Workflow
Section titled “Workflow”- System Decomposition.
- Layer-Specific Threat Modeling.
- Cross-Layer Threat Identification.
- Risk Assessment.
- Mitigation Planning.
- Implementation and Monitoring.
Glossary
Section titled “Glossary”Agent ecosystem The network of agents, users, tools, suppliers, registries, marketplaces and business applications within which an agent operates.
Applicability Whether the assets and pathways required for a canonical threat exist in the selected system.
Attack path The sequence from actor or failure through entry point, weakness and trust transitions to harm.
Canonical threat A threat name and layer placement from the CSA MAESTRO catalogue.
Cross-layer threat A threat that exploits relationships between two or more architectural layers.
Defence in depth Multiple independent preventive, detective, response and recovery controls across a threat path.
Evidence An artefact or operating record supporting a claim about architecture or control operation.
Finding A recorded weakness, exception, failed test or unacceptable risk condition.
Highest threat risk The maximum severity among scored threats in the relevant section or system.
Inherent risk Risk before credit is given for current controls.
Layer A functional area of the agentic architecture used to organise threat analysis.
Residual risk Risk remaining after evidenced and effective controls are considered.
Risk severity The Low-to-Critical band derived from likelihood × impact.
System decomposition The description of components, capabilities, goals, constraints, interactions and trust boundaries.
Threat scenario The canonical threat tailored to a real actor, path, asset and consequence in the selected system.
Treatment The governed decision to avoid, reduce, transfer, accept or monitor risk.
Vertical layer Layer 6, Security & Compliance, which applies across the rest of the architecture.
Workspace roll-up Portfolio summary across registered systems; not a substitute for a system-level assessment.
Zero trust The principle that identity, device, workload, agent, data and action claims are continuously verified and constrained by least privilege.
Common questions
Section titled “Common questions”Is Low the same as fully mitigated?
Section titled “Is Low the same as fully mitigated?”No. Low is a risk conclusion from likelihood and impact. It is not a control-maturity score.
Does every threat need a score?
Section titled “Does every threat need a score?”Every threat must be considered. Applicable threats need assessment. Demonstrably non-applicable threats should record the architectural reason rather than receive an artificial Low score.
Why does a layer use the highest threat?
Section titled “Why does a layer use the highest threat?”To prevent material exposure from being diluted by averaging.
Is the cross-layer section Layer 8?
Section titled “Is the cross-layer section Layer 8?”No. It is a dedicated section for attack chains spanning the seven layers.
Is Security & Compliance Layer 5 or Layer 6?
Section titled “Is Security & Compliance Layer 5 or Layer 6?”In the canonical catalogue implemented by Gamut, Layer 5 is Evaluation & Observability and Layer 6 is Security & Compliance, with Layer 6 treated as vertical.
Does MAESTRO replace GTSAF?
Section titled “Does MAESTRO replace GTSAF?”No. MAESTRO models threats; GTSAF assesses safeguards. They complement each other.
Does AI Assist approve the assessment?
Section titled “Does AI Assist approve the assessment?”No. Human approval is required for applicability, scores, testing, evidence and risk decisions.
Does an API key unlock MAESTRO?
Section titled “Does an API key unlock MAESTRO?”No. Framework, role, model, quota and workspace entitlements are enforced separately.
Does a completed assessment prove CSA certification?
Section titled “Does a completed assessment prove CSA certification?”No. Gamut provides a CSA-aligned workflow and is not CSA-endorsed.