Appendices

Regulatory Alignment

Continuum/AI controls map to requirements in established regulatory frameworks. Organizations can leverage certification to demonstrate compliance with multiple regulatory obligations.

Framework mapping

FrameworkMinimum ProfileCoverage
SOC 2 Type IIElevatedCC6, CC7, CC8 criteria
ISO 27001:2022ElevatedAnnex A controls
ISO 42001:2023ElevatedAI-specific requirements
NIST CSF 2.0StandardAll functions
EU AI ActElevatedHigh-risk system requirements
LGPD (Brazil)ElevatedData protection requirements
HIPAACriticalTechnical safeguards
PCI DSS 4.0CriticalRequirement categories

OWASP Agentic Top 10 mapping

OWASP RiskPrimary Controls
Unauthorized ActionsAZN-01, AZN-04, INT-02
Trust Boundary ViolationsVAL-03, VAL-04, EXE-03
Data ExfiltrationDAT-05, OBS-05, INT-02
Prompt InjectionVAL-01, VAL-02, VAL-04
Privilege EscalationAZN-05, IDN-01, GOV-04
Insufficient LoggingOBS-01, OBS-02, OBS-03
Supply Chain VulnerabilitiesSUP-01, SUP-02, SUP-03
Memory PoisoningVAL-01, EXE-01, DAT-06
Cascading FailuresINT-03, RES-02, RES-04
Resource ExhaustionEXE-02, OBS-04, INT-01

SOC 2 alignment

Continuum/AI Elevated profile provides evidence supporting SOC 2 Common Criteria 6, 7, and 8. CC6 addresses access control through IDN and AZN domain controls. CC7 addresses system operations through OBS, INT, and RES domain controls. CC8 addresses change management through GOV and SUP domain controls.

ISO alignment

Continuum/AI maps to ISO 27001:2022 Annex A controls for information security and ISO 42001:2023 requirements for AI management systems. Organizations with existing ISO certifications can inherit applicable controls when evidence demonstrates equivalence.

Previous
Control quick reference