From 42a4be3fe34e082e76d8296f74b3e610ebf498f4 Mon Sep 17 00:00:00 2001 From: Sima Bagheri <37793675+simaba@users.noreply.github.com> Date: Tue, 7 Jul 2026 15:32:52 +0800 Subject: [PATCH 1/6] docs: record first limited authoritative-source review --- .../2026-07-core-authoritative-sources.md | 27 +++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100644 docs/source-reviews/2026-07-core-authoritative-sources.md diff --git a/docs/source-reviews/2026-07-core-authoritative-sources.md b/docs/source-reviews/2026-07-core-authoritative-sources.md new file mode 100644 index 0000000..5482e7e --- /dev/null +++ b/docs/source-reviews/2026-07-core-authoritative-sources.md @@ -0,0 +1,27 @@ +# Core Authoritative-Source Review — 2026-07-07 + +## Scope + +This was a limited first-pass content review of the core authoritative sources that anchor PRISM's regulatory and security sections. It did **not** validate every linked tool, benchmark, community, course, or secondary guide. + +## Reviewed sources and findings + +| Resource | Result | README description check | Follow-up | +|---|---|---|---| +| ISO/IEC 42001:2023 | Official ISO page identifies it as a published international standard for an AI management system. | Accurate. | Keep the existing ISO link and review on the normal standards cadence. | +| OECD AI Principles | Official OECD page states that the principles promote innovative, trustworthy AI and were updated in May 2024. | Accurate but could eventually note the 2024 update. | Keep the existing link. | +| OWASP Top 10 for LLM Applications | Official OWASP page states that the original Top 10 is now part of the broader OWASP GenAI Security Project and directs readers to the current dedicated LLM Top 10 location. | The current description remains directionally accurate. | Update the README destination to the current dedicated LLM Top 10 URL in the next targeted link-refresh PR. | +| EU AI Act | The README links directly to the official EUR-Lex text for Regulation (EU) 2024/1689. | Accurate as a source classification. | Review implementation dates and related secondary guidance separately; do not rely on the hub's one-line entry for legal interpretation. | +| MITRE ATLAS | The README links to the official MITRE ATLAS site. | Accurate as a source classification. | Perform a separate content review of ATLAS technique coverage and release/versioning. | + +## Review discipline + +- A source was recorded as reviewed only where the source owner and high-level description could be checked directly. +- This review did not certify legal currency, implementation completeness, safety sufficiency, or applicability to any organization. +- Secondary summaries remain secondary. The EU AI Act summary entry should continue to direct readers back to EUR-Lex for legal interpretation. + +## Next review priorities + +1. Update the OWASP link to the current dedicated LLM Top 10 destination. +2. Review NIST AI RMF and related implementation resources separately, including current supporting profiles and resources. +3. Complete the first manual review of open-source tools, benchmarks, and communities using the criteria in `CURATION.md`. From ea059b8c4447467d1a2616a691650118f7d5abc0 Mon Sep 17 00:00:00 2001 From: Sima Bagheri <37793675+simaba@users.noreply.github.com> Date: Tue, 7 Jul 2026 15:33:12 +0800 Subject: [PATCH 2/6] docs: record limited first source review --- REVIEW_STATUS.md | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/REVIEW_STATUS.md b/REVIEW_STATUS.md index 8cb411f..1eddaa8 100644 --- a/REVIEW_STATUS.md +++ b/REVIEW_STATUS.md @@ -6,13 +6,15 @@ This ledger distinguishes automated link health from manual content freshness. A **Review owner:** Repository maintainer **Rule:** Record a dated content review only after checking the linked primary source and the description in `README.md`. +See [`docs/source-reviews/2026-07-core-authoritative-sources.md`](docs/source-reviews/2026-07-core-authoritative-sources.md) for the scope and limits of the first documented source review. + ## Regulatory Frameworks | Section | Last confirmed content review | Next review due | Status | |---|---:|---:|---| -| United States | Not yet recorded | 2026-12-24 | Requires initial manual review | -| European Union | Not yet recorded | 2026-12-24 | Requires initial manual review | -| International Standards | Not yet recorded | 2026-12-24 | Requires initial manual review | +| United States | Not yet recorded | 2026-12-24 | Requires initial manual review of NIST and OMB sources | +| European Union | 2026-07-07 | 2026-10-07 | Initial source classification reviewed; legal-timeline interpretation remains out of scope | +| International Standards | 2026-07-07 | 2026-10-07 | Initial ISO/OECD source and description review completed; IEEE and ISO/IEC 23894 remain pending | ## Other active resources @@ -21,6 +23,8 @@ This ledger distinguishes automated link health from manual content freshness. A | Open-source tools and platforms | Not yet recorded | 2026-09-24 | Requires initial manual review | | Benchmarks and evaluation frameworks | Not yet recorded | 2026-09-24 | Requires initial manual review | | Communities and courses | Not yet recorded | 2026-12-24 | Requires initial manual review | +| LLM security guidance | 2026-07-07 | 2026-10-07 | OWASP source reviewed; README destination needs a targeted link refresh | +| Adversarial-AI knowledge bases | 2026-07-07 | 2026-10-07 | MITRE ATLAS source classification reviewed; technique coverage review remains pending | ## Update procedure From 3c35c47a47e8a9142679b4949f77f0001cc8512c Mon Sep 17 00:00:00 2001 From: Sima Bagheri <37793675+simaba@users.noreply.github.com> Date: Wed, 8 Jul 2026 11:22:28 +0800 Subject: [PATCH 3/6] docs: refresh NIST and OWASP source pointers --- README.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index e297f9d..4db6124 100644 --- a/README.md +++ b/README.md @@ -47,7 +47,7 @@ A blocking link-check workflow runs on pull requests and monthly. `REVIEW_STATUS ### United States - **[NIST AI Risk Management Framework](https://airc.nist.gov/home)** — NIST’s official hub for the voluntary framework organized around Govern, Map, Measure, and Manage. -- **[NIST AI Safety Institute](https://www.nist.gov/artificial-intelligence/executive-order-safe-secure-and-trustworthy-artificial-intelligence)** — Federal AI safety research and standards coordination. +- **[NIST AI Program and Center for AI Standards and Innovation](https://www.nist.gov/artificial-intelligence)** — NIST’s official AI hub covering AI RMF resources, measurement science, standards, evaluations, and related federal AI programs. - **[OMB AI Governance Policy M-24-10](https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf)** — U.S. federal agency governance and risk-management requirements for AI use. ### European Union @@ -70,7 +70,7 @@ A blocking link-check workflow runs on pull requests and monthly. `REVIEW_STATUS - **[Microsoft Responsible AI Standard](https://blogs.microsoft.com/wp-content/uploads/prod/sites/5/2022/06/Microsoft-Responsible-AI-Standard-v2-General-Requirements-3.pdf)** — Public responsible-AI standard and requirements guide. - **[Google PAIR Guidebook](https://pair.withgoogle.com/guidebook/)** — People + AI Research guidebook for human-centered AI design. - **[MITRE ATLAS](https://atlas.mitre.org/)** — Knowledge base of AI-specific adversarial tactics and techniques. -- **[OWASP Top 10 for LLMs](https://owasp.org/www-project-top-10-for-large-language-model-applications/)** — Common security risks in LLM applications. +- **[OWASP Top 10 for LLMs and GenAI Apps](https://genai.owasp.org/llm-top-10/)** — Current OWASP GenAI Security Project page for LLM and generative-AI application risks and mitigations. --- @@ -191,4 +191,4 @@ When adding a resource: [![CC0](https://mirrors.creativecommons.org/presskit/buttons/88x31/svg/cc-zero.svg)](https://creativecommons.org/publicdomain/zero/1.0/) -To the extent possible under law, Sima Bagheri has waived all copyright and related or neighboring rights to this work. +To the extent possible under law, Sima Bagheri has waived all copyright and related or neighboring rights to this work. \ No newline at end of file From 266d43bec7338a335cae1c1443188fb82a85c32f Mon Sep 17 00:00:00 2001 From: Sima Bagheri <37793675+simaba@users.noreply.github.com> Date: Wed, 8 Jul 2026 11:22:47 +0800 Subject: [PATCH 4/6] docs: mark OWASP destination refresh complete --- REVIEW_STATUS.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/REVIEW_STATUS.md b/REVIEW_STATUS.md index 1eddaa8..68e6fcf 100644 --- a/REVIEW_STATUS.md +++ b/REVIEW_STATUS.md @@ -12,7 +12,7 @@ See [`docs/source-reviews/2026-07-core-authoritative-sources.md`](docs/source-re | Section | Last confirmed content review | Next review due | Status | |---|---:|---:|---| -| United States | Not yet recorded | 2026-12-24 | Requires initial manual review of NIST and OMB sources | +| United States | 2026-07-07 | 2026-10-07 | Initial NIST AI hub source classification reviewed; OMB source remains pending | | European Union | 2026-07-07 | 2026-10-07 | Initial source classification reviewed; legal-timeline interpretation remains out of scope | | International Standards | 2026-07-07 | 2026-10-07 | Initial ISO/OECD source and description review completed; IEEE and ISO/IEC 23894 remain pending | @@ -23,7 +23,7 @@ See [`docs/source-reviews/2026-07-core-authoritative-sources.md`](docs/source-re | Open-source tools and platforms | Not yet recorded | 2026-09-24 | Requires initial manual review | | Benchmarks and evaluation frameworks | Not yet recorded | 2026-09-24 | Requires initial manual review | | Communities and courses | Not yet recorded | 2026-12-24 | Requires initial manual review | -| LLM security guidance | 2026-07-07 | 2026-10-07 | OWASP source reviewed; README destination needs a targeted link refresh | +| LLM security guidance | 2026-07-07 | 2026-10-07 | OWASP source reviewed and README destination refreshed to the current GenAI Security Project page | | Adversarial-AI knowledge bases | 2026-07-07 | 2026-10-07 | MITRE ATLAS source classification reviewed; technique coverage review remains pending | ## Update procedure From 3e21301b4f3873649b5e91da3a9bdc8e9480105a Mon Sep 17 00:00:00 2001 From: Sima Bagheri <37793675+simaba@users.noreply.github.com> Date: Wed, 8 Jul 2026 11:23:02 +0800 Subject: [PATCH 5/6] docs: update completed source-review follow-ups --- docs/source-reviews/2026-07-core-authoritative-sources.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/docs/source-reviews/2026-07-core-authoritative-sources.md b/docs/source-reviews/2026-07-core-authoritative-sources.md index 5482e7e..1310261 100644 --- a/docs/source-reviews/2026-07-core-authoritative-sources.md +++ b/docs/source-reviews/2026-07-core-authoritative-sources.md @@ -8,9 +8,10 @@ This was a limited first-pass content review of the core authoritative sources t | Resource | Result | README description check | Follow-up | |---|---|---|---| +| NIST AI program hub | Official NIST page identifies the AI RMF, Center for AI Standards and Innovation, AI Resource Center, standards work, evaluations, and NIST's nonregulatory measurement-science role. | Updated the U.S. entry to point to the broader current NIST AI hub rather than an older executive-order page. | Review the AI RMF and supporting resources separately, including current profiles and implementation guidance. | | ISO/IEC 42001:2023 | Official ISO page identifies it as a published international standard for an AI management system. | Accurate. | Keep the existing ISO link and review on the normal standards cadence. | | OECD AI Principles | Official OECD page states that the principles promote innovative, trustworthy AI and were updated in May 2024. | Accurate but could eventually note the 2024 update. | Keep the existing link. | -| OWASP Top 10 for LLM Applications | Official OWASP page states that the original Top 10 is now part of the broader OWASP GenAI Security Project and directs readers to the current dedicated LLM Top 10 location. | The current description remains directionally accurate. | Update the README destination to the current dedicated LLM Top 10 URL in the next targeted link-refresh PR. | +| OWASP Top 10 for LLM Applications | Official OWASP page states that the original Top 10 is now part of the broader OWASP GenAI Security Project and directs readers to the current dedicated LLM Top 10 location. | Updated the README destination and label to the current GenAI Security Project LLM Top 10 page. | Review OWASP's agentic-app and GenAI governance resources separately. | | EU AI Act | The README links directly to the official EUR-Lex text for Regulation (EU) 2024/1689. | Accurate as a source classification. | Review implementation dates and related secondary guidance separately; do not rely on the hub's one-line entry for legal interpretation. | | MITRE ATLAS | The README links to the official MITRE ATLAS site. | Accurate as a source classification. | Perform a separate content review of ATLAS technique coverage and release/versioning. | @@ -22,6 +23,6 @@ This was a limited first-pass content review of the core authoritative sources t ## Next review priorities -1. Update the OWASP link to the current dedicated LLM Top 10 destination. -2. Review NIST AI RMF and related implementation resources separately, including current supporting profiles and resources. +1. Review NIST AI RMF and related implementation resources separately, including current supporting profiles and resources. +2. Review OWASP's agentic-app security, AI security governance checklist, and GenAI Security Project resources beyond the LLM Top 10. 3. Complete the first manual review of open-source tools, benchmarks, and communities using the criteria in `CURATION.md`. From 251398f81d610d9a5cabae75205e41b2d65708c2 Mon Sep 17 00:00:00 2001 From: Sima Bagheri <37793675+simaba@users.noreply.github.com> Date: Wed, 8 Jul 2026 11:23:33 +0800 Subject: [PATCH 6/6] docs: ensure reviewed links use current labels