Index methodology · Curated sources

Grounded inestablished guidance.

Index references recognized standards where they help explain automation, AI, and cybersecurity risk. Every reference is transparent, scoped, and linked to its official source.

Explore the registry

Standards registry

Source by source.

These sources inform the language and risk themes used in an Index assessment. They are references, not certifications, endorsements, or substitutes for a formal compliance review.

NIST AI RMF

NIST Artificial Intelligence Risk Management Framework

U.S. National Institute of Standards and Technology

Official source

01What it is

Voluntary guidance for identifying and managing risks introduced by AI systems.

02How Index uses it

Index uses its trustworthiness and risk-management themes when AI performs or influences workflow steps.

03What Index does not claim

NIST did not evaluate, rate, certify, or approve this workflow.

NIST AI 600-1

NIST Generative AI Profile

U.S. National Institute of Standards and Technology

Official source

01What it is

A companion profile to the AI RMF focused on risks specific to generative AI.

02How Index uses it

Index references it when generative AI interprets, summarizes, or produces unstructured content.

03What Index does not claim

NIST did not evaluate, rate, certify, or approve this workflow.

NIST CSF 2.0

NIST Cybersecurity Framework 2.0

U.S. National Institute of Standards and Technology

Official source

01What it is

A widely used framework of high-level outcomes for understanding and managing cybersecurity risk.

02How Index uses it

Index uses it to organize concerns involving identity, access, data protection, monitoring, and incident response.

03What Index does not claim

A reference to NIST CSF does not mean the workflow is compliant, certified, or secure.

ISO/IEC 42001

ISO/IEC 42001:2023

International Organization for Standardization / IEC

Official source

01What it is

An international management-system standard for governing AI responsibly across its lifecycle.

02How Index uses it

Index references it when accountability, oversight, monitoring, or organizational AI governance is material.

03What Index does not claim

Index does not reproduce ISO requirements or claim certification or conformity.

OWASP Agentic AI

OWASP Agentic AI Security Guidance

Open Worldwide Application Security Project

Official source

01What it is

Security guidance for AI agents that use tools, access APIs, plan multiple steps, or take external actions.

02How Index uses it

Index references it when AI can invoke tools or act in connected systems.

03What Index does not claim

OWASP did not evaluate or certify this workflow.

A clear boundary

Guidance informs the assessment. People remain accountable.

Index supports structured decision-making. It does not certify compliance, replace legal or security review, or make a deployment decision for your organization.

Start an assessment