OWASP TaSM Workshop Shows How to Map Threats to Security Safeguards

· Original article ↗

Summary

A workshop demonstrated how OWASP’s Threat and Safeguard Matrix maps risks such as phishing and ransomware to safeguards across the NIST Cybersecurity Framework, including controls for preventing sensitive data leaks into AI tools.

Key points

  • TaSM organizes safeguards around material threats and aligns them with the NIST functions: Identify, Protect, Detect, Respond, and Recover.
  • Workshop examples covered phishing, ransomware, web application attacks, and third-party data loss to identify control gaps and prioritize investment.
  • For AI data-leak risks, participants proposed DLP, cloud access security brokers, SASE VPNs, LLM proxies, and user training; the presenter stressed technical enforcement and monitoring alongside policy.
  • The presenter recommended focusing on roughly ten meaningful security metrics, each with a current status, trend, and goal.
  • The workshop emphasized defense-in-depth and measuring security outcomes rather than relying on compliance checklists.

Article Details

Topic
Threat-driven defense planning with the OWASP Threat and Safeguard Matrix, including safeguard coverage, AI data-loss prevention, and security metrics.

People

Products

Tools

Related Articles