Practical governance artifacts for organizations adopting large language models, AI assistants, and agentic workflows in regulated, education, and public-sector environments.
This toolkit is built around a simple premise: AI security is not only a model problem. It is a governance, data, identity, continuity, vendor, assurance, and operating-model problem.
- Information security and risk leaders building AI governance programs
- IT and digital transformation teams introducing AI-assisted workflows
- Education technology teams evaluating AI tutors, assistants, and learning tools
- Internal audit, compliance, and assurance teams reviewing AI control evidence
- Researchers and practitioners translating AI security guidance into practical operations
| Area | Artifacts |
|---|---|
| AI system intake | Initial AI use-case review, data classification, deployment model, ownership, and approval path |
| Risk management | AI risk tiering, AI risk register, risk-register reporting, control ownership, inherent/residual scoring, and decision tracking |
| Risk acceptance | Time-bound model risk acceptance records with affected users, compensating controls, expiry dates, review triggers, approval evidence, and closure conditions |
| Governance forums | Repeatable review agendas, decision logs, risk acceptance records, required participants, and follow-up tracking |
| Decision contestability | Review template for notice, explanation, appeal, correction, human review, and remediation controls for AI-supported decisions |
| Human review calibration | Template for testing reviewer independence, consistency, overrides, workload, bias indicators, escalation, and evidence quality |
| Emergency stop drills | Template for testing AI pause, containment, rollback, fallback, evidence preservation, communications, and restart controls |
| Evaluation contamination review | Template for checking benchmark leakage, holdout exposure, answer-key retrieval, synthetic reuse, reviewer conflict, and vendor boundary evidence |
| Control catalog | Governance, identity, data, model, agent, vendor, monitoring, and continuity controls |
| Evidence management | Evidence register, test records, exception tracking, and audit-ready documentation |
| Evidence quality | Evidence freshness, ownership, source, cadence, status, and owner-review queues |
| Evidence retention | Retention windows, storage controls, deletion triggers, legal holds, and privacy minimization for AI governance evidence |
| Control testing | Evidence packs and examples for AI control design and operating-effectiveness review |
| Evaluation evidence | Release-readiness reporting for AI evaluation suites, dataset lineage, security cases, human review, pass rates, and stale evidence |
| Exception management | Aging report for expired, expiring, missing-expiration, and inconsistent AI governance exceptions |
| Data deletion evidence | Register and report for prompt, output, file, embedding, log, vector-store, and third-party deletion proof |
| Vendor due diligence | AI procurement scoring, vendor questionnaire, data handling, security, model controls, compliance, and continuity |
| Third-party dependency assurance | Provider/subprocessor register, assurance review, DPA status, subprocessor transparency, exit planning, and continuity evidence |
| Shadow AI discovery | Triage template for unmanaged AI tools, data exposure, owner assignment, remediation, and exception handling |
| Synthetic data governance | Release review template for lineage, memorization, re-identification, utility, consent, release boundaries, and post-release monitoring |
| Logging and retention | Checklist for prompt, output, embedding, tool-call, and operational log governance |
| Agentic safety | Tool-use review, privilege boundaries, human approval gates, and execution logging |
| Agent memory governance | Persistent memory register and review report for consent, stale facts, deletion evidence, retrieval boundaries, and memory poisoning risks |
| Agentic risk mapping | Agentic failure modes mapped to controls, evidence, release gates, monitoring signals, and owner roles |
| OWASP LLM 2025 mapping | OWASP LLM application risks mapped to toolkit controls, evidence, release gates, monitoring signals, and owner queues |
| NIST AI RMF crosswalk | Govern, Map, Measure, and Manage functions mapped to controls, evidence, review cadence, and owner roles |
| Access recertification | User, administrator, service account, API key, break-glass, and agent tool permission review |
| Red-team readiness | Scenario-based AI red-team test planning, evidence capture, and release decisions |
| Red-team taxonomy | Finding classification by risk theme, severity floor, release decision, owner role, and control coverage |
| Incident response | AI-specific incident severity classification, escalation triggers, and evidence preservation |
| Incident evidence | Register and report for AI incident timelines, containment evidence, preserved logs, privacy review, communications, and remediation queues |
| Tabletop evidence | Exercise evidence register and reporting for decision logs, containment, communications, fallback, privacy review, and remediation |
| Decommissioning | Retirement checklist for model, provider, data, credential, log, vector-store, and integration shutdown |
| Model/provider changes | Approval workflow for model, provider, endpoint, embedding, safety-filter, region, and agent-runtime changes |
| Model monitoring | KPI register for quality, safety, retrieval integrity, drift, security, reliability, cost, privacy, and oversight |
| Retrieval integrity | Review template for RAG source authority, temporal validity, stale facts, citation precision, and poisoned-source controls |
| EdTech example | AI assistant governance profile for learning platforms and student-facing workflows |
| Playbooks | Prompt injection incident response and AI service outage tabletop scenarios |
| Policy as code | Open Policy Agent examples for AI tool execution decisions |
The toolkit is designed to be framework-aware without pretending to replace formal assurance work.
- NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework
- NIST Cybersecurity Framework: https://www.nist.gov/cyberframework
- OWASP Top 10 for Large Language Model Applications: https://owasp.org/www-project-top-10-for-large-language-model-applications/
- OWASP GenAI Security Project: https://genai.owasp.org/
- Copy
templates/ai-system-intake.mdfor each AI use case. - Classify the use case with
templates/ai-risk-tiering-decision-record.md. - Record risks in
templates/ai-risk-register.csv. - Select controls from
controls/control-catalog.yaml. - Track evidence in
templates/evidence-register.csv. - Schedule operating-effectiveness tests in
templates/ai-control-test-schedule.csv. - Use
templates/agentic-tool-review.mdbefore allowing AI agents to call tools or APIs. - Score external AI products with
templates/ai-procurement-scoring-worksheet.md. - Complete
templates/vendor-ai-due-diligence.mdbefore approving external AI services. - Review logging decisions with
templates/ai-logging-retention-checklist.md. - Run a tabletop exercise from
playbooks/before production rollout. - Track tabletop exercise evidence with
templates/ai-tabletop-exercise-evidence-register.csv. - Use
templates/ai-system-decommissioning-checklist.mdbefore retiring, replacing, or pausing an AI system. - Use
templates/model-provider-change-approval.mdbefore changing models, providers, endpoints, embeddings, regions, or safety filters. - Track production health with
templates/model-monitoring-kpi-register.md. - Package control test evidence with
templates/ai-control-test-evidence-pack.md. - Review active exceptions with
scripts/exception_aging_report.py. - Summarize residual risk and owner review queues with
scripts/risk_register_report.py. - Review deletion evidence gaps with
scripts/data_deletion_evidence_report.py. - Review provider, subprocessor, and critical AI dependency gaps with
scripts/third_party_dependency_report.py. - Review tabletop evidence gaps with
scripts/tabletop_evidence_report.py. - Review AI evaluation evidence readiness with
scripts/evaluation_evidence_report.py. - Map agentic failure modes to controls and release gates with
scripts/agentic_risk_control_report.py. - Review AI access recertification gaps with
scripts/access_recertification_report.py. - Review AI incident evidence gaps with
scripts/incident_evidence_report.py. - Map OWASP LLM 2025 risks to governance controls with
scripts/owasp_llm_mapping_report.py. - Map NIST AI RMF functions to toolkit evidence with
scripts/nist_ai_rmf_crosswalk_report.py. - Summarize AI red-team finding taxonomy coverage with
scripts/red_team_taxonomy_report.py. - Review evidence quality and freshness with
scripts/evidence_quality_report.py. - Review AI data provenance, transformation evidence, transfer records, and owner queues with
scripts/data_lineage_report.py. - Triage AI privacy review and DPIA triggers with
scripts/dpia_triage_report.py. - Review rollback readiness for model, prompt, provider, safety-filter, and RAG releases with
scripts/rollback_readiness_report.py. - Set evidence retention, deletion, storage, and legal-hold expectations with
templates/ai-evidence-retention-schedule.md. - Review persistent memory with
templates/ai-agent-memory-governance-register.mdandtemplates/ai-agent-memory-governance-report.md. - Run governance forums with
templates/ai-governance-review-agenda.md. - Review RAG, knowledge-base, vector-store, and memory retrieval behavior with
templates/ai-retrieval-integrity-review.md. - Triage unmanaged or unclear AI use with
templates/ai-shadow-ai-discovery-triage.md. - Review synthetic data releases with
templates/ai-synthetic-data-release-review.md. - Review appealability and human oversight for high-impact decisions with
templates/ai-decision-contestability-review.md. - Calibrate human review quality with
templates/ai-human-review-calibration.md. - Test emergency stop readiness with
templates/ai-emergency-stop-drill.md. - Review evaluation dataset contamination risk with
templates/ai-evaluation-contamination-review.md. - Record time-bound residual model risk decisions with
templates/ai-model-risk-acceptance-register.md.
Validate repository artifacts before opening a pull request:
python scripts/validate_repository.pyThe validator checks Markdown templates, template index coverage, control catalog structure, CSV headers, and policy-as-code examples.
| Artifact | Purpose |
|---|---|
templates/ai-change-impact-assessment.md |
Review governance, data, model, tool, compliance, and continuity impact after AI system changes |
templates/ai-risk-tiering-decision-record.md |
Classify AI systems into risk tiers, set required control baselines, define approval routes, and record residual-risk decisions |
templates/ai-shadow-ai-discovery-triage.md |
Triage unmanaged AI tools discovered through telemetry, expenses, surveys, DLP alerts, support tickets, procurement, or self-disclosure |
templates/ai-synthetic-data-release-review.md |
Review synthetic data release readiness across lineage, privacy, re-identification, utility, consent, release boundaries, and monitoring |
templates/ai-system-decommissioning-checklist.md |
Retire AI systems safely by handling data, credentials, vector stores, logs, vendor access, integrations, evidence, and residual risk |
templates/ai-data-flow-record.md |
Document AI data sources, processing steps, destinations, classifications, and controls |
templates/ai-decision-contestability-review.md |
Review notice, explanation, evidence access, correction, appeal, human review, and remediation controls for AI-supported decisions |
templates/ai-emergency-stop-drill.md |
Test stop triggers, stop authority, containment, evidence preservation, fallback, rollback, communications, and restart readiness |
templates/ai-evaluation-contamination-review.md |
Check benchmark leakage, holdout exposure, answer-key retrieval, synthetic reuse, reviewer conflict, and vendor boundary evidence before relying on evaluation scores |
templates/ai-model-risk-acceptance-register.md |
Record time-bound residual risk acceptance with compensating controls, affected users, expiry dates, review triggers, approval evidence, rollback conditions, and closure status |
templates/ai-human-review-calibration.md |
Test human review independence, consistency, override quality, automation-bias indicators, reviewer workload, and escalation evidence |
templates/ai-data-lineage-register.csv |
Track source systems, owners, classifications, transformations, legal basis, retention, transfers, and review dates for AI data assets |
templates/ai-data-lineage-report.md |
Operating guide for reviewing data provenance, source ownership, transformation evidence, legal basis, retention, transfer, and review freshness |
templates/ai-data-deletion-evidence-register.csv |
Track AI deletion requests, processors, scopes, due dates, completion evidence, verification, and retention exceptions |
templates/ai-data-deletion-evidence-report.md |
Operating guide for reporting overdue deletions, missing evidence, unverified completions, and retention-exception review queues |
templates/ai-dpia-triage-register.csv |
Track DPIA triggers, personal-data use, automated decisioning, monitoring, transfers, privacy notices, and owner decisions |
templates/ai-dpia-triage-report.md |
Operating guide for privacy review triggers, owner queues, and DPIA launch blockers |
templates/ai-rollback-readiness-register.csv |
Track rollback triggers, runbooks, evaluation baselines, traffic-shift plans, schema compatibility, credentials, communications, drills, and approvals |
templates/ai-rollback-readiness-report.md |
Operating guide for release rollback readiness and owner queues |
templates/ai-access-review.md |
Review user, administrator, service account, API key, and agent tool permissions |
templates/ai-access-recertification-register.csv |
Track AI access assignments, privileged roles, service accounts, tokens, tool permissions, MFA, review dates, and recertification decisions |
templates/ai-access-recertification-report.md |
Operating guide for reviewing stale access, unowned tokens, separated users, break-glass approval, and high-impact agent tool permissions |
templates/ai-agent-memory-governance-register.md |
Record persistent memory assets, write rules, retrieval boundaries, lifecycle evidence, deletion proof, and approval decisions for AI agents and assistants |
templates/ai-agent-memory-governance-report.md |
Review consent, deletion, stale-fact handling, access boundaries, provider transfer, memory poisoning, and owner queues before enabling persistent memory |
templates/human-approval-matrix.md |
Define when AI-assisted actions require review, approval, or dual approval |
templates/board-ai-security-assurance-checklist.md |
Executive assurance checklist for approving high-impact AI systems |
templates/ai-control-evidence-raci.md |
Assign control ownership and evidence accountability across AI governance roles |
templates/ai-control-test-evidence-pack.md |
Package AI control test objectives, population, sample, evidence inventory, exceptions, remediation, and reviewer conclusions |
templates/ai-control-test-evidence-examples.csv |
Spreadsheet-friendly examples for operating-effectiveness evidence packs across agent tools, prompt injection, RAG boundaries, monitoring, and continuity |
templates/ai-evidence-quality-report.md |
Operating guide for reviewing stale, missing, expired, unowned, or incomplete AI governance evidence |
templates/ai-evidence-retention-schedule.md |
Define AI governance evidence retention periods, storage controls, deletion triggers, legal holds, privacy minimization, and owner accountability |
templates/ai-evaluation-evidence-register.csv |
Track AI evaluation suites, dataset lineage, model/prompt/index versions, pass rates, failures, security/bias/citation coverage, human review, and release decisions |
templates/ai-evaluation-evidence-report.md |
Operating guide for reviewing stale, incomplete, low-scoring, or release-blocking AI evaluation evidence |
templates/ai-red-team-test-plan.md |
Plan AI red-team scenarios, evidence capture, pass/fail criteria, and release decisions |
templates/ai-retrieval-integrity-review.md |
Review RAG source authority, temporal validity, stale fact handling, citation precision, retrieval boundaries, and poisoned-source controls |
templates/ai-governance-escalation-decision-tree.md |
Route AI use cases, incidents, model/provider changes, agent tools, and research risks to the correct governance review path |
templates/ai-governance-review-agenda.md |
Run structured governance forums with required participants, pre-read evidence, decision options, risk acceptance, and follow-up tracking |
controls/ai-red-team-finding-taxonomy.md |
Classify AI red-team findings by risk theme, severity floor, evidence, release decision, owner role, and control mapping |
controls/ai-red-team-finding-taxonomy.csv |
Spreadsheet-friendly red-team finding taxonomy for dashboards, approval gates, and remediation queues |
templates/ai-risk-register-report.md |
Operating guide for summarizing residual AI risk by theme, owner, and review-date status |
templates/ai-incident-severity-matrix.md |
Classify AI incidents by data exposure, tool misuse, output harm, identity impact, continuity, and escalation triggers |
templates/ai-incident-evidence-register.csv |
Track AI incident timelines, evidence references, data exposure, tool misuse, containment evidence, preserved logs, privacy review, communications, root cause, remediation due dates, and closure status |
templates/ai-incident-evidence-report.md |
Operating guide for reviewing missing AI incident evidence, privacy review gaps, tool-misuse log preservation, containment proof, incomplete timelines, and overdue remediation |
templates/prompt-injection-test-record.md |
Record direct and indirect prompt injection test cases, outcomes, and remediation |
templates/ai-agent-tool-inventory.csv |
Track agent tools, environments, permissions, data access, owners, and review dates |
templates/ai-control-test-schedule.csv |
Schedule AI control testing, evidence sources, test owners, results, and remediation due dates |
templates/ai-exception-register.csv |
Track AI governance exceptions, expirations, risk owners, and compensating controls |
templates/ai-exception-aging-report.md |
Operational guide for aging AI exceptions and converting registers into risk-owner review queues |
templates/ai-model-card-lite.md |
Capture lightweight model use, limitations, oversight, and risk notes |
templates/ai-procurement-scoring-worksheet.md |
Score AI vendors, hosted models, embedded AI features, and agent platforms before purchase, renewal, or expansion |
templates/ai-procurement-scoring-worksheet.csv |
Spreadsheet-friendly companion for weighted procurement scoring, evidence gaps, and remediation ownership |
templates/ai-third-party-dependency-register.csv |
Track AI providers, subprocessors, critical services, data access, DPA status, assurance evidence, exit plans, and continuity posture |
templates/ai-third-party-dependency-report.md |
Operating guide for reviewing third-party AI dependency gaps before release, renewal, audit, or provider change |
templates/ai-tabletop-exercise-evidence-register.csv |
Track AI tabletop exercise evidence, decision logs, containment tests, communications, fallback, privacy review, and remediation |
templates/ai-tabletop-evidence-report.md |
Operating guide for reviewing tabletop exercise gaps before release, audit, or governance review |
templates/model-provider-exit-plan.md |
Plan provider exit triggers, fallback options, data export, and deletion evidence |
templates/model-provider-change-approval.md |
Review model/provider changes for data handling, quality, safety, RAG behavior, tool use, cost, continuity, and approval routing |
templates/model-monitoring-kpi-register.md |
Define post-approval AI monitoring KPIs, thresholds, evidence sources, owners, and escalation rules |
templates/model-monitoring-kpi-register.csv |
Spreadsheet-friendly companion for model monitoring KPI tracking and review records |
controls/agentic-risk-control-mapping.md |
Map agentic AI failure modes to practical controls, evidence, release gates, monitoring signals, and owner roles |
controls/agentic-risk-control-mapping.csv |
Spreadsheet-friendly companion for agentic risk-to-control mapping |
controls/owasp-llm-2025-control-mapping.md |
Map OWASP LLM 2025 risks to toolkit controls, evidence expectations, release gates, monitoring signals, and owner roles |
controls/owasp-llm-2025-control-mapping.csv |
Spreadsheet-friendly companion for OWASP LLM 2025 governance mapping |
controls/nist-ai-rmf-control-crosswalk.md |
Map NIST AI RMF Govern, Map, Measure, and Manage functions to toolkit controls, evidence, cadence, and owner roles |
controls/nist-ai-rmf-control-crosswalk.csv |
Spreadsheet-friendly companion for NIST AI RMF evidence crosswalks |
policies/ai-log-retention-policy.md |
Define retention expectations for prompts, outputs, embeddings, tool calls, and security events |
playbooks/ai-data-leak-triage.md |
Triage suspected AI data exposure through prompts, outputs, logs, embeddings, or providers |
playbooks/agentic-tool-misuse-response.md |
Contain and investigate incorrect or unauthorized agent tool actions |
scripts/exception_aging_report.py |
Generate Markdown or JSON reports for expired, expiring, missing-expiration, and inconsistent AI exceptions |
scripts/risk_register_report.py |
Generate Markdown or JSON summaries of residual AI risk, owner queues, review dates, and theme-level exposure |
scripts/data_deletion_evidence_report.py |
Generate Markdown or JSON reports for AI data deletion evidence gaps and processor review queues |
scripts/third_party_dependency_report.py |
Generate Markdown or JSON reports for provider, subprocessor, assurance, exit-plan, and continuity gaps |
scripts/tabletop_evidence_report.py |
Generate Markdown or JSON reports for tabletop exercise evidence gaps, owner queues, and release-blocking readiness issues |
scripts/evaluation_evidence_report.py |
Generate Markdown or JSON reports for AI evaluation evidence readiness, stale evidence, missing coverage, release-blocking failures, and owner queues |
scripts/agentic_risk_control_report.py |
Generate Markdown or JSON summaries of agentic risk mappings, owner queues, control coverage, release gates, and monitoring signals |
scripts/access_recertification_report.py |
Generate Markdown or JSON reports for AI access recertification gaps, privileged access, service accounts, API tokens, break-glass access, and high-impact agent tool permissions |
scripts/incident_evidence_report.py |
Generate Markdown or JSON reports for AI incident evidence gaps, privacy review, containment proof, log preservation, timelines, communications, root cause, and remediation queues |
scripts/owasp_llm_mapping_report.py |
Generate Markdown or JSON summaries of OWASP LLM 2025 risk-to-control coverage, release gates, monitoring signals, and owner queues |
scripts/nist_ai_rmf_crosswalk_report.py |
Generate Markdown or JSON summaries of NIST AI RMF function coverage, control coverage, evidence cadence, and owner queues |
scripts/red_team_taxonomy_report.py |
Generate Markdown or JSON summaries of red-team finding severity, release holds, owner queues, and control coverage |
scripts/evidence_quality_report.py |
Generate Markdown or JSON reports for evidence ownership, freshness, overdue items, cadence gaps, and owner queues |
scripts/data_lineage_report.py |
Generate Markdown or JSON reports for AI data lineage completeness, provenance, sensitive-data evidence, transfer records, and owner queues |
examples/ai-data-lineage-sample.csv |
Sample lineage register covering healthy, public-source, owner-missing, transfer-gap, and overdue-review states |
scripts/dpia_triage_report.py |
Generate Markdown or JSON reports for AI DPIA triggers, owner queues, privacy-notice gaps, transfer risks, and launch blockers |
examples/ai-dpia-triage-sample.csv |
Sample DPIA triage register covering student data, automated decisioning, third-party transfers, large-scale monitoring, and low-risk public-source use |
scripts/rollback_readiness_report.py |
Generate Markdown or JSON reports for AI release rollback readiness, drill freshness, evidence gaps, and owner queues |
examples/ai-rollback-readiness-sample.csv |
Sample rollback readiness register covering prompt, model, provider, RAG index, and safety-filter release scenarios |
examples/ai-data-deletion-evidence-sample.csv |
Sample deletion evidence register covering overdue, verified, missing-evidence, and retention-exception states |
examples/ai-access-recertification-sample.csv |
Sample AI access recertification register covering privileged access, unowned tokens, separated identities, break-glass access, and current audit roles |
examples/ai-access-recertification-report.json |
Example machine-readable output from the access recertification report |
examples/ai-incident-evidence-sample.csv |
Sample AI incident evidence register covering privacy review gaps, missing tool logs, incomplete timelines, containment evidence gaps, overdue remediation, and closed incidents |
examples/ai-incident-evidence-report.json |
Example machine-readable output from the incident evidence report |
examples/ai-third-party-dependency-sample.csv |
Sample third-party AI dependency register covering missing DPA, subprocessor transparency, stale assurance, and continuity gaps |
examples/ai-tabletop-exercise-evidence-sample.csv |
Sample tabletop evidence register covering provider fallback, prompt injection, data exposure, and agent tool misuse scenarios |
examples/ai-evaluation-evidence-sample.csv |
Sample evaluation evidence register covering RAG, security, citation, human review, low pass-rate, and stale evidence cases |
examples/ai-exception-register-sample.csv |
Sample exception register for report testing and governance workshop demonstrations |
examples/agentic-risk-control-report.md |
Example Markdown report summarizing agentic risk owner queues, control coverage, release gates, and monitoring signals |
examples/agentic-risk-control-report.json |
Example machine-readable output from the agentic risk control mapping report |
examples/ai-red-team-taxonomy-report.json |
Example machine-readable output from the red-team finding taxonomy report |
examples/evidence-register-quality-sample.csv |
Sample evidence register with current, stale, expired, required, and owner-missing evidence states |
examples/edtech-ai-assistant-privacy-review.md |
Example privacy review for a student-facing AI assistant pilot |
This repo can support:
- internal AI governance workshops
- AI system approval reviews
- EdTech AI assistant assessments
- vendor due diligence
- policy and evidence design
- control mapping work
- research companion material
- public speaking or training demonstrations
- Controls must have owners.
- AI tools must have bounded authority.
- Data classification must happen before model selection.
- Human approval must be explicit for high-impact actions.
- Evidence must be created during operations, not reconstructed after incidents.
- Continuity planning must include model, provider, integration, and data dependencies.
- Security reviews must cover prompts, context, tools, plugins, APIs, vendors, logs, and outputs.
This is an initial public toolkit. It is intended to grow through practical examples, mappings, and implementation notes.
This repository provides practical security governance material. It is not legal advice, regulatory advice, or a substitute for formal risk assessment, audit, or compliance review.
This repository is part of the professional portfolio of Musaab Hasan, focused on cybersecurity, digital forensics, AI governance, EdTech, secure platforms, and research-driven digital transformation.
- Android Digital Forensics Lab - Advanced Android forensics workbench for acquisition planning, anti-forensics evaluation, memory triage, evidence integrity, and case reconstruction.
- Humanoid Robot Forensics Lab - PHP/MySQL forensic casework platform for humanoid robot, companion app, and IoT evidence triage.
- Smart Metering Security Lab - Research portal based on smart metering security analysis for cyber-physical and smart-grid environments.
- Drive-by Download ML Lab - Machine learning research portal for detecting drive-by download attacks and web-based malware delivery.
- SQL Injection ML Detection Lab - Research portal for SQL injection detection using machine learning and security telemetry.
- IoT Board SSH Hardening Lab - SSH exposure assessment and hardening portal for IoT development boards and embedded Linux systems.
- ZigBee WHAS Design Lab - Research portal for designing and evaluating ZigBee wireless home automation systems.
- Mammogram Fourier Analysis Lab - Medical image-processing research portal based on Fourier transform analysis for mammography.
- Human Factors Risk Profiler - Human-centered security risk profiling portal for targeted interventions and behavior-aware controls.
- Security Champion Network Portal - Platform for managing security champion networks, missions, recognition, and measurable impact.
- Crisis Simulation Command Portal - Cyber crisis simulation planning, scoring, and improvement platform for resilience exercises.
- Behavioral Security Metrics Portal - Evidence-based security awareness metrics portal focused on behavior, culture, and intervention outcomes.
- Security Culture Heatmap Portal - Security culture maturity heatmap for norms, leadership signals, and organizational readiness.
- Emerging Technology Security Culture Portal - Adoption-readiness portal for emerging technology, governance, and security culture alignment.
- AI Use Case Evaluation Portal - Evaluation platform for AI use cases across value, feasibility, data readiness, privacy, ethics, and governance.
- Transformation Roadmap Portal - Roadmap platform for moving security culture programs from compliance orientation to resilience and measurable change.
- Professional Development Registration System Framework - Secure registration and Moodle enrollment automation framework for professional development programs.
- Multilingual Certificate Issuer - Arabic/English certificate design, PDF generation, and throttled SMTP distribution platform.
- AI Security Governance Toolkit - Practical AI security governance controls, templates, evidence registers, playbooks, and policy-as-code examples.
Professional profile and research portfolio: https://musaab.info