Agent Security Working Group Plan #21
fergfamster
started this conversation in
Ideas
Replies: 1 comment 1 reply
-
Please raise your hand by commenting of what section of security you want to help contribute to:
|
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Mission: To provide security primitives, objectives, controls and implementation guidance to ensure proper understanding for the field in deploying agentic workflows.
Problem Statement: Agentic Security primitives have been widely defined across sectors. However given the nascent relationship to identity, threat intelligence, proactive security measures, compliance and governance controls, we need to navigate a set of known and unknown outcomes and processes by which companies can be secure while ensuring operational readiness and compliance.
Goals & Success:
What We Want to Achieve
[Primary Goal] - Create a reference matrix and foundational principles for enabling security and production ready agentic systems.
[Secondary Goal] - Create a tool that helps define threat modeling, Pen testing and operational controls for compliance and audibility
[Third Goal] - Support other community teams in their goals of defining security in each lane
How We'll Know We Succeeded:
By the end, we want to have:
[ ] Provided a security matrix and framework for any agentic system to evaluate against
[ ] A comprehensive white paper on agentic security best practices.
[ ] Multiple blogs on Agentic security covering key topics such as identity, observability, networking,
[ ] At least 4 successful adopters of the architecture across different industry verticals.
Top Agentic Security Concerns:
These security concerns require organizations to implement robust risk management strategies, including multi-layered security frameworks and careful limitations on AI autonomy in high-risk scenarios. The balance between leveraging AI capabilities and maintaining security remains a critical challenge.
Data Integrity and System Exploitation
Privacy and Data Protection
Autonomy-Related Risks
Systemic and Operational Risks
Transparency and Trust Issues
Compliance and Governance Challenges
Team and Responsibilities
Core Team:
James Ferguson
Riggs Goodman
Dan Neff
Appendix
Governance Concerns
Beta Was this translation helpful? Give feedback.
All reactions