{ "data_hash": "bd3c80f1438a12d3ec063d604e1e851865c53912d1d4ee0d30fb60a502542264", "descriptions": { "002-630": { "description": "This hub covers the requirement to generate fresh session tokens immediately upon successful user authentication, replacing any pre-authentication session identifiers to prevent session fixation attacks. It specifically addresses the timing and triggering of token generation during the authentication flow, ensuring that authenticated sessions cannot inherit or reuse tokens from unauthenticated states. This hub does not cover the cryptographic strength of tokens (covered by entropy and algorithm requirements), the secure storage methods for tokens in browsers, or session token generation for other lifecycle events like privilege escalation or timeout renewal.", "generated_at": "2026-04-28T23:19:03.499015+00:00", "hierarchy_path": "Technical application security controls > Session management > Session token generation > Generate a new session token after authentication", "hub_id": "002-630", "hub_name": "Generate a new session token after authentication", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "002-801": { "description": "This hub covers requirements for using cryptographically secure algorithms specifically for challenge nonce operations, including proper random number generation, entropy seeding from approved sources, and verification using standardized cryptographic primitives like SHA-256+ or AES-based constructions. It focuses on algorithm selection and implementation standards for nonce-based authentication challenges, distinguishing itself from its sibling hub which addresses nonce size and uniqueness properties rather than cryptographic algorithm choices. This hub does not cover general cryptographic storage, key management lifecycle, or non-nonce authentication mechanisms like passwords or biometrics.", "generated_at": "2026-04-28T23:19:03.989326+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Challenge nonce cryptography > Use approved cryptographic algorithms for generation, seeding and verification", "hub_id": "002-801", "hub_name": "Use approved cryptographic algorithms for generation, seeding and verification", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "007-274": { "description": "This hub covers the processes and controls for identifying, testing, deploying, and verifying security patches and updates across all system components including operating systems, firmware, applications, and libraries. It encompasses patch management workflows, update scheduling, rollback procedures, and patch compliance monitoring, but excludes the actual security configurations of operating systems (covered under OS security) and malware signature updates (covered under Virus/malware protection). The scope is limited to the patching lifecycle and does not include vulnerability scanning or the initial hardening of systems.", "generated_at": "2026-04-28T23:19:02.923623+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Endpoint management > Patching and updating system components", "hub_id": "007-274", "hub_name": "Patching and updating system components", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "010-108": { "description": "This hub covers techniques for hiding or distorting the confidence scores, probability distributions, and certainty indicators that AI models produce alongside their primary outputs, preventing attackers from exploiting this metadata to reverse-engineer model behavior or craft targeted attacks. It encompasses methods like adding noise to confidence values, quantizing probability outputs, and removing intermediate activation information from API responses. Unlike its siblings that focus on protecting inputs (Prompt input segregation, AI Input distortion) or model architecture (Ensemble AI models), this hub specifically addresses output-side information leakage, and does not cover input validation, resource constraints, or the primary prediction outputs themselves.", "generated_at": "2026-04-28T23:19:04.597836+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Obscuring confidence in AI output", "hub_id": "010-108", "hub_name": "Obscuring confidence in AI output", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "011-087": { "description": "Testing against membership inference covers verification methods to determine whether an AI model reveals if specific data points were present in its training dataset, including statistical attacks that exploit model confidence scores, prediction patterns, and output distributions. This hub focuses on detecting privacy leakage through membership determination attacks, distinguishing it from model inversion (reconstructing training data), sensitive data extraction (inferring attributes not explicitly in training data), and model theft (replicating model functionality). The scope excludes general privacy-preserving training techniques, differential privacy implementation details, and attacks that aim to manipulate model behavior rather than extract training set membership information.", "generated_at": "2026-04-28T23:19:04.328488+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > Testing against membership inference", "hub_id": "011-087", "hub_name": "Testing against membership inference", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "011-322": { "description": "Testing against evasion covers verification methods to detect and prevent adversarial inputs that cause AI models to produce incorrect outputs while appearing legitimate to human observers, including techniques like gradient-based perturbations, patch attacks, and semantic manipulations. This hub focuses specifically on attacks that alter model predictions through crafted inputs during inference time, distinguishing it from training-time attacks (backdoor poisoning), privacy attacks (membership inference, model inversion), prompt manipulation attacks (direct/indirect injection), or intellectual property theft (model theft by inference). The scope excludes general robustness testing, benign distribution shifts, and attacks that aim to extract information rather than cause misclassification.", "generated_at": "2026-04-29T15:53:50.179231+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > Testing against evasion", "hub_id": "011-322", "hub_name": "Testing against evasion", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "012-625": { "description": "Indirect prompt injection covers attacks where malicious instructions are embedded in external data sources (documents, websites, emails) that an AI system processes on behalf of a user, causing the model to execute unintended actions without the user's direct input. This hub addresses threats from untrusted third-party content that gets incorporated into the model's context during inference, distinguishing it from direct prompt injection where users themselves provide malicious prompts, and from evasion attacks that manipulate model inputs to cause misclassification rather than instruction hijacking. The scope excludes attacks on model training data, direct user-initiated prompt manipulation, and adversarial perturbations aimed at degrading model accuracy rather than controlling behavior.", "generated_at": "2026-04-28T23:19:10.226841+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > AI model behaviour integrity threats > AI model behaviour integrity threats through inference > Indirect prompt injection", "hub_id": "012-625", "hub_name": "Indirect prompt injection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "013-021": { "description": "This hub covers the definition, assignment, and maintenance of security-specific roles and responsibilities within an organization, including role creation, modification, periodic review processes, and alignment with SDLC phases. It focuses on the structural aspects of security accountability and authority distribution, distinguishing it from Personnel security (which addresses vetting and trustworthiness of individuals) and Security awareness training (which addresses capability development of personnel). This hub does not cover the operational execution of assigned responsibilities, personnel qualification requirements, or the training needed to fulfill roles - it strictly addresses the organizational framework for defining who is accountable for what security functions.", "generated_at": "2026-04-28T23:19:10.637299+00:00", "hierarchy_path": "Governance processes for security > Security governance regarding people > Roles and responsibilities", "hub_id": "013-021", "hub_name": "Roles and responsibilities", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "015-063": { "description": "This hub covers requirements for logging access attempts and operations on sensitive data assets, including who accessed what data, when, and through which system functions, while ensuring the sensitive data values themselves are not recorded in logs. It focuses specifically on audit trails for data access patterns and usage, distinct from general security event logging, authentication/authorization decision logging, or event sequencing requirements covered by sibling hubs. The scope excludes the actual implementation of log storage, retention policies, log analysis mechanisms, and the definition of what constitutes sensitive data, which are addressed elsewhere in the taxonomy.", "generated_at": "2026-04-28T23:19:10.297888+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log relevant > Log access to sensitive data", "hub_id": "015-063", "hub_name": "Log access to sensitive data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "020-540": { "description": "Direct runtime model poisoning encompasses attacks that modify AI model parameters, weights, or behavior during active deployment through direct manipulation of the model's runtime environment, memory, or inference pipeline. This hub covers threats where attackers exploit runtime access vectors such as API vulnerabilities, memory corruption, or privileged system access to alter model behavior without retraining or modifying training data. Unlike data poisoning (which corrupts training inputs), supply-chain poisoning (which compromises pre-deployment artifacts), or development-time poisoning (which targets the model during creation), this hub specifically addresses post-deployment model corruption and excludes attacks on training infrastructure or data pipelines.", "generated_at": "2026-04-29T15:53:50.238710+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > AI model behaviour integrity threats > AI model poisoning > Direct runtime model poisoning", "hub_id": "020-540", "hub_name": "Direct runtime model poisoning", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "026-280": { "description": "This hub covers cryptographic protection and integrity verification of log data during transmission from source systems to remote collection points, including use of TLS/mTLS for transport encryption, message authentication codes or digital signatures for tamper detection, and reliable delivery mechanisms to prevent log loss. It addresses the secure transport layer specifically, not the format of log entries (covered by \"Log in consistent format\"), access controls at endpoints (covered by \"Log access protection\"), timestamp accuracy (covered by \"Log time synchronization\"), or content validation against malicious payloads (covered by \"Log injection protection\"). The scope ends once logs are successfully received at the destination system - it does not cover storage, analysis, or retention of logs after transmission.", "generated_at": "2026-04-28T23:19:17.464562+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log integrity > Securely transfer logs (remotely)", "hub_id": "026-280", "hub_name": "Securely transfer logs (remotely)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "027-210": { "description": "This hub covers the specific requirement to generate GUIDs (Globally Unique Identifiers) using the GUID v4 algorithm with a cryptographically secure pseudo-random number generator (CSPRNG), ensuring unpredictability and resistance to prediction attacks. It focuses exclusively on GUID generation security, distinguishing it from general CSPRNG usage requirements or broader secure random value generation practices covered by sibling hubs. The scope is limited to GUID creation and does not cover other identifier formats, session tokens, or cryptographic keys, even when those require secure randomness.", "generated_at": "2026-04-28T23:19:16.152664+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secure random values > Create random GUIDs with cryptographically secure random number generators", "hub_id": "027-210", "hub_name": "Create random GUIDs with cryptographically secure random number generators", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "027-555": { "description": "This hub covers requirements for enforcing a minimum character length for user-created passwords, specifically addressing the implementation of password length validation rules that reject passwords below a defined threshold (typically 12+ characters). It focuses exclusively on the length dimension of password policy enforcement, including the technical controls needed to validate, reject, and communicate minimum length requirements during password creation or change operations. This hub does not cover other password composition rules such as character type requirements, Unicode support, password history, rotation policies, or strength assessment beyond length—these aspects are addressed by its sibling hubs under the same parent.", "generated_at": "2026-04-28T23:19:17.118280+00:00", "hierarchy_path": "Technical application security controls > Authentication > Credentials directives > Enforce user passwords are of sufficient minimum length", "hub_id": "027-555", "hub_name": "Enforce user passwords are of sufficient minimum length", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "028-254": { "description": "This hub covers implementing cryptographically secure automatic update mechanisms across all layers of the technology stack, including client applications, server components, containers, and infrastructure services. It encompasses secure channel establishment (TLS/mTLS), digital signature verification of update packages, rollback capabilities, and update integrity validation before deployment. Unlike sibling hubs that focus on build-time integrity checks or deployment pipeline security, this hub specifically addresses runtime update delivery and installation security. It does not cover manual update processes, initial deployment security, or the build/compilation phase—only the automated distribution and application of updates to already-deployed systems.", "generated_at": "2026-04-28T23:19:17.242268+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Secure auto-updates over full stack", "hub_id": "028-254", "hub_name": "Secure auto-updates over full stack", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "028-727": { "description": "CSRF protection encompasses requirements for preventing Cross-Site Request Forgery attacks through implementation of anti-CSRF tokens, same-site cookie attributes, origin/referer header validation, and state-changing operation protections. This hub specifically addresses defenses against unauthorized commands transmitted from a user that the web application trusts, distinguishing it from injection-based attacks (covered under Injection protection) and client-side script execution (covered under XSS protection). The scope excludes server-side request forgeries (covered under SSRF protection) and general session management concerns unless directly related to CSRF token implementation.", "generated_at": "2026-04-28T23:19:15.917628+00:00", "hierarchy_path": "Cross-cutting concerns > CSRF protection", "hub_id": "028-727", "hub_name": "CSRF protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "028-728": { "description": "SSRF protection encompasses controls that prevent applications from making unauthorized requests to internal resources, external systems, or cloud metadata services through user-controlled input in URL parameters, file imports, or API integrations. This hub covers request validation, URL allowlisting, network segmentation enforcement, and metadata service protections, distinguishing it from Injection protection which focuses on command/code execution and from CSRF protection which prevents forged requests from external sources to the application. The scope excludes general network security controls, DNS security (covered under Secure name/address resolution service), and authentication/authorization mechanisms unless specifically related to validating outbound request destinations.", "generated_at": "2026-04-28T23:19:22.645655+00:00", "hierarchy_path": "Cross-cutting concerns > SSRF protection", "hub_id": "028-728", "hub_name": "SSRF protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "031-447": { "description": "This hub covers implementing strict allowlist validation for all external HTTP input data, including headers, parameters, cookies, and request bodies, by defining and enforcing explicit rules for acceptable characters, formats, lengths, and patterns. It focuses specifically on HTTP-layer input validation through positive security models (accepting only known-good patterns) rather than blocklist approaches, distinguishing it from siblings that address specific attack vectors (mass assignment, JSON schema) or operate at different layers (trusted service layer validation). This hub does not cover internal application data flows, non-HTTP protocols, output encoding, or the specific business logic validation that occurs after input sanitization.", "generated_at": "2026-04-28T23:19:22.650265+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Input validation > Whitelist all external (HTTP) input", "hub_id": "031-447", "hub_name": "Whitelist all external (HTTP) input", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "032-213": { "description": "This hub covers requirements for performing cryptographic operations within hardware security modules (HSMs), trusted platform modules (TPMs), or isolated software-based security enclaves that prevent direct application access to key material. It encompasses the use of dedicated cryptographic processors, secure elements, and vault services that execute cryptographic functions without exposing keys to application memory or logs. This hub specifically addresses the isolation of cryptographic operations from application logic, distinguishing it from sibling hubs that focus on storage formats (salted/hashed), key management infrastructure (key vaults), or general secrets handling (secrets management solutions). It does not cover the storage mechanisms themselves, key rotation policies, or the specific cryptographic algorithms used within the isolated module.", "generated_at": "2026-04-28T23:19:23.773831+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Use an isolated security module for cryptographic operations", "hub_id": "032-213", "hub_name": "Use an isolated security module for cryptographic operations", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "034-540": { "description": "This hub covers attacks that exploit trained AI models to extract information about their training data, including model inversion attacks that reconstruct training samples from model parameters or outputs, and membership inference attacks that determine whether specific data points were part of the training set. It encompasses techniques that leverage model APIs, gradients, confidence scores, or other model behaviors to compromise the confidentiality of training data through statistical or optimization-based inference methods. This hub excludes direct data leakage through model outputs during normal operation (covered by \"Data disclosure in model output\") and focuses specifically on adversarial techniques that reverse-engineer or probe models to reveal training data characteristics.", "generated_at": "2026-04-29T15:54:29.953197+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Training data confidentiality threats > Training data confidentiality threats through inference > Model inversion / Membership inference", "hub_id": "034-540", "hub_name": "Model inversion / Membership inference", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "036-147": { "description": "This hub covers the proper implementation of HTTP Strict Transport Security (HSTS) headers, including setting appropriate max-age directives, includeSubDomains flags, and preload list submission to enforce HTTPS-only communication and prevent protocol downgrade attacks. Unlike its sibling hubs that focus on content-type validation, framing policies, or content security restrictions, this hub specifically addresses transport layer security enforcement through HSTS response headers. The scope excludes other TLS/SSL configurations, certificate management, or non-HSTS methods of enforcing HTTPS such as redirect rules or mixed content policies.", "generated_at": "2026-04-28T23:19:59.123943+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > HTTP security headers > Configure HSTS configuration properly", "hub_id": "036-147", "hub_name": "Configure HSTS configuration properly", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "036-275": { "description": "This hub covers the establishment and maintenance of centralized repositories containing secure coding standards, guidelines, cheat sheets, and reference materials that developers can access during software development. It encompasses the creation, curation, and distribution mechanisms for security-focused technical resources including threat modeling guides, attack surface analysis tools, and language-specific secure coding practices. The scope excludes the actual implementation of secure coding practices, security testing procedures, and enforcement mechanisms - it focuses solely on making the instructional resources available rather than their application or compliance monitoring.", "generated_at": "2026-04-28T23:19:28.017797+00:00", "hierarchy_path": "Development processes for security > Technical instructions > Make (centrally) available secure coding resources for programmers", "hub_id": "036-275", "hub_name": "Make (centrally) available secure coding resources for programmers", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "036-725": { "description": "This hub covers the requirement to set appropriate Content-Type headers in HTTP responses, including specifying the MIME type and character encoding (e.g., text/html; charset=UTF-8) to prevent content-type confusion attacks and encoding-based bypasses. It focuses on ensuring the declared content type matches the actual response content and includes safe character set declarations for text-based MIME types to mitigate encoding manipulation vulnerabilities. Unlike sibling hubs that address specific security headers (HSTS for transport security, CSP for content restrictions, X-Frame-Options for clickjacking), this hub specifically addresses content type declaration and encoding specification. It does not cover the configuration of other security headers, response body content validation, or input encoding handling—only the proper declaration of what type of content is being served and its character encoding.", "generated_at": "2026-04-28T23:19:30.406236+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > HTTP security headers > Set content HTTP response type", "hub_id": "036-725", "hub_name": "Set content HTTP response type", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "036-810": { "description": "This hub covers requirements for cryptographic modules to handle failures and errors in ways that prevent information leakage, particularly ensuring error messages and timing behaviors do not reveal details about cryptographic operations or enable attacks like Padding Oracle. It encompasses secure error handling for encryption, decryption, signature verification, and key operations, requiring modules to return generic error codes and maintain constant-time behavior during failure conditions. Unlike sibling hubs that focus on algorithm selection, configuration standards, or operational practices like nonce management, this hub specifically addresses the security of failure modes and error handling within cryptographic implementations. It does not cover the selection of cryptographic algorithms themselves, key management practices, or performance optimization of cryptographic operations under normal conditions.", "generated_at": "2026-04-28T23:19:30.987379+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encryption algorithms > Let cryptographic modules fail securely", "hub_id": "036-810", "hub_name": "Let cryptographic modules fail securely", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "041-188": { "description": "Data quality control encompasses technical measures to validate, clean, and sanitize training datasets for AI/ML models, including detection and removal of poisoned samples, outliers, and corrupted data points through statistical analysis and anomaly detection methods. This hub focuses specifically on pre-training data integrity verification and cleansing processes, distinct from runtime evasion defenses (covered in Evasion-preventing training) and intentional backdoor mitigation (covered in Weakening training set backdoors). The scope excludes data privacy controls, access management, and post-deployment data drift monitoring, covering only the technical validation and sanitization of training data inputs.", "generated_at": "2026-04-28T23:19:30.513549+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > Data quality control", "hub_id": "041-188", "hub_name": "Data quality control", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "042-550": { "description": "This hub covers controls to prevent attackers from modifying object properties by injecting unexpected parameters through HTTP requests, APIs, or form submissions that get automatically bound to internal data models. It encompasses techniques like explicit property whitelisting, using data transfer objects (DTOs), marking sensitive fields as non-bindable, and implementing framework-specific protections against automatic parameter binding vulnerabilities. Unlike its sibling hubs that focus on general input validation (whitelisting, schema enforcement) or specific attack vectors (HTTP parameter pollution, redirect validation), this hub specifically addresses the architectural vulnerability where frameworks automatically map external inputs to object properties without proper filtering. It does not cover general input sanitization, authentication/authorization controls, or protection against other injection attacks like SQL injection or XSS.", "generated_at": "2026-04-28T23:19:34.568192+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Input validation > Protect against mass parameter assignment attack", "hub_id": "042-550", "hub_name": "Protect against mass parameter assignment attack", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "043-703": { "description": "This hub covers testing methodologies to verify that AI models cannot reveal sensitive training data through statistical analysis of model outputs, confidence scores, or prediction patterns across multiple queries. It focuses on inference attacks where adversaries extract private information about individuals or datasets by analyzing model behavior, distinct from membership inference (determining if specific data was in training), model inversion (reconstructing training inputs), or direct data extraction through prompts. The scope excludes testing for model architecture theft, adversarial input manipulation, or privacy violations through explicit memorization rather than statistical inference.", "generated_at": "2026-04-29T15:54:31.571889+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > Testing against sensitive data extraction by inference", "hub_id": "043-703", "hub_name": "Testing against sensitive data extraction by inference", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "044-202": { "description": "This hub covers threats where AI models directly expose sensitive training data through their outputs, including cases where models memorize and reproduce verbatim training examples, leak personally identifiable information in generated text, or reveal confidential data patterns through structured predictions. It addresses scenarios where the disclosure is explicit in the model's response rather than requiring statistical analysis or reconstruction techniques. This hub excludes membership inference attacks (determining if specific data was in the training set) and model inversion attacks (reconstructing training data through optimization), focusing only on direct data leakage through normal model operation.", "generated_at": "2026-04-28T23:19:37.034792+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Training data confidentiality threats > Training data confidentiality threats through inference > Data disclosure in model output", "hub_id": "044-202", "hub_name": "Data disclosure in model output", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "046-257": { "description": "This hub covers requirements for removing authentication credentials, tokens, and session data from client-side storage mechanisms (localStorage, sessionStorage, cookies, IndexedDB) when a user logs out or their session expires. It focuses specifically on authentication data cleanup procedures, including proper deletion methods and verification that data cannot be recovered, distinguishing it from siblings that address general sensitive data caching, server-side storage, or memory management. This hub does not cover prevention of initial storage, protection of data while stored, or clearing of non-authentication sensitive data such as personal information or business data.", "generated_at": "2026-04-28T23:19:37.119668+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Manage temporary storage > Clear authentication data from client storage", "hub_id": "046-257", "hub_name": "Clear authentication data from client storage", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "048-612": { "description": "This hub covers the requirement to apply proper encoding or escaping to all user-controlled data before writing it to log files, preventing attackers from injecting malicious content that could corrupt log integrity, execute commands, or forge log entries. It specifically addresses encoding techniques such as escaping newlines, control characters, and log format delimiters to ensure user input cannot break log parsing or create false log entries. This requirement does not cover log access controls, log retention policies, or the selection of what data to log - it solely focuses on the safe transformation of user input before inclusion in log records.", "generated_at": "2026-04-28T23:19:40.541820+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log integrity > Log injection protection > Encode user input before logging", "hub_id": "048-612", "hub_name": "Encode user input before logging", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "052-821": { "description": "This hub covers requirements for Credential Service Providers (CSPs) to communicate authentication event timestamps to Relying Parties (RPs) in federated authentication scenarios, enabling RPs to make informed re-authentication decisions based on session age. Unlike its siblings which focus on user-initiated token revocation and CSP-enforced timeouts, this hub specifically addresses the information flow of authentication metadata between parties in the federation chain. The scope is limited to timestamp relay mechanisms and does not cover the actual re-authentication logic, timeout enforcement policies, or other authentication event attributes beyond timing information.", "generated_at": "2026-04-28T23:19:42.633491+00:00", "hierarchy_path": "Technical application security controls > Session management > Re-authentication from federation or assertion > When using an authentication third party (CSP), relay last authentication event to other parties in the chain", "hub_id": "052-821", "hub_name": "When using an authentication third party (CSP), relay last authentication event to other parties in the chain", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "053-751": { "description": "This hub covers implementing automated checks within CI/CD build pipelines that detect outdated versions and known vulnerabilities in third-party dependencies, failing builds or generating warnings when components fall below security thresholds. It encompasses configuration of dependency scanning tools, vulnerability databases integration, and policy enforcement mechanisms that prevent deployment of applications containing insecure components. Unlike its siblings which focus on the actual update process and inventory tracking, this hub specifically addresses the automated detection and enforcement layer, excluding the remediation workflows and component cataloging activities.", "generated_at": "2026-04-28T23:19:42.600619+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency management > Force build pipeline to check outdated/insecure components", "hub_id": "053-751", "hub_name": "Force build pipeline to check outdated/insecure components", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "058-083": { "description": "Monitoring encompasses the continuous observation and analysis of system activities, security events, and performance metrics through automated tools and manual review to identify anomalies, policy violations, and potential security incidents in real-time or near real-time. This hub covers the collection, aggregation, and analysis of logs, alerts, and system telemetry, including the configuration of monitoring infrastructure, threshold setting, and dashboard creation, but excludes the actual response actions taken after detection. Unlike Incident Response which focuses on containment, eradication, and recovery activities after an incident is confirmed, Monitoring strictly addresses the detection capabilities and ongoing surveillance activities that feed into the incident response process.", "generated_at": "2026-04-28T23:19:43.719155+00:00", "hierarchy_path": "Operating processes for security > Detect and respond > Monitoring", "hub_id": "058-083", "hub_name": "Monitoring", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "058-443": { "description": "Data minimization for AI systems encompasses techniques and controls that reduce the volume, granularity, and sensitivity of data collected and processed during model training and inference, including implementing differential privacy mechanisms, aggregating data points, and removing unnecessary features or attributes. Unlike training data obfuscation which transforms existing data, federated learning which distributes computation, or retention management which controls data lifecycle, this hub specifically addresses reducing data collection and processing scope at the source. This hub excludes post-collection data handling practices, distributed learning architectures, and temporal data management policies, focusing solely on minimizing the initial data footprint and granularity requirements for AI systems.", "generated_at": "2026-04-29T15:53:50.338637+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI impact reduction controls > AI data reduction > Data minimization", "hub_id": "058-443", "hub_name": "Data minimization", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "058-527": { "description": "This hub covers requirements for securing DNS and other name/address resolution services, including DNSSEC implementation, cache poisoning prevention, and protection of both authoritative name servers and recursive resolvers. It addresses the integrity and availability of name resolution infrastructure, distinguishing it from injection protection (which covers query manipulation) and DoS protection (which covers volumetric attacks). The scope is limited to name/address resolution protocols and services, excluding general network routing security, certificate validation mechanisms, and application-layer hostname verification.", "generated_at": "2026-04-28T23:19:48.087152+00:00", "hierarchy_path": "Cross-cutting concerns > Secure name/address resolution service", "hub_id": "058-527", "hub_name": "Secure name/address resolution service", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "060-472": { "description": "This hub covers implementing CSRF (Cross-Site Request Forgery) tokens or equivalent mechanisms to protect state-changing operations for authenticated users, and deploying rate limiting, CAPTCHA, or similar anti-automation controls for publicly accessible functionality. It specifically addresses preventing unauthorized actions through forged requests in authenticated contexts and preventing automated abuse (bots, scrapers, brute force) in unauthenticated contexts. Unlike sibling hubs that focus on authentication strength (multifactor), authorization models (RBAC/ABAC), or access control enforcement points (URI/resource level), this hub specifically targets request authenticity verification and automation prevention. This hub does not cover general access control policies, authentication mechanisms, or protection against other injection attacks like XSS or SQL injection.", "generated_at": "2026-04-28T23:20:37.355720+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Use CSRF protection against authenticated functionality, add anti-automation controls for unauthenticated functionality", "hub_id": "060-472", "hub_name": "Use CSRF protection against authenticated functionality, add anti-automation controls for unauthenticated functionality", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "061-186": { "description": "This hub covers requirements for implementing consistent encoding and parsing mechanisms across all application components to prevent injection attacks and parsing discrepancies that enable SSRF, RFI, and header manipulation vulnerabilities. It encompasses standardization of character encoding schemes, URL/URI parsers, file format parsers, and HTTP header processors throughout the system architecture, ensuring uniform interpretation of data regardless of the processing component. Unlike its sibling hubs that focus on specific protocol implementations (RESTful, SOAP) or access controls (HTTP method limiting, GraphQL authorization), this hub addresses the fundamental data interpretation layer that underlies all API communications. It does not cover authentication mechanisms, rate limiting, or protocol-specific security features, but rather ensures that data transformation and interpretation remain consistent to prevent parser differential attacks.", "generated_at": "2026-04-28T23:19:51.261940+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > Force uniform encoders and parsers throughout system", "hub_id": "061-186", "hub_name": "Force uniform encoders and parsers throughout system", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "064-808": { "description": "This hub covers the requirement to apply output encoding that matches the specific context where data will be interpreted, such as HTML encoding for HTML contexts, JavaScript encoding for JavaScript contexts, or URL encoding for URL contexts. It focuses on selecting and applying the correct encoding function based on the destination interpreter's syntax rules, ensuring that user-supplied data cannot break out of its intended data context to become executable code. This hub differs from sibling hubs by addressing the general principle of context-aware encoding rather than specific injection types (like XML/XPath, LDAP, or OS command injection), and unlike \"Force output encoding for specific interpreter's context,\" it emphasizes the selection process for choosing appropriate encoding based on output destination. The scope excludes input validation, parameterized queries, and specific injection attack patterns, focusing solely on the correct application of encoding functions at the point where data transitions from the application to various output contexts.", "generated_at": "2026-04-28T23:19:56.345946+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Encode output context-specifically", "hub_id": "064-808", "hub_name": "Encode output context-specifically", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "065-183": { "description": "This hub covers requirements for preventing the use of manufacturer-supplied, well-known, or predictable default credentials (such as admin/admin, root/root, or service-specific defaults) in all system components, service accounts, and administrative interfaces. It encompasses both the technical controls to detect and block default credentials during authentication attempts and the administrative processes to ensure all default credentials are changed before system deployment. This hub specifically addresses default credential prevention, not general password policies, credential rotation schedules, or user notification mechanisms which are covered by its sibling hubs.", "generated_at": "2026-04-28T23:19:53.734804+00:00", "hierarchy_path": "Technical application security controls > Secure user management > Disallow default credentials", "hub_id": "065-183", "hub_name": "Disallow default credentials", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "065-388": { "description": "This hub covers the proper configuration of the X-Content-Type-Options HTTP response header, specifically setting it to \"nosniff\" to prevent browsers from MIME-sniffing responses away from the declared Content-Type, which mitigates attacks where malicious content is interpreted as executable code despite being served with a safe MIME type. Unlike sibling headers that control framing (X-Frame-Options), script execution policies (CSP), or referrer information leakage (Referrer-Policy), this header exclusively prevents MIME type confusion attacks by enforcing strict Content-Type adherence. This hub does not cover the actual setting of Content-Type headers themselves, content encoding, or other MIME-related configurations beyond the browser's interpretation behavior controlled by X-Content-Type-Options.", "generated_at": "2026-04-28T23:19:58.098684+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > HTTP security headers > Configure X-Content-Type-Options properly", "hub_id": "065-388", "hub_name": "Configure X-Content-Type-Options properly", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "065-782": { "description": "This hub covers implementing and configuring session timeout mechanisms that automatically terminate user sessions after defined periods of inactivity (soft timeout) or absolute time limits regardless of activity (hard timeout). It encompasses timeout duration configuration, timeout enforcement logic, session state cleanup, and user notification mechanisms for impending timeouts. Unlike its siblings which focus on explicit session termination triggers (password changes, logout actions, multi-session management), this hub specifically addresses time-based automatic session expiration. It does not cover manual session termination, session token rotation, or session persistence mechanisms.", "generated_at": "2026-04-28T23:19:59.354315+00:00", "hierarchy_path": "Technical application security controls > Session management > Minimize session life > Ensure session timeout (soft/hard)", "hub_id": "065-782", "hub_name": "Ensure session timeout (soft/hard)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "067-050": { "description": "This hub covers requirements for preventing the logging of authentication credentials (passwords, API keys, tokens) and payment information (credit card numbers, bank account details, CVV codes) in application logs, including ensuring that session tokens are only logged in irreversibly hashed form when necessary. It specifically addresses the exclusion of these high-risk data types from logging mechanisms, distinguishing it from its sibling hub which broadly covers logging practices for all other non-sensitive data types. The scope is limited to credentials and payment details only - it does not cover other sensitive data categories such as personally identifiable information (PII), health records, or proprietary business data, which would fall under separate privacy or data protection requirements.", "generated_at": "2026-04-28T23:20:03.124440+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log discretely > Do not log credentials or payment details", "hub_id": "067-050", "hub_name": "Do not log credentials or payment details", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "068-102": { "description": "This hub covers requirements for documenting system architecture at a high level and conducting threat modeling activities both on a regular schedule and whenever critical architectural changes occur. It encompasses the creation and maintenance of architectural documentation, identification of security boundaries and trust zones, and systematic analysis of potential threats using established threat modeling methodologies. Unlike its sibling hub \"Manage standard technologies and frameworks\" which focuses on technology selection and standardization policies, this hub specifically addresses the ongoing analysis and documentation of architectural security risks through threat modeling exercises. This hub does not cover detailed implementation-level documentation, specific security control selection, or the actual remediation of identified threats - it is limited to the architectural description and threat analysis processes themselves.", "generated_at": "2026-04-28T23:20:09.807458+00:00", "hierarchy_path": "Development processes for security > Architecture/design processes > Describe high-level system architecture and perform threat modeling on it every critical change and regularly", "hub_id": "068-102", "hub_name": "Describe high-level system architecture and perform threat modeling on it every critical change and regularly", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "072-713": { "description": "This hub covers the establishment and maintenance of approved technology stacks, frameworks, and libraries that development teams must use, including their security configurations, version requirements, and deprecation schedules. It encompasses the processes for evaluating, approving, and retiring technologies based on security assessments, as well as maintaining inventories of permitted components and their associated security baselines. This hub does not cover the actual system architecture design or threat modeling activities, nor does it address the implementation of security controls within individual applications using these technologies.", "generated_at": "2026-04-28T23:20:06.499584+00:00", "hierarchy_path": "Development processes for security > Architecture/design processes > Manage standard technologies and frameworks", "hub_id": "072-713", "hub_name": "Manage standard technologies and frameworks", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "076-470": { "description": "This hub covers requirements for implementing biometric authentication methods (fingerprint, facial recognition, iris scanning, voice recognition) exclusively as secondary authentication factors that must be combined with knowledge-based or possession-based primary factors. It ensures biometric authenticators cannot be used as standalone authentication methods and must always supplement another authentication factor to complete multi-factor authentication. This hub specifically addresses the restricted role of biometrics in MFA implementations, distinguishing it from sibling hubs that focus on OTP generation, transmission security, entropy requirements, or cryptographic standards. It does not cover biometric accuracy standards, anti-spoofing measures, biometric data storage requirements, or the technical implementation details of biometric sensors and matching algorithms.", "generated_at": "2026-04-28T23:20:06.161601+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Biometric authenticators only as secondary factors", "hub_id": "076-470", "hub_name": "Biometric authenticators only as secondary factors", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "077-235": { "description": "Model input leak covers threats where adversaries gain unauthorized access to data being fed into AI models during inference or training, including prompts, queries, uploaded files, or streaming inputs. Unlike augmentation data threats which target supplementary knowledge bases or retrieval systems, this hub specifically addresses the exposure of direct model inputs through channels like API logs, memory dumps, or network interception. This hub excludes output-based leaks, data manipulation attacks, and threats to stored training datasets or model parameters themselves.", "generated_at": "2026-04-29T15:53:55.886977+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Conventional threats to AI input, output and augmentation data > Model input leak", "hub_id": "077-235", "hub_name": "Model input leak", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "077-772": { "description": "This hub covers threats where training or test data is directly exposed through unauthorized access to storage systems, development environments, or model artifacts, resulting in immediate disclosure of the raw datasets without requiring inference or reconstruction techniques. It encompasses scenarios such as exposed data repositories, insecure model checkpoints containing embedded training data, leaked datasets during transfer or processing, and unauthorized access to development systems containing training corpora. This hub excludes indirect data exposure through model inference attacks (covered by its sibling hub), privacy attacks that reconstruct training data from model outputs, and general data breaches unrelated to AI training pipelines.", "generated_at": "2026-04-29T15:53:59.168104+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Training data confidentiality threats > Direct training or test data leak", "hub_id": "077-772", "hub_name": "Direct training or test data leak", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "077-781": { "description": "This hub covers the implementation of pepper (a secret salt value) that is stored separately from password hashes and added during the hashing process to provide an additional layer of defense against offline attacks. The pepper must be generated using approved random bit generators, stored in isolated locations such as hardware security modules or separate databases with restricted access, and applied consistently across all password hashing operations. Unlike sibling hubs that focus on public per-password salts, cryptographic hardware isolation, or general secrets management, this hub specifically addresses the architectural requirement of maintaining a system-wide secret value that augments standard salting mechanisms. This hub does not cover the selection of hashing algorithms, work factors, or iteration counts, nor does it address the storage of other types of secrets beyond the pepper value itself.", "generated_at": "2026-04-28T23:20:13.838675+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Use separately stored secret salt (pepper)", "hub_id": "077-781", "hub_name": "Use separately stored secret salt (pepper)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "078-427": { "description": "This hub covers requirements for configuring bcrypt's computational work factor parameter to the maximum value that maintains acceptable authentication performance, ensuring adequate resistance against brute-force attacks through increased computational cost. It specifically addresses the work factor configuration for bcrypt implementations, distinct from iteration count settings for PBKDF2 or configuration of other password hashing algorithms like Argon2 or scrypt. The scope is limited to bcrypt work factor tuning and does not cover salt generation, pepper usage, key derivation functions, or the selection of alternative hashing algorithms.", "generated_at": "2026-04-28T23:20:15.821821+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Set the highest feasible work factor for bcrypt", "hub_id": "078-427", "hub_name": "Set the highest feasible work factor for bcrypt", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "082-327": { "description": "This hub covers implementing transparent data collection notices and obtaining explicit opt-in consent mechanisms before processing personal data, including requirements for clear privacy policies, consent forms, and user interface elements that inform users about what data is collected, how it will be used, and who it will be shared with. It encompasses both the technical implementation of consent management systems and the business logic that enforces consent-based data processing workflows, ensuring that no personal data is collected or processed without prior user authorization. This hub does not cover data deletion or portability mechanisms (covered by the sibling hub), nor does it address the security controls for protecting data after collection, focusing solely on the pre-collection consent and transparency requirements.", "generated_at": "2026-04-28T23:20:22.248031+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Privacy-preserving personal data logic > Inform users clearly about the collection and use of personal data, and use it only after opt-in consent.", "hub_id": "082-327", "hub_name": "Inform users clearly about the collection and use of personal data, and use it only after opt-in consent.", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "082-530": { "description": "This hub covers requirements for generating and using cryptographically random salt values with at least 32 bits of entropy that are unique for each stored credential, ensuring protection against rainbow table attacks and hash collisions. It specifically addresses salt generation, uniqueness, and entropy requirements, distinguishing it from sibling hubs that cover the hashing algorithms themselves (bcrypt work factor, PBKDF2 iterations), additional security layers (pepper), or broader storage mechanisms (key vaults, secrets management). This hub does not cover the actual hashing process, work factor configuration, pepper implementation, or the secure storage infrastructure for the resulting hashed credentials - only the salt generation and uniqueness requirements.", "generated_at": "2026-04-28T23:20:21.257880+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Use unique random salt with sufficient entropy for each credential", "hub_id": "082-530", "hub_name": "Use unique random salt with sufficient entropy for each credential", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "088-316": { "description": "This hub covers controls that ensure the integrity and trustworthiness of data used to augment AI training datasets, including validation of synthetic data generation processes, detection and removal of poisoned or adversarial samples, and verification of data transformation pipelines. It focuses specifically on the preprocessing and quality assurance of augmentation data before model training, distinguishing it from runtime integrity controls that protect model inputs/outputs during inference and from confidentiality controls that protect augmentation data privacy. This hub excludes controls for the original training data collection process, model architecture integrity, and post-training model validation techniques.", "generated_at": "2026-04-28T23:20:20.106563+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Conventional AI security controls on AI assets > Augmentation data integrity controls", "hub_id": "088-316", "hub_name": "Augmentation data integrity controls", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers controls that preserve the integrity and trustworthiness of data used to augment AI systems, including synthetic data, transformed training examples, retrieval corpora, knowledge base entries, and other supplemental context sources. It includes validation of augmentation pipelines, provenance checks, anomaly detection, and removal of poisoned or manipulated augmentation records before they affect training or inference. It does not cover confidentiality of augmentation data, original training data collection controls, runtime model integrity, or post training model validation.", "reviewer_notes": "Original focused too narrowly on training dataset augmentation and did not cover retrieval or context augmentation sources.", "temperature": 0.0 }, "088-377": { "description": "Automated dynamic security testing encompasses tools and processes that programmatically execute security tests against running applications, including web application scanners, API security testing tools, and fuzzing frameworks that identify vulnerabilities through runtime analysis without human intervention. Unlike manual penetration testing which relies on human expertise and creative attack scenarios, this hub focuses on repeatable, tool-driven testing that can be integrated into CI/CD pipelines and executed at scale. This scope excludes static code analysis, manual security reviews, and human-driven penetration testing activities, covering only those testing approaches that can be fully automated and executed without real-time human decision-making.", "generated_at": "2026-04-28T23:20:21.481403+00:00", "hierarchy_path": "Development processes for security > Verification > Dynamic security testing > Automated dynamic security testing", "hub_id": "088-377", "hub_name": "Automated dynamic security testing", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "101-217": { "description": "This hub covers the requirement that pre-generated lookup secrets (backup codes, recovery codes, or scratch codes) used in multi-factor authentication must be invalidated after a single use, preventing replay attacks where an attacker could reuse a previously intercepted or stolen lookup secret. It specifically addresses the consumption and invalidation logic for static secrets that users receive in advance as fallback authentication methods when primary MFA devices are unavailable. Unlike sibling hubs that address time-based OTPs, out-of-band tokens, or biometric factors, this hub focuses exclusively on pre-shared static secrets that are typically provided as a list during MFA enrollment. This hub does not cover the generation, storage, or distribution of lookup secrets (addressed by other sibling hubs), nor does it address dynamic authentication codes or the broader MFA enrollment and device management processes.", "generated_at": "2026-04-28T23:20:29.194675+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Use lookup secrets only once", "hub_id": "101-217", "hub_name": "Use lookup secrets only once", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "102-811": { "description": "This hub covers requirements for transmitting multi-factor authentication challenges, codes, and tokens through communication channels that are separate from the primary authentication channel, ensuring these secondary channels use encryption and authentication to prevent interception or tampering. It specifically addresses the secure delivery mechanisms for OTP codes via SMS, email, push notifications, or dedicated authenticator apps, including requirements for channel independence, transport security, and protection against man-in-the-middle attacks. This hub does not cover the generation, storage, or validation of authentication codes themselves, nor does it address the selection of appropriate MFA methods or the cryptographic algorithms used in OTP generation - these aspects are covered by sibling hubs.", "generated_at": "2026-04-28T23:20:27.744064+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Communicate out of band multi factor authentication requests, codes or tokens independently and securely", "hub_id": "102-811", "hub_name": "Communicate out of band multi factor authentication requests, codes or tokens independently and securely", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "103-707": { "description": "This hub covers requirements for accepting Unicode characters (including non-ASCII characters, emojis, and language-specific symbols) in password fields during authentication, ensuring systems properly handle UTF-8/UTF-16 encoding, storage, and validation of international character sets. It specifically addresses the technical implementation of Unicode support in password processing, distinguishing it from sibling hubs that focus on password length, complexity rules, or breach detection rather than character set acceptance. This hub does not cover password display, input method handling, or normalization rules for Unicode equivalence; it strictly defines requirements for accepting and processing the full range of Unicode characters as valid password components.", "generated_at": "2026-04-28T23:20:28.300855+00:00", "hierarchy_path": "Technical application security controls > Authentication > Credentials directives > Allow unicode in passwords", "hub_id": "103-707", "hub_name": "Allow unicode in passwords", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "106-447": { "description": "Prompt input segregation encompasses techniques for separating and isolating different components of AI model inputs, including distinguishing system prompts from user inputs, implementing structured prompt templates, and enforcing boundaries between instruction and data segments to prevent prompt injection attacks. Unlike its siblings that focus on output manipulation (Obscuring confidence), model architecture (Ensemble AI models), or general input validation (Generic/Specific input attack controls), this hub specifically addresses the architectural separation and formatting of prompt components during inference. This hub excludes input sanitization techniques, rate limiting mechanisms, and model-level defenses, focusing solely on the structural segregation and formatting of prompts before they reach the AI model.", "generated_at": "2026-04-29T15:53:56.958313+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Prompt input segregation", "hub_id": "106-447", "hub_name": "Prompt input segregation", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "108-316": { "description": "This hub covers controls for detecting and mitigating inputs designed to exhaust computational resources during AI model inference, including adversarial inputs that trigger excessive processing loops, memory allocation, or GPU/CPU utilization through techniques like recursive prompt expansion or computationally expensive token sequences. It focuses specifically on resource-based denial of service attacks at the inference stage, distinct from evasion attacks that aim to manipulate model outputs or prompt injections that seek unauthorized functionality. The scope excludes training-time resource attacks, general system-level DoS protections, and output filtering mechanisms that prevent sensitive information disclosure.", "generated_at": "2026-04-29T15:54:02.546469+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Specific input attack controls at inference > AI resource exhaustion input handling", "hub_id": "108-316", "hub_name": "AI resource exhaustion input handling", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "112-273": { "description": "This hub covers requirements for scanning files from untrusted sources using antivirus/anti-malware engines to detect and prevent known malicious code (viruses, worms, trojans) before the files are stored or processed by the application. It encompasses real-time scanning during upload, quarantine mechanisms, signature updates, and integration with malware detection services, but excludes decompression bomb detection, file execution prevention, and size-based restrictions which are addressed by sibling hubs. The scope is limited to signature-based and heuristic detection of malicious code patterns, not broader file validation, sandboxing, or behavioral analysis of file contents.", "generated_at": "2026-04-28T23:20:35.353691+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File upload > Scan untrusted files for malware", "hub_id": "112-273", "hub_name": "Scan untrusted files for malware", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "112-648": { "description": "Change management encompasses the formal processes for planning, approving, implementing, and reviewing modifications to IT systems, applications, configurations, and security controls, including change advisory boards, impact assessments, rollback procedures, and post-implementation reviews. Unlike vulnerability management which focuses on identifying and remediating security weaknesses, change management ensures all system modifications follow controlled procedures to prevent unauthorized changes and maintain system integrity. This hub excludes incident response procedures, patch management workflows covered under vulnerability management, and strategic business transformation initiatives.", "generated_at": "2026-04-28T23:20:34.468675+00:00", "hierarchy_path": "Operating processes for security > Improvement management > Change management", "hub_id": "112-648", "hub_name": "Change management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "113-133": { "description": "This hub covers requirements for implementing a single, organization-wide authentication service that handles all user authentication requests across multiple applications and systems, including protocols like SAML, OAuth, and LDAP/Active Directory integration. It focuses on the architectural patterns and security controls needed to centralize authentication decisions, token management, and session handling in a dedicated authentication service rather than implementing authentication logic within individual applications. This hub does not cover the specific authentication methods themselves (covered by MFA/OTP and Challenge nonce cryptography), credential storage and recovery mechanisms (covered by Credential recovery and Resist stolen credentials), or the user-facing authentication interfaces (covered by Login functionality).", "generated_at": "2026-04-28T23:20:36.193733+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Use centralized authentication mechanism", "hub_id": "113-133", "hub_name": "Use centralized authentication mechanism", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "114-853": { "description": "This hub covers the security requirements for maintaining physical equipment and facilities, including scheduled maintenance procedures, maintenance personnel authorization and supervision, maintenance tool control, and secure handling of equipment during servicing activities. It encompasses both local and remote maintenance operations, field maintenance protocols, and the secure disposal or reuse of equipment at end-of-life. The scope is limited to maintenance activities on physical assets and does not cover software maintenance, configuration management, or operational monitoring of equipment performance outside of maintenance windows.", "generated_at": "2026-04-28T23:20:38.709707+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Equipment management > Maintenance", "hub_id": "114-853", "hub_name": "Maintenance", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "117-371": { "description": "This hub covers implementing a single, unified access control system that manages all authentication and authorization decisions across an application's data storage layer, replacing distributed or component-specific access control implementations. It encompasses architectural patterns like centralized policy engines, single sign-on (SSO) for data access, and unified permission management systems that enforce consistent access rules across databases, file systems, and object stores. The scope includes the design and deployment of centralized access control services but excludes the specific access control policies themselves, authentication mechanisms, or the implementation details of individual storage systems that consume the centralized service.", "generated_at": "2026-04-28T23:20:41.083269+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Data access control > Use a centralized access control mechanism", "hub_id": "117-371", "hub_name": "Use a centralized access control mechanism", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "118-602": { "description": "This hub covers implementing a global catch-all error handler that captures any exceptions not caught by specific error handling logic, preventing application crashes and uncontrolled error exposure. It focuses on the technical implementation of fallback error handling mechanisms (such as global exception handlers, error boundaries, or top-level try-catch blocks) that activate when all other error handling fails, distinguishing it from siblings that address error message content or consistency of exception handling patterns. The scope is limited to the last-resort handler implementation itself and does not cover specific error handling for known exception types, error logging mechanisms, or the content of error responses shown to users.", "generated_at": "2026-04-28T23:20:42.359126+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Error handling > Use a standard last-resort error handler for unhandled errors", "hub_id": "118-602", "hub_name": "Use a standard last-resort error handler for unhandled errors", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "118-775": { "description": "This hub covers establishing and operating internal communities of practice focused on secure software development, including organizing knowledge-sharing forums, maintaining secure coding guidelines repositories, coordinating security champions across development teams, and facilitating peer learning through code reviews and security workshops. It encompasses the social and collaborative aspects of building security expertise within development teams, distinct from formal process definition (covered by \"Setup and maintain a secure software development process\") or executive-level program governance (covered by \"Steer the secure software development program\"). This hub does not cover external community engagement, formal security training curriculum development, or the technical implementation of security controls and tools.", "generated_at": "2026-04-28T23:20:42.670671+00:00", "hierarchy_path": "Governance processes for security > Security organizing processes > Program management > Program management for secure software development > Manage an internal secure software development community", "hub_id": "118-775", "hub_name": "Manage an internal secure software development community", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "122-287": { "description": "This hub covers requirements for designing cryptographic systems with replaceable components, including the ability to swap algorithms, update key lengths, modify cipher modes, and reconfigure cryptographic parameters without major system changes. It focuses on architectural flexibility that enables rapid response to cryptographic vulnerabilities or algorithm deprecation through modular design and configuration-based cryptography selection. This hub does not cover the selection of specific algorithms (covered by \"Use approved cryptographic algorithms\"), implementation details of cryptographic operations (covered by \"Perform cryptographic operations in constant time\"), or backward compatibility considerations (covered by \"Use weak crypto only for backwards compatibility\").", "generated_at": "2026-04-28T23:20:43.569945+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encryption algorithms > Ensure cryptographic elements can be upgraded or replaced", "hub_id": "122-287", "hub_name": "Ensure cryptographic elements can be upgraded or replaced", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "125-010": { "description": "Password management systems covers the operational processes for deploying, configuring, and maintaining enterprise password management solutions, including password vaults, single sign-on (SSO) systems, and privileged access management (PAM) tools within facility infrastructure. This hub addresses the lifecycle management of password systems as facility assets—their installation, updates, access controls, and integration with facility systems—distinct from endpoint management (device-level controls) and network security (perimeter defenses). It excludes password policy requirements, user authentication methods, and the cryptographic algorithms used by these systems, focusing solely on the operational aspects of running password management infrastructure.", "generated_at": "2026-04-28T23:20:44.886546+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Password management systems", "hub_id": "125-010", "hub_name": "Password management systems", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "130-171": { "description": "This hub covers security controls that ensure the integrity of data flowing into and out of AI models during runtime execution, including input validation, output verification, and protection against data poisoning or manipulation attacks at inference time. It focuses specifically on the data streams and interfaces between the model and external systems, distinct from runtime model integrity controls (which protect the model itself) and augmentation data integrity controls (which protect supplementary datasets used alongside the model). This hub excludes controls for protecting the confidentiality of inputs/outputs (covered by sibling confidentiality hubs), model training data integrity, and integrity protections for the model's internal parameters or architecture during execution.", "generated_at": "2026-04-29T15:54:03.546122+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Conventional AI security controls on AI assets > Runtime model io integrity controls", "hub_id": "130-171", "hub_name": "Runtime model io integrity controls", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "132-146": { "description": "This hub covers the implementation of layered security controls across network infrastructure, including firewalls, intrusion detection/prevention systems, network segmentation, traffic monitoring, and incident response procedures specifically designed to counter network-layer attacks. It focuses on the operational deployment and coordination of multiple defensive mechanisms that work together to protect, detect, and respond to threats targeting network protocols, services, and communications paths. This hub addresses the holistic defense strategy and operational processes for network security, while its siblings focus on specific technical controls (segregation, DNS integrity, sandboxing) rather than the comprehensive layered approach and response capabilities.", "generated_at": "2026-04-28T23:20:48.124501+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Network security > Apply defense-in-depth techniques/processes for protection, detection, and timely response to network-based attacks.", "hub_id": "132-146", "hub_name": "Apply defense-in-depth techniques/processes for protection, detection, and timely response to network-based attacks.", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "134-207": { "description": "This hub covers controls to prevent XML and XPath injection attacks by validating, sanitizing, and properly handling XML data inputs and XPath query construction, including protection against XML External Entity (XXE) attacks and malicious XPath expressions that could manipulate queries or access unauthorized data. It encompasses defensive techniques such as input validation against XML schemas, disabling external entity processing, using parameterized XPath queries, and restricting XPath functions. Unlike sibling hubs that address injection in other contexts (LDAP, OS commands, JavaScript/JSON) or focus on general output encoding techniques, this hub specifically targets vulnerabilities in XML parsing and XPath query processing. It does not cover general output encoding strategies, SQL injection, or injection attacks in non-XML data formats and query languages.", "generated_at": "2026-04-28T23:20:50.700818+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Protect against XML/XPath injection", "hub_id": "134-207", "hub_name": "Protect against XML/XPath injection", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers controls that prevent XML and XPath injection by ensuring user controlled data cannot alter XML structures, XPath expressions, or XML query logic. It includes schema aware validation, escaping XML and XPath metacharacters, parameterized XPath construction where available, and restrictions on dangerous XPath functions. It does not cover XML External Entity parser hardening, general XML schema validation unrelated to injection, SQL injection, or non XML query languages.", "reviewer_notes": "Original included XXE, which is covered by a separate XML parser restriction hub; replacement separates XML or XPath injection from XXE.", "temperature": 0.0 }, "134-412": { "description": "This hub covers implementing synchronization mechanisms and atomic operations to prevent race conditions specifically in security-critical functions such as authentication, authorization, payment processing, and privilege escalation checks. It focuses on eliminating TOCTOU vulnerabilities through proper locking strategies, transaction isolation, and atomic state transitions in code paths that make security decisions or handle sensitive data modifications. Unlike its siblings which address thread safety in general business flows, resource prioritization, or state management patterns, this hub specifically targets race condition vulnerabilities in security boundaries and access control points. It does not cover general concurrency performance optimization, non-security-related race conditions, or distributed system consistency issues beyond local application boundaries.", "generated_at": "2026-04-28T23:20:49.712841+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Parallel execution robustness > Protect sensitive functionalities against race conditions", "hub_id": "134-412", "hub_name": "Protect sensitive functionalities against race conditions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "135-200": { "description": "This hub covers the systematic evaluation and validation of existing security policies to ensure they remain current, effective, and aligned with organizational objectives and regulatory requirements. It encompasses policy review cycles, gap analysis against current threats and compliance standards, stakeholder feedback incorporation, and approval workflows for policy updates. This hub specifically addresses the review process for already-established policies, distinguishing it from Security requirements (which defines what policies must contain), Contingency planning (which focuses on incident response procedures), and Security risk assessment (which evaluates threats rather than policy adequacy). It excludes initial policy creation, implementation procedures, and enforcement mechanisms.", "generated_at": "2026-04-28T23:20:50.688661+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Review of security policies", "hub_id": "135-200", "hub_name": "Review of security policies", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "138-448": { "description": "This hub covers requirements for proactively notifying users when their authentication credentials or tokens are approaching expiration, including timing of notifications, delivery methods, and clear renewal instructions. It specifically addresses time-bound authenticators like certificates, API keys, and temporary access tokens that require periodic renewal, distinguishing it from sibling hubs that focus on reactive notifications (credential changes, anomalies) or password management mechanics. The scope excludes the actual renewal process implementation, credential storage mechanisms, and authentication strength requirements - it solely encompasses the user communication aspects of impending authentication expiration.", "generated_at": "2026-04-28T23:20:52.980477+00:00", "hierarchy_path": "Technical application security controls > Secure user management > Inform users for authentication renewal", "hub_id": "138-448", "hub_name": "Inform users for authentication renewal", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "141-385": { "description": "Model exfiltration encompasses threats where attackers extract proprietary AI model information through indirect methods, including inference-based attacks that reconstruct model parameters, architecture, or training data by analyzing API responses and model behavior. This hub covers extraction techniques such as model inversion, membership inference, and functional approximation attacks that operate without requiring direct access to model files or development environments. It excludes direct theft scenarios where attackers gain unauthorized access to model artifacts during runtime or development phases, which are addressed by its sibling hubs.", "generated_at": "2026-04-28T23:20:53.751209+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Model confidentiality threats > Model exfiltration", "hub_id": "141-385", "hub_name": "Model exfiltration", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers indirect extraction of proprietary AI model information through observation of model behavior, such as reconstructing model functionality, decision boundaries, parameters, architecture details, or hyperparameters from repeated queries and response analysis. It focuses on model confidentiality attacks that do not require direct access to model files, development environments, or runtime memory. It does not cover training data privacy attacks such as membership inference or model inversion except when they are incidental signals, nor direct model theft during development or runtime.", "reviewer_notes": "Original incorrectly blended model confidentiality with training data confidentiality by naming membership inference and model inversion as core scope.", "temperature": 0.0 }, "141-555": { "description": "Fail securely encompasses requirements for applications to maintain security properties during failure conditions, including defaulting to deny access, preventing information disclosure through error states, and ensuring partial failures don't compromise overall security controls. This hub focuses on the security implications of failure modes rather than general error handling practices (covered by Error handling) or logging aspects of failures (covered by logging-related siblings). It excludes business continuity, disaster recovery, or availability concerns unless they directly impact security posture during failure states.", "generated_at": "2026-04-28T23:20:55.358701+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Fail securely", "hub_id": "141-555", "hub_name": "Fail securely", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "145-310": { "description": "This hub covers security controls for handling untrusted SVG (Scalable Vector Graphics) content by removing, disabling, or isolating dangerous scriptable elements including inline scripts, event handlers, and foreignObject tags that can execute JavaScript or other code. It specifically addresses SVG-based XSS vectors through sanitization of SVG DOM elements, attributes, and namespaces, or through sandboxing techniques like CSP restrictions or iframe isolation. This hub excludes general HTML sanitization, template injection prevention, and other vector graphics formats, focusing solely on the unique security challenges posed by SVG's XML-based structure and its ability to embed executable content.", "generated_at": "2026-04-28T23:20:57.203442+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > Sanitize, disable, or sandbox untrusted SVG scriptable content", "hub_id": "145-310", "hub_name": "Sanitize, disable, or sandbox untrusted SVG scriptable content", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "146-706": { "description": "This hub covers the enforcement of JSON schema validation as a mandatory preprocessing step before any JSON payload is parsed or processed by the application, ensuring that incoming JSON data conforms to predefined structural and type constraints including required fields, data types, value ranges, and nested object structures. Unlike sibling hubs that address general input validation patterns (whitelist external input), specific attack vectors (mass parameter assignment, HTTP parameter pollution), or operate at different layers (trusted service layer validation), this hub specifically targets JSON-formatted data validation at the parsing stage. The scope excludes validation of non-JSON data formats, business logic validation beyond schema conformance, and post-processing validation of already-parsed JSON objects.", "generated_at": "2026-04-28T23:20:57.608634+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Input validation > Enforce JSON schema before processing", "hub_id": "146-706", "hub_name": "Enforce JSON schema before processing", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers enforcing JSON Schema or equivalent structural validation before JSON data is trusted by application logic or business processing. It includes validation of required fields, data types, nested structures, value ranges, additional property rules, and rejection of malformed or schema nonconforming payloads after safe parsing. It does not cover non JSON formats, business rules beyond schema conformance, post processing authorization, or general HTTP input allowlisting.", "reviewer_notes": "Original said schema validation occurs before parsing, which is technically inaccurate; replacement clarifies safe parsing before schema validation and before business processing.", "temperature": 0.0 }, "146-871": { "description": "Ensemble AI models covers security controls for implementing multiple AI models that work together to produce more robust predictions, including techniques like bagging, boosting, stacking, and voting mechanisms that reduce the impact of adversarial inputs by aggregating diverse model outputs. This hub focuses specifically on architectural patterns where multiple models collaborate to improve security resilience, distinguishing it from single-model hardening approaches covered by sibling hubs like AI Input distortion or confidence obscuring techniques. The scope excludes general model robustness training, input sanitization controls, and resource management aspects of inference, focusing solely on the security benefits achieved through multi-model architectures and their aggregation strategies.", "generated_at": "2026-04-28T23:20:59.593306+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Ensemble AI models", "hub_id": "146-871", "hub_name": "Ensemble AI models", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "148-853": { "description": "This hub covers establishing and operating the foundational security infrastructure and processes required for secure software development, including securing development environments, defining toolchain requirements, and maintaining security requirements for development infrastructures. It focuses on the technical and procedural setup of secure development capabilities, distinct from community management, stakeholder engagement, providing reusable controls, or strategic program steering which are addressed by sibling hubs. The scope is limited to the development process infrastructure and does not extend to the actual coding practices, security testing methodologies, or deployment of the developed software.", "generated_at": "2026-04-28T23:21:00.153326+00:00", "hierarchy_path": "Governance processes for security > Security organizing processes > Program management > Program management for secure software development > Setup and maintain a secure software development process", "hub_id": "148-853", "hub_name": "Setup and maintain a secure software development process", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "152-725": { "description": "This hub covers requirements for restricting access to administrative interfaces, management consoles, and privileged functionality within applications to only authorized administrators through authentication, authorization controls, and network segmentation. It focuses specifically on protecting admin-level features like configuration panels, user management interfaces, and system administration endpoints from unauthorized access, distinguishing it from general least privilege controls that apply to all users or OS-level account restrictions. The scope excludes general user permission models, API access controls for non-administrative functions, and infrastructure-level management interfaces that exist outside the application boundary.", "generated_at": "2026-04-28T23:21:00.996062+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Minimize permissions > Limit access to admin/management functionality", "hub_id": "152-725", "hub_name": "Limit access to admin/management functionality", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "154-031": { "description": "This hub covers requirements for removing or disabling unnecessary features, modules, and code paths within an application's own codebase to reduce attack surface and prevent hidden malicious functionality. It focuses on hardening through feature exclusion at the application level, including detection and removal of Easter eggs, backdoors, and other intentionally hidden code, distinct from its sibling hub that addresses removing elements from external components. This hub does not cover dependency management, third-party library security, or client-side technology restrictions, which are addressed by sibling hubs under supply chain management.", "generated_at": "2026-04-28T23:21:02.743750+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Harden application by excluding unwanted functionality", "hub_id": "154-031", "hub_name": "Harden application by excluding unwanted functionality", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "155-155": { "description": "The Architecture hub covers security requirements for system design decisions including component boundaries, trust zones, data flow patterns, and architectural security patterns such as defense-in-depth layering and least privilege enforcement. Unlike its sibling hubs that address specific attack vectors or protection mechanisms, Architecture focuses on structural security properties and design-level controls that prevent entire classes of vulnerabilities through proper system decomposition and interaction models. This hub excludes implementation-specific controls, runtime protections, and detailed cryptographic specifications, which are covered by respective sibling hubs.", "generated_at": "2026-04-28T23:21:03.284389+00:00", "hierarchy_path": "Cross-cutting concerns > Architecture", "hub_id": "155-155", "hub_name": "Architecture", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "157-430": { "description": "This hub covers requirements for protecting sensitive data while temporarily cached in any system component (client or server) and ensuring complete removal of such data after use, including encryption of cached data, access controls on cache storage, and secure deletion mechanisms. It focuses specifically on the lifecycle management of cached sensitive data from creation through destruction, distinguishing it from siblings that address specific cache locations (client storage, browser cache, server components) or specific data types (authentication data). This hub does not cover prevention of caching (addressed by anti-caching headers and client storage restrictions) or memory management (covered by zeroization requirements), but rather the protection and clearing of sensitive data that must be cached for legitimate functionality.", "generated_at": "2026-04-28T23:21:06.929963+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Manage temporary storage > Protect and clear cached sensitive data", "hub_id": "157-430", "hub_name": "Protect and clear cached sensitive data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "158-874": { "description": "This hub covers requirements for systems to accept passwords of substantial length, specifically permitting passwords of at least 64 characters while setting reasonable upper bounds (typically 128 characters) to prevent denial-of-service attacks. It addresses the security benefit of allowing users to create long passphrases or password manager-generated strings that are resistant to brute force and dictionary attacks, distinguishing it from sibling hubs that focus on minimum length enforcement, character composition rules, or password validation mechanisms. This hub does not cover password storage mechanisms, hashing algorithms, or the actual enforcement of minimum password lengths—it solely addresses the system's capability to accept and process long password inputs without artificial truncation or rejection.", "generated_at": "2026-04-28T23:21:07.272962+00:00", "hierarchy_path": "Technical application security controls > Authentication > Credentials directives > Allow long passwords", "hub_id": "158-874", "hub_name": "Allow long passwords", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "162-655": { "description": "This hub covers requirements for documenting each system component's specific business purpose and security role, including what functions each module, service, or subsystem performs and how it contributes to overall system security posture. It focuses on functional documentation that explains the \"what\" and \"why\" of each component's existence, distinct from trust boundary documentation (which maps security perimeters) and key management documentation (which details cryptographic material handling). The scope includes component inventories, functional specifications, and security responsibility matrices, but excludes implementation details, data flow diagrams, API specifications, and operational procedures which belong to other documentation categories.", "generated_at": "2026-04-28T23:21:07.290343+00:00", "hierarchy_path": "Development processes for security > Technical system documentation > Documentation of all components' business or security function", "hub_id": "162-655", "hub_name": "Documentation of all components' business or security function", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "163-518": { "description": "This hub covers implementing controls to detect and prevent decompression attacks where maliciously crafted archive files (zip, gz, tar, etc.) expand to consume excessive disk space or memory when extracted, including recursive compression bombs and files with extreme compression ratios. It specifically addresses validation of compressed file characteristics before extraction, such as checking uncompressed size limits, file count limits, and compression ratio thresholds, distinct from malware scanning or file execution prevention covered by sibling hubs. This hub excludes general file size validation for non-archive uploads, malware detection within archives, and controls for preventing code execution from uploaded files, focusing solely on resource exhaustion risks from the decompression process itself.", "generated_at": "2026-04-28T23:21:10.462420+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File upload > Check uploaded archives for decompression attacks (eg zip bombs)", "hub_id": "163-518", "hub_name": "Check uploaded archives for decompression attacks (eg zip bombs)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "166-151": { "description": "This hub covers implementing secure default-deny mechanisms that block access when authorization checks fail, encounter errors, or cannot complete, ensuring that system failures or exceptions do not inadvertently grant unauthorized access. It encompasses designing access control systems to fail closed rather than open, including proper exception handling, timeout behaviors, and fallback states that maintain security posture during component failures or unexpected conditions. Unlike sibling hubs that focus on specific authentication methods (multifactor authentication), attack prevention (CSRF, directory browsing), or authorization models (RBAC/ABAC), this hub specifically addresses the failure modes and exception handling of access control systems themselves. It does not cover the implementation of specific authorization schemes, authentication mechanisms, or normal-case access control logic, but rather ensures that when any of these systems fail or encounter edge cases, the default behavior preserves security.", "generated_at": "2026-04-28T23:21:11.209003+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Ensure that secure fail-safe is in place for access control", "hub_id": "166-151", "hub_name": "Ensure that secure fail-safe is in place for access control", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "168-186": { "description": "This hub covers requirements for ensuring that out-of-band authentication elements (requests, codes, or tokens) can only be used a single time during their validity period, preventing replay attacks where an intercepted or compromised authentication factor could be reused. It specifically addresses the one-time use constraint for authentication factors delivered through separate communication channels (SMS, email, push notifications, hardware tokens) rather than entered directly into the primary authentication interface. This hub focuses exclusively on the single-use enforcement mechanism and does not cover the generation, transmission security, storage, or expiration timing of these authentication factors, which are addressed by sibling hubs.", "generated_at": "2026-04-28T23:21:12.780637+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Use out of band authentication requests, codes or tokens only once", "hub_id": "168-186", "hub_name": "Use out of band authentication requests, codes or tokens only once", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "170-772": { "description": "The Cryptography hub encompasses requirements for implementing cryptographic controls including encryption algorithms, key management lifecycle, certificate handling, and cryptographic protocol selection across applications and systems. It covers the proper use of symmetric and asymmetric cryptography, hashing functions, digital signatures, and the secure generation, storage, rotation, and destruction of cryptographic materials. This hub excludes transport layer security configurations (covered under Architecture), cryptographic failures arising from injection attacks (covered under Injection protection), and privacy-specific encryption requirements for personal data (covered under Personal data handling).", "generated_at": "2026-04-28T23:21:12.319105+00:00", "hierarchy_path": "Cross-cutting concerns > Cryptography", "hub_id": "170-772", "hub_name": "Cryptography", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "The Cryptography hub covers requirements for correct use of cryptographic controls across applications and systems, including encryption, hashing, digital signatures, certificate use, and secure generation, storage, rotation, and destruction of cryptographic material. It focuses on cryptographic mechanisms and key lifecycle concerns rather than the business purpose of the protected data. It does not cover TLS endpoint configuration, transport protocol hardening, injection protection, or privacy governance except where those topics specifically depend on cryptographic control selection or key handling.", "reviewer_notes": "Original incorrectly stated that transport layer security configuration is covered under Architecture; replacement points that boundary to secure communication concerns.", "temperature": 0.0 }, "171-222": { "description": "This hub covers verification of compiled binary files' integrity through cryptographic signatures, checksums, or hash validation before deploying them to production environments. It encompasses checking that binaries haven't been tampered with during build processes, storage, or transit, and validating that deployed executables match their expected cryptographic fingerprints. Unlike sibling hubs that address build pipeline security, source code integrity, or deployment configuration, this hub specifically focuses on the final binary artifacts themselves. It does not cover source code verification, build process security controls, or runtime integrity monitoring after deployment.", "generated_at": "2026-04-28T23:21:12.839508+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Check binary integrity before deployment", "hub_id": "171-222", "hub_name": "Check binary integrity before deployment", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "172-101": { "description": "Personnel security encompasses the policies and procedures for vetting, onboarding, managing, and offboarding individuals who access organizational resources, including background screening, access agreements, position risk assessments, and termination processes. This hub covers the lifecycle management of personnel from pre-employment screening through post-employment obligations, including disciplinary actions and asset return requirements, but excludes the definition of job roles (covered in Roles and responsibilities) and security education programs (covered in Security awareness training). The scope includes both internal employees and external personnel such as contractors, focusing on trust verification and access control measures rather than ongoing security behavior modification or organizational structure.", "generated_at": "2026-04-28T23:21:17.048140+00:00", "hierarchy_path": "Governance processes for security > Security governance regarding people > Personnel security", "hub_id": "172-101", "hub_name": "Personnel security", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "173-554": { "description": "This hub covers threats where auxiliary data used to enhance AI model inputs (such as retrieved documents, knowledge bases, or context databases) is exposed through unauthorized access or exfiltration. It specifically addresses leakage of augmentation data repositories and retrieval mechanisms, distinguishing it from direct model input/output leaks or manipulation of the augmentation data itself. The scope excludes threats to the primary model inputs, model outputs, or scenarios where augmentation data is tampered with rather than leaked.", "generated_at": "2026-04-29T15:54:04.432592+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Conventional threats to AI input, output and augmentation data > Augmentation data leak", "hub_id": "173-554", "hub_name": "Augmentation data leak", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "175-235": { "description": "This hub covers requirements for verifying that files received from untrusted sources match their expected type through content-based validation techniques such as magic number verification, file structure analysis, and format-specific parsing, preventing type confusion attacks where malicious files masquerade as benign formats. It focuses specifically on the validation logic and methods used to confirm file type authenticity, distinct from sibling hubs that address the mechanics of downloading, uploading, storing, or executing files. The scope is limited to type validation mechanisms and does not include file content sanitization, malware scanning, size restrictions, or the actual handling operations covered by its sibling hubs.", "generated_at": "2026-04-28T23:21:23.342612+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > Validate file type of data from untrusted sources", "hub_id": "175-235", "hub_name": "Validate file type of data from untrusted sources", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "176-154": { "description": "This hub covers implementing rate limiting and resource consumption monitoring controls that detect and respond to abnormal request volumes, including tracking metrics like requests per IP, user, or time period to prevent resource exhaustion attacks. It focuses specifically on volumetric abuse detection through request counting and throttling mechanisms, distinguishing it from sibling hubs that validate data structure, content, or format rather than quantity. This hub does not cover validation of individual input contents, data type enforcement, or structural validation of requests - only the monitoring and limiting of request frequency and resource allocation patterns.", "generated_at": "2026-04-28T23:21:18.707684+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Input validation > Monitor expectation of usage intensity (e.g. number of requests)", "hub_id": "176-154", "hub_name": "Monitor expectation of usage intensity (e.g. number of requests)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "180-488": { "description": "This hub covers the establishment and implementation of secure default configurations for all application components, frameworks, and runtime environments, including documentation of security-relevant settings and their rationale. It encompasses baseline hardening requirements across application servers, containers, frameworks, and platform services, ensuring each configurable security parameter is set to minimize attack surface and prevent common misconfiguration vulnerabilities. This hub does not cover HTTP-specific security headers (handled by its sibling) or the configuration of data flow controls between sources and sinks, focusing instead on the foundational security posture of the application infrastructure itself.", "generated_at": "2026-04-28T23:21:19.294762+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > Proper Configuration for all applications and frameworks", "hub_id": "180-488", "hub_name": "Proper Configuration for all applications and frameworks", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "182-732": { "description": "Direct runtime model leak encompasses threats where an attacker extracts model parameters, architecture details, or training data through legitimate API interactions during model inference, including techniques like model inversion, membership inference, and gradient-based extraction attacks. Unlike model exfiltration which involves unauthorized copying of entire model files, and development-time leaks which occur during training or deployment phases, this hub specifically addresses information leakage through the model's intended query-response interface. This scope excludes side-channel attacks, physical access exploits, and vulnerabilities in the underlying infrastructure or hosting environment.", "generated_at": "2026-04-29T15:54:11.544471+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Model confidentiality threats > Direct runtime model leak", "hub_id": "182-732", "hub_name": "Direct runtime model leak", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "184-284": { "description": "This hub covers logging of security-critical application events including authentication attempts (both successful and failed), access control violations, deserialization errors, input validation failures, and other events that indicate potential security incidents or attacks. It encompasses the comprehensive capture of events that security teams need to detect threats, investigate incidents, and maintain security posture, but excludes the specific logging requirements for sensitive data access (covered by sibling hub) and authentication details that might expose credentials (covered by authentication logging hub). The scope is limited to event logging itself and does not include log storage, retention, protection, or analysis requirements.", "generated_at": "2026-04-28T23:21:23.941959+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log relevant > Log all security relevant events", "hub_id": "184-284", "hub_name": "Log all security relevant events", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "186-540": { "description": "This hub covers requirements to prevent sensitive data exposure through HTTP request methods (GET, POST, PUT, DELETE, etc.) by ensuring data is transmitted only in appropriate message components like headers or request bodies, not in URL parameters or query strings. It specifically addresses vulnerabilities where sensitive information becomes visible in server logs, browser history, or network traffic when improperly placed in HTTP verb parameters, distinguishing it from sibling hubs that focus on parameter quantity reduction or API URL data exposure prevention. The scope is limited to data placement within HTTP request structure and does not cover encryption requirements, authentication mechanisms, or the security of the data transmission channel itself.", "generated_at": "2026-04-28T23:21:24.781487+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Minimize communication > Do not expose data through HTTP verb", "hub_id": "186-540", "hub_name": "Do not expose data through HTTP verb", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "187-083": { "description": "This hub covers technical controls that restrict the frequency and volume of requests to AI inference endpoints, including query-per-second limits, token bucket algorithms, and user/session-based throttling mechanisms to prevent resource exhaustion and abuse. It encompasses both application-layer rate limiting (API gateways, middleware) and model-specific constraints (context window limits, batch size restrictions) that protect AI systems from denial-of-service attacks, cost exploitation, and adversarial probing attempts. This hub excludes authentication/authorization mechanisms (covered by Access control to AI inference), detection of malicious input patterns (covered by Anomalous AI input handling), and monitoring/alerting on rate limit violations (covered by Monitor inference).", "generated_at": "2026-04-28T23:21:26.217546+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Generic input attack controls at inference > Rate limiting against AI input attacks", "hub_id": "187-083", "hub_name": "Rate limiting against AI input attacks", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "201-246": { "description": "This hub covers implementing multifactor authentication (MFA) specifically for administrative interfaces, requiring administrators to provide multiple forms of verification (such as passwords plus hardware tokens, biometrics, or SMS codes) before accessing privileged system functions. It focuses on securing high-privilege access points that control system configuration, user management, and other administrative operations, distinguishing it from general user authentication or API-specific access controls covered by sibling hubs. This hub does not cover MFA for regular user interfaces, programmatic API authentication, or the broader authorization decisions that occur after authentication is complete.", "generated_at": "2026-04-28T23:21:29.000713+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Use multifactor authentication on administrative interfaces", "hub_id": "201-246", "hub_name": "Use multifactor authentication on administrative interfaces", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "202-604": { "description": "Human AI oversight encompasses controls that require human review, approval, or intervention in AI system decisions and actions, including manual review checkpoints, human-in-the-loop decision gates, and override mechanisms for critical operations. Unlike automated AI oversight which relies on technical monitoring and algorithmic safeguards, this hub focuses on direct human judgment and control, while differing from AI user transparency by emphasizing active human intervention rather than passive information disclosure. This hub excludes fully automated monitoring systems, technical access controls covered under model action privilege minimization, and user-facing transparency features that don't involve human decision-making authority.", "generated_at": "2026-04-29T15:54:10.200634+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI impact reduction controls > Impact limitation of unwanted model behaviour > Human AI oversight", "hub_id": "202-604", "hub_name": "Human AI oversight", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "204-272": { "description": "Sensitive AI output handling encompasses controls for preventing AI models from exposing confidential data, personally identifiable information, or proprietary knowledge through their generated responses, including techniques like output filtering, differential privacy, and response sanitization. Unlike its siblings that focus on malicious inputs (prompt injection, evasion attacks) or resource abuse, this hub specifically addresses the risk of legitimate queries inadvertently extracting sensitive information from the model's training data or internal representations. This scope excludes input validation controls and model architecture defenses, focusing solely on post-generation output inspection and modification mechanisms.", "generated_at": "2026-04-29T15:54:10.152595+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Specific input attack controls at inference > Sensitive AI output handling", "hub_id": "204-272", "hub_name": "Sensitive AI output handling", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "205-522": { "description": "Automated AI oversight encompasses technical controls that continuously monitor, analyze, and intervene in AI system operations without human involvement, including real-time output filtering, automated anomaly detection in model behavior, and programmatic enforcement of safety constraints through guardrails and moderator systems. Unlike Human AI oversight which requires manual review and intervention, this hub focuses on algorithmic and system-based supervision mechanisms that operate at machine speed, while differing from Model action privilege minimization by addressing behavioral monitoring rather than capability restriction, and from AI user transparency by focusing on system-to-system oversight rather than user-facing explanations. This hub excludes manual review processes, static model architecture constraints, and transparency features designed for human interpretation.", "generated_at": "2026-04-28T23:21:31.999466+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI impact reduction controls > Impact limitation of unwanted model behaviour > Automated AI oversight", "hub_id": "205-522", "hub_name": "Automated AI oversight", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "206-254": { "description": "This hub covers requirements for generating initial authentication codes (such as setup codes for MFA enrollment or initial OTP seeds) using cryptographically secure random number generators with at least 20 bits of entropy. It specifically addresses the randomness quality and entropy requirements for codes used during the initial setup or provisioning phase of multi-factor authentication mechanisms, distinguishing it from sibling hubs that focus on ongoing authentication operations, storage methods, or specific authenticator types. This hub does not cover the generation of session-based OTPs, password policies, or the cryptographic algorithms used in OTP verification - these are addressed by sibling hubs focusing on time-based OTPs, initial passwords, and approved cryptographic algorithms respectively.", "generated_at": "2026-04-28T23:21:33.232004+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Use secure random to generate initial authentication codes", "hub_id": "206-254", "hub_name": "Use secure random to generate initial authentication codes", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "208-355": { "description": "This hub covers requirements for implementing deterministic, reproducible deployment processes that ensure identical application states can be recreated from source code and configuration across different environments and time periods. It encompasses version-controlled infrastructure definitions, immutable build artifacts, documented dependency management, and automated deployment procedures that eliminate manual variations and environmental drift. Unlike sibling hubs that focus on security controls during deployment (integrity checks, trusted sources) or specific deployment mechanisms (auto-updates, SDI), this hub specifically addresses the consistency and repeatability aspects of the deployment process itself. It does not cover the security hardening of deployed applications, runtime protection mechanisms, or the specific tools used for automation—only that deployments must be reproducible through documented, automated means.", "generated_at": "2026-04-28T23:21:36.690445+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Ensure repeatability of deployment", "hub_id": "208-355", "hub_name": "Ensure repeatability of deployment", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "208-805": { "description": "This hub covers requirements for detecting and preventing debug mode activation in production environments, including disabling debug flags, removing debug endpoints, and eliminating verbose error messages that expose system internals. It encompasses application-level debug settings, framework debug modes, and server debug configurations that could reveal stack traces, database schemas, or internal paths. Unlike its sibling hub which focuses on passive information leakage through HTTP headers and responses, this hub specifically addresses active debug features and developer tools that must be disabled. It does not cover general error handling strategies, logging practices, or non-debug related information disclosure such as directory listings or version banners.", "generated_at": "2026-04-28T23:21:36.427864+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Prevent security disclosure > Disable debug mode in production", "hub_id": "208-805", "hub_name": "Disable debug mode in production", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "217-112": { "description": "This hub covers requirements for reducing the attack surface of web applications by limiting the quantity of parameters accepted in HTTP requests, including hidden form fields, AJAX variables, cookies, and header values. It focuses specifically on parameter count reduction as a security control, distinct from its siblings which address data exposure through HTTP verbs and URL structures rather than parameter volume. The scope is limited to parameter quantity minimization and does not cover parameter validation, sanitization, or the security of parameter values themselves - only the reduction of their number to prevent parameter pollution and manipulation attacks.", "generated_at": "2026-04-28T23:21:35.991935+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Minimize communication > Minimize the number of parameters in a request", "hub_id": "217-112", "hub_name": "Minimize the number of parameters in a request", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "217-163": { "description": "This hub covers threats where attackers manipulate auxiliary data sources that AI systems use to enhance their responses, including retrieval-augmented generation (RAG) databases, knowledge bases, and external context stores that supplement model training data. It focuses on poisoning attacks against these augmentation sources and integrity violations of the retrieval pipeline, distinct from direct model input attacks or data exfiltration scenarios. The scope excludes manipulation of core training datasets, prompt injection attacks, and scenarios where augmentation data is leaked rather than corrupted.", "generated_at": "2026-04-29T15:54:16.168486+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Conventional threats to AI input, output and augmentation data > Augmentation data manipulation", "hub_id": "217-163", "hub_name": "Augmentation data manipulation", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "220-442": { "description": "Model action privilege minimization encompasses controls that restrict AI models' permissions to execute actions, access resources, or invoke tools based on the principle of least privilege. This hub covers technical implementations of role-based access control (RBAC) for AI agents, configuration of tool permissions, and restrictions on model capabilities when processing untrusted data. Unlike its siblings which focus on monitoring (Human/Automated AI oversight) or disclosure (AI user transparency), this hub specifically addresses preventive access controls that limit what actions an AI model can perform. It excludes detection mechanisms, audit logging, or user notification requirements, focusing solely on permission boundaries and capability restrictions enforced at the model execution layer.", "generated_at": "2026-04-29T15:54:16.630686+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI impact reduction controls > Impact limitation of unwanted model behaviour > Model action privilege minimization", "hub_id": "220-442", "hub_name": "Model action privilege minimization", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "224-321": { "description": "This hub covers requirements for encrypting health-related data at rest, including medical records, medical device information, de-anonymized research data, and other data regulated under healthcare privacy laws like HIPAA, GDPR Article 9, or similar frameworks. It encompasses encryption methods, key management, and implementation standards specific to healthcare data storage systems, whether in databases, file systems, or backup media. Unlike its siblings that address financial data (subject to PCI-DSS, banking regulations) or general personal data (names, addresses, standard PII), this hub specifically targets health information that requires enhanced protection due to its sensitive medical nature and stricter regulatory requirements. This hub does not cover encryption of health data in transit, access control mechanisms, or the handling of fully anonymized health data that no longer qualifies as regulated personal information.", "generated_at": "2026-04-28T23:21:42.906702+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Securely store regulated data > Encrypt health data at rest", "hub_id": "224-321", "hub_name": "Encrypt health data at rest", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "227-045": { "description": "This hub covers the identification of sensitive data within an organization's assets and the establishment of governance policies that dictate how such data must be handled, protected, and controlled throughout its lifecycle. It encompasses discovery mechanisms to locate sensitive information across systems, networks, and storage locations, as well as the creation of enforceable policies that define access controls, usage restrictions, and security requirements for identified sensitive data. Unlike its sibling hubs that focus on classification schemes (protection levels), retention schedules (deletion policies), or documentation of protection requirements, this hub specifically addresses the operational processes of finding sensitive data and binding it to security policies. This hub does not cover the technical implementation of data protection controls, the actual classification taxonomy design, or the execution of data retention/deletion activities—it strictly focuses on the identification process and policy assignment framework.", "generated_at": "2026-04-28T23:21:44.253368+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Asset management > Data classification and handling > Identify sensitive data and subject it to a policy", "hub_id": "227-045", "hub_name": "Identify sensitive data and subject it to a policy", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "230-318": { "description": "AI resource exhaustion attacks target the computational resources of AI systems by exploiting their processing-intensive operations, such as forcing excessive model inference requests, triggering computationally expensive edge cases, or submitting adversarial inputs designed to maximize processing time (sponge examples). This hub covers attacks that specifically abuse the resource-intensive nature of AI operations to degrade availability, including inference-time DoS attacks and algorithmic complexity exploits unique to machine learning workloads. It excludes attacks on training data or model parameters (covered by sibling hubs), conventional DoS attacks not specific to AI characteristics, and attacks that compromise model behavior or confidentiality rather than availability.", "generated_at": "2026-04-28T23:21:43.506652+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > AI resource exhaustion attack", "hub_id": "230-318", "hub_name": "AI resource exhaustion attack", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "232-034": { "description": "This hub covers the implementation of the '__Host-' cookie prefix for session tokens, which enforces that cookies must be set with the Secure flag, from a secure origin (HTTPS), with no Domain attribute, and with Path set to '/'. It specifically addresses the use of this prefix to prevent subdomain takeover attacks and ensure cookies are only sent to the exact host that created them, distinguishing it from sibling controls that configure individual cookie attributes like SameSite, Secure, HttpOnly, or Path independently. This hub does not cover the '__Secure-' prefix, non-session cookies, or cookie attributes beyond those automatically enforced by the '__Host-' prefix requirement.", "generated_at": "2026-04-28T23:21:46.546682+00:00", "hierarchy_path": "Technical application security controls > Session management > Cookie-config > Set '_Host' prefix for cookie-based session tokens", "hub_id": "232-034", "hub_name": "Set '_Host' prefix for cookie-based session tokens", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "232-217": { "description": "This hub covers security controls that validate and restrict URL redirection and forwarding destinations to prevent open redirect vulnerabilities, where attackers manipulate redirect parameters to send users to malicious sites. It specifically addresses validation of redirect/forward URL parameters against an allowlist of trusted destinations, including both server-side redirects (HTTP 3xx responses) and client-side redirects (JavaScript location changes, meta refresh tags). Unlike its sibling hubs that focus on general input validation (HTTP parameters, JSON schemas, structured data), this hub exclusively targets the validation of URL destinations in redirect/forward functionality. It does not cover validation of other URL components (query parameters, fragments), general URL input validation for non-redirect purposes, or the implementation of redirect functionality itself - only the security controls that restrict where redirects can send users.", "generated_at": "2026-04-28T23:21:48.112682+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Input validation > Whitelist redirected/forwarded URLs", "hub_id": "232-217", "hub_name": "Whitelist redirected/forwarded URLs", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "232-325": { "description": "This hub covers architectural requirements for treating any secrets stored or accessible on client-side systems (including symmetric keys, passwords, API tokens, and similar credentials) as inherently compromised, prohibiting their use for protecting sensitive data or authorizing access to backend resources. It mandates that client-side secrets must never be relied upon for security decisions, instead requiring server-side validation and secrets management for all sensitive operations. This hub specifically addresses the insecurity of client-side secret storage and does not cover server-side secrets management, the technical implementation of encryption algorithms, or regulatory compliance requirements for data storage.", "generated_at": "2026-04-28T23:21:48.483719+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Treat client-secrets as insecure", "hub_id": "232-325", "hub_name": "Treat client-secrets as insecure", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "234-282": { "description": "This hub encompasses controls for protecting information systems and facilities from physical threats and environmental hazards, including physical access controls, environmental monitoring systems (temperature, humidity, fire, water), power infrastructure protection, and secure area management. It covers the full spectrum from perimeter security and visitor management to emergency systems and environmental controls, but excludes logical access controls, data protection mechanisms, and the management of IT equipment itself (which falls under Equipment management). The scope is bounded to physical security measures and environmental safeguards for facilities housing information systems, not extending to cybersecurity controls, personnel security procedures, or the operational management of the equipment within those facilities.", "generated_at": "2026-04-28T23:21:50.615429+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Physical & environment protection", "hub_id": "234-282", "hub_name": "Physical & environment protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "235-658": { "description": "This hub covers requirements for notifying users when their authentication credentials (passwords, security questions, MFA tokens) are modified, replaced, or reset through any mechanism including self-service, administrative action, or account recovery. It encompasses the timing, delivery methods, and content of notifications sent to users about credential changes to their accounts. Unlike sibling hubs that address credential policies (disallow defaults), authentication workflows (change with old/new), or behavioral monitoring (anomaly detection), this hub specifically focuses on the notification mechanism itself following a credential change event. It does not cover the actual credential change process, authentication renewal reminders, or notifications about non-credential account modifications.", "generated_at": "2026-04-28T23:21:50.563349+00:00", "hierarchy_path": "Technical application security controls > Secure user management > Notify user about credential change", "hub_id": "235-658", "hub_name": "Notify user about credential change", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "238-346": { "description": "This hub covers requirements for automatically terminating all active user sessions across an application when a password change occurs, including sessions established through federated authentication and at relying parties. It specifically addresses the security control of invalidating existing authentication tokens and session identifiers after password updates through any mechanism (direct change, reset, or recovery), ensuring compromised sessions cannot persist after credential rotation. This hub does not cover general session timeout policies, voluntary logout mechanisms, or user-initiated termination of sessions, which are addressed by its sibling hubs.", "generated_at": "2026-04-28T23:21:51.780015+00:00", "hierarchy_path": "Technical application security controls > Session management > Minimize session life > Terminate all sessions when password is changed", "hub_id": "238-346", "hub_name": "Terminate all sessions when password is changed", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "240-274": { "description": "This hub covers requirements for preventing the logging of sensitive data beyond credentials and payment information, including personally identifiable information (PII), health records, authentication tokens, session identifiers, and any data classified as sensitive under privacy regulations or organizational security policies. It addresses the implementation of data classification mechanisms, log sanitization controls, and filtering rules to ensure only operationally necessary non-sensitive data enters log files. This hub excludes specific controls for credentials and payment data (covered by its sibling hub) and does not address log retention policies, log access controls, or the secure storage and transmission of log files themselves.", "generated_at": "2026-04-28T23:21:53.889811+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log discretely > Log only non-sensitive data", "hub_id": "240-274", "hub_name": "Log only non-sensitive data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "240-464": { "description": "Contingency planning encompasses the development, documentation, and maintenance of procedures to ensure critical system operations continue during and after disruptions, including backup strategies, alternate processing sites, recovery procedures, and failover mechanisms. This hub covers business continuity planning, disaster recovery documentation, backup and restoration procedures, alternate site selection, and testing protocols for contingency measures, distinguishing it from Security risk assessment which identifies threats rather than response procedures, and from Security requirements which defines baseline controls rather than disruption responses. This hub excludes incident response procedures for active security breaches (covered under incident management), preventive security controls implementation, and routine operational procedures that do not specifically address disruption scenarios.", "generated_at": "2026-04-28T23:21:55.796825+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Contingency planning", "hub_id": "240-464", "hub_name": "Contingency planning", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "244-750": { "description": "Technical application security training encompasses the design, delivery, and maintenance of security education programs specifically for developers, architects, and technical staff involved in building applications, covering secure coding practices, vulnerability identification, security testing techniques, and framework-specific security features. This hub focuses exclusively on training content and delivery mechanisms for technical roles in the software development lifecycle, distinguishing it from general security awareness training or non-technical security education, and from the actual implementation of security controls covered by sibling hubs like Architecture/design processes or Verification. The scope excludes security training for non-technical roles, general IT security training, and the documentation of security procedures (covered under Technical instructions), instead concentrating on building the security knowledge and skills required by technical personnel to implement secure development practices.", "generated_at": "2026-04-28T23:22:44.773263+00:00", "hierarchy_path": "Development processes for security > Technical application security training", "hub_id": "244-750", "hub_name": "Technical application security training", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "248-646": { "description": "This hub covers requirements for disabling deprecated SSL/TLS protocol versions (SSL 2.0, SSL 3.0, TLS 1.0, TLS 1.1) and enforcing only current secure versions (TLS 1.2 and TLS 1.3) in application configurations and server settings. It focuses specifically on protocol version control rather than cipher suite selection, certificate validation, or connection logging, distinguishing it from sibling hubs that address those complementary aspects of TLS security. The scope excludes implementation details of specific TLS features, fallback mechanisms, or the cryptographic algorithms used within the allowed protocol versions.", "generated_at": "2026-04-28T23:21:57.054932+00:00", "hierarchy_path": "Technical application security controls > Secure communication > TLS > Disable insecure SSL/TLS versions", "hub_id": "248-646", "hub_name": "Disable insecure SSL/TLS versions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "251-446": { "description": "This hub covers the processes for securing formal commitment from executive leadership, management, and authorizing officials to support secure software development initiatives, and the mechanisms for communicating that commitment throughout the development organization. It encompasses activities such as obtaining written endorsements, establishing security champions at leadership levels, defining accountability structures, and creating communication channels to cascade security priorities from executives to all development-related roles. This hub does not cover the actual implementation of secure development practices, the creation of security communities among practitioners, or the technical controls and processes used in secure development - it strictly focuses on the organizational commitment and communication aspects.", "generated_at": "2026-04-28T23:21:58.462336+00:00", "hierarchy_path": "Governance processes for security > Security organizing processes > Program management > Program management for secure software development > Organize stakeholder commitment for secure software development", "hub_id": "251-446", "hub_name": "Organize stakeholder commitment for secure software development", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "253-452": { "description": "This hub covers the implementation of security controls within automated CI/CD pipelines, including secure credential management, pipeline-as-code security, build environment isolation, and automated security scanning integration at each pipeline stage. It focuses specifically on securing the automation infrastructure and processes themselves, distinguishing it from siblings that address binary integrity verification, source trust validation, or compiler-level security features which operate as discrete security checks rather than pipeline orchestration concerns. The scope excludes manual deployment procedures, post-deployment runtime security, and the security of the artifacts produced by the pipeline, concentrating instead on the security of the automation framework that executes builds and deployments.", "generated_at": "2026-04-28T23:22:03.022517+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Securely automate build and deployment in pipeline", "hub_id": "253-452", "hub_name": "Securely automate build and deployment in pipeline", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "257-117": { "description": "This hub covers the operational execution of backup schedules for critical data assets and the validation of backup integrity through periodic restoration testing, including defining backup frequencies, identifying data criticality levels, and documenting restoration procedures. It focuses specifically on the active backup and recovery testing processes, distinguishing it from \"Store backups securely\" which addresses the physical and logical security controls for backup storage media and locations. This hub excludes backup infrastructure design, storage security controls, and disaster recovery planning beyond the scope of routine backup verification.", "generated_at": "2026-04-28T23:22:01.467585+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Backup > Perform regular backups of important data and test restoration", "hub_id": "257-117", "hub_name": "Perform regular backups of important data and test restoration", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "257-668": { "description": "This hub covers the proper implementation and configuration of Content Security Policy (CSP) headers, including directive selection, source whitelisting, nonce/hash usage, and report-only mode testing to prevent XSS, data injection, and unauthorized resource loading attacks. It focuses specifically on CSP header syntax, directive combinations, and policy refinement strategies, distinguishing it from sibling hubs that address other security headers like HSTS (transport security), X-Frame-Options (clickjacking), or content-type controls. This hub excludes CSP deployment infrastructure, browser compatibility workarounds, and the implementation of the actual security controls that CSP policies reference (such as the secure coding practices that prevent XSS vulnerabilities themselves).", "generated_at": "2026-04-28T23:22:04.022071+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > HTTP security headers > Configure CSP configuration properly", "hub_id": "257-668", "hub_name": "Configure CSP configuration properly", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "260-200": { "description": "This hub covers requirements for implementing standardized log formats, schemas, and field structures across all system components to ensure logs can be parsed, correlated, and analyzed consistently. It encompasses log format specifications, field naming conventions, data type consistency, and structured logging approaches (such as JSON or CEF) that enable automated processing and cross-system event correlation. This hub excludes log transmission security (covered by \"Securely transfer logs\"), access controls for log files (\"Log access protection\"), timestamp accuracy (\"Log time synchronization\"), and preventing malicious log content injection (\"Log injection protection\").", "generated_at": "2026-04-28T23:22:03.624370+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log integrity > Log in consistent format across system", "hub_id": "260-200", "hub_name": "Log in consistent format across system", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "263-184": { "description": "This hub covers the automation of secure build and deployment processes, with specific emphasis on Software-Defined Infrastructure (SDI) environments where infrastructure is provisioned through code, templates, or scripts. It focuses on implementing automated security controls within build pipelines that verify secure deployment configurations, particularly for cloud-native and infrastructure-as-code scenarios. Unlike sibling hubs that address specific aspects like binary integrity checking, source trust verification, or build archival, this hub encompasses the end-to-end automation framework that orchestrates these security measures within the deployment pipeline. It does not cover manual deployment processes, runtime security monitoring, or the specific technical implementation of individual security tools—rather, it defines requirements for integrating and automating security verification steps within the build-to-deployment workflow.", "generated_at": "2026-04-28T23:22:08.677377+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Automate secure build and deployment, especially with SDI", "hub_id": "263-184", "hub_name": "Automate secure build and deployment, especially with SDI", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers automating secure build and deployment controls in software defined infrastructure and infrastructure as code environments, including scripted provisioning, policy as code checks, secure template enforcement, and automated verification of deployment guardrails. It focuses on ensuring secure deployment controls are applied consistently through codified infrastructure automation. It does not cover securing the CI or CD pipeline platform itself, binary integrity checks, source trust validation, manual deployment processes, or runtime security monitoring after deployment.", "reviewer_notes": "Original overlapped heavily with the sibling hub for securing automated build and deployment pipelines; replacement narrows this hub to SDI and IaC automation.", "temperature": 0.0 }, "265-800": { "description": "This hub covers requirements for scanning and analyzing source code and third-party libraries to detect and prevent the inclusion of actively malicious code such as malware, trojans, or code designed to compromise system security or steal data. It focuses on identifying code that performs unauthorized malicious actions when executed, distinguishing it from sibling hubs that address specific attack vectors like timebombs (delayed activation), backdoors (unauthorized access mechanisms), or unauthorized data collection (privacy violations). The scope is limited to detection of overtly malicious code patterns and behaviors, excluding vulnerabilities, bugs, or poor coding practices that could be exploited but are not inherently malicious in intent.", "generated_at": "2026-04-28T23:22:09.496363+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency integrity > Check source code and third party libraries to not contain malicious code", "hub_id": "265-800", "hub_name": "Check source code and third party libraries to not contain malicious code", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "267-031": { "description": "This hub covers implementing resource allocation mechanisms that dynamically assign more computational resources (CPU time, memory, I/O bandwidth) to processes based on their business criticality or priority levels, ensuring high-priority operations maintain performance during resource contention. It focuses on priority-based resource scheduling and allocation strategies within the application layer, distinct from its siblings which address race condition prevention and thread safety in business logic execution. This hub does not cover infrastructure-level resource management, operating system scheduling policies, or protection against resource exhaustion attacks (DoS) - it specifically addresses application-controlled resource distribution among competing internal processes.", "generated_at": "2026-04-28T23:22:09.921663+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Parallel execution robustness > Protect the availability of resources by providing more to higher-priority processes", "hub_id": "267-031", "hub_name": "Protect the availability of resources by providing more to higher-priority processes", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "267-468": { "description": "This hub covers encryption requirements for financial data at rest, including payment card data, bank account information, transaction records, credit histories, tax records, and financial beneficiary information stored in databases, file systems, or backup media. It addresses encryption algorithms, key management, and implementation standards specific to financial regulations like PCI-DSS, SOX, and banking compliance frameworks, distinguishing it from health data encryption (which follows HIPAA/HITECH) and personal data encryption (which follows GDPR/privacy laws). This hub excludes encryption of financial data in transit, tokenization methods, or encryption requirements for non-financial regulated data types.", "generated_at": "2026-04-28T23:22:09.811365+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Securely store regulated data > Encrypt financial data at rest", "hub_id": "267-468", "hub_name": "Encrypt financial data at rest", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "268-088": { "description": "This hub covers controls to prevent denial-of-service attacks through GraphQL queries and data layer expressions by limiting query complexity, depth, and resource consumption through techniques like query allowlists, depth limiting, amount limiting, and query cost analysis. It specifically addresses attacks that exploit nested queries, recursive field selections, and computationally expensive operations in GraphQL APIs and similar data query languages to exhaust server resources. This hub focuses exclusively on query-level DoS prevention in structured query languages and does not cover general input sanitization, template injection, or protocol-level flooding attacks addressed by its sibling hubs.", "generated_at": "2026-04-28T23:22:14.854426+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > Limit query impact GraphQL/data layer expression DoS", "hub_id": "268-088", "hub_name": "Limit query impact GraphQL/data layer expression DoS", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "268-100": { "description": "This hub covers the proper configuration of the Referrer-Policy HTTP response header to control how much referrer information (the URL of the previous page) is included when navigating from one page to another or when making requests. It encompasses selecting appropriate policy directives (no-referrer, origin, strict-origin, etc.) based on security requirements and ensuring the header is consistently applied across all responses to prevent information leakage through the Referer header. Unlike sibling hubs that focus on preventing content-type attacks (X-Content-Type-Options), enforcing HTTPS (HSTS), or controlling resource loading and framing (CSP, X-Frame-Options), this hub specifically addresses referrer information disclosure risks. It does not cover other privacy-related headers like Feature-Policy or Permissions-Policy, nor does it address URL parameter sanitization or other forms of information leakage outside the Referer header mechanism.", "generated_at": "2026-04-28T23:22:16.818113+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > HTTP security headers > Configure Referrer-Policy properly", "hub_id": "268-100", "hub_name": "Configure Referrer-Policy properly", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "268-272": { "description": "This hub covers the classification of personal data specifically for retention scheduling and automated deletion, requiring organizations to categorize personal information based on time-based retention requirements and establish mechanisms for systematic data disposal when retention periods expire. It focuses exclusively on temporal aspects of personal data lifecycle management, distinguishing it from sibling hubs that address initial sensitivity identification, protection level requirements documentation, or security-based data classification schemes. The scope is limited to personal data retention classification and deletion processes, excluding broader data governance activities such as access control implementation, data minimization at collection, or technical security controls for data in use.", "generated_at": "2026-04-28T23:22:16.541380+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Asset management > Data classification and handling > Classify personal data regarding retention so that old or outdated data is deleted", "hub_id": "268-272", "hub_name": "Classify personal data regarding retention so that old or outdated data is deleted", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "270-634": { "description": "This hub covers requirements for transmitting authentication secrets (passwords, OTP seeds, recovery codes, activation tokens) using encryption during credential recovery processes, ensuring these secrets are protected in transit through secure channels like TLS/HTTPS or encrypted email. It specifically addresses the transmission security aspect of recovery mechanisms, distinguishing it from sibling hubs that focus on identity verification requirements, information disclosure prevention, recovery method selection, and avoiding weak authentication questions. The scope is limited to encryption during transmission of secrets and does not cover the generation of secure secrets, storage encryption, or the overall recovery workflow design beyond the transmission phase.", "generated_at": "2026-04-28T23:22:16.700544+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Credential recovery > Send authentication secrets encrypted", "hub_id": "270-634", "hub_name": "Send authentication secrets encrypted", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "273-600": { "description": "This hub covers the implementation of network segmentation controls to isolate systems, applications, and data based on their security trust levels, including the use of firewalls, API gateways, reverse proxies, and cloud security groups to enforce boundaries between high-trust internal resources and lower-trust external or public-facing components. It focuses specifically on architectural separation techniques that prevent lateral movement and contain breaches by restricting communication paths between zones of different sensitivity levels, distinguishing it from sibling hubs that address defense layering, DNS security, and application-level isolation. This hub does not cover physical security segregation, data classification policies, or the specific configuration of individual security controls beyond their role in enforcing trust boundaries.", "generated_at": "2026-04-28T23:22:21.353141+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Network security > Segregate components of differing trust levels", "hub_id": "273-600", "hub_name": "Segregate components of differing trust levels", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "276-748": { "description": "Runtime model integrity controls ensure that AI/ML models remain unmodified and authentic during execution, protecting against tampering, corruption, or unauthorized alterations to model weights, architecture, and configuration parameters while loaded in memory or during inference operations. These controls specifically address threats to the model itself as a computational artifact, distinct from data integrity (covered by augmentation data integrity controls), input/output integrity (covered by runtime model io integrity controls), or confidentiality measures that protect against unauthorized access rather than modification. This hub excludes controls for model integrity during storage, training, or deployment phases, focusing solely on protecting model integrity during active runtime execution.", "generated_at": "2026-04-28T23:22:23.270528+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Conventional AI security controls on AI assets > Runtime model integrity controls", "hub_id": "276-748", "hub_name": "Runtime model integrity controls", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "278-413": { "description": "This hub covers mutual authentication requirements between application components (APIs, middleware, data layers) where each component verifies the identity of others before establishing communication, combined with the principle of least privilege to restrict each component's access rights to the minimum necessary for its function. It addresses authentication at the inter-component level to prevent unauthorized access through unpublished interfaces, CSRF attacks, and communication channel manipulation, ensuring that compromised or malicious components cannot freely access other parts of the system. This hub does not cover user-to-application authentication, external API authentication, or the specific cryptographic methods used for authentication - it focuses solely on the authentication relationships and privilege constraints between internal application components.", "generated_at": "2026-04-28T23:22:22.990838+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Authenticate consistently > Mutually authenticate application components. Minimize privileges", "hub_id": "278-413", "hub_name": "Mutually authenticate application components. Minimize privileges", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "284-521": { "description": "This hub covers implementing supplementary authorization mechanisms beyond basic access control, including step-up authentication for sensitive operations, adaptive authentication based on risk factors, and enforcing segregation of duties where multiple authorized users must collaborate to complete critical transactions. It encompasses anti-fraud controls through authorization workflows that prevent single actors from executing high-risk operations independently, particularly in financial or high-value systems. This hub specifically addresses additional layers of authorization and duty separation, distinguishing it from sibling hubs that focus on specific attack vectors (CSRF, IDOR), authentication methods (MFA), or authorization models (RBAC/ABAC). It does not cover basic access control implementation, specific authentication technologies, or the underlying permission models themselves - only the additional authorization checks and segregation requirements layered on top of existing access control systems.", "generated_at": "2026-04-28T23:22:25.126866+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Enforce additional authorization and segregation of duties", "hub_id": "284-521", "hub_name": "Enforce additional authorization and segregation of duties", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "286-500": { "description": "OS security encompasses the configuration, hardening, and access control mechanisms applied directly to operating systems to reduce attack surface and enforce security policies, including kernel-level protections, file system permissions, service restrictions, and security-specific OS features like SELinux or AppLocker. This hub focuses on the baseline security posture of the OS itself, distinct from patch management (which addresses vulnerability remediation through updates) and malware protection (which provides runtime threat detection and prevention). The scope excludes application-level security controls, network-based protections, and security tools that run on top of the OS rather than being integrated into its core functionality.", "generated_at": "2026-04-28T23:22:27.043832+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Endpoint management > OS security", "hub_id": "286-500", "hub_name": "OS security", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "287-251": { "description": "This hub covers requirements for generating challenge nonces with sufficient entropy and size to prevent prediction, collision, and brute-force attacks in authentication protocols. It specifically addresses nonce length requirements (minimum 64 bits), uniqueness guarantees over the device lifetime, and proper randomness characteristics to resist cryptanalysis and replay attacks. This hub focuses on the size and uniqueness properties of challenge nonces, while its sibling hub addresses the cryptographic algorithms and seeding mechanisms used to generate and verify them. It does not cover the cryptographic primitives themselves, key management, or the broader authentication protocol design beyond nonce generation parameters.", "generated_at": "2026-04-28T23:22:29.394952+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Challenge nonce cryptography > Use a unique challenge nonce of sufficient size", "hub_id": "287-251", "hub_name": "Use a unique challenge nonce of sufficient size", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "287-305": { "description": "This hub covers requirements for documenting cryptographic key and secret management procedures, including key generation, storage, rotation, revocation, and destruction processes throughout their lifecycle. It encompasses documentation of key management policies, procedures for handling different key types (encryption, signing, authentication), and compliance with standards like NIST SP 800-57. This hub does not cover the actual implementation of cryptographic storage mechanisms, general component documentation, or the mapping of trust boundaries and data flows between system components.", "generated_at": "2026-04-28T23:22:28.737820+00:00", "hierarchy_path": "Development processes for security > Technical system documentation > Document explicit key/secret management", "hub_id": "287-305", "hub_name": "Document explicit key/secret management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "304-667": { "description": "This hub covers implementing authorization controls to prevent Insecure Direct Object Reference (IDOR) vulnerabilities in APIs, where attackers manipulate object identifiers (IDs, keys, or references) in API requests to access or modify resources belonging to other users. It encompasses validation of user-supplied identifiers against authorization rules, ensuring that API endpoints verify the requesting user has legitimate access to the referenced objects before performing create, read, update, or delete operations. This hub specifically addresses IDOR vulnerabilities in API contexts, distinguishing it from broader access control measures like CSRF protection, directory browsing prevention, or role-based permissions that don't focus on object reference manipulation. It does not cover authentication mechanisms, session management, or authorization vulnerabilities that don't involve direct object reference manipulation such as privilege escalation through role modification or business logic flaws.", "generated_at": "2026-04-28T23:22:32.331869+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Protect API against unauthorized access/modification (IDOR)", "hub_id": "304-667", "hub_name": "Protect API against unauthorized access/modification (IDOR)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "307-111": { "description": "This hub covers security controls for storing files received from untrusted sources, including user uploads, third-party integrations, and external data feeds, focusing on isolation techniques such as storing files outside web-accessible directories, applying restrictive permissions, and implementing sandboxed storage locations. It addresses the specific risks of storing untrusted files where they could be executed, accessed directly via web paths, or compromise sensitive system areas through directory traversal or privilege escalation. This hub excludes file validation, sanitization, or scanning controls (which occur before storage) and does not cover the secure transmission or processing of these files after storage.", "generated_at": "2026-04-28T23:22:34.383943+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File storage > Securely store files with untrusted origin", "hub_id": "307-111", "hub_name": "Securely store files with untrusted origin", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "307-507": { "description": "This hub covers requirements for validating the authenticity and integrity of all code, libraries, dependencies, and resources consumed during both build-time and runtime execution through cryptographic verification mechanisms like code signing, checksums, and certificate validation. It encompasses controls for establishing trusted source repositories, implementing supply chain security measures, and enforcing policies that reject unsigned or tampered components throughout the software lifecycle. This hub specifically addresses trust and integrity verification of external inputs, distinguishing it from sibling hubs that focus on binary integrity post-build, deployment repeatability, or configuration security. It does not cover the mechanics of build automation, update distribution mechanisms, or compiler-level security features, which are addressed by its sibling hubs.", "generated_at": "2026-04-28T23:22:35.758275+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Allow only trusted sources both build time and runtime; therefore perform integrity checks on all resources and code", "hub_id": "307-507", "hub_name": "Allow only trusted sources both build time and runtime; therefore perform integrity checks on all resources and code", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "314-131": { "description": "This hub covers the configuration and utilization of security features provided by compilers, interpreters, and build tools to harden executables against memory corruption vulnerabilities, including enabling stack protections, data execution prevention, address space layout randomization, and compile-time warnings for unsafe operations. It encompasses selecting appropriate toolchains with security capabilities and configuring build flags to detect and prevent buffer overflows, integer overflows, format string vulnerabilities, and other memory safety issues during the compilation and linking phases. Unlike its sibling hubs that focus on deployment integrity, update mechanisms, or pipeline automation, this hub specifically addresses compile-time and link-time security hardening of the executable artifacts themselves. It does not cover runtime security controls, deployment verification processes, or the security of the build infrastructure and pipeline.", "generated_at": "2026-04-28T23:22:36.431114+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Use features in compile and build tools for executable security", "hub_id": "314-131", "hub_name": "Use features in compile and build tools for executable security", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "314-701": { "description": "This hub covers implementing and maintaining file extension allowlists at the web server or application tier to control which file types can be served to clients, preventing exposure of sensitive files like backups (.bak), editor temporary files (.swp), source code, and compressed archives. It encompasses configuration of web servers, application frameworks, and content delivery systems to explicitly permit only intended file extensions (e.g., .html, .css, .js, .jpg) while blocking all others by default. This hub does not cover file upload validation, file content inspection, or access control mechanisms for authorized file downloads—it strictly addresses the technical controls for restricting file serving based on extension filtering at the web tier.", "generated_at": "2026-04-28T23:22:38.394364+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File download > Whitelist file extensions served by web tier", "hub_id": "314-701", "hub_name": "Whitelist file extensions served by web tier", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "316-272": { "description": "This hub covers implementing and maintaining strict allowlists for Cross-Origin Resource Sharing (CORS) configurations, specifically controlling which external domains can access application resources through proper Access-Control-Allow-Origin header validation. It encompasses defining trusted origin patterns, rejecting null origins, and implementing granular subdomain controls to prevent unauthorized cross-origin requests while enabling legitimate integrations. Unlike its siblings which focus on Origin header authentication misuse, HTTP method restrictions, or proxy-added headers, this hub specifically addresses CORS policy configuration and enforcement. It does not cover general input validation, non-CORS header validation, or authentication mechanisms—only the security controls for cross-origin resource access permissions.", "generated_at": "2026-04-28T23:22:41.033188+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Validate HTTP request headers > Whitelist CORS resources", "hub_id": "316-272", "hub_name": "Whitelist CORS resources", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "317-743": { "description": "This hub covers the prohibition and mitigation of dynamic code execution functions like eval(), Function(), setTimeout() with strings, and similar constructs that interpret user-controlled data as executable code at runtime. It encompasses preventing code injection vulnerabilities by eliminating or strictly controlling dynamic code generation mechanisms across all programming languages and execution contexts (JavaScript, Python exec(), PHP eval(), etc.). Unlike its sibling hubs that focus on sanitizing specific content types (HTML, SVG, templates) or protecting particular injection vectors (SMTP, GraphQL), this hub specifically targets the elimination of language-level code execution primitives. It does not cover static code vulnerabilities, compilation-time code generation, or sanitization of non-executable content formats.", "generated_at": "2026-04-28T23:22:43.207995+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > Do not use eval or dynamic code execution functions", "hub_id": "317-743", "hub_name": "Do not use eval or dynamic code execution functions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "327-505": { "description": "This hub covers requirements for password change mechanisms that mandate users provide both their current password and new password during the change process, ensuring authenticated password updates cannot be performed without proving knowledge of the existing credential. It encompasses validation of the old password before accepting the new one, secure handling of both passwords during the transaction, and proper error messaging that doesn't reveal whether the old password was correct. This hub specifically addresses the authentication aspect of password changes and does not cover password recovery/reset flows where the old password is unknown, password complexity requirements, or notification mechanisms about password changes which are handled by sibling hubs.", "generated_at": "2026-04-28T23:22:42.537077+00:00", "hierarchy_path": "Technical application security controls > Secure user management > Change password with presence of old and new password", "hub_id": "327-505", "hub_name": "Change password with presence of old and new password", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "330-281": { "description": "This hub covers requirements for configuring operating system accounts used by application components, services, and servers to run with minimal necessary privileges rather than administrative or root access. It specifically addresses the OS-level account permissions under which application processes execute, including database services, web servers, application servers, and other system components. Unlike its siblings which focus on application-level access controls (admin functionality, user permissions, access modification), this hub exclusively addresses the OS account context for process execution. It does not cover application user permissions, network access controls, or the privileges within the application itself - only the operating system account privileges assigned to the processes running the application components.", "generated_at": "2026-04-28T23:22:44.550771+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Minimize permissions > Use least privilege OS accounts for system (components)", "hub_id": "330-281", "hub_name": "Use least privilege OS accounts for system (components)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "333-858": { "description": "This hub covers technical controls that prevent attackers from successfully using stolen authentication credentials, including defenses against credential stuffing, pass-the-hash/ticket attacks, and phishing-resistant authentication methods. It encompasses both preventive measures (like cryptographic authentication devices and client certificates) and detective controls that identify and block the use of compromised credentials across various attack vectors including remote services, Kerberos exploitation, and administrative share access. Unlike sibling hubs that focus on authentication implementation (MFA/OTP, centralized authentication) or operational aspects (credential recovery, login functionality), this hub specifically addresses post-compromise credential abuse scenarios and does not cover initial credential creation, storage security, or authentication flow design.", "generated_at": "2026-04-28T23:22:47.265154+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Resist stolen credentials", "hub_id": "333-858", "hub_name": "Resist stolen credentials", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "333-888": { "description": "This hub covers requirements for preventing sensitive data exposure through API URL components, including path segments, query parameters, and URL fragments that may be logged, cached, or visible in browser history. It addresses the secure design of API endpoints to ensure that authentication tokens, session identifiers, API keys, personally identifiable information, and business-sensitive data are transmitted through request headers or bodies rather than URLs. This hub specifically excludes requirements for HTTP verb selection (covered by its sibling) and general parameter minimization strategies, focusing solely on the URL-based exposure vector rather than the broader API design considerations.", "generated_at": "2026-04-28T23:22:49.409341+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Minimize communication > Do not expose data through API URLs", "hub_id": "333-888", "hub_name": "Do not expose data through API URLs", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "336-512": { "description": "This hub covers requirements for protecting DNS infrastructure integrity through validation of DNS records, prevention of DNS hijacking and poisoning attacks, and continuous monitoring of domain ownership and DNS entry validity. It encompasses defensive measures against DNS-specific threats including subdomain takeovers, cache poisoning, rebinding attacks, and exploitation of expired or misconfigured DNS entries across all DNS resolution layers. This hub specifically addresses DNS and domain name system security, excluding general network segmentation, application sandboxing, or broader defense-in-depth strategies that are covered by sibling hubs.", "generated_at": "2026-04-28T23:22:48.792326+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Network security > Ensure integrity of DNS entries and domains", "hub_id": "336-512", "hub_name": "Ensure integrity of DNS entries and domains", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "338-370": { "description": "This hub covers requirements to eliminate mandatory password expiration policies and restrictions on reusing previous passwords, recognizing that forced rotation often leads to predictable password patterns and reduced security. It encompasses removing time-based password changes, password history checks that prevent reuse of previous passwords, and age-based credential expiration mechanisms. Unlike sibling hubs that focus on password composition rules (length, character types, complexity), this hub specifically addresses temporal password policies and reuse restrictions. It does not cover password strength requirements, composition rules, or validation against breach databases - only the elimination of rotation schedules and history tracking.", "generated_at": "2026-04-28T23:22:51.127163+00:00", "hierarchy_path": "Technical application security controls > Authentication > Credentials directives > Do not enforce password rotation rules or history requirements", "hub_id": "338-370", "hub_name": "Do not enforce password rotation rules or history requirements", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "340-375": { "description": "This hub covers requirements for implementing and using dedicated secrets management platforms (such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault) to centrally store, access control, rotate, and audit secrets including API keys, database credentials, certificates, and encryption keys. It encompasses the architectural decision to adopt a purpose-built secrets management solution rather than storing secrets in code, configuration files, or general-purpose databases, and includes requirements for integrating applications with these platforms through secure APIs. This hub specifically addresses the use of specialized secrets management tools and does not cover the cryptographic methods for protecting secrets (covered by sibling hubs on hashing, salting, and HSMs), manual key management practices, or the storage of non-secret configuration data.", "generated_at": "2026-04-28T23:22:52.121924+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Use a dedicated secrets management solution", "hub_id": "340-375", "hub_name": "Use a dedicated secrets management solution", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers using a purpose built secrets management platform to store, retrieve, rotate, audit, and access control application secrets such as API keys, service credentials, database passwords, and certificates through secure runtime integrations. It focuses on adopting centralized secret management instead of embedding secrets in code, configuration files, or general purpose databases. It does not cover password hashing parameters, pepper or salt design, HSM based cryptographic operation isolation, or key vault requirements when cryptographic key custody is the primary control.", "reviewer_notes": "Original examples and scope overlapped with the key vault sibling; replacement distinguishes general application secret management from key custody controls.", "temperature": 0.0 }, "342-055": { "description": "This hub covers requirements for implementing the SameSite attribute on session cookies to prevent cross-site request forgery (CSRF) attacks by controlling when cookies are sent with cross-origin requests. It encompasses the proper configuration of SameSite values (Strict, Lax, or None) based on application requirements and ensuring compatibility with authentication flows. Unlike sibling hubs that address cookie confidentiality (Secure, HttpOnly), naming conventions (_Host prefix), or scope limitation (Path), this hub specifically focuses on cross-site request behavior control. It does not cover other CSRF defenses like anti-CSRF tokens, origin validation, or cookie attributes unrelated to cross-site request handling.", "generated_at": "2026-04-28T23:22:53.311662+00:00", "hierarchy_path": "Technical application security controls > Session management > Cookie-config > Set \"samesite\" attribute for cookie-based session tokens", "hub_id": "342-055", "hub_name": "Set \"samesite\" attribute for cookie-based session tokens", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "342-641": { "description": "This hub covers technical controls for detecting and handling individual anomalous or adversarial inputs during AI model inference, including statistical outlier detection, adversarial example identification algorithms, and response mechanisms when suspicious inputs are identified. It focuses specifically on point-in-time analysis of single inputs for anomalies, distinguishing it from \"Unwanted AI input series handling\" which addresses patterns across multiple inputs, and from \"Rate limiting\" which controls input volume rather than content. This hub excludes training-time adversarial defenses, general input validation that isn't AI-specific, and monitoring of model outputs or system behavior - these belong to model hardening, general input validation, and \"Monitor inference\" hubs respectively.", "generated_at": "2026-04-29T15:54:23.442298+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Generic input attack controls at inference > Anomalous AI input handling", "hub_id": "342-641", "hub_name": "Anomalous AI input handling", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "342-764": { "description": "This hub covers requirements for storing multi-factor authentication codes (including OTP codes, out-of-band verification codes, and lookup secrets) exclusively in hashed form using cryptographically secure one-way functions, preventing recovery of the original authentication code even if storage is compromised. It focuses specifically on the storage format of authentication codes after generation, distinguishing it from sibling hubs that address code generation entropy, transmission security, usage constraints, or authenticator type selection. This hub does not cover the hashing algorithms to use, the generation of the codes themselves, or the storage of long-term authentication credentials like passwords.", "generated_at": "2026-04-28T23:22:56.469827+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Only store hashed authentication codes", "hub_id": "342-764", "hub_name": "Only store hashed authentication codes", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "342-781": { "description": "This hub covers threats where AI model artifacts (weights, architectures, training data, or intermediate checkpoints) are exposed through insecure development environments, version control systems, or collaboration tools before deployment. It addresses leaks via compromised developer workstations, misconfigured repositories, insecure model registries, and unauthorized access to training infrastructure, distinguishing it from runtime leaks (which occur during inference) and exfiltration (which involves active theft rather than passive exposure). This hub excludes post-deployment model extraction through API queries, side-channel attacks during inference, or deliberate insider threats that involve active data theft mechanisms.", "generated_at": "2026-04-29T15:54:23.517051+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Model confidentiality threats > Direct development-time model leak", "hub_id": "342-781", "hub_name": "Direct development-time model leak", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "344-611": { "description": "This hub covers the implementation and integration of centralized, standardized security controls that can be reused across multiple applications and systems, including authentication services, logging frameworks, access control mechanisms, and vulnerability management interfaces. It encompasses both the selection of vetted security components and their proper integration into application architectures to avoid redundant or proprietary security implementations. The scope excludes the design of individual security controls themselves, security testing methodologies, and operational deployment procedures - focusing instead on the architectural decisions and implementation patterns that enable security control reuse and centralization.", "generated_at": "2026-04-28T23:22:57.861545+00:00", "hierarchy_path": "Technical application security controls > Secure implemented architecture > Use centralized reusable security controls", "hub_id": "344-611", "hub_name": "Use centralized reusable security controls", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "346-640": { "description": "This hub covers requirements for generating multi-factor authentication lookup secrets (recovery codes, backup codes) with cryptographically sufficient entropy of at least 112 bits, or alternatively using proper salting and hashing techniques when lower entropy is necessary. It addresses the secure generation of these static secrets that users store for account recovery or as backup authentication methods when primary MFA devices are unavailable. Unlike sibling hubs that focus on time-based OTPs, biometric factors, or out-of-band authentication channels, this hub specifically addresses the entropy requirements and cryptographic strength of pre-generated static secrets. The scope is limited to the generation phase of lookup secrets and does not cover their storage, transmission, usage policies, or revocation mechanisms, which are addressed by other sibling hubs.", "generated_at": "2026-04-28T23:23:00.344838+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Generate multi-factor lookup secrets with sufficient entropy", "hub_id": "346-640", "hub_name": "Generate multi-factor lookup secrets with sufficient entropy", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "347-352": { "description": "This hub covers requirements for establishing and validating the integrity of security-specific configuration settings during deployment, including cryptographic verification of security policies, access controls, encryption settings, and other security parameters before and after deployment. It focuses specifically on the integrity verification mechanisms for security configurations themselves, distinct from binary integrity checks or general deployment repeatability, and encompasses both the initial setting of security configurations and ongoing verification that these configurations remain unmodified. This hub does not cover the integrity of application binaries, general deployment automation practices, or the security of the deployment pipeline infrastructure itself - only the specific security configuration data and its integrity verification.", "generated_at": "2026-04-28T23:23:01.648468+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Set and confirm integrity of security deployment configuration", "hub_id": "347-352", "hub_name": "Set and confirm integrity of security deployment configuration", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "354-752": { "description": "This hub covers requirements for implementing risk-based multi-factor authentication (MFA) selection, specifically mandating cryptographically strong authenticators (hardware tokens, authenticator apps, FIDO2 keys) for high-privilege or sensitive access while restricting weak authenticators (SMS, email) to low-risk secondary verification only. It distinguishes from sibling hubs by focusing on authenticator strength classification and access-based prioritization rather than specific authenticator implementation details, token generation, or storage mechanisms. This hub does not cover the technical implementation of individual authenticator types, general MFA deployment requirements, or specific cryptographic algorithms used within authenticators.", "generated_at": "2026-04-28T23:23:02.766929+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Prioritize strong multi-factor authenticators (e.g. NOT SMS/mail) for critical access", "hub_id": "354-752", "hub_name": "Prioritize strong multi-factor authenticators (e.g. NOT SMS/mail) for critical access", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "354-753": { "description": "This hub requires systems to configure multi-factor authentication (MFA) to prioritize cryptographically-protected authenticators (like push notifications, TOTP apps, or hardware tokens) over clear text channels (SMS, email, voice calls) in default settings and user interfaces. It addresses the vulnerability of clear text MFA methods to interception, SIM swapping, and adversary-in-the-middle attacks by mandating that systems present stronger alternatives first or exclusively when users enable MFA. This hub specifically covers the default presentation and prioritization of MFA options, distinguishing it from sibling hubs that address specific authenticator types (biometric, OTP), cryptographic requirements, or usage constraints; it does not cover the complete prohibition of weak authenticators, implementation details of specific MFA methods, or post-enrollment authenticator management.", "generated_at": "2026-04-28T23:23:05.576567+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Do not offer weak (clear text) multi-factor authenticators by default", "hub_id": "354-753", "hub_name": "Do not offer weak (clear text) multi-factor authenticators by default", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "356-282": { "description": "This hub covers requirements for limiting the proliferation and persistence of sensitive data across application components, including techniques to minimize data copies, enforce retention limits, and ensure timely deletion of temporary sensitive data artifacts. It focuses on architectural patterns and implementation controls that prevent unnecessary data duplication, enforce data lifecycle policies, and reduce the attack surface by limiting where and how long sensitive information exists within the system. This hub does not cover privacy-specific transformations or anonymization techniques (covered by Privacy-preserving personal data logic), nor does it address runtime anomaly detection or concurrency issues covered by its sibling hubs.", "generated_at": "2026-04-28T23:23:04.237035+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Minimize sensitive data scattering and retention", "hub_id": "356-282", "hub_name": "Minimize sensitive data scattering and retention", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "358-860": { "description": "This hub covers requirements for identity verification processes during OTP or multi-factor authentication recovery, mandating that the proof of identity must match or exceed the rigor of the original enrollment verification (such as government ID verification, biometric matching, or in-person verification). It specifically addresses the recovery workflow for lost or compromised OTP devices, authenticator apps, or other MFA factors, ensuring attackers cannot bypass strong enrollment controls through weaker recovery mechanisms. Unlike its sibling hubs that focus on password-specific recovery mechanisms and secure transmission of secrets, this hub exclusively addresses identity proofing standards for non-password authentication factors. It does not cover the technical implementation of OTP/MFA systems, the recovery of passwords or static credentials, or the specific methods of identity verification—only the requirement that recovery verification must equal enrollment verification strength.", "generated_at": "2026-04-28T23:23:08.476457+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Credential recovery > Require proof of identity of the same level as during enrollment when recovering OTP or MFA", "hub_id": "358-860", "hub_name": "Require proof of identity of the same level as during enrollment when recovering OTP or MFA", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "362-550": { "description": "Personal data handling encompasses requirements for collecting, processing, storing, and disposing of personally identifiable information (PII) in compliance with privacy regulations, including data minimization, purpose limitation, consent management, and data subject rights implementation. This hub specifically addresses the lifecycle management of personal data and privacy controls, distinct from technical security controls like CSRF/XSS protection or cryptographic implementation which may protect but do not govern the handling of such data. The scope excludes general data security measures not specific to personal information, authentication/authorization mechanisms, and technical vulnerability mitigations covered by sibling hubs.", "generated_at": "2026-04-28T23:23:07.738781+00:00", "hierarchy_path": "Cross-cutting concerns > Personal data handling", "hub_id": "362-550", "hub_name": "Personal data handling", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "366-835": { "description": "This hub covers the specific techniques and controls for escaping output data to prevent Cross-Site Scripting (XSS) attacks, including HTML entity encoding, JavaScript escaping, and attribute value sanitization across reflected, stored, and DOM-based XSS contexts. Unlike its siblings that address other injection types (LDAP, XML/XPath, OS command) or focus on general encoding principles (context-specific encoding, preserving formatting), this hub specifically targets XSS prevention through output escaping mechanisms in web applications. The scope excludes input validation, Content Security Policy (CSP) implementation, and other non-escaping XSS defenses, as well as injection attacks that don't involve client-side script execution in browsers.", "generated_at": "2026-04-28T23:23:08.653409+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Escape output against XSS", "hub_id": "366-835", "hub_name": "Escape output against XSS", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "368-633": { "description": "Enforce least privilege requires applications to grant users and processes only the minimum access rights necessary to perform their legitimate functions, preventing unauthorized access to resources through privilege escalation or abuse. This hub covers runtime enforcement mechanisms that restrict user permissions to the smallest possible scope, including access control checks, privilege dropping after authentication, and dynamic permission validation based on current context and need. Unlike sibling hubs that focus on specific aspects like admin access restrictions or OS-level accounts, this hub addresses the general principle of minimal privilege enforcement across all application functions and data. It does not cover the initial permission design or architecture decisions (covered by \"Let application request minimal permissions\"), nor does it address the specific implementation of access control modifications or default deny policies for new users.", "generated_at": "2026-04-28T23:23:11.850603+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Minimize permissions > Enforce least privilege", "hub_id": "368-633", "hub_name": "Enforce least privilege", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "370-877": { "description": "This hub covers threats where attackers craft inputs specifically designed to cause AI models to produce incorrect outputs during inference, including adversarial examples that exploit model decision boundaries through subtle perturbations, gradient-based attacks, and other techniques that manipulate model predictions without modifying the model itself. It encompasses both white-box attacks (where attackers have model access) and black-box attacks (using transferability or query-based methods), distinguishing it from prompt injection attacks which exploit natural language processing systems through malicious instructions rather than mathematical manipulation of input features. This hub excludes training-time attacks like data poisoning, model extraction attempts, and attacks that target the deployment infrastructure rather than the model's inference behavior.", "generated_at": "2026-04-28T23:23:12.430281+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > AI model behaviour integrity threats > AI model behaviour integrity threats through inference > Evasion (e.g. adversarial examples)", "hub_id": "370-877", "hub_name": "Evasion (e.g. adversarial examples)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "377-680": { "description": "This hub covers implementing strict content-type validation that rejects any HTTP requests containing Content-Type headers not explicitly allowed on a whitelist, preventing attacks that exploit content-type confusion such as MIME sniffing vulnerabilities, parser differential attacks, and malicious file uploads disguised through content-type manipulation. Unlike its siblings that focus on encoding consistency, protocol-specific controls (REST/SOAP/GraphQL), or automation detection, this hub specifically addresses the attack surface created by accepting arbitrary content types that may trigger unintended parsing behaviors or bypass security controls. The scope is limited to content-type header validation and does not cover the actual parsing logic, content validation within allowed types, or other HTTP header validations beyond Content-Type.", "generated_at": "2026-04-28T23:23:15.471639+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > Reject non-whitelisted content types", "hub_id": "377-680", "hub_name": "Reject non-whitelisted content types", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "380-540": { "description": "This hub covers requirements for implementing thread-safe business logic flows that prevent race conditions through proper synchronization mechanisms, atomic operations, and elimination of time-of-check time-of-use (TOCTOU) vulnerabilities in multi-threaded execution environments. It focuses on ensuring deterministic execution of business processes regardless of thread scheduling or timing, distinct from its siblings which address protecting specific sensitive functions from races, resource prioritization schemes, or state isolation patterns. The scope is limited to thread safety and race condition prevention within application business logic flows and excludes infrastructure-level concurrency controls, database transaction isolation, or distributed system consistency mechanisms.", "generated_at": "2026-04-28T23:23:14.701023+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Parallel execution robustness > Ensure business flows' thread safety/resistance to race conditions", "hub_id": "380-540", "hub_name": "Ensure business flows' thread safety/resistance to race conditions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "384-344": { "description": "This hub covers security controls for storing and serving user-uploaded files to prevent server-side execution (e.g., through path traversal or interpreter invocation) and client-side attacks (e.g., XSS via content-type confusion or active content). It encompasses techniques such as serving files from isolated domains, enforcing Content-Type headers as application/octet-stream, implementing Content Security Policies, and storing files outside the web root or in sandboxed environments. This hub does not cover pre-upload validation (handled by siblings), malware scanning, size restrictions, or archive bomb detection - it specifically addresses post-upload storage architecture and delivery mechanisms.", "generated_at": "2026-04-28T23:23:15.658826+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File upload > Store and serve user-uploaded files such that they cannot execute/damage server or client", "hub_id": "384-344", "hub_name": "Store and serve user-uploaded files such that they cannot execute/damage server or client", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "387-848": { "description": "This hub covers secure JSON parsing practices that prevent code execution and injection attacks by using safe parsing methods like JSON.parse() instead of eval() or other dynamic code execution functions. It encompasses validation of JSON structure, handling of malformed JSON, and prevention of prototype pollution attacks during JSON deserialization in both browser and server-side JavaScript environments. This hub specifically addresses JSON parsing security, distinguishing it from siblings that focus on blocking untrusted serialization entirely, securing other serialized formats through integrity checks, or avoiding deserialization logic altogether. It does not cover XML parsing, binary serialization formats, or general input validation beyond JSON-specific concerns.", "generated_at": "2026-04-28T23:23:18.362474+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Deserialization Prevention > Parse JSON safely", "hub_id": "387-848", "hub_name": "Parse JSON safely", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "402-133": { "description": "This hub covers requirements for preventing session tokens from appearing in URLs through GET parameters, query strings, or URL paths, which could expose them in browser history, server logs, referrer headers, or shared links. It specifically addresses the secure transmission of session identifiers by mandating their placement in HTTP headers (such as cookies or authorization headers) or POST request bodies instead of URLs. This hub does not cover the configuration of session cookies themselves (handled by Cookie-config), the cryptographic strength of token generation (Session token generation), or other session security measures like timeout policies or re-authentication requirements.", "generated_at": "2026-04-28T23:23:18.026224+00:00", "hierarchy_path": "Technical application security controls > Session management > Do not expose session token in URL", "hub_id": "402-133", "hub_name": "Do not expose session token in URL", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "404-126": { "description": "This hub covers requirements for ensuring time-based one-time passwords (TOTP) maintain their single-use property within their validity window, including detection and rejection of replay attempts, proper token state management, and notification mechanisms when reuse is attempted. It specifically addresses the temporal uniqueness constraint of TOTP tokens, distinguishing it from sibling hubs that cover other OTP aspects like generation algorithms, storage methods, or delivery mechanisms. This hub does not cover the cryptographic generation of TOTP values, the length of validity periods, or requirements for other OTP types like HOTP or lookup secrets.", "generated_at": "2026-04-28T23:23:21.034314+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Use time-based OTP only once", "hub_id": "404-126", "hub_name": "Use time-based OTP only once", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers enforcing the single use property of time based one time passwords during their validity window, including maintaining enough server side state to reject a TOTP value after it has already been accepted. It focuses on replay prevention for TOTP verification logic. It does not cover TOTP generation algorithms, validity period configuration, storage of OTP secrets, logging and notification of reuse attempts, or one time use rules for lookup secrets and out of band codes.", "reviewer_notes": "Original overlapped with the sibling hub that logs, rejects, and notifies on TOTP reuse; replacement keeps this hub focused on the one time use rule.", "temperature": 0.0 }, "405-411": { "description": "This hub requires applications to reject the HTTP Origin header as a sole mechanism for authentication or access control decisions, as attackers can trivially spoof this client-supplied header to bypass security checks. It specifically addresses the vulnerability where developers mistakenly trust the Origin header for CORS validation, session management, or API access control instead of implementing proper authentication tokens, cryptographic signatures, or server-side session validation. This hub focuses exclusively on preventing Origin header misuse for security decisions, distinguishing it from sibling controls that address proper CORS whitelisting, HTTP method restrictions, and validation of proxy-added headers which may be trustworthy within specific network architectures.", "generated_at": "2026-04-28T23:23:21.661065+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Validate HTTP request headers > Avoid using of Origin header for authentication of access control", "hub_id": "405-411", "hub_name": "Avoid using of Origin header for authentication of access control", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers preventing applications from using the HTTP Origin header as the sole basis for authentication or authorization decisions. It addresses cases where client supplied or intermediary supplied Origin values are trusted instead of server side sessions, bearer tokens, signatures, client certificates, or other verifiable credentials. It does not cover proper CORS allowlist configuration, supplemental CSRF origin checks, HTTP method allowlisting, or validation of headers inserted by trusted proxies or SSO devices.", "reviewer_notes": "Original overstated spoofability and conflated Origin misuse with proper CORS or CSRF validation; replacement clarifies that Origin must not be the sole access control signal.", "temperature": 0.0 }, "408-838": { "description": "Adversarial training encompasses techniques that augment AI model training datasets with adversarial examples—inputs specifically crafted to cause misclassification—to improve model robustness against evasion attacks during inference. This hub covers the generation, selection, and incorporation of adversarial samples into training pipelines, including methods like projected gradient descent (PGD) training, fast gradient sign method (FGSM) augmentation, and min-max optimization approaches. Unlike adversarial robust distillation which transfers robustness from a hardened teacher model to a student model, this hub focuses on direct training with adversarial examples; it excludes post-training defenses, input preprocessing techniques, and architectural modifications for robustness.", "generated_at": "2026-04-28T23:23:20.883566+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > Evasion-preventing training > Adversarial training", "hub_id": "408-838", "hub_name": "Adversarial training", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "411-684": { "description": "Manual code review encompasses human-driven examination of source code to identify security vulnerabilities, logic flaws, and violations of secure coding standards through direct inspection and analysis. This hub covers processes where developers or security professionals systematically read and evaluate code without primary reliance on automated tools, including peer reviews, security-focused code walkthroughs, and manual verification of security controls implementation. Unlike its siblings that focus on automated scanning (Automated static security analysis), runtime testing (Dynamic security testing), AI-specific validation (AI security assurance), or architecture evaluation (Design review), this hub specifically addresses human cognitive analysis of code structure and logic. It excludes fully automated scanning processes, dynamic runtime analysis, and architectural or design-level reviews that don't involve direct code inspection.", "generated_at": "2026-04-28T23:23:25.629916+00:00", "hierarchy_path": "Development processes for security > Verification > Manual code review", "hub_id": "411-684", "hub_name": "Manual code review", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "417-342": { "description": "This hub covers the creation, maintenance, and distribution of standardized security components (authentication modules, input validation libraries, cryptographic wrappers, secure communication handlers) that development teams can integrate into applications rather than building security functionality from scratch. It encompasses the governance of component repositories, versioning strategies, documentation standards, and usage guidelines to ensure consistent security implementation across the organization's application portfolio. This hub does not cover the broader SDLC process management (handled by \"Setup and maintain a secure software development process\"), community building aspects (covered by \"Manage an internal secure software development community\"), or the strategic program direction and stakeholder management (addressed by \"Steer the secure software development program\" and \"Organize stakeholder commitment\").", "generated_at": "2026-04-28T23:23:24.855285+00:00", "hierarchy_path": "Governance processes for security > Security organizing processes > Program management > Program management for secure software development > Provide reusable application security controls", "hub_id": "417-342", "hub_name": "Provide reusable application security controls", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "418-525": { "description": "This hub covers requirements for detecting and preventing time-triggered malicious functionality (logic bombs) in source code and dependencies through analysis of date/time functions, scheduled tasks, and conditional execution based on temporal conditions. It focuses specifically on code that remains dormant until activated by reaching a predetermined date, time, or duration, distinguishing it from immediate malicious code (covered by the malicious code sibling) or persistent access mechanisms (covered by the backdoors sibling). The scope excludes general code quality issues, non-temporal conditional logic, and runtime behavior monitoring—it strictly addresses static analysis and review processes to identify time-based activation mechanisms before deployment.", "generated_at": "2026-04-28T23:23:27.213457+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency integrity > Check source code and third party libraries to not contain timebombs", "hub_id": "418-525", "hub_name": "Check source code and third party libraries to not contain timebombs", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "418-853": { "description": "This hub covers implementing monitoring systems that detect anomalous patterns in business logic execution, including out-of-sequence operations, abnormal parameter combinations, and actions inconsistent with typical user behavior profiles. It focuses on runtime detection of business logic abuse through behavioral analysis and pattern recognition, distinct from its siblings which address timing constraints, flow sequencing enforcement, hard limits, and alerting mechanisms. The scope is limited to detection and monitoring capabilities for business logic anomalies, excluding the enforcement mechanisms, response actions, or technical security monitoring such as system resource usage or network traffic analysis.", "generated_at": "2026-04-28T23:23:27.428886+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Detect and prevent unusual activity > Monitor unusual activities on system", "hub_id": "418-853", "hub_name": "Monitor unusual activities on system", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "421-513": { "description": "This hub covers controls that prevent Reflective File Download (RFD) attacks by either ignoring user-supplied filenames entirely or validating them against malicious patterns when files are served back to users through web responses. It specifically addresses scenarios where untrusted filenames could be reflected in HTTP response headers (Content-Disposition) or download contexts, potentially causing browsers to execute malicious content by interpreting safe file types as executable formats. Unlike its siblings that focus on sanitizing filename metadata, blocking file execution, or validating filenames for local/remote file inclusion contexts, this hub exclusively targets the reflection of filenames in download scenarios where the primary risk is client-side execution through content-type confusion. It does not cover server-side file processing, file upload validation, or scenarios where filenames are used to access server resources directly.", "generated_at": "2026-04-28T23:23:29.368145+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File execution > Ignore/at least validate filenames from untrusted origin (against RFD)", "hub_id": "421-513", "hub_name": "Ignore/at least validate filenames from untrusted origin (against RFD)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "422-005": { "description": "This hub covers controls for preventing template injection attacks by sanitizing or sandboxing user input before it is processed by template engines (e.g., Jinja2, Twig, Freemarker) where malicious template syntax could execute arbitrary code or access sensitive data. It focuses specifically on scenarios where user-controlled data is incorporated into templates that are then rendered server-side, requiring input validation, escaping of template delimiters, or execution within restricted sandboxes. Unlike sibling hubs that address specific injection vectors (SMTP, HTML, SVG) or execution contexts (eval functions, GraphQL), this hub exclusively targets template engine vulnerabilities and does not cover client-side templating frameworks, static template files without user input, or general code injection outside of template processing contexts.", "generated_at": "2026-04-28T23:23:32.289150+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > Sanitize/sandbox user input where template-injection is a threat", "hub_id": "422-005", "hub_name": "Sanitize/sandbox user input where template-injection is a threat", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "423-055": { "description": "Data supply chain management encompasses controls for securing the acquisition, validation, versioning, and provenance tracking of datasets used to train, validate, and test AI models throughout their lifecycle. This hub focuses specifically on data integrity, authenticity verification, and access controls for training datasets, unlike AI model supply chain management which addresses pre-trained model components and Model hosting supply chain management which covers deployment infrastructure. The scope excludes runtime data processing controls, model architecture decisions, and deployment environment security, focusing solely on the security of data assets before and during model development.", "generated_at": "2026-04-28T23:23:30.453776+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > AI supply chain management > Data supply chain management", "hub_id": "423-055", "hub_name": "Data supply chain management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "424-242": { "description": "Decommissioning encompasses the secure retirement of software systems, including data sanitization, credential revocation, license termination, and removal of system dependencies and integrations. This hub addresses end-of-life processes that prevent data leakage and unauthorized access after system shutdown, distinguishing it from Deploy/build which handles system activation, and Configuration Management which governs changes during active operation. It excludes ongoing legacy system maintenance (covered under Architecture/design processes) and focuses solely on the permanent cessation of system operations and associated security controls.", "generated_at": "2026-04-28T23:23:32.848248+00:00", "hierarchy_path": "Development processes for security > Decommissioning", "hub_id": "424-242", "hub_name": "Decommissioning", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "426-842": { "description": "This hub covers cryptographic verification mechanisms that ensure both message headers and payload data have not been tampered with during transmission, including TLS integrity checks, digital signatures, and message authentication codes (MACs). It focuses specifically on detecting and preventing modification attacks during transit, distinguishing it from \"Protect communication between application components\" which addresses broader inter-component security including authentication, authorization, and secure channel establishment. This hub does not cover encryption for confidentiality, authentication of communication endpoints, or protection against replay attacks - it strictly addresses integrity verification of transmitted data.", "generated_at": "2026-04-28T23:23:32.239252+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Communication encryption > Verify the authenticity of both headers and payload", "hub_id": "426-842", "hub_name": "Verify the authenticity of both headers and payload", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "428-544": { "description": "Security awareness training encompasses the design, delivery, and management of educational programs that develop personnel's understanding of security threats, policies, and safe practices, including general security literacy for all staff and role-specific training for specialized positions. This hub covers training content development, delivery methods, effectiveness measurement, and record-keeping, distinguishing it from Roles and responsibilities (which defines security duties and accountability structures) and Personnel security (which addresses background checks, access provisioning, and insider threat management). The scope excludes technical security control implementation training and professional certification programs, focusing instead on organizational security awareness and behavior modification through structured education.", "generated_at": "2026-04-28T23:23:35.117873+00:00", "hierarchy_path": "Governance processes for security > Security governance regarding people > Security awareness training", "hub_id": "428-544", "hub_name": "Security awareness training", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "430-636": { "description": "This hub covers requirements for validating TLS certificates against trusted certificate authorities (CAs) and verifying the complete certificate chain from leaf to root, including checking certificate validity periods, revocation status, and hostname matching. It encompasses both public CA validation and proper configuration of internal/self-signed certificate trust stores, distinguishing it from sibling hubs that address protocol versions, cipher selection, or connection logging. This hub excludes requirements for selecting TLS versions or cipher suites (covered by siblings), certificate pinning implementation details, and the cryptographic strength of certificates themselves - focusing solely on the validation logic and trust chain verification process.", "generated_at": "2026-04-28T23:23:36.956341+00:00", "hierarchy_path": "Technical application security controls > Secure communication > TLS > Verify TLS certificates and trust chain", "hub_id": "430-636", "hub_name": "Verify TLS certificates and trust chain", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "430-722": { "description": "This hub covers technical controls for encoding and transforming AI model outputs to prevent information leakage, including differential privacy mechanisms, output perturbation techniques, and response sanitization methods that reduce the extractable information from model predictions. It focuses specifically on post-processing transformations applied to model outputs before they reach end users, distinguishing it from runtime integrity controls that protect the model execution environment and confidentiality controls that secure data in transit or at rest. This hub excludes input encoding mechanisms, model architecture modifications for privacy preservation, and access control policies for output distribution.", "generated_at": "2026-04-29T15:54:23.276542+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Conventional AI security controls on AI assets > Encode model output", "hub_id": "430-722", "hub_name": "Encode model output", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "433-122": { "description": "This hub covers requirements for ensuring that nonces (numbers used once) and initialization vectors (IVs) are never reused with the same encryption key, preventing cryptographic attacks that exploit IV/nonce reuse such as stream cipher key recovery or CBC mode plaintext disclosure. It encompasses proper generation methods for IVs and nonces including cryptographically secure random generation for CBC/GCM modes and deterministic counter-based generation for CTR mode, as well as tracking mechanisms to prevent accidental reuse. This hub specifically addresses the uniqueness and proper generation of IVs/nonces, while sibling hubs cover other aspects of cryptographic implementation such as algorithm selection, secure failure modes, or timing attack prevention. It does not cover key generation, key rotation policies, or the selection of encryption modes themselves - only the correct use of their initialization parameters.", "generated_at": "2026-04-28T23:23:40.467645+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encryption algorithms > Use nonces and initialization vectors only once", "hub_id": "433-122", "hub_name": "Use nonces and initialization vectors only once", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "440-361": { "description": "This hub covers requirements for implementing immediate and complete revocation capabilities for physical single-factor OTP generators (hardware tokens) when reported lost or stolen, ensuring all active sessions using that token are terminated across all systems and locations. It specifically addresses the revocation mechanism's effectiveness and immediacy, distinguishing it from sibling hubs that focus on OTP generation algorithms, entropy requirements, or usage constraints. This hub does not cover software-based OTP generators, multi-factor authentication scenarios where the physical token is combined with other factors, or the initial provisioning and distribution of physical tokens.", "generated_at": "2026-04-28T23:23:38.622770+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Ensure that physical single factor OTP generator can be revoked fully immediately when lost", "hub_id": "440-361", "hub_name": "Ensure that physical single factor OTP generator can be revoked fully immediately when lost", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "440-372": { "description": "This hub covers technical controls that protect the confidentiality of data used to augment AI training datasets, including synthetic data generation outputs, data augmentation transformations, and external datasets merged during training. It encompasses encryption of augmentation pipelines, access controls for augmentation data stores, and differential privacy mechanisms applied during data synthesis or transformation processes. This hub specifically addresses augmentation data confidentiality and excludes controls for the original training data, model parameters, or runtime inference data, which are covered by sibling hubs focusing on model confidentiality and input/output controls.", "generated_at": "2026-04-28T23:23:41.172207+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Conventional AI security controls on AI assets > Augmentation data confidentiality controls", "hub_id": "440-372", "hub_name": "Augmentation data confidentiality controls", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers confidentiality controls for augmentation data used by AI systems, including synthetic data, transformed samples, retrieval corpora, knowledge bases, embeddings, and supplemental context stores used during training or inference. It includes encryption, access controls, tenant separation, and privacy controls that prevent unauthorized disclosure of augmentation sources and derived records. It does not cover augmentation data integrity, original training data confidentiality, model parameter confidentiality, or runtime input and output confidentiality controls.", "reviewer_notes": "Original limited augmentation data to training dataset augmentation; replacement includes inference and retrieval augmentation while preserving confidentiality scope.", "temperature": 0.0 }, "441-132": { "description": "This hub covers requirements for implementing deprecated cryptographic algorithms (such as MD5, SHA1, Triple-DES, ECB mode) exclusively when necessary to maintain interoperability with legacy systems that cannot be upgraded. It specifies controls for isolating weak cryptography usage, documenting business justifications, implementing compensating controls, and establishing migration timelines away from insecure algorithms. Unlike sibling hubs that focus on implementing strong cryptography (approved algorithms, state-of-the-art configuration) or cryptographic implementation details (constant time operations, secure failure modes), this hub specifically addresses the controlled exception handling when weak cryptography cannot be avoided. This hub does not cover the selection or implementation of modern cryptographic algorithms, key management practices, or scenarios where weak cryptography can be eliminated through system upgrades.", "generated_at": "2026-04-28T23:23:45.224979+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encryption algorithms > Use weak crypto only for backwards compatibility", "hub_id": "441-132", "hub_name": "Use weak crypto only for backwards compatibility", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "443-447": { "description": "This hub covers logging of authorization decisions made by access control mechanisms, including both successful and failed attempts to access protected resources, functions, or data along with contextual metadata such as user identity, requested resource, timestamp, and decision outcome. It focuses specifically on capturing the decision-making process of access control systems (e.g., role-based, attribute-based, or ACL-based controls) rather than the actual data accessed or authentication events. This hub excludes logging of authentication processes (covered by \"Log authentication decisions\"), the sensitive data itself (covered by \"Log access to sensitive data\"), and general security events outside of access control decisions.", "generated_at": "2026-04-28T23:23:47.618237+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log relevant > Log access control decisions", "hub_id": "443-447", "hub_name": "Log access control decisions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "444-058": { "description": "This hub covers techniques that mitigate training set backdoors by diluting malicious samples through the addition of clean, correctly-labeled data to the training dataset, reducing the relative influence of poisoned examples during model training. Unlike its siblings that modify existing data (train data distortion), alter model architecture (model size reduction), or apply post-training interventions (benign fine-tuning and pruning), this approach maintains the original training process while counteracting backdoors through increased volume of benign samples. The scope excludes data augmentation techniques that transform existing samples and methods that actively identify or remove poisoned data rather than diluting their effect.", "generated_at": "2026-04-29T15:54:29.668224+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > Weakening training set backdoors > Benign train data increase", "hub_id": "444-058", "hub_name": "Benign train data increase", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "455-358": { "description": "This hub covers requirements for securely storing session tokens within web browsers, specifically mandating the use of HttpOnly and Secure cookie flags, SameSite attributes, or HTML5 sessionStorage API rather than localStorage or unprotected cookies. It focuses exclusively on client-side storage mechanisms and their security configurations, distinguishing it from sibling hubs that address token generation entropy, algorithmic strength, and post-authentication token renewal. This hub does not cover server-side session storage, token transmission security, session timeout policies, or the cryptographic properties of the tokens themselves—only the secure storage methods once tokens reach the browser.", "generated_at": "2026-04-28T23:23:46.749960+00:00", "hierarchy_path": "Technical application security controls > Session management > Session token generation > When storing session tokens in browser, use secure methods only", "hub_id": "455-358", "hub_name": "When storing session tokens in browser, use secure methods only", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers secure browser storage choices for session tokens, especially use of cookies with HttpOnly, Secure, SameSite, and appropriate scope attributes when cookie based sessions are used. It focuses on preventing client side script access, unintended persistence, and exposure of session tokens in browser storage mechanisms. It does not cover server side session stores, session token generation entropy, session timeout, token transmission security, or general storage of non session sensitive data; localStorage and other script accessible persistent stores are out of scope as acceptable storage locations.", "reviewer_notes": "Original treated sessionStorage as generally secure for session tokens; replacement avoids endorsing script accessible storage and sharpens browser session token storage boundaries.", "temperature": 0.0 }, "456-535": { "description": "This hub covers monitoring and detection of automated attacks against business logic by tracking whether user actions occur within realistic human timeframes, such as detecting form submissions completed faster than humanly possible or transactions executed with superhuman speed. It focuses specifically on temporal analysis of user behavior patterns to identify bot-driven or scripted attacks, distinguishing it from siblings that monitor general system anomalies, enforce workflow sequences, implement risk-based limits, or generate configurable alerts. This hub does not cover rate limiting implementation, CAPTCHA systems, or authentication mechanisms - it strictly addresses the detection layer that identifies when business processes are being executed faster than legitimate human users could perform them.", "generated_at": "2026-04-28T23:23:48.608945+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Detect and prevent unusual activity > Monitor for realistic \"human time\" business logic flows", "hub_id": "456-535", "hub_name": "Monitor for realistic \"human time\" business logic flows", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "456-636": { "description": "This hub covers implementing cryptographic integrity verification mechanisms specifically for SOAP message payloads, including digital signatures via WS-Security standards, message authentication codes (MACs), and hash-based integrity checks to detect tampering during transmission. It encompasses both the generation of integrity proofs at the sender and validation at the receiver, addressing attacks like message manipulation, replay attacks, and man-in-the-middle modifications of SOAP body content. This hub does not cover XML schema validation (handled by its sibling), transport-layer security like TLS, authentication/authorization of SOAP requests, or integrity of SOAP headers and envelopes beyond the payload itself.", "generated_at": "2026-04-28T23:23:51.762952+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > SOAP > Add integrity check to SOAP payload", "hub_id": "456-636", "hub_name": "Add integrity check to SOAP payload", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "457-165": { "description": "This hub covers requirements for completely invalidating session tokens server-side when users explicitly log out, ensuring that session identifiers cannot be reused for authentication after logout occurs. It specifically addresses the technical implementation of logout functionality that prevents session resumption through browser back buttons, cached tokens, or downstream systems that may have stored the session identifier. This hub excludes automatic session termination due to inactivity (covered by session timeout), bulk session termination triggered by password changes, or user-initiated termination of remote sessions - it focuses solely on the immediate and complete invalidation of the current session upon user-initiated logout.", "generated_at": "2026-04-28T23:23:52.243078+00:00", "hierarchy_path": "Technical application security controls > Session management > Minimize session life > Terminate session after logout", "hub_id": "457-165", "hub_name": "Terminate session after logout", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "461-680": { "description": "This hub covers the secure storage and retention of build artifacts, binaries, and associated metadata (including integrity hashes, build logs, dependency manifests, and provenance data) in tamper-resistant repositories with access controls and audit trails. It encompasses archival policies, retention periods, and retrieval mechanisms for both successful and failed builds to support forensic analysis, compliance requirements, and rollback capabilities. This hub does not cover the build process itself, deployment mechanisms, or real-time integrity verification during execution—it focuses solely on post-build archival and preservation of build-related information.", "generated_at": "2026-04-28T23:23:53.117922+00:00", "hierarchy_path": "Development processes for security > Deploy/build > Securely archive builds and build information", "hub_id": "461-680", "hub_name": "Securely archive builds and build information", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "462-245": { "description": "This hub covers the systematic removal of non-essential components from third-party dependencies and external libraries, including unused features, example code, default configurations, and documentation files that could expose attack surface or sensitive information. It focuses specifically on reducing the footprint of external components after acquisition, distinct from dependency management (selecting/tracking dependencies), dependency integrity (verifying authenticity), and hardening (disabling functionality in your own application). The scope excludes the initial selection or verification of dependencies, runtime configuration changes, and the removal of functionality from internally-developed code - it strictly addresses post-acquisition minimization of third-party components before integration.", "generated_at": "2026-04-28T23:23:54.004762+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Remove unnecessary elements from external components (e.g. features, documentation, configuration)", "hub_id": "462-245", "hub_name": "Remove unnecessary elements from external components (e.g. features, documentation, configuration)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "463-577": { "description": "The Incident response hub encompasses the structured processes, procedures, and capabilities required to detect, analyze, contain, eradicate, and recover from security incidents, including evidence collection, incident classification, response coordination, and post-incident analysis. This hub focuses on the reactive handling of confirmed security events and breaches, distinguishing it from Monitoring which covers the proactive detection and alerting mechanisms that identify potential incidents before they require formal response procedures. The scope excludes preventive security controls, vulnerability management processes that occur outside of active incidents, and the continuous monitoring infrastructure itself, instead concentrating on the mobilization and execution of response activities once an incident has been declared.", "generated_at": "2026-04-28T23:23:54.481178+00:00", "hierarchy_path": "Operating processes for security > Detect and respond > Incident response", "hub_id": "463-577", "hub_name": "Incident response", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "463-820": { "description": "This hub covers implementing technical controls to restrict the maximum size of individual uploaded files and the total number of files a user can upload, preventing resource exhaustion attacks through excessive file storage consumption. It focuses specifically on quota enforcement mechanisms and size validation at the application layer, distinct from malware scanning, archive bomb detection, or file execution prevention which are addressed by sibling hubs. The scope is limited to storage-based denial of service prevention through file upload restrictions and does not cover network-level flooding attacks, memory exhaustion through deserialization, or computational resource exhaustion through decompression operations.", "generated_at": "2026-04-28T23:23:57.604396+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File upload > Limit size and number of uploaded files", "hub_id": "463-820", "hub_name": "Limit size and number of uploaded files", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "464-084": { "description": "This hub covers implementing Cross-Site Request Forgery (CSRF) protection mechanisms specifically for RESTful web services that use cookie-based authentication, including techniques such as synchronizer tokens, double-submit cookies, same-site cookie attributes, and origin/referer header validation. Unlike its sibling hub which focuses on content-type validation for data integrity, this hub addresses the authentication context vulnerability where attackers can forge requests using a victim's existing session cookies. The scope is limited to cookie-based REST services and does not cover CSRF protection for services using stateless authentication methods like bearer tokens in headers, nor does it address other session-related vulnerabilities like session fixation or hijacking.", "generated_at": "2026-04-28T23:23:57.874927+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > RESTful > Add CSRF protection for cookie based REST services", "hub_id": "464-084", "hub_name": "Add CSRF protection for cookie based REST services", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "467-215": { "description": "Adversarial robust distillation covers techniques that transfer adversarial robustness from a hardened teacher model to a student model through knowledge distillation, enabling deployment of smaller, efficient models that maintain resistance to adversarial examples. Unlike adversarial training which directly exposes models to adversarial examples during training, this approach distills robustness properties through soft labels and intermediate representations from pre-trained robust models. This hub excludes standard knowledge distillation for model compression without robustness objectives and does not cover direct adversarial training methods or post-training defenses.", "generated_at": "2026-04-28T23:23:58.440302+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > Evasion-preventing training > Adversarial robust distillation", "hub_id": "467-215", "hub_name": "Adversarial robust distillation", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "473-758": { "description": "This hub covers configuring HTTP response headers (Cache-Control, Pragma, Expires) to prevent web browsers from storing sensitive application data in their local cache, including setting appropriate directives like no-store, no-cache, and must-revalidate for pages containing authentication tokens, personal information, or confidential business data. It focuses specifically on server-side header configuration to control browser caching behavior, distinct from siblings that address clearing already-stored data, protecting cached content, or managing other storage mechanisms like localStorage or memory. This hub does not cover server-side caching mechanisms, CDN configuration, or non-browser client applications that may ignore standard HTTP caching headers.", "generated_at": "2026-04-28T23:24:00.685286+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Manage temporary storage > Set sufficient anti-caching headers", "hub_id": "473-758", "hub_name": "Set sufficient anti-caching headers", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "474-203": { "description": "Model obfuscation encompasses techniques that transform AI model architectures, parameters, or inference processes to prevent unauthorized extraction of model internals while preserving functional accuracy, including methods like parameter encryption, architecture randomization, and computation splitting. This hub covers runtime protection mechanisms that make it computationally infeasible for attackers to reverse-engineer model weights, training data, or architectural details through API queries or side-channel analysis. It excludes static model protection methods (like watermarking), access control mechanisms, and techniques that protect training data privacy rather than the model itself.", "generated_at": "2026-04-28T23:23:59.968048+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Conventional AI security controls on AI assets > Runtime model confidentiality controls > Model obfuscation", "hub_id": "474-203", "hub_name": "Model obfuscation", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "480-071": { "description": "This hub covers the implementation of clickjacking prevention mechanisms through the X-Frame-Options HTTP header or Content Security Policy (CSP) frame-ancestors directive, which control whether a web page can be embedded within frames, iframes, or other embedding contexts. It encompasses configuration requirements for preventing UI redress attacks where malicious sites overlay transparent frames to trick users into clicking on hidden elements, including specific header values (DENY, SAMEORIGIN, ALLOW-FROM) and CSP frame-ancestors syntax. This hub specifically addresses frame-based clickjacking prevention, distinguishing it from sibling hubs that cover other security headers like HSTS for transport security, Content-Type-Options for MIME-type sniffing prevention, or broader CSP configurations beyond frame control. It does not cover non-frame-based UI manipulation attacks, JavaScript-based click event hijacking, or other CSP directives unrelated to framing restrictions.", "generated_at": "2026-04-28T23:24:05.472280+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > HTTP security headers > Prevent Click jacking through X-Frame-Options or CSP", "hub_id": "480-071", "hub_name": "Prevent Click jacking through X-Frame-Options or CSP", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers clickjacking prevention through frame embedding controls, primarily Content Security Policy frame ancestors and, where appropriate, X Frame Options values such as DENY or SAMEORIGIN. It focuses on preventing hostile sites from embedding application pages in frames or iframes to trick users into interacting with hidden UI elements. It does not cover non frame UI manipulation, JavaScript click event abuse, general CSP configuration unrelated to frame control, or other HTTP security headers such as HSTS or X Content Type Options.", "reviewer_notes": "Original included legacy ALLOW FROM wording and mixed broader CSP concerns; replacement focuses on supported frame control mechanisms.", "temperature": 0.0 }, "482-771": { "description": "This hub covers requirements for implementing runtime and compile-time checks that detect and prevent integer overflow conditions, including signed/unsigned wraparound, truncation errors, and arithmetic operations that exceed type boundaries. It encompasses validation techniques such as range checking, pre-computation verification, and safe arithmetic libraries, distinguishing itself from memory-safe functions (which address buffer operations) and format string controls (which address string interpretation vulnerabilities). The scope excludes general input validation, type confusion vulnerabilities, and overflow conditions in non-integer data types such as floating-point arithmetic.", "generated_at": "2026-04-28T23:24:04.193709+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Memory, String, and Unmanaged Code > Check boundaries against integer overflow weaknesses", "hub_id": "482-771", "hub_name": "Check boundaries against integer overflow weaknesses", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "482-866": { "description": "This hub covers requirements for encrypting personally identifiable information (PII) and sensitive personal data while stored in databases, file systems, backups, and other persistent storage mechanisms, including data subject to privacy regulations like GDPR. It encompasses encryption key management, algorithm selection, and implementation patterns specific to personal data protection, distinct from health data (which requires HIPAA-compliant encryption) and financial data (which requires PCI-DSS compliant encryption). This hub excludes encryption of data in transit, encryption of non-personal regulated data types, and general-purpose encryption not specific to personal data protection requirements.", "generated_at": "2026-04-28T23:24:04.290717+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Securely store regulated data > Encrypt personal data at rest", "hub_id": "482-866", "hub_name": "Encrypt personal data at rest", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "483-253": { "description": "This hub covers testing methodologies to detect and prevent indirect prompt injection attacks, where malicious instructions are embedded in external data sources (documents, emails, web pages) that AI systems process, causing them to execute unintended commands when users interact with that content. It focuses on validation techniques for scenarios where attackers compromise AI behavior through poisoned context rather than direct user input, including testing retrieval-augmented generation systems, document processors, and multi-modal AI applications that consume external content. This hub excludes direct prompt injection (where users directly input malicious prompts), other adversarial attacks like evasion or model extraction, and general AI performance validation unrelated to security vulnerabilities.", "generated_at": "2026-04-29T15:54:30.849435+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > Testing against indirect prompt injection", "hub_id": "483-253", "hub_name": "Testing against indirect prompt injection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "483-715": { "description": "This hub covers the implementation of HTTP method restrictions by explicitly allowing only necessary methods (GET, POST, PUT, DELETE, etc.) for each endpoint while blocking all others, including proper handling of OPTIONS for CORS preflight requests. It focuses specifically on method-level access control at the application layer, distinct from its siblings which address CORS resource whitelisting, Origin header security, and proxy-added header authentication. The scope is limited to HTTP method validation and does not cover request body validation, parameter sanitization, or authentication/authorization mechanisms beyond method-level restrictions.", "generated_at": "2026-04-28T23:24:06.763099+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Validate HTTP request headers > White-list HTTP methods", "hub_id": "483-715", "hub_name": "White-list HTTP methods", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "483-883": { "description": "This hub covers requirements for implementing cryptographically secure stateless tokens (such as JWTs) including proper digital signatures, encryption algorithms, key management, and protection against specific attacks like replay, null cipher, and key substitution. It focuses on the cryptographic properties and implementation details that ensure token integrity and authenticity cannot be compromised through manipulation or cryptographic weaknesses. This hub specifically addresses stateless token security and does not cover session management using server-side state, cookie-based sessions without cryptographic protection, or general authentication mechanisms beyond token integrity verification.", "generated_at": "2026-04-28T23:24:09.220998+00:00", "hierarchy_path": "Technical application security controls > Session management > Session integrity > When using stateless tokens, ensure cryptographically secure characteristics", "hub_id": "483-883", "hub_name": "When using stateless tokens, ensure cryptographically secure characteristics", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "486-813": { "description": "The Configuration hub covers requirements for establishing, maintaining, and enforcing secure baseline configurations across systems, applications, and infrastructure components, including hardening standards, default settings management, and configuration drift prevention. Unlike its sibling hubs that address specific attack vectors (CSRF, SSRF, XSS) or functional domains (Cryptography, Personal data handling), this hub focuses on the systematic management of configuration states and settings that prevent security misconfigurations across all technology layers. This hub excludes architectural design decisions (covered by Architecture), specific protection mechanisms (covered by respective protection hubs), and runtime behavioral controls, instead concentrating on static configuration parameters and their governance processes.", "generated_at": "2026-04-28T23:24:10.855320+00:00", "hierarchy_path": "Cross-cutting concerns > Configuration", "hub_id": "486-813", "hub_name": "Configuration", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "487-305": { "description": "This hub covers requirements for implementing password visibility toggle features that allow users to temporarily unmask their password input during authentication, either revealing the entire password or just the most recently typed character. It encompasses both custom implementations for platforms lacking native support and the security considerations for preventing shoulder-surfing while maintaining usability. This hub specifically addresses visual feedback mechanisms during password entry, distinguishing it from \"Allow password helpers, including paste functionality\" which focuses on input methods and clipboard operations rather than display controls. The scope is limited to temporary visibility options during active password entry and does not cover password storage display, password strength indicators, or post-authentication password management features.", "generated_at": "2026-04-28T23:24:12.493751+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Login functionality > Provide options to view entire password or last typed character", "hub_id": "487-305", "hub_name": "Provide options to view entire password or last typed character", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "488-626": { "description": "Training data obfuscation encompasses techniques that transform or mask sensitive attributes in AI training datasets while preserving their statistical properties and model utility, including differential privacy, data perturbation, synthetic data generation, and privacy-preserving transformations. Unlike data minimization which reduces data volume, federated learning which distributes computation, or retention management which controls data lifecycle, this hub specifically addresses methods that modify data representation to prevent reconstruction of original sensitive information while maintaining training effectiveness. This hub excludes post-training model privacy techniques, inference-time protections, and organizational data governance policies, focusing solely on technical transformations applied to training data before model development.", "generated_at": "2026-04-28T23:24:13.411059+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI impact reduction controls > AI data reduction > Training data obfuscation", "hub_id": "488-626", "hub_name": "Training data obfuscation", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "504-340": { "description": "This hub covers the implementation of authenticated encryption algorithms (such as AES-GCM, ChaCha20-Poly1305) that simultaneously provide confidentiality through encryption and integrity through authentication tags for sensitive data at rest. It encompasses algorithm selection, proper implementation including secure key management, and verification that both properties are achieved through cryptographic primitives that resist tampering and unauthorized access. This hub specifically addresses algorithms with built-in integrity protection, distinguishing it from \"Encryption algorithms\" which may cover confidentiality-only schemes, and focuses on cryptographic implementation rather than the data classification aspects covered by \"Securely store regulated data\" or the key management practices in \"Treat client-secrets as insecure.\" The scope excludes data in transit encryption, algorithm-specific vulnerabilities not related to the confidentiality-integrity combination, and non-cryptographic data protection methods.", "generated_at": "2026-04-28T23:24:14.799276+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encrypt sensitive data with algorithms that provide both confidentiality and integrity", "hub_id": "504-340", "hub_name": "Encrypt sensitive data with algorithms that provide both confidentiality and integrity", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "508-702": { "description": "This hub covers requirements for implementing dedicated key vault services (such as AWS KMS, Azure Key Vault, or HashiCorp Vault) to store and manage cryptographic keys, certificates, and secrets through centralized, hardware-backed security modules with access control, audit logging, and key lifecycle management capabilities. It focuses specifically on using enterprise-grade key vault solutions rather than application-level storage mechanisms, distinguishing it from siblings that address algorithmic requirements (work factors, salt generation), implementation patterns (code-level storage, isolated modules), or general secrets management without vault-specific features. This hub does not cover the cryptographic algorithms themselves, key generation procedures, or requirements for secrets that are stored outside of key vault systems such as in configuration files or databases.", "generated_at": "2026-04-28T23:24:17.022144+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Use key vaults", "hub_id": "508-702", "hub_name": "Use key vaults", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "510-324": { "description": "Compliance encompasses the systematic processes for ensuring organizational adherence to internal security policies, external regulations, and industry standards through continuous monitoring, assessment, and remediation activities. This hub covers compliance program management, regulatory mapping, control implementation verification, non-conformance tracking, and liaison with regulatory authorities and external auditors. The scope excludes the actual security controls being verified (covered under their respective domains), policy creation processes (covered under Policy Management), and internal audit methodologies (covered under Internal Audit).", "generated_at": "2026-04-28T23:24:15.996116+00:00", "hierarchy_path": "Governance processes for security > Assurance processes > Audit & accountability > Compliance", "hub_id": "510-324", "hub_name": "Compliance", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "513-845": { "description": "This hub covers requirements for generating multi-factor authentication lookup secrets (such as backup codes, recovery codes, or grid-based authentication values) with sufficient randomness and unpredictability to resist offline brute-force and prediction attacks. It specifically addresses the entropy and randomness characteristics of pre-generated secrets that users store for future authentication use, ensuring these values cannot be guessed or derived through pattern analysis. Unlike sibling hubs that focus on one-time usage constraints, communication channels, or specific authenticator types like biometrics or OTP tokens, this hub exclusively addresses the cryptographic strength of lookup secret generation. It does not cover the storage, transmission, or usage policies of these secrets, nor does it address dynamic authentication factors like time-based OTPs or push notifications.", "generated_at": "2026-04-28T23:24:20.029385+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Use unpredictable multi-factor lookup secrets", "hub_id": "513-845", "hub_name": "Use unpredictable multi-factor lookup secrets", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers ensuring MFA lookup secrets, such as backup codes or recovery codes, are unpredictable and not user chosen, sequential, patterned, derived from account data, or generated by weak deterministic processes. It focuses on the qualitative unpredictability requirement that makes each lookup secret resistant to guessing and prediction. It does not cover explicit entropy thresholds or generation formulas, single use invalidation, storage format, delivery to users, or revocation of lookup secrets.", "reviewer_notes": "Original substantially duplicated the sibling hub on sufficient entropy for lookup secret generation; replacement distinguishes unpredictability from explicit entropy requirements.", "temperature": 0.0 }, "515-021": { "description": "This hub covers the implementation of network-level isolation techniques including sandboxing, containerization, and network segmentation to prevent lateral movement between applications and contain potential compromises. It encompasses deployment architectures that create network boundaries between applications of different trust levels, particularly for high-risk operations like deserialization, through technologies such as container networking, microsegmentation, and virtualized network functions. This hub excludes host-level isolation mechanisms, application-layer security controls, and general network defense techniques like intrusion detection or firewall rules that don't specifically create isolated execution environments.", "generated_at": "2026-04-28T23:24:19.163694+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Network security > Sandbox, containerize and/or isolate applications at the network level", "hub_id": "515-021", "hub_name": "Sandbox, containerize and/or isolate applications at the network level", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "522-616": { "description": "Media protection encompasses controls for securing physical and digital storage media throughout their lifecycle, including classification marking, access restrictions, secure transport, sanitization procedures, and controlled disposal of hard drives, tapes, optical discs, and removable storage devices. Unlike endpoint management which focuses on device configuration and network security which addresses data in transit, this hub specifically addresses data at rest on portable media and the physical handling procedures required to prevent unauthorized disclosure or modification. The scope excludes backup procedures (covered under Backup), general equipment security (Equipment management), and environmental controls for media storage facilities (Physical & environment protection).", "generated_at": "2026-04-28T23:24:21.030874+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Media protection", "hub_id": "522-616", "hub_name": "Media protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "524-446": { "description": "This hub covers requirements for enforcing multi-factor authentication (MFA) as a mandatory security control, including policies, implementation standards, and compliance verification mechanisms that ensure users must authenticate with multiple independent factors before accessing protected resources. It encompasses organizational mandates, technical enforcement mechanisms, exception handling procedures, and monitoring capabilities to ensure MFA adoption across systems and user populations. Unlike its sibling hubs that focus on specific MFA implementation details (such as OTP generation algorithms, authenticator types, or cryptographic specifications), this hub addresses the governance and policy layer that requires MFA usage rather than how individual MFA components function. This hub does not cover the technical specifications of MFA mechanisms themselves, user experience design, or specific authentication flow implementations—only the requirements for mandating and enforcing that MFA be used.", "generated_at": "2026-04-28T23:24:23.910556+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Mandate using multi factor authentication", "hub_id": "524-446", "hub_name": "Mandate using multi factor authentication", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "524-603": { "description": "This hub covers requirements for restricting the ability to modify, create, or delete access control configurations (including roles, permissions, policies, and access rules) to only those users explicitly authorized for access control administration. It encompasses protections against unauthorized manipulation of access control metadata, policy definitions, and permission assignments through both direct administrative interfaces and indirect methods like parameter tampering or injection attacks. Unlike its siblings which focus on limiting end-user permissions and access to functionality, this hub specifically addresses who can change the access control system itself, not who can access protected resources. It does not cover the enforcement of existing access controls, the principle of least privilege for regular operations, or the initial permission states of users.", "generated_at": "2026-04-28T23:24:24.576850+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Minimize permissions > Limit modification of access controls to specifically authorized actors/users", "hub_id": "524-603", "hub_name": "Limit modification of access controls to specifically authorized actors/users", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "525-361": { "description": "This hub covers authentication mechanisms that require active user participation through either manual entry of one-time password tokens (numeric codes from authenticator apps, SMS, or hardware tokens) or physical interaction with a multi-factor device (button press on FIDO keys, biometric scan on security keys). It encompasses both time-based and counter-based OTP implementations as well as cryptographic challenge-response protocols initiated by user action. This hub differs from sibling hubs by focusing on the user interaction aspect of authentication rather than the cryptographic generation, storage, or transmission of authentication factors - it addresses the moment of authentication verification through user input, not the backend processes or security requirements for generating or managing those factors. The scope excludes passive authentication methods (like proximity-based or continuous authentication), authentication factor generation algorithms, secure storage mechanisms, and policy decisions about which authentication methods to prioritize or mandate.", "generated_at": "2026-04-28T23:24:28.799486+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Authenticate by OTP token entry or user-initiated action on multi factor device", "hub_id": "525-361", "hub_name": "Authenticate by OTP token entry or user-initiated action on multi factor device", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "527-034": { "description": "This hub covers encryption requirements for data transmission between distinct application components, including microservices, APIs, databases, message queues, and other internal services that communicate across process boundaries, containers, or network segments. It focuses on implementing transport-layer security (TLS/SSL) and application-layer encryption for inter-component communication channels, preventing eavesdropping and man-in-the-middle attacks on internal application traffic. Unlike its sibling hub which addresses message integrity and authentication through cryptographic signatures, this hub specifically targets confidentiality through encryption of the communication channel itself. The scope excludes encryption of data at rest, client-to-application encryption, and authentication mechanisms—it strictly addresses the cryptographic protection of data in transit between application components.", "generated_at": "2026-04-28T23:24:26.918689+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Communication encryption > Protect communication between application components", "hub_id": "527-034", "hub_name": "Protect communication between application components", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "530-671": { "description": "This hub covers requirements for bidirectional authentication between application components, where each component cryptographically verifies the identity of the other component before establishing communication, typically through mutual TLS (mTLS) or similar protocols that validate certificates and chains on both sides. Unlike \"Authenticate all external connections\" which focuses on verifying external entities connecting to the application, this hub specifically addresses authentication between internal application components (microservices, APIs, databases), and unlike \"Enable certification revocation\" which handles certificate lifecycle management, this hub focuses on the authentication handshake itself. This hub does not cover authorization decisions after authentication, session management post-authentication, or the specific cryptographic algorithms used in the authentication process.", "generated_at": "2026-04-28T23:24:27.014452+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Communication authentication > Mutually authenticate application components", "hub_id": "530-671", "hub_name": "Mutually authenticate application components", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "531-558": { "description": "This hub covers security controls that prevent LDAP injection attacks by validating, sanitizing, or parameterizing user input before constructing LDAP queries, including techniques such as escaping LDAP special characters, using parameterized LDAP queries, and implementing allowlists for LDAP search filters. Unlike its sibling hubs that address injection vulnerabilities in other contexts (SQL, OS commands, XML), this hub specifically targets the LDAP protocol's unique syntax and metacharacters such as parentheses, asterisks, and null bytes that can modify LDAP query logic. This hub does not cover general LDAP authentication security, LDAP over TLS configuration, or directory permission models - it strictly addresses input validation and query construction to prevent injection attacks.", "generated_at": "2026-04-28T23:24:31.184380+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Protect against LDAP injection", "hub_id": "531-558", "hub_name": "Protect against LDAP injection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "532-102": { "description": "This hub covers testing methodologies to detect and prevent model inversion attacks, where adversaries reconstruct training data or input features by exploiting model outputs, gradients, or intermediate representations. It encompasses techniques for evaluating vulnerability to feature reconstruction, training data recovery, and attribute inference attacks through methods like gradient-based optimization, generative model inversion, and confidence score analysis. Unlike membership inference (determining if data was in training set) or model theft (replicating model functionality), this hub specifically addresses recovering actual data content; it excludes privacy-preserving training techniques and focuses solely on post-training vulnerability assessment.", "generated_at": "2026-04-28T23:24:30.667896+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > Testing against model inversion", "hub_id": "532-102", "hub_name": "Testing against model inversion", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "532-878": { "description": "This hub covers requirements for restricting HTTP methods (GET, POST, PUT, DELETE, PATCH, etc.) in REST APIs to only those necessary for each endpoint's functionality, preventing unauthorized operations through method-based access control. It focuses specifically on method-level restrictions at the HTTP protocol layer, distinct from content-type validation, encoding/parsing controls, or authentication/authorization logic that operate at different layers of the API stack. The scope excludes non-REST protocols (SOAP, GraphQL), general input validation, and abuse detection mechanisms that monitor patterns rather than individual method usage.", "generated_at": "2026-04-28T23:24:33.311525+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > Limit REST HTTP methods", "hub_id": "532-878", "hub_name": "Limit REST HTTP methods", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "533-516": { "description": "This hub covers techniques for encoding user-supplied data in output contexts while maintaining the original visual formatting and semantic meaning that users intended, such as preserving line breaks, spacing, and special characters through safe encoding methods like HTML entities or CSS white-space properties. It focuses specifically on the balance between security encoding and user experience preservation, distinguishing it from context-specific encoding which prioritizes interpreter-appropriate encoding over formatting retention, and from other injection prevention hubs that address specific attack vectors rather than formatting concerns. This hub does not cover input validation, sanitization of user data, or the prevention of specific injection attack types - it strictly addresses the output encoding phase where legitimate user formatting must be preserved while preventing interpretation as executable code.", "generated_at": "2026-04-28T23:24:35.761569+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Encode output while preserving user input formatting", "hub_id": "533-516", "hub_name": "Encode output while preserving user input formatting", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "533-635": { "description": "AI security Education encompasses the development and delivery of training programs, awareness initiatives, and competency frameworks specifically addressing AI/ML security risks, threat modeling, and secure development practices for all stakeholders involved in AI system lifecycle. This hub focuses on educational content design, delivery methods, and competency assessment for AI-specific security topics, distinguishing it from AI compliance management which handles regulatory adherence and audit processes. The scope excludes general cybersecurity training not specific to AI systems, compliance documentation, and operational security controls implementation.", "generated_at": "2026-04-28T23:24:34.422510+00:00", "hierarchy_path": "Governance processes for security > Organizational AI security controls > AI management system > AI security Education", "hub_id": "533-635", "hub_name": "AI security Education", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "534-605": { "description": "This hub covers controls that enforce the correct sequential order of multi-step business processes, preventing users from bypassing required steps, jumping ahead in workflows, or executing operations out of their intended sequence (such as accessing checkout before adding items to cart or submitting forms before completing prerequisites). It focuses specifically on maintaining the logical dependencies and temporal relationships between business process steps, distinct from its siblings that monitor for suspicious patterns, enforce timing constraints, set quantitative limits, or generate alerts. This hub does not cover detection of unusual user behavior patterns, enforcement of human-realistic timing between actions, rate limiting or threshold controls, or alerting mechanisms for anomalous usage - these are addressed by its sibling hubs under unusual activity detection.", "generated_at": "2026-04-28T23:24:38.507169+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Detect and prevent unusual activity > Enforce natural sequence of business flows to avoid abuse", "hub_id": "534-605", "hub_name": "Enforce natural sequence of business flows to avoid abuse", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "536-158": { "description": "This hub covers testing methodologies to detect and prevent direct prompt injection attacks where malicious users craft input prompts to manipulate AI model behavior, bypass safety controls, or execute unintended actions through the primary user interface. It encompasses validation of input sanitization, prompt filtering mechanisms, and model response boundaries when processing user-supplied prompts in conversational AI, code generation, and instruction-following systems. This hub excludes indirect prompt injection through external data sources, attacks targeting model architecture or training data (backdoor poisoning, model theft), privacy-focused attacks (membership inference, model inversion), and general model performance or robustness testing unrelated to prompt manipulation.", "generated_at": "2026-04-29T15:54:35.539032+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > Testing against direct prompt injection", "hub_id": "536-158", "hub_name": "Testing against direct prompt injection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "537-367": { "description": "This hub covers requirements for implementing and configuring certificate revocation mechanisms, including OCSP, OCSP Stapling, and CRL checking, to ensure applications can detect and reject communications using compromised or invalid certificates. It focuses specifically on the technical controls needed to query, cache, and enforce certificate revocation status during TLS/SSL handshakes and certificate validation processes. This hub does not cover the initial certificate validation process, certificate pinning, or the mutual authentication requirements between application components, which are addressed by sibling hubs.", "generated_at": "2026-04-28T23:24:38.614389+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Communication authentication > Enable certification revocation", "hub_id": "537-367", "hub_name": "Enable certification revocation", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "538-446": { "description": "This hub covers the sanitization of unstructured data formats that lack predefined schemas or rigid formatting rules, including free-text fields, log entries, file paths, URLs, and other variable-length string inputs that may contain special characters, delimiters, or control sequences. It encompasses techniques to neutralize malicious payloads embedded in such data by removing or escaping dangerous characters, enforcing length limits, validating against allowlists, and preventing injection attacks through delimiter manipulation, null byte injection, or encoding bypass techniques. Unlike its sibling hubs that address specific structured formats (HTML, SVG, GraphQL) or particular injection contexts (SMTP, template engines), this hub focuses on general-purpose string sanitization applicable across multiple contexts where the data format is not predetermined. It does not cover sanitization of structured data formats with defined grammars, binary data sanitization, or context-specific escaping rules that require understanding of the consuming system's parser.", "generated_at": "2026-04-28T23:24:43.370174+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > Sanitize unstructured data", "hub_id": "538-446", "hub_name": "Sanitize unstructured data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "540-566": { "description": "This hub covers implementing application-level permission request mechanisms that allow applications to explicitly declare and request only the minimum necessary permissions for their functionality, particularly for accessing privacy-sensitive resources like cameras, microphones, location services, and user data. It focuses on the application's ability to self-limit its permission scope through proper permission manifests, runtime permission requests, and granular permission models rather than requesting blanket access to system resources. Unlike its siblings which address enforcing restrictions externally (Enforce least privilege), limiting specific user types (Use least privilege OS accounts), or controlling administrative access (Limit access to admin/management functionality), this hub specifically addresses the application's own responsibility to minimize its permission footprint. It does not cover server-side access controls, network-level permissions, or the enforcement mechanisms that actually grant or deny the requested permissions - only the application's request behavior itself.", "generated_at": "2026-04-28T23:24:44.465866+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Minimize permissions > Let application request minimal permissions", "hub_id": "540-566", "hub_name": "Let application request minimal permissions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "542-445": { "description": "This hub covers the removal or encoding of dangerous HTML elements, attributes, and JavaScript from user-provided HTML content before rendering it in web applications, including sanitization of WYSIWYG editor output, user comments, and any HTML markup that could execute scripts or manipulate the DOM. It specifically addresses preventing XSS attacks through HTML injection vectors while preserving safe HTML formatting, distinguishing it from sibling hubs that handle other content types like SVG, template languages, or email headers. This hub does not cover sanitization of non-HTML formats, server-side code injection, or input validation for data that won't be rendered as HTML.", "generated_at": "2026-04-28T23:24:44.982229+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > Sanitize untrusted HTML input", "hub_id": "542-445", "hub_name": "Sanitize untrusted HTML input", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "542-488": { "description": "This hub covers the implementation and verification of cryptographically secure random number generators (CSRNGs) for generating unpredictable values in security-critical contexts such as session tokens, cryptographic keys, nonces, and initialization vectors. It encompasses the selection of approved CSRNG algorithms (like /dev/urandom, CryptGenRandom, or NIST-approved DRBGs), proper seeding mechanisms, and validation that the implementation resists statistical analysis and prediction attacks. Unlike its sibling hubs that focus on specific applications (GUIDs) or general secure random generation principles, this hub specifically addresses the cryptographic properties and implementation requirements of the RNG itself. It does not cover the usage patterns of generated random values, performance optimization of random number generation, or non-security random number requirements like Monte Carlo simulations.", "generated_at": "2026-04-28T23:24:45.632587+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secure random values > Use cryptographically secure random number generators", "hub_id": "542-488", "hub_name": "Use cryptographically secure random number generators", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "543-428": { "description": "This hub covers requirements for storing one-time password (OTP) verification keys within hardware security modules (HSMs) or secure operating system-based key storage facilities to protect the symmetric keys used in OTP validation processes. It focuses specifically on the secure storage infrastructure for OTP verification keys, ensuring these cryptographic materials are isolated from general-purpose storage and protected against extraction or tampering. Unlike sibling hubs that address OTP generation algorithms, transmission methods, or usage policies, this hub exclusively concerns the physical or logical security boundaries where OTP verification keys reside. It does not cover the OTP generation process, distribution mechanisms, validation logic, or user-facing authentication flows - only the hardened storage requirements for the server-side keys that verify submitted OTP values.", "generated_at": "2026-04-28T23:24:46.145572+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Use security module to store one-time password verification keys", "hub_id": "543-428", "hub_name": "Use security module to store one-time password verification keys", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "543-512": { "description": "This hub covers requirements for validating and enforcing correct Content-Type headers in REST service requests, ensuring services reject requests with missing, incorrect, or unexpected media types (e.g., accepting only application/json when JSON is expected). It encompasses both the verification logic implementation and proper error handling when Content-Type mismatches occur, preventing attacks like HTTP request smuggling and parser confusion vulnerabilities. This hub specifically addresses Content-Type validation while its sibling focuses on CSRF token implementation for cookie-authenticated REST services. The scope excludes other HTTP header validations, response Content-Type settings, or content parsing/sanitization after type verification.", "generated_at": "2026-04-28T23:24:50.240826+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > RESTful > Verify content-type for REST services", "hub_id": "543-512", "hub_name": "Verify content-type for REST services", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "543-621": { "description": "This hub covers requirements for password recovery mechanisms that prevent disclosure of the user's current password through any channel during the recovery process, including error messages, recovery emails, temporary passwords, or system responses. It specifically addresses the security principle that existing credentials must remain confidential even when a user initiates account recovery, distinguishing it from sibling hubs that focus on recovery communication encryption, identity verification strength, recovery mechanism security, and authentication factor selection. This hub does not cover the strength of new passwords set during recovery, the authentication methods used to verify identity during recovery, or the security of the recovery communication channel itself - only that the current password must not be exposed during the recovery workflow.", "generated_at": "2026-04-28T23:24:51.093860+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Credential recovery > Do not reveal the current password during password recovery", "hub_id": "543-621", "hub_name": "Do not reveal the current password during password recovery", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "545-243": { "description": "This hub covers security controls that prevent uploaded files from being executed as code or rendered as active content by the application or web server, including blocking script execution in upload directories, setting non-executable permissions, and serving files with content-type headers that prevent browser interpretation. It focuses specifically on neutralizing uploaded files after they reach the server through configuration and access controls, distinct from validation during upload (covered by \"Validate file type\") or the upload process itself (covered by \"File upload\"). This hub does not cover file storage security, download protections, or pre-upload validation mechanisms.", "generated_at": "2026-04-28T23:24:51.597667+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > Block execution/output of uploaded files", "hub_id": "545-243", "hub_name": "Block execution/output of uploaded files", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "547-283": { "description": "This hub covers security controls that prevent Local File Inclusion (LFI) and Remote File Inclusion (RFI) attacks, where attackers manipulate file path parameters to include unauthorized local files or remote code into the application's execution context. It encompasses validation of file paths, restriction of file operations to safe directories, disabling dangerous functions like PHP's include/require with user input, and implementing allowlists for acceptable file references. Unlike its sibling hubs that focus on encoding output for specific contexts (XSS, SQL, LDAP) or parameterizing queries, this hub specifically addresses file system traversal and code inclusion vulnerabilities through path manipulation. It does not cover general command injection, deserialization attacks, or malicious file upload content validation, focusing solely on preventing the inclusion of unintended files through path manipulation techniques.", "generated_at": "2026-04-28T23:24:53.053304+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Protect against LFI / RFI", "hub_id": "547-283", "hub_name": "Protect against LFI / RFI", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "547-824": { "description": "AI model performance validation encompasses testing and verification of AI models' functional correctness, accuracy metrics, and operational behavior under expected conditions, including validation of training/test data quality, model convergence, prediction reliability, and performance degradation over time. This hub covers performance benchmarking, drift detection, and functional testing of model outputs against defined acceptance criteria, distinguishing it from security-focused siblings that address adversarial attacks, data extraction, or malicious manipulation. It excludes security vulnerability testing, adversarial robustness evaluation, and privacy attack resistance, focusing solely on whether the model performs its intended function correctly and maintains that performance throughout its lifecycle.", "generated_at": "2026-04-28T23:25:33.701515+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > AI model performance validation", "hub_id": "547-824", "hub_name": "AI model performance validation", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "551-054": { "description": "This hub covers requirements for implementing time-limited, dynamically generated secrets (such as session tokens, temporary API keys, and OAuth tokens) instead of permanent credentials like hardcoded API keys or static passwords. It encompasses the generation, rotation, and expiration mechanisms for ephemeral secrets, including proper entropy sources, secure storage during their lifetime, and automatic invalidation processes. This hub does not cover the cryptographic algorithms or protocols used to secure tokens (covered by the sibling hub on cryptographically secure characteristics), nor does it address the broader session lifecycle management or authentication mechanisms that generate these secrets.", "generated_at": "2026-04-28T23:24:57.515679+00:00", "hierarchy_path": "Technical application security controls > Session management > Session integrity > Use ephemeral secrets rather than static secrets", "hub_id": "551-054", "hub_name": "Use ephemeral secrets rather than static secrets", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "551-400": { "description": "This hub covers requirements for implementing user-controlled OAuth token revocation mechanisms, enabling users to terminate access granted to third-party applications through OAuth authorization flows. It encompasses the technical controls for token invalidation endpoints, user interfaces for viewing and revoking active tokens, and the immediate propagation of revocation across all relying parties. Unlike its siblings which focus on authentication event propagation and timeout enforcement with identity providers, this hub specifically addresses post-authorization token lifecycle management from the user's perspective. The scope excludes administrative token revocation, token expiration policies, and OAuth grant flow security - it strictly covers user-initiated revocation capabilities for already-issued OAuth access and refresh tokens.", "generated_at": "2026-04-28T23:24:58.184175+00:00", "hierarchy_path": "Technical application security controls > Session management > Re-authentication from federation or assertion > Allow user revocation of Oauth tokens", "hub_id": "551-400", "hub_name": "Allow user revocation of Oauth tokens", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "553-413": { "description": "This hub covers requirements for applications to accept and integrate authentication devices that users bring and manage themselves, such as FIDO security keys, U2F tokens, or personal hardware authenticators. It encompasses the technical controls needed to register, validate, and manage these external devices within the application's authentication framework, including device attestation, secure enrollment processes, and revocation mechanisms. Unlike sibling hubs that focus on specific authenticator types (biometric, OTP) or implementation details (entropy, algorithms), this hub specifically addresses the infrastructure and processes required to support user-owned hardware tokens regardless of their underlying technology. This hub does not cover application-generated authenticators (SMS, TOTP apps), software-based credentials, or the cryptographic specifications of the authentication protocols themselves—only the application's ability to interface with and manage externally-provided authentication devices.", "generated_at": "2026-04-28T23:24:59.935422+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Support subscriber-provided authentication devices", "hub_id": "553-413", "hub_name": "Support subscriber-provided authentication devices", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "555-048": { "description": "This hub covers requirements for logging events with sufficient temporal precision and contextual data to enable accurate reconstruction of event sequences, including timestamps with adequate granularity, sequence identifiers, and correlation data between related events. It focuses specifically on the ordering and sequencing aspects of logging, distinct from siblings that address what types of events to log (security-relevant events, access control, authentication) or special handling for sensitive data logging. This hub does not cover log storage, retention, protection mechanisms, or the specific content requirements for individual event types - only the temporal and sequential metadata necessary for event ordering.", "generated_at": "2026-04-28T23:25:00.051598+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log relevant > Log events sufficiently to recreate their order", "hub_id": "555-048", "hub_name": "Log events sufficiently to recreate their order", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "555-083": { "description": "This hub covers testing methodologies to detect and validate against backdoor attacks where malicious triggers are embedded during AI model training to cause misclassification or unintended behavior when specific inputs are presented. It encompasses techniques for identifying poisoned training data, detecting hidden model behaviors activated by backdoor triggers, and validating model integrity against trojan patterns inserted through compromised datasets or training pipelines. This hub specifically addresses pre-deployment contamination of AI models through training manipulation, distinguishing it from runtime attacks (evasion, prompt injection) or post-deployment extraction attacks (model theft, inversion, membership inference). It excludes testing for naturally occurring biases, performance degradation from benign data drift, or attacks that don't involve deliberate training-time model corruption.", "generated_at": "2026-04-29T15:54:37.538923+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > Testing against backdoor poisoning", "hub_id": "555-083", "hub_name": "Testing against backdoor poisoning", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "558-807": { "description": "This hub covers requirements for establishing bidirectional cryptographic authentication between applications and external Credential Service Providers (CSPs), ensuring both parties verify each other's identity through mutual TLS authentication before exchanging authentication data. It specifically addresses the secure channel establishment and certificate-based trust validation required when authentication verification is delegated to a separate CSP, preventing man-in-the-middle attacks and unauthorized credential interception during the authentication handshake. This hub does not cover the authentication mechanisms themselves (covered by sibling hubs like MFA/OTP), internal authentication within a single application boundary, or general TLS configuration beyond the mutual authentication context.", "generated_at": "2026-04-28T23:25:04.581624+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Mutually authenticate application and credential service provider", "hub_id": "558-807", "hub_name": "Mutually authenticate application and credential service provider", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "560-224": { "description": "Planning and resource management encompasses the allocation, capacity planning, and optimization of security resources including personnel, budget, tools, and infrastructure to meet organizational security objectives. This hub covers resource baseline selection and tailoring, capacity management processes, and the establishment of resource-related rules of behavior, distinguishing it from Program management which focuses on overall security program governance and execution rather than specific resource allocation decisions. The scope excludes strategic program direction, security architecture design, and operational deployment of resources, focusing instead on the planning frameworks and resource decision-making processes themselves.", "generated_at": "2026-04-28T23:25:04.982916+00:00", "hierarchy_path": "Governance processes for security > Security organizing processes > Planning and resource management", "hub_id": "560-224", "hub_name": "Planning and resource management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "567-025": { "description": "Train data distortion covers techniques that modify or transform existing training samples to neutralize backdoor triggers while preserving the model's primary task performance. This hub encompasses methods like input preprocessing, data augmentation, and adversarial perturbations that alter the statistical properties of potentially poisoned samples without removing them entirely from the dataset. Unlike its siblings that focus on dataset expansion (Benign train data increase), architectural changes (Model size reduction), or post-training modifications (Benign fine-tuning and pruning), this hub specifically addresses in-place transformations of the training data itself. It excludes complete removal of suspicious samples (covered under data sanitization) and does not cover detection mechanisms or model-level defenses.", "generated_at": "2026-04-28T23:25:07.114202+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > Weakening training set backdoors > Train data distortion", "hub_id": "567-025", "hub_name": "Train data distortion", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "570-487": { "description": "Manual penetration testing encompasses human-driven security assessments where skilled testers actively probe applications, systems, and networks to identify vulnerabilities through techniques like exploitation attempts, privilege escalation, and business logic manipulation that require human intuition and creativity. Unlike automated dynamic security testing which relies on tools and scripts to scan for known vulnerability patterns, manual penetration testing involves adaptive methodologies where testers chain multiple vulnerabilities, bypass security controls, and simulate real attacker behaviors based on contextual understanding. This hub excludes automated vulnerability scanning, static code analysis, and security testing that can be fully scripted or performed without human decision-making during execution.", "generated_at": "2026-04-28T23:25:08.886887+00:00", "hierarchy_path": "Development processes for security > Verification > Dynamic security testing > Manual penetration testing", "hub_id": "570-487", "hub_name": "Manual penetration testing", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "571-640": { "description": "Personal data handling management encompasses the operational controls and procedures for processing, storing, and protecting personally identifiable information (PII) throughout its lifecycle, including consent management, privacy notices, data minimization, de-identification, and quality operations. This hub focuses on the implementation of privacy-specific controls and PII processing activities, distinguishing it from Data classification and handling which addresses general data categorization and protection requirements across all data types. The scope excludes broader privacy governance structures, privacy impact assessments, and general data security controls that apply to non-personal data.", "generated_at": "2026-04-28T23:25:09.989314+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Asset management > Personal data handling management", "hub_id": "571-640", "hub_name": "Personal data handling management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "576-042": { "description": "This hub covers requirements for maintaining uniform authentication strength across all authentication pathways, APIs, and identity management interfaces within an application, ensuring no pathway offers weaker security controls that could be exploited as a bypass. It encompasses consistency checks for authentication mechanisms, enforcement of minimum authentication standards across all entry points, and prevention of authentication downgrade attacks. Unlike \"Mutually authenticate application components\" which focuses on bidirectional trust between system components, and \"Minimize privileges\" which addresses post-authentication access controls, this hub specifically addresses the uniformity of authentication strength regardless of the pathway used. It does not cover the specific authentication methods themselves, privilege management after authentication, or the mutual authentication protocols between components.", "generated_at": "2026-04-28T23:25:11.639854+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Authenticate consistently > Consistently apply authentication strength", "hub_id": "576-042", "hub_name": "Consistently apply authentication strength", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "576-262": { "description": "This hub covers controls for detecting and mitigating coordinated sequences of malicious inputs designed to manipulate AI model behavior over multiple inference requests, including prompt injection chains, context poisoning attacks, and multi-turn adversarial strategies. It focuses specifically on identifying patterns across input series that indicate systematic exploitation attempts, distinguishing it from single-input anomaly detection (covered by Anomalous AI input handling) and volumetric protections (covered by Rate limiting). The scope excludes access restrictions to the inference endpoint, monitoring of model outputs or performance metrics, and detection of individual adversarial examples in isolation—addressing only the temporal and sequential relationships between inputs that constitute an attack campaign.", "generated_at": "2026-04-28T23:25:14.300307+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Generic input attack controls at inference > Unwanted AI input series handling", "hub_id": "576-262", "hub_name": "Unwanted AI input series handling", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "576-651": { "description": "This hub covers implementing validation mechanisms that check user-submitted passwords against databases of known compromised credentials, typically using local breach lists (e.g., top 10,000 common passwords) or external APIs with privacy-preserving techniques like k-anonymity or zero-knowledge proofs. Unlike sibling controls that focus on password composition rules (length, character types, rotation), this hub specifically addresses preventing the reuse of passwords that have been exposed in data breaches, requiring users to select alternative passwords when matches are detected. The scope excludes password strength metrics, composition requirements, or storage mechanisms, focusing solely on the breach status verification process during password creation or change operations.", "generated_at": "2026-04-28T23:25:15.503091+00:00", "hierarchy_path": "Technical application security controls > Authentication > Credentials directives > Validate new passwords are not in commonly breached passwords list", "hub_id": "576-651", "hub_name": "Validate new passwords are not in commonly breached passwords list", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "577-260": { "description": "This hub covers implementing cryptographic integrity verification mechanisms for assets loaded from external sources, such as using Subresource Integrity (SRI) hashes to validate JavaScript libraries, CSS files, and web fonts served from CDNs or third-party providers. Unlike sibling hubs that focus on pre-deployment code analysis (malicious code, backdoors, timebombs) or runtime isolation (sandboxing), this hub specifically addresses runtime verification of external resources through hash-based integrity checks. The scope is limited to integrity verification of externally hosted assets and does not cover authentication of asset sources, vulnerability scanning, or integrity checks for internally hosted resources.", "generated_at": "2026-04-28T23:25:47.642805+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency integrity > Enforce integrity check for externally hosted assets (eg SRI)", "hub_id": "577-260", "hub_name": "Enforce integrity check for externally hosted assets (eg SRI)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "581-525": { "description": "This hub covers the implementation of cryptographically secure password recovery mechanisms that verify user identity without exposing credentials, including time-based OTP (TOTP), soft tokens, mobile push notifications, and offline recovery codes. It focuses on the technical security properties of the recovery mechanism itself - ensuring tamper resistance, replay protection, and secure token generation/validation - rather than the identity verification process or communication security aspects covered by sibling hubs. This hub excludes password hints, security questions, or knowledge-based authentication (which are inherently insecure), the encryption of recovery tokens during transmission (covered by \"Send authentication secrets encrypted\"), and the identity proofing requirements during recovery (covered by \"Require proof of identity of the same level as during enrollment\").", "generated_at": "2026-04-28T23:25:17.560012+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Credential recovery > Use secure recovery mechanisms for forgotten passwords", "hub_id": "581-525", "hub_name": "Use secure recovery mechanisms for forgotten passwords", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "582-541": { "description": "This hub covers requirements for forcing users to re-authenticate or provide secondary verification before executing sensitive operations such as financial transactions, password changes, privilege modifications, or accessing critical data. It encompasses mechanisms like step-up authentication, transaction-specific PINs, biometric confirmation, and time-based re-authentication challenges that occur within an existing authenticated session. Unlike session token generation or cookie configuration which focus on session establishment and transport security, this hub specifically addresses authentication elevation during an active session. It does not cover initial authentication requirements, federated authentication flows, or general session timeout policies unless they are triggered specifically by sensitive transaction attempts.", "generated_at": "2026-04-28T23:25:20.744486+00:00", "hierarchy_path": "Technical application security controls > Session management > Re-authenticate before sensitive transactions", "hub_id": "582-541", "hub_name": "Re-authenticate before sensitive transactions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "604-025": { "description": "This hub covers requirements for implementing visual or programmatic feedback mechanisms that evaluate and communicate password strength to users during password creation or modification, typically through indicators showing weak/medium/strong ratings based on entropy, length, and complexity factors. It focuses specifically on the user interface component that guides password selection, distinct from sibling hubs that enforce backend validation rules like minimum length, character requirements, or breach list checking. The scope includes the presentation layer and calculation algorithms for strength assessment but excludes the actual enforcement of password policies, storage mechanisms, or authentication protocols themselves.", "generated_at": "2026-04-28T23:25:22.346348+00:00", "hierarchy_path": "Technical application security controls > Authentication > Credentials directives > Provide a password strength meter", "hub_id": "604-025", "hub_name": "Provide a password strength meter", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "605-735": { "description": "This hub covers requirements for authenticating all connections originating from outside the application's trust boundary, including API calls, web requests, and service-to-service communications from external systems. It encompasses verification of caller identity through mechanisms like API keys, OAuth tokens, client certificates, or other authentication protocols before granting access to application resources. Unlike \"Mutually authenticate application components\" which focuses on bidirectional authentication between internal components, this hub addresses unidirectional authentication of external entities only. It excludes certificate management and revocation mechanisms (covered by \"Enable certification revocation\") and does not address authentication between internal application components or user authentication workflows.", "generated_at": "2026-04-28T23:25:23.084810+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Communication authentication > Authenticate all external connections", "hub_id": "605-735", "hub_name": "Authenticate all external connections", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "607-671": { "description": "This hub covers security controls that prevent malicious JavaScript code or JSON payloads from being injected and executed through application inputs, including protection against JSON eval attacks, JavaScript expression evaluation, and dynamic script injection in both server-side and client-side contexts. It focuses specifically on JavaScript and JSON injection vectors, distinguishing it from sibling hubs that address other injection types (XML/XPath, LDAP, OS commands) or broader output encoding strategies (context-specific encoding, XSS escaping). This hub does not cover general input validation, parameterized queries for SQL injection, or injection attacks targeting non-JavaScript interpreters and data formats.", "generated_at": "2026-04-28T23:25:27.046035+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Protect against JS or JSON injection attacks", "hub_id": "607-671", "hub_name": "Protect against JS or JSON injection attacks", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "611-051": { "description": "This hub covers the implementation of XML schema validation (XSD) to enforce strict structural and data type constraints on SOAP message payloads, ensuring that XML elements, attributes, and their values conform to predefined schemas before processing. It encompasses schema definition, validation engine configuration, and rejection of malformed or non-conforming XML inputs to prevent injection attacks and parser exploitation. Unlike its sibling \"Add integrity check to SOAP payload\" which focuses on cryptographic verification of message authenticity and tampering detection, this hub specifically addresses syntactic and semantic validation of XML structure. This hub does not cover message-level security features like encryption, digital signatures, or transport-layer protections, nor does it address non-XML data formats or general input validation outside the SOAP/XML context.", "generated_at": "2026-04-28T23:25:28.580726+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > SOAP > Enforce schema on XML structure/field", "hub_id": "611-051", "hub_name": "Enforce schema on XML structure/field", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "611-158": { "description": "This hub covers the implementation and configuration of static analysis tools specifically designed to identify code patterns and behaviors indicative of malicious intent, such as unauthorized network connections, suspicious file operations, time-based triggers for logic bombs, unsafe ActiveX methods, and injection vulnerabilities in WebViews. It focuses on detecting intentionally harmful code constructs and backdoors rather than general security vulnerabilities or coding errors, requiring tools with rulesets and heuristics specifically tuned to recognize obfuscation techniques, data exfiltration patterns, and other indicators of malicious behavior. This hub does not cover static analysis for general code quality issues, performance problems, or unintentional security weaknesses like buffer overflows or SQL injection vulnerabilities that arise from coding mistakes rather than malicious intent.", "generated_at": "2026-04-28T23:25:30.561642+00:00", "hierarchy_path": "Development processes for security > Verification > Automated static security analysis of code and configuration > Use static analysis tooling to detect potentially malicious actions", "hub_id": "611-158", "hub_name": "Use static analysis tooling to detect potentially malicious actions", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers automated static analysis configured to detect code constructs that suggest intentionally malicious behavior, such as hidden remote access paths, credential theft, unauthorized outbound communication, destructive file operations, time triggered logic, obfuscation, or covert data exfiltration. It focuses on malicious intent indicators in source code and configuration, not ordinary vulnerability discovery. It does not cover general code quality, performance issues, unintentional coding weaknesses, or routine SAST rules for common bugs unless they are evidence of deliberate malicious functionality.", "reviewer_notes": "Original mixed malicious behavior detection with ordinary vulnerability examples; replacement separates malicious intent analysis from general SAST.", "temperature": 0.0 }, "612-252": { "description": "This hub covers implementing authorization checks for GraphQL APIs (and similar query languages like OData) at the business logic layer rather than within the GraphQL resolver layer itself, ensuring that data access controls are enforced consistently regardless of the query path or field selection. It specifically addresses the architectural pattern of separating authorization logic from the GraphQL schema and resolver functions, preventing authorization bypass through query manipulation, batched queries, or nested field access that could expose unauthorized data. Unlike its sibling hubs that focus on input validation, content type restrictions, or HTTP method controls, this hub specifically targets the architectural placement of authorization logic in systems using flexible query languages. The scope is limited to authorization architecture patterns and does not cover authentication mechanisms, rate limiting, query complexity analysis, or other GraphQL-specific security concerns like introspection disabling or query depth limiting.", "generated_at": "2026-04-28T23:25:34.765533+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > Separate GraphQL (or similar) authorization logic from data layer", "hub_id": "612-252", "hub_name": "Separate GraphQL (or similar) authorization logic from data layer", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "612-435": { "description": "This hub covers requirements for displaying sanitized, non-revealing error messages to users when security exceptions (authentication failures, authorization denials, input validation errors) or unexpected runtime exceptions occur, while logging detailed error information internally with correlation IDs for debugging. It specifically addresses the user-facing error response mechanism that prevents information disclosure through error messages, replacing technical details with generic messages like \"An error occurred. Reference ID: 12345.\" This hub does not cover the technical implementation of exception catching mechanisms (covered by \"Use exception handling uniformly\"), the fallback error handling architecture (covered by \"Use a standard last-resort error handler\"), or the internal logging of error details - it solely focuses on what error information is presented to the end user.", "generated_at": "2026-04-28T23:25:35.845207+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Error handling > Show generic message for security exceptions or unanticipated exceptions", "hub_id": "612-435", "hub_name": "Show generic message for security exceptions or unanticipated exceptions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "614-353": { "description": "This hub covers the secure storage of backup media and files, including encryption at rest, access control mechanisms, physical security of backup locations, and protection against unauthorized modification or deletion. It focuses specifically on the security controls and storage mechanisms after backups are created, distinct from the backup creation and restoration testing processes covered by its sibling hub. This hub does not cover the backup scheduling, execution procedures, or restoration validation processes, nor does it address the selection of what data to backup or backup retention policies.", "generated_at": "2026-04-28T23:25:35.495797+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Backup > Store backups securely", "hub_id": "614-353", "hub_name": "Store backups securely", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "615-663": { "description": "This hub covers attacks that compromise AI model behavior by injecting malicious samples, modifying labels, or manipulating features within training, fine-tuning, or augmentation datasets before model development begins. It encompasses backdoor attacks where specific triggers cause misclassification, label flipping to degrade accuracy, and strategic data injection to bias model decisions, distinguishing it from runtime poisoning (which occurs during inference), supply-chain poisoning (which targets pre-trained models in transit), and direct development-time poisoning (which manipulates the training process itself rather than the data). This hub excludes attacks on model architectures, hyperparameters, or training algorithms, focusing solely on compromises to the data pipeline that feeds model training.", "generated_at": "2026-04-28T23:25:41.589805+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > AI model behaviour integrity threats > AI model poisoning > Data poisoning of train/finetune/augmentation data", "hub_id": "615-663", "hub_name": "Data poisoning of train/finetune/augmentation data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "615-744": { "description": "This hub covers controls that prevent unauthorized enumeration and exposure of directory structures, file listings, and metadata through web interfaces, including protection against automated scanning attempts and accidental disclosure of system files like .git, .svn, .DS_Store, or Thumbs.db. It focuses specifically on directory-level information disclosure vulnerabilities distinct from API-level access control (covered by IDOR protection) or functional access restrictions (covered by feature-based authorization controls). The scope is limited to directory browsing and discovery attacks; it does not address file content access control, path traversal vulnerabilities, or authentication mechanisms.", "generated_at": "2026-04-28T23:25:42.123298+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Protect against directory browsing/discovery attacks", "hub_id": "615-744", "hub_name": "Protect against directory browsing/discovery attacks", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "617-524": { "description": "This hub covers requirements for preventing sensitive data from being stored in client-side browser storage mechanisms including localStorage, sessionStorage, IndexedDB, cookies, and WebSQL. It focuses specifically on avoiding the initial storage of sensitive information in these browser-accessible locations, rather than clearing data after storage or controlling caching behavior. The scope is limited to browser storage APIs and does not cover server-side caching, memory management, HTTP cache headers, or authentication token handling which are addressed by sibling hubs.", "generated_at": "2026-04-28T23:25:40.597098+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Manage temporary storage > Do not store sensitive data on client (browser) storage", "hub_id": "617-524", "hub_name": "Do not store sensitive data on client (browser) storage", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "618-403": { "description": "This hub covers requirements for Relying Parties (RPs) to enforce maximum authentication time limits when federating authentication to external Credential Service Providers (CSPs), ensuring users are re-authenticated if their CSP session exceeds the specified timeout period. It focuses specifically on the RP's responsibility to communicate and enforce temporal session constraints with CSPs, distinct from sibling requirements about relaying authentication timestamps or managing OAuth token revocation. This hub excludes direct session timeout management within the RP's own application boundaries and does not cover initial authentication flows or non-temporal session validation criteria.", "generated_at": "2026-04-28T23:25:41.667772+00:00", "hierarchy_path": "Technical application security controls > Session management > Re-authentication from federation or assertion > Enforce authentication timeout when dealing with an authentication third party (CSP)", "hub_id": "618-403", "hub_name": "Enforce authentication timeout when dealing with an authentication third party (CSP)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "620-101": { "description": "This hub covers requirements for enforcing mandatory output encoding that matches the specific syntax and context of the target interpreter (HTML, JavaScript, SQL, LDAP, OS shell, etc.), ensuring that data is transformed using the correct encoding function before being passed to each interpreter. It focuses on the enforcement mechanisms and policies that guarantee appropriate encoding is applied based on the destination context, rather than the specific encoding techniques themselves. This hub differs from \"Encode output context-specifically\" which addresses the selection and implementation of encoding methods, while this hub ensures those methods are mandatorily applied; it also differs from interpreter-specific protection hubs (XML/XPath, LDAP, OS command injection) which focus on preventing specific attack types rather than enforcing encoding policies across all interpreter contexts. The scope excludes input validation, parameterized queries, and the technical details of individual encoding algorithms, focusing instead on the systematic enforcement of context-appropriate encoding before data reaches any interpreter.", "generated_at": "2026-04-28T23:25:49.854900+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Force output encoding for specific interpreter's context", "hub_id": "620-101", "hub_name": "Force output encoding for specific interpreter's context", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "622-203": { "description": "This hub covers the cryptographic protection of passwords through the combined use of salt values and one-way hashing functions, requiring that each password be processed with a unique random salt before applying approved hashing algorithms like bcrypt, scrypt, or Argon2. It encompasses the selection of appropriate hashing functions, salt generation requirements (including entropy and uniqueness), and the proper combination of these elements to produce stored password hashes resistant to rainbow table and offline brute-force attacks. This hub specifically addresses password hashing and salting only, excluding the configuration of work factors/iteration counts (covered by sibling hubs), the use of pepper values, general cryptographic key storage, or the broader infrastructure for secrets management.", "generated_at": "2026-04-28T23:25:49.437556+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Store passwords salted and hashed", "hub_id": "622-203", "hub_name": "Store passwords salted and hashed", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "622-835": { "description": "This hub covers requirements for generating and managing initial passwords during account provisioning, specifically mandating the use of cryptographically secure random generation methods, enforcing short validity periods (typically hours to days), and implementing controls to prevent these temporary credentials from becoming permanent passwords. It encompasses password generation entropy requirements, expiration enforcement mechanisms, and technical controls that force users to create new passwords upon first login rather than continuing to use the initial password. This hub differs from its sibling hubs by focusing exclusively on the initial password lifecycle rather than ongoing authentication factors (like OTP tokens or biometric authenticators), and it addresses password-based authentication rather than multi-factor authentication mechanisms. The scope explicitly excludes requirements for permanent passwords, password complexity rules for user-chosen passwords, and authentication mechanisms beyond the initial provisioning phase.", "generated_at": "2026-04-28T23:25:49.210313+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Generate initial passwords with sufficient secure random, short expiration time and do not allow to reuse the initial password.", "hub_id": "622-835", "hub_name": "Generate initial passwords with sufficient secure random, short expiration time and do not allow to reuse the initial password.", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "623-347": { "description": "This hub covers requirements for preventing the use of shared accounts with elevated privileges, including detection and remediation of default administrative accounts (root, admin, sa) and enforcement of individual accountability for high-privilege access. It encompasses technical controls to block shared credential usage, processes for identifying and eliminating existing shared privileged accounts, and implementation of unique user authentication for all administrative functions. The scope excludes general access control policies, standard user account management, and privilege escalation controls that don't specifically address account sharing.", "generated_at": "2026-04-28T23:25:47.332294+00:00", "hierarchy_path": "Operating processes for security > Access control processes > Disallow shared high privileged accounts", "hub_id": "623-347", "hub_name": "Disallow shared high privileged accounts", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "623-550": { "description": "Denial Of Service protection encompasses controls and mechanisms that prevent or mitigate attacks aimed at exhausting system resources, network bandwidth, or application availability through volumetric floods, protocol exploitation, or resource-intensive requests. This hub covers rate limiting, traffic filtering, resource allocation controls, and resilience patterns specifically designed to maintain service availability under attack conditions, distinguishing it from injection-based attacks (covered by Injection protection) or request forgery attacks (covered by CSRF/SSRF protection). The scope excludes general availability engineering practices like redundancy or failover that are not specifically designed as DoS countermeasures, as well as attacks that achieve denial through exploitation of vulnerabilities rather than resource exhaustion.", "generated_at": "2026-04-28T23:25:53.948716+00:00", "hierarchy_path": "Cross-cutting concerns > Denial Of Service protection", "hub_id": "623-550", "hub_name": "Denial Of Service protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "626-250": { "description": "Design review encompasses systematic evaluation of software architecture, system design documents, and technical specifications to verify security requirements are properly addressed before implementation begins. This hub covers human-led and tool-assisted analysis of design artifacts including threat models, data flow diagrams, component interfaces, and architectural decisions to identify security flaws, validate risk mitigations, and ensure compliance with security policies. It excludes code-level analysis (covered by code review hubs), runtime testing (covered by dynamic testing), and post-implementation validation activities.", "generated_at": "2026-04-28T23:25:52.483848+00:00", "hierarchy_path": "Development processes for security > Verification > Design review", "hub_id": "626-250", "hub_name": "Design review", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "630-573": { "description": "This hub covers detection and prevention mechanisms for automated attacks against APIs and web services, including rate limiting, behavioral analysis, and bot detection to counter mass data scraping, business logic abuse, and resource exhaustion attacks. It focuses specifically on identifying and blocking non-human interaction patterns through techniques like CAPTCHA challenges, request throttling, anomaly detection, and IP-based restrictions, distinct from sibling hubs that address data encoding standards, protocol-specific controls, or architectural separation concerns. The scope excludes authentication/authorization mechanisms, input validation for malicious payloads, and general application-layer DoS protections that don't specifically target automation patterns.", "generated_at": "2026-04-28T23:25:55.738073+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > API/web services > Detect and protect against automation abuse", "hub_id": "630-573", "hub_name": "Detect and protect against automation abuse", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "630-577": { "description": "This hub covers requirements for applications to permit password management tools, including clipboard paste operations, browser-integrated password autofill features, and third-party password manager extensions to function within password input fields. It encompasses removing technical restrictions like disabling paste events, blocking autofill attributes, or preventing programmatic field population that would interfere with these password assistance mechanisms. Unlike its sibling hub which focuses on visual feedback mechanisms for manual password entry, this hub addresses the integration and compatibility with external password management systems. It does not cover password strength requirements, password storage mechanisms, or the implementation of password managers themselves—only the application's responsibility to allow their operation.", "generated_at": "2026-04-28T23:25:57.222162+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Login functionality > Allow password helpers, including paste functionality", "hub_id": "630-577", "hub_name": "Allow password helpers, including paste functionality", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "635-851": { "description": "This hub covers the strategic direction and governance activities for secure software development programs, including setting security objectives, defining program roadmaps, allocating resources, and conducting periodic reviews to ensure the program aligns with organizational security goals. It encompasses executive oversight, program-level decision making, performance measurement against security KPIs, and strategic adjustments based on threat landscape changes and lessons learned from security incidents. Unlike its siblings which focus on community building, process implementation, stakeholder engagement, or providing technical controls, this hub specifically addresses the leadership and strategic management aspects of the program. It does not cover the tactical implementation of secure coding practices, the creation of specific security tools or libraries, or the day-to-day operational management of development teams.", "generated_at": "2026-04-28T23:25:56.992065+00:00", "hierarchy_path": "Governance processes for security > Security organizing processes > Program management > Program management for secure software development > Steer the secure software development program", "hub_id": "635-851", "hub_name": "Steer the secure software development program", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "636-854": { "description": "This hub covers requirements for implementing end-to-end encryption across all application communication channels, including API calls, database connections, management interfaces, and third-party integrations using TLS or equivalent cryptographic protocols. It focuses on the mandatory application of encryption to prevent cleartext transmission vulnerabilities and session hijacking attacks, distinguishing itself from sibling hubs that address specific TLS configuration aspects like protocol versions, certificate validation, or cipher strength. This hub does not cover the technical implementation details of TLS configuration, certificate management, logging mechanisms, or fallback prevention strategies, which are addressed by its sibling hubs.", "generated_at": "2026-04-28T23:26:33.934153+00:00", "hierarchy_path": "Technical application security controls > Secure communication > TLS > Encrypt all communications", "hub_id": "636-854", "hub_name": "Encrypt all communications", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "637-021": { "description": "This hub covers techniques for embedding detectable signatures into AI models to establish ownership, track unauthorized distribution, and verify model authenticity, including both static watermarks in model parameters and dynamic watermarks in model outputs. It encompasses watermarking methods for neural networks, foundation models, and generated content (text, images, audio), distinguishing itself from AI engineering controls (which focus on development practices) and secure AI inference (which addresses runtime protection). This hub excludes general model security controls like access management or encryption, data watermarking techniques not specific to AI systems, and watermarking of training datasets rather than the models themselves.", "generated_at": "2026-04-28T23:26:00.289163+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Watermarking AI models", "hub_id": "637-021", "hub_name": "Watermarking AI models", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "640-364": { "description": "This hub covers implementing access control mechanisms exclusively within trusted server-side components, including application servers, API gateways, serverless functions, and backend services, ensuring that authorization decisions and enforcement occur only in environments under the application's direct control. It specifically addresses the security principle that client-side code cannot be trusted for access control decisions, requiring all authorization logic to execute on server-controlled infrastructure where tampering is prevented. This hub does not cover the specific types of access control models (RBAC, ABAC), authentication mechanisms, or protection against specific attack vectors like CSRF or directory traversal, which are addressed by its sibling hubs.", "generated_at": "2026-04-28T23:26:02.259200+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Enforce access control on trusted parts/serverside", "hub_id": "640-364", "hub_name": "Enforce access control on trusted parts/serverside", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "641-760": { "description": "AI Input distortion covers techniques that deliberately modify or transform AI model inputs during inference to prevent adversarial attacks and improve robustness, including methods like randomized smoothing, input perturbation, and restoration mechanisms. Unlike its siblings that focus on output manipulation (Obscuring confidence), architectural defenses (Ensemble models), or resource constraints (Limit inference resources), this hub specifically addresses input-space transformations that maintain model functionality while disrupting adversarial patterns. This hub excludes prompt-specific controls for language models (covered by Prompt input segregation) and detection-based approaches that identify but don't transform malicious inputs (covered by attack control siblings).", "generated_at": "2026-04-28T23:26:03.667708+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > AI Input distortion", "hub_id": "641-760", "hub_name": "AI Input distortion", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "646-227": { "description": "This hub covers the detection and prevention of time-based OTP token replay attacks by implementing logging mechanisms that record attempted re-use of valid tokens within their time window, rejection of such attempts, and real-time notification systems to alert the legitimate device holder of potential compromise. It specifically addresses the security gap where attackers might intercept and quickly re-use a valid OTP before expiration, requiring systems to maintain state tracking of used tokens and implement secure notification channels (push notifications, SMS, email) to the registered device or account holder. This hub does not cover the cryptographic generation or validation of OTP tokens, the storage mechanisms for OTP secrets, the choice of OTP algorithm parameters (time windows, digit length), or the initial provisioning and revocation of OTP devices—these aspects are addressed by sibling hubs focusing on OTP generation security, storage, and lifecycle management.", "generated_at": "2026-04-28T23:26:06.270454+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Log and reject re-use of valid time-based OTP tokens and notify device holder.", "hub_id": "646-227", "hub_name": "Log and reject re-use of valid time-based OTP tokens and notify device holder.", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "646-285": { "description": "AI compliance management encompasses the processes and controls for ensuring AI systems adhere to applicable laws, regulations, and standards throughout their lifecycle, including assessment of regulatory requirements, implementation of compliance controls, and ongoing monitoring of adherence. This hub focuses specifically on regulatory and legal compliance aspects of AI systems, distinct from AI security education which addresses training and awareness programs for personnel working with AI technologies. The scope excludes general organizational compliance frameworks not specific to AI, technical security controls for AI systems, and AI ethics considerations that fall outside of formal regulatory requirements.", "generated_at": "2026-04-28T23:26:05.189679+00:00", "hierarchy_path": "Governance processes for security > Organizational AI security controls > AI management system > AI compliance management", "hub_id": "646-285", "hub_name": "AI compliance management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "646-462": { "description": "This hub covers security controls for neutralizing malicious code execution risks from user-supplied content containing scriptable or expression-based template languages, including Markdown, CSS/XSL stylesheets, BBCode, and similar templating systems that can execute arbitrary code or expressions. It encompasses techniques to sanitize dangerous constructs, disable scripting capabilities, or execute untrusted templates within isolated sandbox environments to prevent template injection, code injection, and expression language attacks. Unlike sibling hubs that address specific content types (SVG, HTML) or injection contexts (GraphQL, SMTP), this hub focuses specifically on template engines and expression languages that process user input into executable code patterns. This hub does not cover direct code execution functions (eval), static HTML sanitization, or server-side request forgery prevention, which are addressed by its sibling nodes.", "generated_at": "2026-04-28T23:26:59.704712+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > Sanitize, disable, or sandbox untrusted scriptable or template language content", "hub_id": "646-462", "hub_name": "Sanitize, disable, or sandbox untrusted scriptable or template language content", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers neutralizing untrusted content written in scriptable, active, or expression capable formats, including Markdown configurations that allow embedded HTML or scripts, CSS or XSL constructs, BBCode variants, and other template like content that can trigger execution or unsafe rendering. It includes sanitization, disabling active features, or sandboxing before the content is interpreted. It does not cover server side template injection into engines such as Jinja2 or Twig, direct eval style code execution, plain HTML sanitization, SVG specific controls, or SSRF prevention.", "reviewer_notes": "Original overstated that formats such as Markdown are inherently executable and overlapped with server side template injection; replacement clarifies active content variants and boundaries.", "temperature": 0.0 }, "650-560": { "description": "This hub covers implementing access control enforcement specifically within trusted service layers, ensuring that authorization decisions are made on server-side components that cannot be manipulated by clients, particularly when client-side controls exist as a convenience layer. It focuses on architectural patterns where access control logic resides in dedicated service layers (such as API gateways, middleware services, or backend service meshes) that act as trusted intermediaries between clients and protected resources. Unlike sibling hubs that address specific attack vectors (CSRF, IDOR) or authentication mechanisms (MFA), this hub specifically targets the architectural placement of authorization logic in trusted tiers, distinguishing it from \"Enforce access control on trusted parts/serverside\" by focusing on service layer architecture rather than general server-side enforcement. This hub does not cover the specific authorization models (RBAC, ABAC) or implementation details of access control rules, but rather ensures that whatever rules exist are enforced in a tamper-proof service layer.", "generated_at": "2026-04-28T23:26:12.630681+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Enforce access control on trusted service layer", "hub_id": "650-560", "hub_name": "Enforce access control on trusted service layer", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "653-242": { "description": "This hub covers enforcing strict validation rules on structured data formats (JSON, XML, YAML, etc.) by verifying that data types, field names, nested structures, and value constraints match predefined schemas before processing. It specifically addresses schema-based validation of complex data structures, distinguishing it from siblings that focus on HTTP-specific validation, request rate limiting, or general whitelisting approaches. This hub does not cover unstructured data validation, authentication/authorization checks, or business logic validation beyond structural conformance.", "generated_at": "2026-04-28T23:26:10.941354+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Input validation > Enforce schema on type/contents of structured data", "hub_id": "653-242", "hub_name": "Enforce schema on type/contents of structured data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "657-084": { "description": "This hub covers the prevention of Server-Side Request Forgery (SSRF) attacks by implementing validation, sanitization, and whitelisting controls when applications make requests based on user-controlled input that triggers internal server operations. It specifically addresses scenarios where user input influences URLs, file paths, or network destinations that the server will access, requiring strict input validation against allowed protocols, domains, ports, and paths. Unlike its sibling hubs that focus on client-side injection threats (XSS, template injection) or data processing vulnerabilities (GraphQL DoS, mail injection), this hub exclusively targets server-initiated requests to internal or external resources. The scope is limited to SSRF prevention through input controls and does not cover broader server hardening, network segmentation, or authentication mechanisms for internal services.", "generated_at": "2026-04-28T23:26:13.992126+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > (SSRF) When depending on internal server input, use validation sanitization and whitelisting", "hub_id": "657-084", "hub_name": "(SSRF) When depending on internal server input, use validation sanitization and whitelisting", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "660-052": { "description": "This hub covers implementing and enforcing maximum size limits for file uploads and input data to prevent resource exhaustion attacks, including checks on individual file sizes, total upload volumes, and memory consumption during processing. It encompasses validation of content length headers, streaming upload size enforcement, and rejection of oversized inputs before they consume server resources, but excludes malware scanning, archive bomb detection, or file type validation. The hub's scope is limited to size-based controls and does not address file content security, execution prevention, or storage location security, which are covered by sibling hubs.", "generated_at": "2026-04-28T23:26:16.908221+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File upload > Validate max input/file sizes", "hub_id": "660-052", "hub_name": "Validate max input/file sizes", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "660-867": { "description": "This hub covers implementing quantitative and qualitative constraints within application business logic to mitigate specific business risks identified through threat modeling, such as transaction limits, rate limits, volume thresholds, and value boundaries that prevent financial fraud, inventory manipulation, or resource exhaustion attacks. It focuses on proactive enforcement of predetermined limits based on risk analysis, distinguishing it from its siblings that monitor for anomalies, enforce timing constraints, validate workflow sequences, or generate alerts after detection. This hub excludes reactive monitoring capabilities, temporal flow validation, sequence enforcement mechanisms, and alert configuration systems, which are addressed by its sibling hubs.", "generated_at": "2026-04-28T23:26:19.430670+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Detect and prevent unusual activity > Implement business logic limits against identified business risks", "hub_id": "660-867", "hub_name": "Implement business logic limits against identified business risks", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "661-440": { "description": "Federated learning encompasses controls for training machine learning models across decentralized data sources without centralizing raw training data, including secure aggregation protocols, differential privacy mechanisms, and client-server communication security. Unlike its siblings that focus on reducing or obscuring centralized training data, federated learning distributes the training process itself while keeping data at its source locations. This hub excludes general distributed computing security, model deployment controls, and centralized machine learning pipeline security which are covered elsewhere in the taxonomy.", "generated_at": "2026-04-28T23:26:19.758251+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI impact reduction controls > AI data reduction > Federated learning", "hub_id": "661-440", "hub_name": "Federated learning", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "663-550": { "description": "This hub covers testing methodologies to detect and prevent unauthorized extraction of AI model parameters, architectures, or decision boundaries through repeated queries and analysis of model outputs. It encompasses techniques for identifying model extraction attacks, hyperparameter stealing, and functional approximation attempts where adversaries reconstruct proprietary models by observing input-output relationships. This hub excludes membership inference attacks (determining if specific data was in training sets), data extraction attacks (recovering training data content), and prompt-based attacks (manipulating model behavior through inputs), focusing solely on threats that aim to replicate the model itself rather than extract information about its training data or manipulate its outputs.", "generated_at": "2026-04-29T15:54:37.023686+00:00", "hierarchy_path": "Development processes for security > Verification > AI security assurance & validation > Testing against model theft by inference", "hub_id": "663-550", "hub_name": "Testing against model theft by inference", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "664-080": { "description": "This hub covers implementing authorization checks at two distinct layers: first at the URI/route level through controller-based or declarative security mechanisms, and second at the resource/data model level where permissions are evaluated against the actual objects being accessed. It ensures that authorization is enforced both when requests enter the application (URI routing) and when they interact with backend resources, preventing bypass attacks that might exploit gaps between these layers. Unlike sibling hubs that focus on specific authorization patterns (CSRF protection, RBAC/ABAC models) or attack vectors (IDOR, directory browsing), this hub specifically addresses the architectural requirement of dual-layer authorization enforcement. This hub does not cover the specific authorization models to use (covered by ABAC/FBAC sibling), authentication mechanisms (covered by multifactor authentication sibling), or protection against specific attack types - it solely defines where authorization checks must occur in the application flow.", "generated_at": "2026-04-28T23:26:30.863193+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Enforce model-based authorization both at URI and final resource", "hub_id": "664-080", "hub_name": "Enforce model-based authorization both at URI and final resource", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "664-571": { "description": "This hub covers requirements for implementing and validating cryptographically secure random number generation, including proper entropy sources, initialization procedures, and verification that the random number generator maintains security properties under various operating conditions. It focuses on the implementation details of secure randomness generation such as proper seeding, entropy pool management, and handling edge cases like system startup or high load scenarios. This hub does not cover the specific use cases for random values (like GUID generation) or the selection criteria for choosing appropriate random number generators, which are addressed by its sibling hubs.", "generated_at": "2026-04-28T23:26:26.498373+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secure random values > Ensure proper generation of secure random", "hub_id": "664-571", "hub_name": "Ensure proper generation of secure random", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "668-364": { "description": "This hub covers requirements for logging and monitoring failed TLS handshakes, certificate validation errors, protocol negotiation failures, and cipher suite mismatches during connection establishment. It encompasses logging mechanisms that capture failure reasons, timestamps, source/destination endpoints, and attempted TLS versions/ciphers to enable security monitoring and troubleshooting of TLS communication issues. This hub specifically addresses TLS failure logging and does not cover successful connection logging, application-layer encryption failures, or the configuration of TLS protocols and cipher suites themselves (which are covered by sibling hubs).", "generated_at": "2026-04-28T23:26:28.161246+00:00", "hierarchy_path": "Technical application security controls > Secure communication > TLS > Log TLS connection failures", "hub_id": "668-364", "hub_name": "Log TLS connection failures", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "670-660": { "description": "This hub covers requirements for preventing shared mutable state access without proper synchronization mechanisms in critical business logic paths, specifically authentication, session management, and access control flows. It focuses on eliminating unsynchronized state sharing that could lead to data corruption, security bypasses, or inconsistent authorization decisions when multiple threads or processes execute concurrently. Unlike its siblings which address race condition exploitation, resource prioritization, and general thread safety, this hub specifically targets the architectural pattern of state isolation in security-critical code paths. It does not cover general concurrency best practices, performance optimization through parallelism, or race conditions in non-security-critical business logic.", "generated_at": "2026-04-28T23:26:32.255286+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Parallel execution robustness > Do not share unsynchronized state on high-value logic flows", "hub_id": "670-660", "hub_name": "Do not share unsynchronized state on high-value logic flows", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "673-475": { "description": "This hub covers requirements for preventing the use of obsolete, unsupported, or deprecated client-side technologies (such as Flash, ActiveX, Silverlight, Java applets, and NSAPI plugins) in application development and deployment. It focuses specifically on client-side execution technologies that pose security risks due to lack of vendor support or known vulnerabilities, distinguishing it from general dependency management which addresses server-side and build-time components, and from hardening practices that remove features from supported technologies. The scope is limited to client-side browser plugins and execution environments, excluding server-side deprecated technologies, outdated JavaScript frameworks, or deprecated HTML/CSS features that don't involve separate runtime environments.", "generated_at": "2026-04-28T23:26:34.733937+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Disallow unsupported/deprecated client-side technologies", "hub_id": "673-475", "hub_name": "Disallow unsupported/deprecated client-side technologies", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "673-736": { "description": "This hub covers requirements for implementing user-controlled termination of all active sessions across multiple devices or browsers through a single action, typically via a \"log out everywhere\" or \"log out all devices\" feature. It focuses specifically on giving users the ability to invalidate all their existing session tokens simultaneously, distinct from automatic session termination (timeout), password-change triggered termination, or single-session logout functionality. The scope includes the user interface for viewing active sessions and the backend mechanisms to track and invalidate multiple concurrent sessions, but excludes automatic session expiration policies, single-session management, and authentication-event triggered terminations.", "generated_at": "2026-04-28T23:26:38.093560+00:00", "hierarchy_path": "Technical application security controls > Session management > Minimize session life > Enable option to log out from all active session", "hub_id": "673-736", "hub_name": "Enable option to log out from all active session", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "674-425": { "description": "This hub covers requirements for configuring cryptographic implementations with current security parameters, including appropriate key lengths, secure cipher modes, proper padding schemes, and recommended protocol versions that reflect the latest cryptographic research and threat landscape. It focuses on the configuration aspects of cryptographic systems rather than algorithm selection or implementation details, ensuring parameters like RSA key sizes (≥2048 bits), AES modes (GCM over CBC), and TLS versions (1.2+) meet current security standards. This hub does not cover the selection of which cryptographic algorithms to use (covered by \"Use approved cryptographic algorithms\"), the secure handling of cryptographic failures, or the implementation-level concerns like timing attacks or proper IV usage.", "generated_at": "2026-04-28T23:26:39.697926+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encryption algorithms > Use state of the art cryptographic configuration", "hub_id": "674-425", "hub_name": "Use state of the art cryptographic configuration", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers configuring cryptographic implementations with current security parameters, such as sufficient key lengths, approved cipher modes, safe padding schemes, secure hash options, and deprecated parameter removal. It focuses on parameter and mode choices inside cryptographic mechanisms after an approved algorithm family has been selected. It does not cover algorithm approval decisions, TLS protocol configuration, nonce and IV uniqueness, key management lifecycle, constant time implementation, secure failure behavior, or weak cryptography exceptions for legacy interoperability.", "reviewer_notes": "Original used TLS protocol versions as examples even though the hub is for encryption algorithm configuration; replacement removes transport protocol scope.", "temperature": 0.0 }, "675-168": { "description": "This hub covers requirements for sanitizing filename metadata (including path components, extensions, and special characters) from untrusted sources when the application must process or store files based on user-provided naming information. It focuses on removing or encoding dangerous characters, path traversal sequences, and malicious patterns that could lead to unauthorized file system access or code execution when the filename metadata is used in file operations. Unlike its siblings that focus on ignoring/validating filenames for specific attack vectors (RFD, LFI, RFI) or blocking direct execution, this hub specifically addresses cases where filename metadata must be actively processed and transformed to be safe for use. It does not cover validation-only approaches or scenarios where filenames can be completely ignored or replaced with system-generated identifiers.", "generated_at": "2026-04-28T23:26:42.403120+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File execution > Sanitize filename metadata from untrusted origin if processing is required", "hub_id": "675-168", "hub_name": "Sanitize filename metadata from untrusted origin if processing is required", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "681-823": { "description": "This hub covers requirements for configuring the validity period of time-based one-time passwords (TOTP), including setting appropriate expiration windows that balance security with usability and ensuring tokens expire after a defined timeframe. It focuses specifically on the temporal aspects of TOTP implementation, distinct from sibling hubs that address other OTP characteristics like entropy, storage, reuse prevention, or cryptographic algorithms. This hub does not cover the generation mechanisms, transmission methods, or verification processes for OTPs, nor does it address other multi-factor authentication methods beyond time-based tokens.", "generated_at": "2026-04-28T23:26:40.614168+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Defined lifetime of time-based one-time password", "hub_id": "681-823", "hub_name": "Defined lifetime of time-based one-time password", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "683-036": { "description": "Wireless link protection encompasses security controls for radio frequency communications including Wi-Fi, Bluetooth, cellular, and other wireless protocols, focusing on preventing eavesdropping, jamming, and unauthorized access through techniques like WPA3 encryption, frequency hopping, and signal strength management. Unlike its siblings that address general communication security principles (TLS for transport layer, encryption/authentication for data protection, minimization for reducing attack surface), this hub specifically targets vulnerabilities unique to wireless transmission such as signal interception, replay attacks, and rogue access points. This hub excludes wired communication security, application-layer wireless protocols, and physical security of wireless infrastructure.", "generated_at": "2026-04-28T23:26:44.801391+00:00", "hierarchy_path": "Technical application security controls > Secure communication > Wireless link protection", "hub_id": "683-036", "hub_name": "Wireless link protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "683-722": { "description": "This hub covers security controls that prevent direct execution of file metadata (such as filenames, paths, extensions, or attributes) received from untrusted sources by blocking their use as executable commands or parameters in system calls, shell commands, or interpreter invocations. It focuses specifically on preventing scenarios where file metadata strings are passed directly to execution contexts without sanitization, such as using untrusted filenames in system(), exec(), or eval() functions. Unlike its sibling hubs that address validation and sanitization of file metadata for various contexts (RFD, LFI, RFI) or general execution logic blocking, this hub specifically targets the execution vector of file metadata itself. It does not cover the validation or sanitization of file content, nor does it address indirect execution through file processing or interpretation - only the direct execution of metadata strings as commands.", "generated_at": "2026-04-28T23:26:47.562366+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File execution > Block direct execution of file metadata from untrusted origin", "hub_id": "683-722", "hub_name": "Block direct execution of file metadata from untrusted origin", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "686-110": { "description": "Direct prompt injection covers attacks where malicious instructions are embedded directly into user-provided prompts to manipulate AI model outputs, causing the model to ignore its original instructions, leak sensitive data, or perform unintended actions. This hub focuses on threats where the attacker has direct control over the input prompt sent to the model, distinguishing it from indirect prompt injection where malicious content is retrieved from external sources, and from evasion attacks that use adversarial perturbations to bypass model detection capabilities. The scope excludes attacks that rely on intermediary data sources, model poisoning during training, or attacks that manipulate the model's perception through imperceptible input modifications rather than explicit instruction manipulation.", "generated_at": "2026-04-29T15:54:37.521030+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > AI model behaviour integrity threats > AI model behaviour integrity threats through inference > Direct prompt injection", "hub_id": "686-110", "hub_name": "Direct prompt injection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "688-081": { "description": "This hub covers the requirement to set the \"Secure\" attribute on all cookies containing session tokens, ensuring they are only transmitted over encrypted HTTPS connections and preventing interception via unencrypted HTTP. It specifically addresses the configuration of the Secure flag in Set-Cookie headers and programmatic cookie creation, distinct from sibling controls that address other cookie attributes like HttpOnly (script access), SameSite (cross-site requests), path restrictions (scope limiting), or Host prefix (domain locking). The scope is limited to the Secure attribute configuration and does not cover the underlying HTTPS/TLS implementation, certificate management, or other session security measures like token entropy, rotation, or storage mechanisms.", "generated_at": "2026-04-28T23:26:49.698825+00:00", "hierarchy_path": "Technical application security controls > Session management > Cookie-config > Set \"secure\" attribute for cookie-based session tokens", "hub_id": "688-081", "hub_name": "Set \"secure\" attribute for cookie-based session tokens", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "701-654": { "description": "Supply-chain model poisoning encompasses attacks where adversaries compromise AI models through third-party sources, including poisoned pre-trained models, malicious model weights distributed through model hubs, and backdoored models embedded in software dependencies or frameworks. This hub specifically addresses threats introduced before the model reaches the end user's environment, distinguishing it from direct runtime poisoning (attacks during model execution), data poisoning (contaminating training datasets), and direct development-time poisoning (compromising the model during the user's own development process). The scope excludes attacks on the model after deployment in the user's infrastructure and poisoning that occurs through the user's own data collection or model training activities.", "generated_at": "2026-04-29T15:54:38.877717+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > AI model behaviour integrity threats > AI model poisoning > Supply-chain model poisoning", "hub_id": "701-654", "hub_name": "Supply-chain model poisoning", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "703-813": { "description": "Monitor inference encompasses the collection, analysis, and alerting on AI model behavior metrics during runtime, including input patterns, output distributions, latency, resource utilization, and prediction confidence scores to detect anomalies, attacks, or degradation. Unlike its siblings that actively block or modify inference requests (rate limiting, input handling) or restrict who can access the model (access control), this hub focuses on passive observation and measurement of inference operations without intervening in the request flow. This scope excludes training-time monitoring, model development metrics, and the actual implementation of response actions based on monitoring alerts—it covers only the detection and reporting mechanisms during inference execution.", "generated_at": "2026-04-28T23:26:53.748995+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Generic input attack controls at inference > Monitor inference", "hub_id": "703-813", "hub_name": "Monitor inference", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "704-530": { "description": "This hub covers requirements for ensuring session tokens contain sufficient randomness (minimum 64 bits of entropy) to prevent prediction attacks through brute force or statistical analysis. It focuses specifically on the entropy measurement and validation of generated tokens, distinct from its siblings which address token regeneration timing, secure storage methods, and the cryptographic algorithms used for generation. This hub does not cover the implementation details of random number generators, the specific algorithms for token generation, or the secure transmission and storage of tokens after generation.", "generated_at": "2026-04-28T23:26:53.215911+00:00", "hierarchy_path": "Technical application security controls > Session management > Session token generation > Enforce high entropy session tokens", "hub_id": "704-530", "hub_name": "Enforce high entropy session tokens", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "705-182": { "description": "This hub covers requirements for configuring the Path attribute in HTTP cookies used for session management to restrict cookie scope to the minimum necessary directory path within the application's URL structure. It addresses setting explicit path values (e.g., \"/app/admin/\" instead of \"/\") to prevent session tokens from being transmitted to unintended application areas or sibling applications on the same domain, mitigating session hijacking and unauthorized access risks. This hub specifically focuses on the Path attribute configuration, distinct from sibling hubs that address other cookie security attributes like HttpOnly (XSS protection), Secure (HTTPS enforcement), SameSite (CSRF protection), or Host prefix (domain locking), and does not cover non-cookie session storage mechanisms or path-based access control policies.", "generated_at": "2026-04-28T23:26:57.222004+00:00", "hierarchy_path": "Technical application security controls > Session management > Cookie-config > Set path attribute in cookie-based session tokens as precise as possible", "hub_id": "705-182", "hub_name": "Set path attribute in cookie-based session tokens as precise as possible", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "713-683": { "description": "This hub covers technical controls that prevent unauthorized users and processes from reading, accessing, or retrieving log files and their contents through access control mechanisms, encryption at rest, and secure storage configurations. It encompasses protection against both external attackers attempting reconnaissance and internal threats seeking to access logs containing sensitive operational data, authentication records, or system events. The scope includes log file permissions, log storage security, and access authentication mechanisms, but excludes log transmission security (covered under transport protection), log tampering prevention (covered under log integrity verification), and log retention/disposal policies (covered under log lifecycle management).", "generated_at": "2026-04-28T23:26:58.839041+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log integrity > Log access protection > Protect logs against unauthorized access", "hub_id": "713-683", "hub_name": "Protect logs against unauthorized access", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "715-223": { "description": "This hub covers verification and validation of the source authenticity and provenance of third-party components, ensuring they originate from legitimate, authorized repositories and maintainers through cryptographic signatures, checksums, and trusted registry controls. It focuses on establishing chain of custody and preventing supply chain attacks through dependency confusion, typosquatting, or compromised distribution channels, distinct from siblings that address post-acquisition integrity checks (SRI enforcement) or malicious code detection within already-obtained components. This hub excludes runtime sandboxing, behavioral analysis of third-party code, or detection of specific malicious patterns like backdoors and timebombs, which are covered by sibling hubs.", "generated_at": "2026-04-28T23:27:00.544808+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency integrity > Ensure trusted origin of third party resources", "hub_id": "715-223", "hub_name": "Ensure trusted origin of third party resources", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "715-304": { "description": "This hub covers requirements for actively overwriting sensitive data in volatile memory (RAM) with zeros or random values immediately after processing completes, preventing recovery through memory dumps, cold boot attacks, or process inspection. It specifically addresses server-side and application-level memory management for cryptographic keys, passwords, payment data, and other secrets during runtime execution, distinct from sibling hubs that focus on persistent storage, caching layers, or client-side data handling. This hub excludes requirements for secure memory allocation, memory encryption during use, or clearing data from non-volatile storage devices like SSDs or hard drives.", "generated_at": "2026-04-28T23:27:00.552324+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Manage temporary storage > Zeroize sensitive information in memory after use", "hub_id": "715-304", "hub_name": "Zeroize sensitive information in memory after use", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "715-334": { "description": "This hub covers requirements for integrating automated dependency update mechanisms directly into build and compilation processes, including configuration of build tools to fetch latest secure versions, implementation of version pinning strategies, and establishment of update policies that balance security with stability. It specifically addresses the technical implementation of dependency updates during the build phase, distinguishing it from inventory tracking (covered by the inventory management sibling) and security scanning (covered by the pipeline checking sibling). The scope is limited to update mechanisms executed during build/compile time and excludes runtime dependency updates, manual update processes, or post-deployment patching strategies.", "generated_at": "2026-04-28T23:27:03.925550+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency management > Update third party components build- or compile time", "hub_id": "715-334", "hub_name": "Update third party components build- or compile time", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "715-644": { "description": "Access control to AI inference defines authentication, authorization, and access management requirements for AI model endpoints, APIs, and inference services, including user identity verification, role-based permissions, and API key management for model invocation. This hub focuses on who can access and invoke AI models during inference, distinct from rate limiting (how often), anomalous input handling (what inputs), unwanted series handling (input patterns), and monitoring (observability of access). It excludes training-time access controls, model weight protection, and the security of the inference infrastructure itself.", "generated_at": "2026-04-28T23:27:04.848108+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Generic input attack controls at inference > Access control to AI inference", "hub_id": "715-644", "hub_name": "Access control to AI inference", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "715-681": { "description": "This hub requires systems to accept and store passwords at their full submitted length without truncating characters, ensuring that users' intended password complexity is preserved. The exception allows replacing consecutive multiple spaces with a single space to prevent input errors while maintaining security. Unlike sibling controls that address password length requirements, character sets, or composition rules, this hub specifically prohibits the practice of silently cutting off password characters beyond a certain length, which would weaken passwords without users' knowledge.", "generated_at": "2026-04-28T23:27:05.759506+00:00", "hierarchy_path": "Technical application security controls > Authentication > Credentials directives > Avoid password truncation, with exception of consecutive spaces", "hub_id": "715-681", "hub_name": "Avoid password truncation, with exception of consecutive spaces", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "725-682": { "description": "This hub covers implementing configurable alerting mechanisms that trigger when application usage patterns deviate from established baselines, including abnormal transaction volumes, atypical access patterns, or statistical outliers in user behavior metrics. It focuses specifically on the alerting infrastructure and configuration capabilities, distinguishing it from siblings that address activity monitoring (data collection), temporal flow validation, sequence enforcement, or risk-based limits. The scope excludes the actual detection algorithms, monitoring infrastructure, or response actions - it solely addresses the ability to configure thresholds, notification channels, and alert parameters for anomaly-based triggers.", "generated_at": "2026-04-28T23:27:06.830191+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Detect and prevent unusual activity > Enable configurable alert against usage anomalies", "hub_id": "725-682", "hub_name": "Enable configurable alert against usage anomalies", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "727-043": { "description": "This hub covers the selection and implementation of cryptographically secure algorithms for session token generation, including approved random number generators (RNGs), cryptographic pseudo-random number generators (CSPRNGs), and hash-based token generation methods that resist prediction and falsification attacks. It focuses specifically on the algorithmic strength and cryptographic properties of the generation process, distinct from token entropy requirements (covered by sibling hub), token storage mechanisms (covered by sibling hub), or token lifecycle events like post-authentication renewal (covered by sibling hub). This hub does not cover the length or entropy measurements of generated tokens, secure transmission protocols, token validation mechanisms, or session management policies beyond the generation algorithm itself.", "generated_at": "2026-04-28T23:27:07.292058+00:00", "hierarchy_path": "Technical application security controls > Session management > Session token generation > Ensure secure algorithms for generating session tokens", "hub_id": "727-043", "hub_name": "Ensure secure algorithms for generating session tokens", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "731-120": { "description": "This hub covers the formal documentation of security requirements that must be applied to each data protection level, including specific controls for encryption, integrity, retention, and confidentiality. It focuses on creating and maintaining the written policies and requirement sets that define how data at each classification level must be protected, distinct from the actual classification process (covered by sibling hubs) or the implementation of these requirements. The scope excludes the identification and categorization of data itself, as well as the technical implementation or verification of the documented protection measures.", "generated_at": "2026-04-28T23:27:09.698062+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Asset management > Data classification and handling > Document requirements for (data) protection levels", "hub_id": "731-120", "hub_name": "Document requirements for (data) protection levels", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "732-148": { "description": "Vulnerability management encompasses the systematic identification, analysis, prioritization, and remediation of security weaknesses in software, infrastructure, and third-party components throughout their lifecycle. This hub covers vulnerability discovery through multiple channels (automated scanning, user reports, public sources), root cause analysis, risk assessment, remediation planning and tracking, and the establishment of metrics to measure program effectiveness. Unlike Change management which focuses on controlling modifications to systems and processes, Vulnerability management specifically addresses the detection and elimination of security flaws, though it excludes the broader incident response activities that occur after vulnerabilities are exploited or the initial secure development practices that prevent vulnerabilities from being introduced.", "generated_at": "2026-04-28T23:27:10.772194+00:00", "hierarchy_path": "Operating processes for security > Improvement management > Vulnerability management", "hub_id": "732-148", "hub_name": "Vulnerability management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "732-873": { "description": "This hub covers the use of parameterized queries, prepared statements, and stored procedures to prevent SQL and NoSQL injection attacks by separating query structure from user-supplied data through compile-time query definition. It encompasses techniques for binding user input as data parameters rather than concatenating them into query strings, including ORM-based parameterization and database-specific prepared statement implementations. Unlike its sibling hubs that focus on output encoding for specific contexts (XSS, XML, LDAP) or command injection prevention, this hub specifically addresses database query construction and excludes other injection types, output encoding strategies, and runtime query validation techniques.", "generated_at": "2026-04-28T23:27:13.045007+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Lock/precompile queries (parameterization) to avoid injection attacks", "hub_id": "732-873", "hub_name": "Lock/precompile queries (parameterization) to avoid injection attacks", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "736-237": { "description": "This hub covers requirements for configuring the Content-Disposition HTTP response header in API responses to force file downloads rather than inline browser rendering, preventing XSS attacks through malicious file content and ensuring proper filename handling. It specifically addresses setting the header with \"attachment\" disposition type and appropriate filename parameters for various API content types (JSON, XML, etc.), distinct from sibling hubs that focus on other security headers like CSP for content restrictions or X-Frame-Options for clickjacking prevention. This hub excludes Content-Disposition usage for non-API responses (HTML pages, static assets) and does not cover the related Content-Type header configuration or validation of user-supplied filenames in multipart uploads.", "generated_at": "2026-04-28T23:27:14.313247+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > HTTP security headers > Set metadata/content-Disposition for API responses", "hub_id": "736-237", "hub_name": "Set metadata/content-Disposition for API responses", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "736-554": { "description": "This hub covers security controls that prevent systems from accepting and processing serialized data formats (such as Java serialization, Python pickle, or .NET binary serialization) from untrusted external clients, enforcing architectural decisions to use safer data exchange formats instead. Unlike its siblings which focus on secure parsing of specific formats (JSON), integrity verification of serialized objects, or avoiding deserialization in application logic, this hub specifically addresses blocking the acceptance of serialized content at system boundaries before any processing occurs. The scope excludes internal system-to-system serialization between trusted components and does not cover the secure implementation of serialization when it must be used.", "generated_at": "2026-04-28T23:27:14.513376+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Deserialization Prevention > Block serialization of content from untrusted clients", "hub_id": "736-554", "hub_name": "Block serialization of content from untrusted clients", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "737-086": { "description": "This hub covers security controls that prevent Local File Inclusion (LFI) attacks by either ignoring filename metadata from untrusted sources entirely or validating it against path traversal sequences, encoding bypasses, and directory references before any file system operations occur. Unlike its siblings that address remote file contexts (RFI), direct execution blocking, or sanitization approaches, this hub specifically focuses on preventing unauthorized access to local files through manipulated filename inputs such as \"../../../etc/passwd\" or encoded variants. The scope is limited to local file system access prevention and does not cover remote file retrieval, file content validation, or scenarios where the filename metadata itself needs to be processed rather than ignored.", "generated_at": "2026-04-28T23:27:16.448196+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File execution > Ignore/at least validate filename metadata from untrusted origin (local file context, eg LFI)", "hub_id": "737-086", "hub_name": "Ignore/at least validate filename metadata from untrusted origin (local file context, eg LFI)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "742-056": { "description": "This hub covers security controls for handling filename metadata (paths, extensions, references) from untrusted remote sources to prevent Remote File Inclusion (RFI) attacks, requiring applications to either completely ignore such metadata or validate it against strict allowlists before any file operations. It specifically addresses scenarios where attackers attempt to manipulate filename metadata to force applications to fetch and execute remote files via URLs or network paths, distinguishing it from local file inclusion controls that handle filesystem-based attacks and from siblings that focus on sanitization or blocking execution rather than validation/ignoring strategies. This hub excludes local file traversal attacks, direct code execution prevention, and scenarios where filename metadata requires processing rather than being ignored or validated.", "generated_at": "2026-04-28T23:27:18.514064+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File execution > Ignore/at least validate filename metadata from untrusted origin (remote file context, eg RFI)", "hub_id": "742-056", "hub_name": "Ignore/at least validate filename metadata from untrusted origin (remote file context, eg RFI)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "742-431": { "description": "This hub covers requirements for selecting and implementing cryptographic algorithms that have been validated by recognized standards bodies (NIST, IETF, ISO) or government agencies, including specific approved algorithms like AES, RSA-OAEP, and SHA-256/SHA-3. It encompasses both the selection criteria for approved algorithms and the requirement to avoid deprecated, broken, or custom-developed cryptographic primitives. Unlike sibling hubs that address implementation details (constant time operations, secure failure modes) or configuration aspects (state of the art settings, nonce usage), this hub focuses solely on algorithm selection and approval status. It does not cover key management practices, cryptographic protocol design, or the specific implementation parameters of approved algorithms—only whether the core algorithms themselves meet established approval criteria.", "generated_at": "2026-04-28T23:27:22.004627+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encryption algorithms > Use approved cryptographic algorithms", "hub_id": "742-431", "hub_name": "Use approved cryptographic algorithms", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "743-110": { "description": "This hub covers requirements for preventing the disclosure of system implementation details through HTTP headers and responses, including server versions, framework identifiers, stack traces, and internal error messages that could aid attackers in fingerprinting or targeting vulnerabilities. It differs from \"Disable debug mode in production\" by focusing specifically on HTTP-transmitted information rather than debug configurations, addressing both standard headers (like Server, X-Powered-By) and custom application responses that leak technical details. This hub does not cover non-HTTP protocols, client-side information disclosure, or general access control for sensitive business data—only technical metadata exposed via HTTP communications.", "generated_at": "2026-04-28T23:27:20.976775+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Prevent security disclosure > Do not disclose technical information in HTTP header or response", "hub_id": "743-110", "hub_name": "Do not disclose technical information in HTTP header or response", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "743-237": { "description": "This hub covers validation and enforcement mechanisms specifically designed to prevent HTTP Parameter Pollution (HPP) attacks, where attackers inject multiple parameters with the same name to bypass security controls or cause unexpected application behavior. It encompasses techniques to detect and reject duplicate parameter names across different HTTP sources (GET, POST, cookies, headers) and ensure consistent parameter handling regardless of the framework's parameter source abstraction. Unlike sibling hubs that address general input whitelisting, mass assignment, or schema validation, this hub focuses exclusively on the parameter duplication and source confusion aspects of HTTP requests. It does not cover validation of parameter values themselves, JSON/XML schema enforcement, or protection against other injection attacks - only the structural integrity of HTTP parameter submission.", "generated_at": "2026-04-28T23:27:21.764496+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Input validation > Validatie/enforce HTTP inputs (against HTTP parameter pollution attacks)", "hub_id": "743-237", "hub_name": "Validatie/enforce HTTP inputs (against HTTP parameter pollution attacks)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "745-045": { "description": "This hub covers requirements for preventing TLS connections from downgrading to plaintext protocols (HTTP, Telnet, FTP) or weaker encryption methods when TLS negotiation fails, including implementing strict transport security mechanisms and rejecting fallback attempts. It focuses specifically on protocol-level fallback prevention rather than cipher suite selection or certificate validation, which are addressed by sibling hubs. The scope excludes application-layer protocol downgrades (like SAML to Basic Auth) and covers only transport-layer protocol fallback scenarios within TCP-based communications.", "generated_at": "2026-04-28T23:27:22.509520+00:00", "hierarchy_path": "Technical application security controls > Secure communication > TLS > Do not fall back to insecure protocols in TCP", "hub_id": "745-045", "hub_name": "Do not fall back to insecure protocols in TCP", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "745-356": { "description": "Development process audit trail covers the generation, collection, and retention of evidence documenting security-related activities throughout the software development lifecycle, including code reviews, security testing results, approval records, and tool-generated artifacts that demonstrate compliance with secure development practices. This hub focuses specifically on the auditability and traceability aspects of development activities, distinguishing it from Configuration Management (which handles version control and change tracking), Verification (which performs the actual security testing), and Technical system documentation (which creates the deliverable documentation itself). The scope excludes the actual execution of security activities or the tools themselves, covering only the audit trail mechanisms that prove these activities occurred according to organizational standards.", "generated_at": "2026-04-28T23:27:24.165357+00:00", "hierarchy_path": "Development processes for security > Development process audit trail", "hub_id": "745-356", "hub_name": "Development process audit trail", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "746-705": { "description": "This hub covers implementing controls that restrict each user's access to only the application functionality they are authorized to use, including rate limiting and resource consumption controls to prevent abuse of permitted functions. It focuses on enforcing functional boundaries through mechanisms like transaction limits, API call quotas, and business logic constraints that apply after authentication has occurred. This hub does not cover authentication mechanisms, data-level access controls, or the specific authorization models (RBAC/ABAC) used to determine permissions - it addresses only the enforcement of functional restrictions once authorization decisions are made.", "generated_at": "2026-04-28T23:27:27.187563+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Limit/authorize user's access to functionality", "hub_id": "746-705", "hub_name": "Limit/authorize user's access to functionality", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "751-176": { "description": "This hub covers requirements for implementing secure password change functionality that allows authenticated users to update their credentials through self-service interfaces. It encompasses the technical controls for password update workflows, validation of new passwords against security policies, and the secure handling of password change requests within the application. This hub specifically addresses voluntary password changes initiated by authenticated users, distinguishing it from forced password resets (covered under authentication renewal), credential compromise notifications, or the validation requirements for old/new password pairs during the change process. It does not cover password recovery mechanisms for forgotten passwords, notification systems for credential changes, or the detection of anomalous authentication patterns.", "generated_at": "2026-04-28T23:27:28.071619+00:00", "hierarchy_path": "Technical application security controls > Secure user management > Offer password changing functionality", "hub_id": "751-176", "hub_name": "Offer password changing functionality", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "757-271": { "description": "This hub covers implementing source code control systems that enforce access controls for who can view, modify, and commit code changes, while maintaining complete traceability of all modifications including author, timestamp, and change rationale. It encompasses version control platforms (Git, SVN, Perforce) configured with authentication, authorization matrices, commit signing, audit logging, and integration with change management workflows to track code evolution from development through production deployment. This hub specifically addresses source code versioning and access control mechanisms, excluding broader configuration management concerns like build automation, dependency management, infrastructure-as-code, or runtime configuration management which would fall under separate Developer Configuration Management hubs.", "generated_at": "2026-04-28T23:27:28.697107+00:00", "hierarchy_path": "Development processes for security > Configuration Management > Developer Configuration Management > Use source code control system with change traceability and access control", "hub_id": "757-271", "hub_name": "Use source code control system with change traceability and access control", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "760-764": { "description": "Injection protection encompasses requirements for preventing untrusted data from being interpreted as code or commands across all application layers, including SQL, NoSQL, OS command, LDAP, XPath, and expression language injection vulnerabilities. This hub specifically addresses input validation, parameterized queries, stored procedures, escaping mechanisms, and allowlist validation techniques that prevent malicious data from altering the intended logic of database queries, system commands, or interpreter contexts. Unlike XSS protection which focuses on client-side script injection, this hub covers server-side injection flaws; it excludes SSRF attacks (which involve forcing server-side requests) and does not address injection vulnerabilities specific to AI/ML models which fall under Protection against AI-Specific Threats.", "generated_at": "2026-04-28T23:27:29.037088+00:00", "hierarchy_path": "Cross-cutting concerns > Injection protection", "hub_id": "760-764", "hub_name": "Injection protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "760-765": { "description": "XSS protection encompasses requirements for preventing, detecting, and mitigating Cross-Site Scripting attacks where malicious scripts are injected into web applications to execute in users' browsers, including defenses against reflected, stored, and DOM-based XSS variants through input validation, output encoding, and Content Security Policy implementation. Unlike injection protection which covers server-side code execution vulnerabilities (SQL, command, LDAP), XSS protection specifically addresses client-side script injection that targets browser execution contexts and user sessions. This hub excludes server-side template injection, API-specific injection attacks, and general input validation requirements not directly related to preventing malicious script execution in browsers.", "generated_at": "2026-04-28T23:27:30.282873+00:00", "hierarchy_path": "Cross-cutting concerns > XSS protection", "hub_id": "760-765", "hub_name": "XSS protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "761-417": { "description": "Evasion attack input handling encompasses controls for detecting and mitigating adversarial examples that manipulate AI model predictions through subtle input perturbations, including detection mechanisms for adversarial patterns, input restoration techniques, and multi-modal validation approaches. This hub specifically addresses attacks that exploit model decision boundaries through crafted inputs designed to cause misclassification, distinct from prompt injection attacks that target language model instruction following or resource exhaustion attacks that overwhelm computational capacity. The scope excludes output-side controls, training-time defenses, and attacks that don't involve deliberate input manipulation to evade correct classification.", "generated_at": "2026-04-28T23:27:33.054729+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Specific input attack controls at inference > Evasion attack input handling", "hub_id": "761-417", "hub_name": "Evasion attack input handling", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "762-451": { "description": "This hub covers requirements for implementing user-controlled data deletion and portability mechanisms, including secure data removal from all storage locations (primary databases, caches, backups, alternate data streams) and providing data export in standard, machine-readable formats. It encompasses both the technical implementation of deletion/export APIs and the verification that sensitive data is properly cleared from all system resources, including debug information and temporary storage. This hub does not cover the consent mechanisms for initial data collection (covered by sibling hub), data retention policies, or the user interface design for deletion/export requests.", "generated_at": "2026-04-28T23:27:34.840676+00:00", "hierarchy_path": "Technical application security controls > Robust business logic > Privacy-preserving personal data logic > Ensure users can remove or export their data", "hub_id": "762-451", "hub_name": "Ensure users can remove or export their data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "762-616": { "description": "This hub covers cryptographic and integrity verification mechanisms applied to serialized data structures to detect tampering and prevent malicious object instantiation during deserialization. It encompasses techniques such as digital signatures, HMACs, authenticated encryption, and checksum validation specifically for serialized objects across formats including binary, XML, and JSON. Unlike its siblings which focus on safe parsing practices (Parse JSON safely), blocking untrusted input entirely (Block serialization from untrusted clients), or avoiding deserialization altogether (Avoid deserialization logic), this hub assumes deserialization will occur and mandates protective measures on the serialized data itself. It excludes input validation, sandboxing, or type restrictions during the deserialization process - focusing solely on ensuring the serialized payload's integrity and authenticity before processing begins.", "generated_at": "2026-04-28T23:27:36.265984+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Deserialization Prevention > Secure serialized objects (e.g. integrity checks)", "hub_id": "762-616", "hub_name": "Secure serialized objects (e.g. integrity checks)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "764-507": { "description": "This hub covers security controls that prevent XML External Entity (XXE) attacks by restricting XML parser configurations, specifically disabling external entity resolution, DTD processing, and other unsafe XML features. It focuses exclusively on XXE prevention through parser hardening and configuration, distinguishing it from general input validation (which covers broader input checks), deserialization prevention (which addresses object reconstruction attacks), and output encoding (which prevents injection during data rendering). This hub does not cover XML schema validation, XML encryption/signing, or general XML data validation rules - only the specific parser restrictions needed to prevent XXE vulnerabilities.", "generated_at": "2026-04-28T23:27:34.941487+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Restrict XML parsing (against XXE)", "hub_id": "764-507", "hub_name": "Restrict XML parsing (against XXE)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "765-788": { "description": "This hub covers the systematic categorization of identified sensitive data into defined protection tiers (such as public, internal, confidential, and restricted) based on impact assessments and regulatory requirements. It focuses on assigning appropriate security controls and handling procedures to each protection level, distinct from identifying what constitutes sensitive data or determining retention periods. The scope excludes the initial discovery and identification of sensitive data, personal data retention scheduling, and the documentation of protection level requirements—it specifically addresses the classification decision-making process and tier assignment methodology.", "generated_at": "2026-04-28T23:28:05.201951+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Asset management > Data classification and handling > Classify sensitive data in protection levels", "hub_id": "765-788", "hub_name": "Classify sensitive data in protection levels", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "767-435": { "description": "This hub covers the configuration of PBKDF2 (Password-Based Key Derivation Function 2) iteration counts to maximize computational cost while maintaining acceptable system performance, specifically requiring implementations to use at least 100,000 iterations or the highest count that verification servers can handle without degrading user experience. It focuses exclusively on the iteration parameter of PBKDF2, distinguishing it from sibling hubs that address other password hashing algorithms (bcrypt work factors), salt generation, or broader cryptographic storage concerns. This hub does not cover PBKDF2 salt configuration, memory-hard alternatives like Argon2, or the selection of which key derivation function to use.", "generated_at": "2026-04-28T23:27:39.986971+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Set the highest feasible iteration count for PBKDF2", "hub_id": "767-435", "hub_name": "Set the highest feasible iteration count for PBKDF2", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers setting PBKDF2 iteration counts to the highest feasible value that meets operational performance requirements for password verification and key derivation. It focuses only on PBKDF2 cost tuning, including periodic reassessment as hardware and guidance change. It does not cover bcrypt work factors, Argon2 or scrypt parameters, salt entropy, pepper use, password storage architecture, or selection of the key derivation function itself.", "reviewer_notes": "Original cited a fixed minimum iteration count that may become stale and distracts from the hub's highest feasible PBKDF2 tuning scope.", "temperature": 0.0 }, "767-701": { "description": "This hub covers the validation of TLS cipher suite configurations through active testing, including verification that only strong algorithms (AES-256, ChaCha20-Poly1305) are enabled, weak ciphers (RC4, 3DES, export-grade) are disabled, and cipher preference ordering prioritizes the strongest available options. It encompasses both automated scanning tools and manual protocol analysis techniques to confirm that TLS endpoints reject weak cipher negotiations and properly implement forward secrecy through ECDHE/DHE key exchanges. This hub excludes certificate validation, protocol version configuration, fallback behavior, and logging mechanisms, focusing solely on the cryptographic algorithm strength verification process.", "generated_at": "2026-04-28T23:27:41.350633+00:00", "hierarchy_path": "Technical application security controls > Secure communication > TLS > Verify strong TLS algorithms by testing", "hub_id": "767-701", "hub_name": "Verify strong TLS algorithms by testing", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "768-532": { "description": "Model input confidentiality controls encompass technical measures that protect the privacy and confidentiality of data fed into AI models during inference or prediction phases, including encryption of input data streams, access controls on prediction APIs, and differential privacy techniques applied to queries. These controls specifically target the protection of user-submitted or system-generated inputs to deployed models, distinguishing them from augmentation data controls (which protect training enhancement data) and runtime model controls (which protect the model parameters and architecture itself). This hub excludes controls for training data confidentiality, model output protection, and integrity-focused measures that prevent input tampering rather than unauthorized disclosure.", "generated_at": "2026-04-28T23:27:41.997492+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Conventional AI security controls on AI assets > Model input confidentiality controls", "hub_id": "768-532", "hub_name": "Model input confidentiality controls", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "770-361": { "description": "This hub covers requirements for configuring logging systems to record timestamps in consistent time zones across distributed applications and infrastructure, including UTC standardization for global systems and proper time zone metadata preservation. It encompasses time zone configuration in application code, logging frameworks, and log aggregation systems to ensure timestamps can be accurately correlated during incident investigation and forensic analysis. This hub excludes clock synchronization protocols (NTP/PTP), timestamp format standardization, and the actual time source accuracy - focusing solely on the time zone representation aspect of logged events.", "generated_at": "2026-04-28T23:27:43.278949+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log integrity > Log time synchronization > Synchronize time zones for logs", "hub_id": "770-361", "hub_name": "Synchronize time zones for logs", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "772-358": { "description": "This hub covers requirements to prohibit the use of password hints and knowledge-based authentication (KBA) questions as credential recovery mechanisms, including static security questions about personal information (mother's maiden name, pet names, birthplace) and user-defined hints that could be guessed or researched. It encompasses both the elimination of these weak recovery methods from authentication systems and the validation that applications do not implement or expose such mechanisms during password reset flows. This hub specifically addresses the removal of hint and question-based recovery, while its siblings focus on encryption of recovery communications, identity verification standards for OTP/MFA recovery, preventing exposure of current passwords, and implementing secure alternative recovery methods. The scope excludes the implementation details of secure recovery alternatives (covered by sibling hubs) and does not address other weak authentication factors like biometrics or SMS-based recovery.", "generated_at": "2026-04-28T23:27:48.173464+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Credential recovery > Do not use password hints or secret questions", "hub_id": "772-358", "hub_name": "Do not use password hints or secret questions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "774-888": { "description": "This hub covers requirements for preventing the storage of sensitive credentials, API keys, passwords, and cryptographic secrets directly in application source code, configuration files, or compiled binaries. It encompasses detection and remediation of hard-coded secrets, ensuring secrets are externalized from code repositories, and implementing secure retrieval mechanisms at runtime. Unlike sibling hubs that address specific secret storage technologies (key vaults, HSMs) or cryptographic operations (hashing, salting), this hub focuses exclusively on the separation of secrets from code artifacts. It does not cover the implementation details of external secret storage solutions, cryptographic algorithms, or runtime secret management operations—only that secrets must not exist within the codebase itself.", "generated_at": "2026-04-28T23:27:48.510710+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Do not store secrets in the code", "hub_id": "774-888", "hub_name": "Do not store secrets in the code", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "777-470": { "description": "This hub covers security controls that prevent applications from executing code, scripts, or other executable content originating from untrusted external sources, including CDNs, third-party libraries, remote files, and user-supplied content. It encompasses blocking mechanisms for various code inclusion attacks (local/remote file inclusion, DTD injection, malicious extensions) and validation of external dependencies before execution. Unlike its sibling hubs that focus on filename and metadata validation or sanitization, this hub specifically addresses the execution of the file's actual content and logic, not just its naming or attributes. The scope excludes controls for trusted code execution, code integrity verification after trust is established, and non-executable file content handling.", "generated_at": "2026-04-28T23:27:48.618317+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > File handling > File execution > Ignore/block execution logic from untrusted sources", "hub_id": "777-470", "hub_name": "Ignore/block execution logic from untrusted sources", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "780-757": { "description": "This hub covers vulnerabilities where AI model outputs contain traditional injection payloads (SQL, command, script, or other code injections) that can compromise downstream systems consuming the model's responses. It focuses specifically on cases where the AI system generates or passes through malicious code in its output that exploits conventional injection vulnerabilities in connected applications, distinguishing it from siblings that address data leakage or augmentation data tampering. The scope excludes prompt injection attacks targeting the AI model itself and is limited to scenarios where the model's output serves as an attack vector for traditional injection exploits in non-AI components.", "generated_at": "2026-04-29T15:54:42.695558+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > Conventional threats to AI input, output and augmentation data > Model output contains conventional injection", "hub_id": "780-757", "hub_name": "Model output contains conventional injection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "782-234": { "description": "This hub defines requirements for establishing clear, policy-compliant specifications for handling input and output data across systems, ensuring that I/O processing aligns with legal, regulatory, and organizational policies. It encompasses the documentation of explicit rules for data validation, encoding, sanitization, and transformation to prevent injection attacks and data manipulation vulnerabilities while maintaining compliance with applicable laws and regulations. The scope includes defining requirements for how systems should process various data types and formats, but excludes the actual implementation of security controls, testing procedures, or specific technical countermeasures against the linked attack vectors.", "generated_at": "2026-04-28T23:27:54.489324+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Security requirements > Clear policy compliant I/O requirements", "hub_id": "782-234", "hub_name": "Clear policy compliant I/O requirements", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "783-255": { "description": "This hub covers requirements for protecting cryptographic keys at rest through secure storage mechanisms, including hardware security modules (HSMs), Trusted Platform Modules (TPMs), secure enclaves, and OS-provided key storage services that prevent unauthorized access or extraction. It focuses specifically on the storage layer security controls for cryptographic keys, distinct from sibling hubs that address operational use of keys (isolated security modules), general secret storage (passwords, salts), or key management workflows (rotation, replacement). This hub does not cover key generation, key exchange protocols, cryptographic algorithm selection, or the use of keys during cryptographic operations - only their secure storage when not in active use.", "generated_at": "2026-04-28T23:27:54.983049+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Store cryptographic keys securely", "hub_id": "783-255", "hub_name": "Store cryptographic keys securely", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "786-224": { "description": "This hub covers requirements for adding authentication mechanisms to encrypted data, including the use of digital signatures, authenticated encryption modes (like AES-GCM), or HMAC to verify that ciphertext has not been tampered with or modified by unauthorized parties. It focuses specifically on cryptographic techniques that provide both confidentiality through encryption and integrity/authenticity guarantees, protecting against ciphertext manipulation attacks. Unlike sibling hubs that address algorithm selection, configuration, or implementation details, this hub exclusively concerns the authentication layer that must accompany encryption to prevent attacks where adversaries modify encrypted data without detection. It does not cover the encryption process itself, key management practices, or the selection of specific encryption algorithms - only the requirement to cryptographically bind authentication to the encrypted data.", "generated_at": "2026-04-28T23:27:55.692367+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encryption algorithms > Authenticate encrypted data", "hub_id": "786-224", "hub_name": "Authenticate encrypted data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "788-323": { "description": "Model size reduction mitigates training set backdoors by compressing neural networks through techniques like quantization, knowledge distillation, and structured pruning, which disrupts the precise weight patterns that backdoor triggers rely on to activate malicious behaviors. Unlike its siblings that manipulate training data (benign data increase, data distortion) or modify model parameters post-training (fine-tuning/pruning), this approach specifically targets architectural compression during or after training to eliminate backdoor pathways. This hub excludes unstructured pruning methods that don't reduce overall model size, data-centric defenses, and detection-only techniques that identify but don't remove backdoors.", "generated_at": "2026-04-29T15:54:44.057645+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > Weakening training set backdoors > Model size reduction", "hub_id": "788-323", "hub_name": "Model size reduction", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "801-310": { "description": "This hub covers implementing Attribute-Based Access Control (ABAC) or Feature-Based Access Control (FBAC) at the data object and feature level to provide fine-grained authorization decisions based on user attributes, resource attributes, and environmental context, even when Role-Based Access Control (RBAC) is used for broader permission management. It focuses on augmenting RBAC systems with dynamic, context-aware access decisions that evaluate multiple attributes (user department, data classification, time of access, location) rather than relying solely on static role assignments. Unlike sibling hubs that address specific attack vectors (CSRF protection, IDOR prevention) or authentication mechanisms (multifactor authentication), this hub specifically addresses the authorization model architecture and the granularity of access control decisions. This hub does not cover the implementation of pure RBAC systems, authentication mechanisms, or the specific technical controls for preventing particular attack types—it strictly focuses on the architectural pattern of layering attribute-based or feature-based controls on top of existing role-based systems.", "generated_at": "2026-04-28T23:28:03.185924+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Use ABAC/FBAC on data/feature level, even when using RBAC for permissions", "hub_id": "801-310", "hub_name": "Use ABAC/FBAC on data/feature level, even when using RBAC for permissions", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "802-056": { "description": "This hub covers controls that prevent and mitigate automated authentication attacks by limiting the rate, frequency, and volume of authentication attempts against user accounts. It encompasses rate limiting, account lockouts, CAPTCHA challenges, progressive delays, IP-based restrictions, and anomaly detection mechanisms that trigger when authentication patterns indicate credential stuffing, brute forcing, or password spraying attacks. Unlike sibling hubs that address authentication factors (MFA/OTP), credential storage (Resist stolen credentials), or authentication protocols (Challenge nonce cryptography), this hub specifically focuses on detecting and blocking excessive authentication attempts regardless of the authentication method used. This hub does not cover the strength of authentication mechanisms themselves, credential recovery processes, or the cryptographic aspects of authentication protocols - it strictly addresses controls that limit authentication attempt frequency and volume.", "generated_at": "2026-04-28T23:28:03.745515+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > Restrict excessive authentication", "hub_id": "802-056", "hub_name": "Restrict excessive authentication", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "804-220": { "description": "This hub covers the requirement to set the HttpOnly attribute on all cookies used for session management, preventing client-side scripts from accessing session tokens through document.cookie API and mitigating XSS-based session hijacking attacks. It specifically addresses the HttpOnly flag configuration, distinct from sibling controls that cover other cookie security attributes like Secure (HTTPS-only transmission), SameSite (CSRF protection), Host prefix (domain/path restrictions), and path precision settings. This requirement excludes non-session cookies (such as user preferences or analytics cookies) and does not address cookie encryption, expiration settings, or server-side session validation mechanisms.", "generated_at": "2026-04-28T23:28:07.193817+00:00", "hierarchy_path": "Technical application security controls > Session management > Cookie-config > Set httponly attribute for cookie-based session tokens", "hub_id": "804-220", "hub_name": "Set httponly attribute for cookie-based session tokens", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "806-367": { "description": "This hub covers requirements for performing output encoding at the point immediately before data is passed to its consuming interpreter, ensuring encoding decisions match the actual runtime context and interpreter version. It focuses on the architectural placement and timing of encoding operations rather than specific encoding techniques, requiring that encoding logic be positioned adjacent to interpreter boundaries to prevent context mismatches and encoding bypass vulnerabilities. This hub does not cover the specific encoding methods themselves (covered by context-specific encoding and interpreter-specific protection hubs), nor does it address input validation, parameterization techniques, or scenarios where output formatting must be preserved.", "generated_at": "2026-04-28T23:28:09.569225+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Encode output near the consuming interpreter", "hub_id": "806-367", "hub_name": "Encode output near the consuming interpreter", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "807-565": { "description": "This hub covers requirements that prevent systems from restricting which character types (uppercase, lowercase, numbers, special characters) users can include in their passwords. It ensures password systems accept any valid character combination without mandating specific character class requirements, distinguishing it from siblings that address password length, Unicode support, or validation against breach databases. This hub specifically addresses character type restrictions only - it does not cover password length requirements, character encoding support, or other composition rules like preventing dictionary words or repeated characters.", "generated_at": "2026-04-28T23:28:09.342826+00:00", "hierarchy_path": "Technical application security controls > Authentication > Credentials directives > Do not limit character types for password composition", "hub_id": "807-565", "hub_name": "Do not limit character types for password composition", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "808-425": { "description": "This hub covers requirements for detecting and alerting users about unusual patterns in their account activity, such as login attempts from new locations, devices, or at abnormal times, or atypical transaction volumes. It focuses specifically on anomaly detection mechanisms and user notification channels (push, SMS, email) for usage-based irregularities, distinct from siblings that address credential management workflows or authentication mechanics. The scope excludes the actual anomaly detection algorithms, incident response procedures, or notifications for explicit security events like credential changes (covered by sibling hubs).", "generated_at": "2026-04-28T23:28:11.683737+00:00", "hierarchy_path": "Technical application security controls > Secure user management > Notify users about anomalies in their usage patterns", "hub_id": "808-425", "hub_name": "Notify users about anomalies in their usage patterns", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "810-884": { "description": "AI user transparency encompasses requirements for disclosing to end users when they are interacting with AI systems, including clear identification of AI-generated content, automated decision-making processes, and the AI's capabilities and limitations. This hub focuses specifically on user-facing transparency mechanisms and disclosure obligations, distinct from human/automated oversight which monitor AI behavior internally, and from privilege minimization which restricts AI system permissions. The scope excludes technical transparency for developers/auditors (model interpretability, explainability) and organizational transparency practices (AI governance documentation, impact assessments).", "generated_at": "2026-04-28T23:28:12.686237+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI impact reduction controls > Impact limitation of unwanted model behaviour > AI user transparency", "hub_id": "810-884", "hub_name": "AI user transparency", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "813-610": { "description": "This hub covers requirements for eliminating hardcoded, unchanging credentials (passwords, API keys, tokens) in application code, configuration files, and service-to-service authentication, mandating instead the use of dynamic secrets with rotation mechanisms, temporary credentials, or cryptographic authentication methods. It focuses specifically on the technical implementation of credential management systems that prevent static secret usage, distinguishing it from sibling hubs that address user-facing authentication workflows (password changes, notifications) or default credential policies. The scope excludes user password policies, session management after authentication, and the specific mechanisms for secret rotation or key management infrastructure implementation details.", "generated_at": "2026-04-28T23:28:16.171321+00:00", "hierarchy_path": "Technical application security controls > Secure user management > Do not use static secrets", "hub_id": "813-610", "hub_name": "Do not use static secrets", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "814-322": { "description": "This hub covers security controls that restrict applications to only interact with pre-approved external resources by implementing allow lists for data sources (where applications can read from) and sinks (where applications can write to), including URLs, file paths, databases, and APIs. It specifically addresses preventing server-side request forgery (SSRF) and unvalidated redirects by enforcing strict validation of all outbound connections and data flows against predefined whitelists, distinct from general configuration hardening which focuses on secure defaults and HTTP headers which control browser behavior. This hub excludes input validation, authentication mechanisms, and network-level firewall rules, focusing solely on application-layer restrictions for resource access.", "generated_at": "2026-04-28T23:28:16.690336+00:00", "hierarchy_path": "Technical application security controls > Configuration hardening > Whitelist data sources and sinks", "hub_id": "814-322", "hub_name": "Whitelist data sources and sinks", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "816-631": { "description": "This hub covers requirements for implementing time-based expiration controls on out-of-band authentication elements, including authentication requests, verification codes, and tokens used in multi-factor authentication flows. It specifies that these elements must have defined expiration periods (typically 10 minutes or less) after which they become invalid and cannot be used for authentication, preventing replay attacks and reducing the window of opportunity for interception. Unlike sibling hubs that address one-time use restrictions, cryptographic generation methods, or secure transmission channels, this hub specifically focuses on the temporal validity aspect of out-of-band authentication elements. This hub does not cover the generation algorithms, storage mechanisms, or delivery methods for these authentication elements, nor does it address the strength of the authentication factors themselves or user notification requirements.", "generated_at": "2026-04-28T23:28:19.054094+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Ensure timely expiration of out of band authentication request, code, or tokens", "hub_id": "816-631", "hub_name": "Ensure timely expiration of out of band authentication request, code, or tokens", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "817-808": { "description": "This hub covers implementing default-deny access policies for newly created user accounts, requiring explicit permission grants before users can access any application functionality or data. It encompasses automatic assignment of minimal or null permission sets to new accounts, mandatory approval workflows before granting initial access rights, and preventing inheritance of default group permissions that would grant immediate access. This hub specifically addresses the initial state of new user accounts at creation time, distinct from ongoing permission management (Enforce least privilege), runtime permission requests (Let application request minimal permissions), or restrictions on who can modify permissions (Limit modification of access controls). It does not cover authentication mechanisms, user provisioning processes, or the specific permissions that should be granted after the default-deny state is lifted.", "generated_at": "2026-04-28T23:28:21.036010+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Minimize permissions > Deny new users by default", "hub_id": "817-808", "hub_name": "Deny new users by default", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "818-434": { "description": "Protection of technical AI information encompasses controls for restricting access to and disclosure of AI model artifacts, architectures, training methodologies, and implementation details that could enable adversarial attacks or unauthorized replication. This hub focuses on information security measures specific to AI technical assets, including model weights, hyperparameters, training datasets metadata, and architectural specifications, distinguishing it from data quality (which addresses dataset integrity), training-specific defenses (backdoors/evasion), model behavior controls (alignment), and third-party component risks (supply chain). The scope excludes protection of general business information about AI systems, privacy controls for training data subjects, and runtime security measures for deployed models.", "generated_at": "2026-04-28T23:28:22.620372+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > Protection of technical AI information", "hub_id": "818-434", "hub_name": "Protection of technical AI information", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "820-421": { "description": "This hub covers the authentication and validation of HTTP headers injected by trusted intermediary devices such as reverse proxies, API gateways, or Single Sign-On (SSO) systems, ensuring that applications verify the authenticity of headers like bearer tokens, user identifiers, or session attributes before trusting them. Unlike its siblings which focus on CORS whitelisting, Origin header security, and HTTP method restrictions, this hub specifically addresses the trust boundary between applications and their upstream authentication infrastructure. The scope is limited to validating headers added by known trusted sources and does not cover general HTTP header validation, direct client authentication mechanisms, or the configuration of the proxy/SSO devices themselves.", "generated_at": "2026-04-28T23:28:22.966621+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Validate HTTP request headers > Authenticate HTTP headers added by a trusted proxy or SSO device", "hub_id": "820-421", "hub_name": "Authenticate HTTP headers added by a trusted proxy or SSO device", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "820-878": { "description": "This hub covers requirements for documenting where data crosses security boundaries between different trust zones (such as user-to-application, application-to-database, or internal-to-external networks) and mapping the paths that sensitive data takes through the system, including transformations and storage points. It focuses specifically on architectural-level data flow diagrams and trust boundary identification, distinguishing it from component function documentation which describes what each part does, and from key management documentation which details cryptographic material handling. This hub does not cover implementation details of security controls at boundaries, runtime behavior documentation, or the actual security mechanisms used to protect data in transit—only the identification and documentation of where boundaries exist and how data moves across them.", "generated_at": "2026-04-28T23:28:26.524494+00:00", "hierarchy_path": "Development processes for security > Technical system documentation > Document all trust boundaries and significant data flows", "hub_id": "820-878", "hub_name": "Document all trust boundaries and significant data flows", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "821-832": { "description": "This hub covers requirements for implementing key and password rotation capabilities, including versioning mechanisms, re-encryption processes, and automated replacement workflows to ensure cryptographic materials can be changed without service disruption or data loss. It focuses on the replaceability infrastructure and procedures rather than the storage mechanisms themselves, distinguishing it from sibling hubs that address specific storage technologies (key vaults, HSMs) or cryptographic parameters (salt, work factors). The scope excludes initial key generation, access control policies, and the actual storage security measures, which are covered by other sibling hubs.", "generated_at": "2026-04-28T23:28:27.105288+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Ensure keys and passwords are replaceable", "hub_id": "821-832", "hub_name": "Ensure keys and passwords are replaceable", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "822-100": { "description": "This hub covers implementing authorization controls that directly map to documented user stories and functional requirements, ensuring that each feature's access constraints are explicitly defined and enforced based on the intended user interactions specified during design. It focuses on translating user story constraints (e.g., \"users can only edit their own profiles\") into concrete authorization checks within the application's business logic layer. This hub does not cover general authorization frameworks (RBAC/ABAC), API-specific protections, or technical implementation details of access control mechanisms - it specifically addresses the alignment between functional requirements documentation and their corresponding authorization enforcement.", "generated_at": "2026-04-28T23:28:30.093105+00:00", "hierarchy_path": "Technical application security controls > Technical application access control > Strong authorization checking > Constrain functional features based on user stories", "hub_id": "822-100", "hub_name": "Constrain functional features based on user stories", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "824-732": { "description": "This hub covers requirements for ensuring format string functions (printf, sprintf, syslog, etc.) only accept compile-time constant format specifiers, preventing attackers from injecting format string tokens (%s, %x, %n) through user-controlled input. It specifically addresses format string vulnerabilities where external input could be interpreted as format specifiers, leading to information disclosure, memory corruption, or arbitrary code execution. This hub does not cover general string handling safety, buffer overflow prevention in non-format string contexts, or integer overflow issues in string operations - these are addressed by its sibling hubs focusing on memory-safe functions and integer boundary checking.", "generated_at": "2026-04-28T23:28:29.162086+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Memory, String, and Unmanaged Code > Force format strings as constants", "hub_id": "824-732", "hub_name": "Force format strings as constants", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "831-563": { "description": "This hub covers requirements for eliminating or minimizing the use of deserialization mechanisms in application architectures, focusing on design patterns and architectural decisions that avoid processing serialized data formats altogether. It encompasses strategies such as using primitive data types, implementing allowlists for simple data structures, or replacing serialization-based communication with safer alternatives like REST APIs with JSON schemas. This hub does not cover secure implementation of deserialization when it cannot be avoided (covered by sibling hubs), nor does it address specific parsing techniques or integrity verification of serialized objects.", "generated_at": "2026-04-28T23:28:32.790767+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Deserialization Prevention > Avoid deserialization logic", "hub_id": "831-563", "hub_name": "Avoid deserialization logic", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "831-570": { "description": "This hub covers requirements for replacing unsafe memory manipulation functions (like strcpy, sprintf, gets) with their secure equivalents that enforce boundary checking and prevent buffer overflows. It encompasses the exclusive use of functions that validate destination buffer sizes, implement automatic null-termination, and prevent writing beyond allocated memory boundaries across all programming contexts including API calls, command-line utilities, and environment variable processing. Unlike its sibling hub on integer overflow checking which focuses on arithmetic operations and type conversions, this hub specifically addresses memory copy and string manipulation operations. It does not cover format string vulnerabilities (handled by the format string constants hub) or the detection of existing overflow conditions, focusing instead on preventing overflows through proper function selection at the implementation level.", "generated_at": "2026-04-28T23:28:34.724809+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Memory, String, and Unmanaged Code > Use memory-safe functions exclusively", "hub_id": "831-570", "hub_name": "Use memory-safe functions exclusively", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "833-030": { "description": "This hub covers requirements for establishing and maintaining formal connections between an organization's security program and external security communities, including participation in special interest groups, industry associations, and information sharing forums. It encompasses the processes for selecting relevant communities, defining engagement protocols, and managing bidirectional information exchange to enhance the organization's security posture through collective intelligence. This hub specifically addresses external community engagement and does not cover internal stakeholder management, vendor relationships, or customer communication channels, which are addressed in separate governance areas.", "generated_at": "2026-04-28T23:28:34.575260+00:00", "hierarchy_path": "Governance processes for security > Security organizing processes > Program management > Connect with the community", "hub_id": "833-030", "hub_name": "Connect with the community", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "834-645": { "description": "This hub covers requirements for detecting and preventing third-party dependencies from collecting user data without authorization, including analytics SDKs, telemetry libraries, and tracking components that harvest device identifiers, usage patterns, or personal information. It focuses specifically on data exfiltration risks from legitimate-appearing libraries that contain hidden collection capabilities, requiring verification that dependencies only collect data with explicit user consent. Unlike sibling hubs that address malicious code execution (backdoors, timebombs) or integrity verification (SRI, trusted origins), this hub exclusively targets privacy violations through unauthorized data harvesting, excluding security vulnerabilities or code tampering concerns.", "generated_at": "2026-04-28T23:28:35.746466+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency integrity > Avoid unauthorized client data collection", "hub_id": "834-645", "hub_name": "Avoid unauthorized client data collection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "838-636": { "description": "This hub covers requirements for detecting and preventing intentionally hidden unauthorized access mechanisms in source code and third-party libraries, including hard-coded credentials, undocumented accounts, rootkits, and covert communication channels that enable persistent remote access. It specifically addresses deliberate backdoors designed to bypass normal authentication and authorization controls, distinguishing it from general malicious code (which may have other purposes like data destruction) and timebombs (which execute based on triggers rather than providing ongoing access). The scope excludes unintentional vulnerabilities, legitimate debugging features that are properly documented, and malicious behaviors that don't provide unauthorized access capabilities such as cryptominers or adware.", "generated_at": "2026-04-28T23:28:36.628787+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency integrity > Check source code and third party libraries to not contain backdoors", "hub_id": "838-636", "hub_name": "Check source code and third party libraries to not contain backdoors", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "841-710": { "description": "This hub covers logging authentication events including successful/failed login attempts, account lockouts, password resets, and multi-factor authentication challenges while ensuring passwords, session tokens, API keys, and other authentication secrets are excluded or properly masked in log entries. It focuses specifically on authentication-related logging requirements that balance security monitoring needs with data protection, distinguishing it from access control logging (which covers authorization after authentication) and general security event logging (which encompasses broader security incidents). The scope excludes logging of post-authentication activities like data access or authorization decisions, and does not cover the storage, retention, or analysis infrastructure for these logs - only the generation of sanitized authentication event records.", "generated_at": "2026-04-28T23:28:39.578194+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Log relevant > Log authentication decisions without exposing sensitive data", "hub_id": "841-710", "hub_name": "Log authentication decisions without exposing sensitive data", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "841-757": { "description": "This hub covers requirements for using cryptographically secure algorithms specifically in OTP (One-Time Password) systems, including the generation of OTP values, seeding of OTP generators, and verification processes. It encompasses standards-approved algorithms (such as HMAC-SHA256 for TOTP/HOTP) and proper implementation of cryptographic primitives to ensure OTP unpredictability and resistance to cryptanalysis. Unlike sibling hubs that address OTP lifecycle management (expiration, reuse prevention) or delivery mechanisms (out-of-band communication), this hub focuses exclusively on the cryptographic foundation of OTP systems. It does not cover non-cryptographic aspects such as OTP length requirements, user interface considerations, or storage mechanisms for OTP secrets.", "generated_at": "2026-04-28T23:28:41.105505+00:00", "hierarchy_path": "Technical application security controls > Authentication > Authentication mechanism > MFA/OTP > Use approved cryptographic algorithms in generation, seeding and verification of OTPs", "hub_id": "841-757", "hub_name": "Use approved cryptographic algorithms in generation, seeding and verification of OTPs", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "843-475": { "description": "This hub covers security controls for detecting, filtering, and mitigating prompt injection attacks during AI model inference, including techniques for identifying malicious prompt patterns, sanitizing user inputs, and restoring compromised prompts to safe states. It focuses specifically on the input/output pipeline defenses against prompt manipulation attempts that seek to override model instructions or extract unauthorized information, distinguishing it from resource exhaustion controls (which address computational abuse), sensitive output handling (which manages information disclosure), and evasion attacks (which target model decision boundaries). The scope excludes training-time defenses, model architecture hardening, and attacks that don't involve direct prompt manipulation such as data poisoning or model extraction.", "generated_at": "2026-04-29T15:54:44.539819+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Specific input attack controls at inference > Prompt injection I/O handling", "hub_id": "843-475", "hub_name": "Prompt injection I/O handling", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "846-302": { "description": "This hub covers requirements for preventing server-side components (load balancers, reverse proxies, CDNs, application-level caches) from storing sensitive data in their cache layers, including configuration of cache-control directives and cache key management. It focuses specifically on server infrastructure caching mechanisms, distinguishing it from client-side browser caching controls (\"Set sufficient anti-caching headers\") and in-memory data handling (\"Zeroize sensitive information in memory after use\"). The scope excludes database query caching, session storage mechanisms, and persistent server-side storage solutions, addressing only temporary caching layers within the server infrastructure stack.", "generated_at": "2026-04-28T23:28:41.618387+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Manage temporary storage > Prevent caching of sensitive data in server components", "hub_id": "846-302", "hub_name": "Prevent caching of sensitive data in server components", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "847-247": { "description": "This hub covers the establishment and maintenance of formal policies and procedures that ensure systems, applications, and data can operate across different platforms and be transferred between environments without vendor lock-in or technical barriers. It encompasses documentation of data formats, API specifications, migration procedures, and technical standards that enable seamless integration and movement of assets between internal systems, cloud providers, and third-party services. This hub specifically addresses technical and procedural interoperability requirements, excluding the broader security risk assessments, asset inventories, or contingency measures that may result from portability decisions, which are covered by sibling hubs.", "generated_at": "2026-04-28T23:28:42.304288+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Interoperability and portability policy and procedures", "hub_id": "847-247", "hub_name": "Interoperability and portability policy and procedures", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "848-711": { "description": "This hub covers implementing input validation logic within trusted backend service layers rather than relying on client-side or edge validation, ensuring that all data entering core application logic has been verified against business rules and security constraints. It focuses on architectural placement of validation controls, requiring that validation occurs after authentication boundaries but before data processing, distinguishing it from sibling hubs that address specific validation techniques (whitelisting, schema enforcement) or attack vectors (parameter pollution, mass assignment). The scope excludes the specific validation methods themselves, which are covered by sibling hubs, and does not address output encoding, authentication, or authorization controls that may also reside in service layers.", "generated_at": "2026-04-28T23:28:46.237506+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Input validation > Enforce input validation on a trusted service layer", "hub_id": "848-711", "hub_name": "Enforce input validation on a trusted service layer", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "852-770": { "description": "AI model supply chain management covers security controls for the acquisition, validation, and integration of pre-trained models, model components, and model artifacts from external sources into AI systems. This hub addresses model provenance tracking, integrity verification, vulnerability assessment of imported models, and security requirements for model registries and repositories - distinct from data supply chain management which focuses on training data sources, and model hosting supply chain management which covers deployment infrastructure dependencies. The scope excludes controls for internally developed models, data pipeline security, and runtime hosting environment supply chain risks.", "generated_at": "2026-04-28T23:28:45.988408+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > AI supply chain management > AI model supply chain management", "hub_id": "852-770", "hub_name": "AI model supply chain management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "854-183": { "description": "This hub covers techniques that remove or neutralize backdoor triggers embedded during model training through additional training on clean data (fine-tuning) or selective removal of compromised model components (pruning). It encompasses methods that modify already-trained models to eliminate malicious behaviors while preserving legitimate functionality, including defensive distillation and trigger-agnostic pruning approaches. This hub excludes preventive measures taken during initial training (covered by sibling hubs), focusing solely on post-training remediation techniques that operate on existing models rather than modifying training data or architecture before training begins.", "generated_at": "2026-04-28T23:28:48.230914+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > Weakening training set backdoors > Benign fine-tuning and pruning", "hub_id": "854-183", "hub_name": "Benign fine-tuning and pruning", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "857-718": { "description": "This hub covers techniques and controls to prevent attackers from injecting malicious operating system commands through application inputs, including parameterization of OS calls, input validation against shell metacharacters, and safe alternatives to direct command execution. It specifically addresses vulnerabilities where user-controlled data can be interpreted as OS commands or command arguments, distinct from other injection types like SQL, LDAP, or XPath which target different interpreters. The scope is limited to OS command injection prevention and does not cover file path traversal attacks (LFI/RFI), code injection into application languages, or injection into other non-OS interpreters.", "generated_at": "2026-04-28T23:28:47.823603+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Output encoding and injection prevention > Protect against OS command injection attack", "hub_id": "857-718", "hub_name": "Protect against OS command injection attack", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "858-745": { "description": "Training data retention management encompasses controls for defining and enforcing time-based retention policies for AI training datasets, including automated deletion schedules, access logging during retention periods, and secure disposal mechanisms. Unlike data minimization which reduces data volume at collection, or training data obfuscation which transforms data while preserving it, this hub specifically addresses temporal lifecycle management of unmodified training data from storage through deletion. This hub excludes controls for data archival, backup retention policies, or retention of model artifacts and inference data.", "generated_at": "2026-04-28T23:28:48.242685+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI impact reduction controls > AI data reduction > Training data retention management", "hub_id": "858-745", "hub_name": "Training data retention management", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "860-084": { "description": "This hub covers techniques and requirements for isolating third-party libraries within restricted execution environments to limit their access to system resources, application data, and APIs beyond their intended functionality. It encompasses containerization, process isolation, permission restrictions, and runtime sandboxing mechanisms that prevent libraries from accessing file systems, network resources, or memory spaces outside their designated boundaries. Unlike sibling hubs that focus on pre-deployment validation (malicious code detection, backdoor checking) or cryptographic verification (integrity checks, trusted origins), this hub addresses runtime containment after dependencies are already integrated. It does not cover the selection, vetting, or authentication of libraries, nor does it address vulnerabilities within the sandbox implementation itself.", "generated_at": "2026-04-28T23:28:54.835998+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency integrity > Sandbox third party libraries", "hub_id": "860-084", "hub_name": "Sandbox third party libraries", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "860-723": { "description": "GenAI model alignment encompasses techniques and controls for ensuring generative AI models produce outputs that conform to intended behaviors, values, and safety constraints through methods like RLHF, constitutional AI, and preference learning. This hub specifically addresses the alignment problem in generative models - making them helpful, harmless, and honest - distinguishing it from siblings that focus on data integrity (Data quality control), adversarial robustness (Weakening training set backdoors, Evasion-preventing training), or operational security (Protection of technical AI information, AI supply chain management). The scope excludes non-generative AI alignment, deployment-time safety measures, and general model performance optimization that doesn't relate to value alignment or behavioral safety.", "generated_at": "2026-04-29T15:54:45.210594+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > GenAI model alignment", "hub_id": "860-723", "hub_name": "GenAI model alignment", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "863-521": { "description": "This hub covers the creation and maintenance of comprehensive inventories documenting all third-party components, libraries, and dependencies used within software projects, including their versions, licenses, and metadata typically captured in formats like SBOM. It encompasses the processes for discovering, cataloging, and tracking these external components throughout their lifecycle, but excludes the actual scanning for vulnerabilities or the update/remediation processes which are handled by its sibling hubs. The scope is limited to inventory management activities and does not include the technical implementation of dependency checking in build pipelines or the execution of component updates.", "generated_at": "2026-04-28T23:28:54.168109+00:00", "hierarchy_path": "Development processes for security > Supply chain management > Dependency management > Maintain/manage inventory of third party components", "hub_id": "863-521", "hub_name": "Maintain/manage inventory of third party components", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "863-636": { "description": "This hub covers requirements for implementing consistent exception handling patterns across an application's codebase, including standardized exception types, uniform try-catch structures, and consistent error propagation mechanisms. It focuses on the architectural consistency of exception handling code rather than the content of error messages or specific handlers for unhandled exceptions, which are addressed by its sibling hubs. The scope excludes logging mechanisms, error message content, and security-specific exception handling strategies, concentrating solely on the structural uniformity of how exceptions are caught, processed, and re-thrown throughout the application.", "generated_at": "2026-04-28T23:28:53.705042+00:00", "hierarchy_path": "Technical application security controls > Logging and error handling > Error handling > Use exception handling uniformly", "hub_id": "863-636", "hub_name": "Use exception handling uniformly", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "867-642": { "description": "Direct development-time model poisoning encompasses attacks where adversaries directly manipulate AI model components (weights, parameters, hyperparameters, or architecture) during the development phase before deployment, including backdoor insertion and malicious parameter modification. This hub covers poisoning that occurs through direct access to the model development environment or build pipeline, distinguishing it from runtime poisoning (which occurs after deployment), data poisoning (which corrupts training data rather than model components), and supply-chain poisoning (which compromises third-party dependencies or pre-trained models). The scope excludes indirect manipulation through training data corruption, post-deployment model modifications, and attacks on external model dependencies or hosting infrastructure.", "generated_at": "2026-04-28T23:28:54.315467+00:00", "hierarchy_path": "Cross-cutting concerns > Protection against AI-Specfic Threats > AI model behaviour integrity threats > AI model poisoning > Direct development-time model poisoning", "hub_id": "867-642", "hub_name": "Direct development-time model poisoning", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "872-574": { "description": "This hub covers the deployment, configuration, and maintenance of anti-malware solutions on managed endpoints, including signature updates, scanning policies, quarantine procedures, and incident response for malware detection events. It focuses specifically on malware prevention and remediation tools and processes, distinct from OS security which addresses operating system hardening and configuration, and from patching which handles vulnerability remediation through software updates. This hub excludes network-based malware detection, email security gateways, and malware analysis/reverse engineering activities which fall under separate security domains.", "generated_at": "2026-04-28T23:28:58.614669+00:00", "hierarchy_path": "Operating processes for security > Facilities management > Endpoint management > Virus/malware protection", "hub_id": "872-574", "hub_name": "Virus/malware protection", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "878-880": { "description": "This hub covers requirements for implementing cryptographic operations that execute in fixed time regardless of input values, preventing timing-based side-channel attacks that could leak sensitive information through execution time variations. It specifically addresses constant-time implementations of cryptographic primitives, comparison operations, and mathematical calculations within cryptographic modules to eliminate timing differences that could reveal secret keys, plaintext patterns, or authentication outcomes. Unlike sibling hubs that focus on algorithm selection, configuration standards, or failure modes, this hub exclusively addresses the temporal execution properties of cryptographic implementations. It does not cover other side-channel protections (power analysis, electromagnetic emissions), the mathematical strength of algorithms, or non-cryptographic timing considerations in the application.", "generated_at": "2026-04-28T23:29:00.502254+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Encrypt data at rest > Encryption algorithms > Perform cryptographic operations in constant time", "hub_id": "878-880", "hub_name": "Perform cryptographic operations in constant time", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "881-321": { "description": "This hub covers the secure storage of authentication credentials (passwords, API keys, tokens) using cryptographic protection methods including hashing, salting, and encryption to prevent unauthorized access and offline recovery attacks. It encompasses both the cryptographic algorithms and parameters for credential protection (work factors, iteration counts, salt generation) as well as the storage mechanisms and access controls that prevent credential exposure in configuration files, code, or memory. This hub does not cover the transmission of credentials over networks, credential validation logic, or the operational aspects of credential lifecycle management such as rotation policies or revocation procedures.", "generated_at": "2026-04-28T23:28:59.692035+00:00", "hierarchy_path": "Technical application security controls > Secure data storage > Secret storage > Store credentials securely", "hub_id": "881-321", "hub_name": "Store credentials securely", "model": "claude-opus-4-20250514", "review_status": "edited", "reviewed_description": "This hub covers secure storage practices for authentication credentials broadly, including protecting passwords, API keys, service account credentials, and tokens with storage controls appropriate to each credential type. It includes limiting access to credential stores, preventing exposure in code or configuration, using encryption or hashing where appropriate, and reducing offline recovery risk. It does not cover password specific salt, pepper, work factor, or PBKDF2 tuning requirements, dedicated key vault adoption, isolated cryptographic modules, credential transmission, or credential lifecycle actions such as rotation and revocation.", "reviewer_notes": "Original duplicated several sibling hubs by covering salts, work factors, and storage mechanisms in detail; replacement makes this a general credential storage boundary.", "temperature": 0.0 }, "881-434": { "description": "This hub covers the sanitization of user-controlled input that will be incorporated into email commands or headers before transmission to SMTP servers or IMAP systems, preventing injection of malicious SMTP/IMAP protocol commands through techniques like CRLF injection, header manipulation, or command sequence exploitation. Unlike sibling hubs that address web-specific injection vectors (XSS, template injection) or query-based attacks (GraphQL DoS), this hub specifically targets email protocol command injection where attackers could send unauthorized emails, modify recipients, or execute arbitrary mail server commands. The scope excludes email content filtering for spam or malware, authentication mechanisms, and general email security configurations that don't involve user input sanitization.", "generated_at": "2026-04-28T23:29:01.375783+00:00", "hierarchy_path": "Technical application security controls > Input and output protection > Sanitization and sandboxing > Sanitize user input before passing content to mail systems (SMTP/IMAP injection)", "hub_id": "881-434", "hub_name": "Sanitize user input before passing content to mail systems (SMTP/IMAP injection)", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "883-173": { "description": "Model hosting supply chain management covers security controls for the infrastructure and platforms used to deploy, serve, and operate AI models in production environments, including cloud services, edge devices, and on-premises systems. This hub addresses the security of model serving endpoints, containerization platforms, orchestration systems, and the dependencies required for model inference, distinguishing it from Data supply chain management (which focuses on data pipelines and storage) and AI model supply chain management (which covers the model artifacts and training dependencies themselves). The scope excludes the security of the model development process, training infrastructure, and data preparation pipelines, focusing specifically on the operational hosting environment from deployment through runtime.", "generated_at": "2026-04-28T23:29:01.380271+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > AI engineering controls > AI supply chain management > Model hosting supply chain mannagement", "hub_id": "883-173", "hub_name": "Model hosting supply chain mannagement", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "886-662": { "description": "This hub covers controls that restrict computational resources (CPU, memory, GPU time, API calls) available to AI models during inference to prevent resource exhaustion attacks and limit the model's ability to perform complex adversarial computations. It focuses on resource quotas, timeouts, and throttling mechanisms specific to inference operations, distinguishing it from input-based controls (prompt segregation, input distortion) and output-based controls (confidence obscuring, ensemble methods). This hub excludes training-time resource limits, general system resource management not specific to AI inference, and controls that modify model behavior through architectural changes rather than resource constraints.", "generated_at": "2026-04-28T23:29:04.423584+00:00", "hierarchy_path": "Technical application security controls > Technical AI security controls > Secure AI inference > Limit inference resources", "hub_id": "886-662", "hub_name": "Limit inference resources", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 }, "888-770": { "description": "This hub covers the continuous collection, analysis, and integration of external threat intelligence feeds, vulnerability disclosures, and emerging attack patterns into an organization's security risk assessment processes. It encompasses establishing threat intelligence sources, maintaining awareness of new threat actors and techniques, and systematically evaluating their relevance to the organization's specific technology stack and threat landscape. This hub excludes the operational implementation of threat hunting activities, incident response procedures, or the technical configuration of security controls based on threat intelligence.", "generated_at": "2026-04-28T23:29:04.993580+00:00", "hierarchy_path": "Governance processes for security > Security Analysis and documentation > Security risk assessment > Threat intelligence - stay up to date with new threats and consider them", "hub_id": "888-770", "hub_name": "Threat intelligence - stay up to date with new threats and consider them", "model": "claude-opus-4-20250514", "review_status": "accepted", "reviewed_description": null, "reviewer_notes": null, "temperature": 0.0 } }, "generation_model": "claude-opus-4-20250514", "generation_timestamp": "2026-04-29T15:54:47.289568+00:00", "total_generated": 400, "total_pending_review": 0 }