← rajpenchala.com
Security Reference Architecture · v1.2 · Sept 2026

Agentic Defense-in-Depth

End-to-end protection for an AI agent running on Azure AI Foundry, AWS Bedrock AgentCore, or GCP Vertex AI / Gemini Enterprise Agent Engine — seven defense layers from the network edge to the data plane, plus three cross-cutting planes (detection & IR, resilience & cost, posture & discovery), covering deployment-time and runtime, single-agent and multi-agent (A2A) topologies, and the MCP tool layer underneath. Every layer lists native controls for all three platforms plus best-of-breed third-party options, mapped to OWASP Agentic/LLM Top 10, MITRE ATLAS, NIST AI RMF, and DASF 3.0. v1.2 adds Microsoft Copilot Studio as the low-code build surface on the Microsoft side — same layers, different enforcement points.

L1 NetworkL2 Identity (NHI)L3 Runtime GuardrailsL4 Agent RuntimeL5 Multi-Agent / A2AL6 Tools / MCPL7 Data+ Copilot Studio (low-code)+ Deploy-time+ Detection & IR+ Resilience & Cost+ Posture (AI-SPM)+ Governance
§1

Reference Architecture

One request path, guarded at every hop. Nothing reaches the agent except through the AI gateway; the agent holds no secrets and reaches nothing except through identity-scoped, policy-checked calls. A peer agent is a separate trust zone — authenticated, schema-validated, and never implicitly trusted.

IDENTITY PLANE L2 · agent = NHI agent directory: Entra · AgentCore · GCP Agent Identity short-lived tokens no static secrets Conditional Access for agents per-tool IAM role least privilege on-behalf-of user context propagated lifecycle: owner, expiry, revocation OBSERVABILITY detect & respond OTel traces per step + tool call Defender for Cloud GuardDuty · SCC AI Protection SIEM: Sentinel · Security Lake · Google SecOps agent behavior analytics (UEBA) tamper-evident audit log continuous evals + red-team in CI/CD L1 NETWORK BOUNDARY Private Link · PrivateLink · VPC-SC perimeter deny-by-default ingress + egress USER / CHANNEL app · API · M365 TLS 1.3 · authN'd session L3 AI GATEWAY + GUARDRAILS Prompt Shields · Bedrock Guardrails · Model Armor in+out: injection · jailbreak · PII · groundedness only path in — no gateway bypass L4 AGENT RUNTIME Foundry · Copilot Studio · AgentCore · Vertex LLM + planner pinned, scanned model session isolation microVM / container L5 TRUST ZONE PEER AGENT signed AgentCard A2A: mTLS + OAuth/JWT schema-validated · replay-proof tool call · scoped token policy check per action retrieval · doc-level security trimming L6 MCP GATEWAY tool allowlist · schema validation · authZ broker MCP srv vetted sandbox code exec L7 DATA PLANE vector DB · memory · KB CMK encrypted · labeled RAG index ACL-scoped memory FGAC GOVERNANCE PLANE — spans every layer agent registry & inventory · use-case approval · model cards NIST AI RMF / ISO 42001 / EU AI Act · HITL for consequential actions
Fig. 1 — Agent defense-in-depth. The user's only path to the agent is through the guardrail gateway (L3); the runtime (L4) is session-isolated and secretless, drawing short-lived identity from the left plane (L2). Tool calls exit only through an MCP gateway (L6) and data access is trimmed to the calling user's entitlements (L7). A peer agent lives in its own trust zone reached over authenticated A2A (L5). Every hop emits traces to the observability plane; the governance plane owns approval, inventory, and the kill switch.
§2

Defense Layers & Controls

Outside-in, the order an attacker meets them. Each layer states its objective, the threats it absorbs, native controls on all three platforms, and best-of-breed third-party options where native coverage runs out.

Pro-code vs. low-code: the same seven layers govern a Copilot Studio agent — what changes is the enforcement point. Identity is still Entra Agent ID (Copilot Studio agents auto-register there, with Agent 365 as the registry and lifecycle layer); the L3 gateway role is played by Power Platform DLP policies and environment routing; L4 isolation by Power Platform environments, CMK, and the IP firewall; the L6 tool layer by connector governance. Makers ship agents faster than security registers them — which is why Plane C treats maker-built agents as the canonical shadow-agent population.
L1

Network Isolation & Egress Control

Objective: the agent is unreachable from the public internet, and can itself reach only an explicit allowlist. Deny-by-default in both directions — an agent's outbound path is the exfiltration path.

data exfiltrationC2 callbackslateral movementshadow AI egress

Azure AI Foundry

  • Standard Setup + BYO VNet with subnet delegation — agents run inside your network boundary
  • Private Link to Foundry, AOAI, AI Search, Storage; disable public network access
  • NSGs + Azure Firewall FQDN egress allowlist; force-tunnel all outbound
  • No public inbound — front user traffic with APIM / App Gateway + WAF

AWS Bedrock AgentCore

  • VPC endpoints (PrivateLink) for Bedrock, AgentCore, KBs — no traffic over public internet
  • Gateway-only invocation — runtime accepts calls solely from your AgentCore Gateway, blocking bypass
  • Identity VPC egress — agents reach private resources and in-VPC IdPs directly
  • Security groups + Network Firewall egress allowlisting per agent workload

GCP Vertex AI

  • VPC Service Controls perimeter around Vertex / Agent Engine — data can't leave the perimeter; now supports agent identities in ingress/egress rules
  • Private Service Connect + Private Google Access — no public endpoints for model or agent APIs
  • VPC firewall + Cloud NGFW egress allowlisting; org policy to block external IPs

Best-of-Breed

  • Zscaler / Netskope SSE — detect & control shadow-AI egress from the rest of the estate
  • Palo Alto NGFW AI App-ID — classify and police AI service traffic at the perimeter
  • Wiz — cloud exposure paths: find agents reachable from the internet before attackers do
Maps toDASF: runtime planeATLAS: ExfiltrationNIST AI RMF: ManageZero Trust: assume breach
L2

Identity & Access — the Agent as a Non-Human Identity

Objective: every agent is a first-class, governed identity — owned, scoped, credentialed with short-lived tokens, and revocable. No static secrets anywhere in the agent's reach; every tool call carries the least privilege for that one action, and user context propagates so the agent can never do more than the human it acts for.

credential theftprivilege escalationconfused deputyorphaned agentssecret sprawl

Azure AI Foundry

  • Entra Agent ID (GA) — every Foundry agent auto-registered in a tenant-wide agent directory
  • Managed identity + federated credentials — Entra issues short-lived tokens; zero secrets at runtime
  • Conditional Access & Identity Protection for agents — risk-based blocking, sign-in policies on NHIs
  • On-behalf-of (OBO) flows — downstream calls trimmed to the end-user's entitlements
  • RBAC + PIM on Foundry projects; lifecycle governance (owner, review, expiry)
  • Copilot Studio (low-code) — agents auto-register in Entra Agent ID; Agent 365 adds registry, ownership, and lifecycle governance across M365 agents

AWS Bedrock AgentCore

  • AgentCore Identity — workload identities per agent with OAuth token vault; agent never sees raw credentials
  • Per-tool IAM roles — each tool call executes under a role you control, scoped to that tool only
  • Service-linked runtime identity role manages token issuance and rotation
  • Inbound auth (SigV4 / JWT) on runtime; outbound OAuth 2.0 to SaaS tools with user consent
  • AgentCore Policy — evaluate agent actions against identity-aware policy at the gateway

GCP Vertex AI

  • Agent Identity — unique cryptographic ID per agent; the agent itself is the IAM principal you grant to
  • Workload Identity Federation — keyless, short-lived credentials; no exported service-account keys
  • IAM Conditions + per-tool service accounts — least privilege per action; Secret Manager for anything residual
  • VPC-SC rules keyed to agent identity — network policy that knows which agent is calling

Best-of-Breed

  • NHI governance: Astrix (Cisco), Oasis (Cyera), Entro — inventory, ownership, and risk-tiering of agent/service identities across clouds
  • GitGuardian — secrets detection + NHI governance: catch credentials leaking into prompts, repos, configs
  • CyberArk / SailPoint — vaulting, JIT elevation, and certification campaigns extended to agent identities
  • Okta — cross-IdP identity fabric for agents spanning all three clouds
Maps toOWASP NHI Top 10OWASP Agentic: excessive agencyATLAS: Credential AccessDASF: model serving
L3

AI Gateway & Runtime Guardrails

Objective: a mandatory inspection point on every prompt in and every response out — and on every intermediate step. Detect and block prompt injection, jailbreaks, PII leakage, ungrounded output, and unsafe tool invocations in real time. The gateway is the single door; the runtime refuses traffic from anywhere else.

prompt injection (direct + indirect)jailbreaksensitive-data leakagehallucinated actionsunsafe output

Azure AI Foundry

  • Azure AI Content Safety: Prompt Shields — direct + indirect (document-borne) injection detection
  • Groundedness detection — flag responses unsupported by retrieved sources
  • Content filters (harm categories, custom blocklists) on both directions of every model call
  • Defender for Cloud AI threat protection — runtime alerts for jailbreak, data leakage, poisoning signals into Defender XDR
  • APIM GenAI gateway policies: token limits, model routing, per-consumer quotas
  • Copilot Studio — Power Platform DLP policies + environment routing play the gateway role; Purview labels/DLP flow through Copilot interactions

AWS Bedrock AgentCore

  • Bedrock Guardrails — content filters, denied topics, PII redaction, contextual grounding checks
  • AgentCore Policy + Guardrails at the gateway — evaluate tool calls and agent actions in-line, pre-execution
  • Automated Reasoning checks — formally verify responses against encoded policy for high-stakes flows
  • Prompt-injection defense patterns on KB ingestion (treat retrieved content as untrusted)

GCP Vertex AI

  • Model Armor — screens prompts/responses for injection, jailbreak, sensitive data, malicious URLs; floor settings enforce a minimum org-wide
  • Agent Gateway — brokered, policy-checked path for agent traffic
  • Gemini safety filters + configurable harm thresholds per model call
  • Sensitive Data Protection (DLP) inline inspection/de-identification; Apigee as AI gateway for quotas and routing

Best-of-Breed

  • Palo Alto Prisma AIRS — runtime blocking of injection, jailbreaks, tool poisoning, leakage; cross-cloud consistency
  • Cisco AI Defense — guardrails enforced in the network path, model-agnostic
  • Lakera / Straiker — low-latency prompt-attack detection APIs
  • Noma / Zenity — agent behavior guardrails + posture for low-code and custom agents
Maps toOWASP LLM01 injectionOWASP LLM02 outputATLAS: Prompt InjectionDASF: inference plane
L4

Agent Runtime & Session Isolation

Objective: blast-radius containment. Each session runs in its own isolated compute with nothing shared across users; the model and orchestration code are pinned, scanned, and reproducible; consequential actions require a human gate. A compromised session dies with the session.

cross-session contaminationmemory poisoningrogue autonomous actionsruntime compromise persistence

Azure AI Foundry

  • Hosted agents — container-isolated execution inside your network boundary
  • Thread/session scoping — conversation state partitioned per user, BYO Cosmos DB under CMK
  • Agent evaluations + AI Red Teaming Agent — pre-deploy adversarial testing of the actual agent
  • Human-in-the-loop via approval tools for consequential actions
  • Copilot Studio — environment isolation + routing, CMK, IP firewall / VNet support, customer lockbox

AWS Bedrock AgentCore

  • MicroVM per session — dedicated CPU/memory/filesystem; VM terminated and memory sanitized at session end
  • Session limits — max duration, idle timeout; long-running agents bounded (8-hr cap)
  • Code Interpreter sandbox — agent-generated code runs in isolated, network-restricted compute
  • Return-of-control / confirmation patterns before high-impact tool execution

GCP Vertex AI

  • Agent Engine managed runtime — isolated sessions + managed memory, CMEK, HIPAA support
  • ADK sandboxed code execution — generated code confined away from the runtime
  • SCC AI Protection — agentic threat detection on Agent Engine logs: exfil attempts, suspicious token generation, unauthorized SA calls
  • Vertex evaluation service + adversarial evals pre-deploy; HITL confirmation in ADK flows

Best-of-Breed

  • Zenity — runtime agent behavior monitoring + drift from approved behavior profiles
  • HiddenLayer — model integrity: detect tampered/backdoored weights before load
  • Gauntlet-style CI red-teaming — continuous adversarial regression against the deployed agent (OWASP LLM + ATLAS scenarios)
Maps toOWASP Agentic: memory poisoningATLAS: PersistenceDASF: model planeSAIF 2.0 agents
L5

Multi-Agent Communication (A2A)

Objective: every peer agent is a separate trust zone. Agents authenticate each other cryptographically, exchange only schema-valid messages, and treat each other's output as untrusted input — a compromised agent must not be able to propagate instructions, poison memory, or replay tasks across the mesh.

cross-agent injection propagationagent impersonationtask replaycascading privilege abuserogue-agent joins

Azure AI Foundry

  • Connected agents / A2A support in Agent Service with Entra-issued identity per agent
  • Entra Agent ID as the trust root — each agent authenticates with its own token; Conditional Access applies per hop
  • Foundry tracing spans multi-agent chains end-to-end for forensics

AWS Bedrock AgentCore

  • AgentCore Gateway as A2A broker — inter-agent calls routed, authorized, and logged centrally
  • AgentCore Identity per agent — OAuth/JWT on every inter-agent request, no ambient trust
  • Policy at the boundary — Guardrails evaluate cross-agent requests like any tool call

GCP Vertex AI

  • A2A first-class — the protocol originated at Google; native in Agent Engine + ADK with Agent Identity per peer
  • Agent Gateway brokers inter-agent calls; agent registry in Gemini Enterprise governs who may join
  • VPC-SC conditional rules on agent/MCP attributes — perimeter policy per agent-to-agent path

Best-of-Breed / Protocol

  • A2A protocol hygiene — mTLS (TLS 1.3), signed AgentCards verified before first contact, per-request JWT, nonce-based replay prevention
  • Strict schema validation both directions; reject free-text instruction passthrough between agents
  • Agent gateway platforms (Airia, Kong AI Gateway, Prisma AIRS 3.0) — cross-agent policy, identity, and audit spanning interaction chains
  • Registry of approved agents — unknown AgentCards can't join the mesh
Maps toOWASP Agentic Top 10ATLAS: Lateral MovementSAGA governance modelDASF 3.0 agent risks
L6

Tool & MCP Layer

Objective: the agent's hands are its highest-risk surface. Broker every tool and MCP connection through a gateway that enforces which agent may call which tool, with what arguments, under whose identity — and vet the tools themselves like third-party software, because that's what they are.

tool poisoningrug-pull MCP serversexcessive tool permissionsargument injectionmalicious tool supply chain

Azure AI Foundry

  • Curated tool catalog — only registered, reviewed tools/connections available to agents
  • OBO auth per tool — Logic Apps / OpenAPI tools called with trimmed user context
  • Network-isolated tool egress through the VNet — tools can't be swapped for lookalikes off-network
  • Copilot Studio connector governance — business / non-business / blocked connector classes; MCP servers admitted under the same policy

AWS Bedrock AgentCore

  • AgentCore Gateway — converts APIs/Lambda into MCP tools with centralized authZ + logging per call
  • Per-tool IAM role — the L2 principle enforced here: each tool call is its own least-privilege principal
  • Guardrails on tool calls — block risky invocations (injection-driven, sensitive-data-bearing) pre-execution

GCP Vertex AI

  • ADK MCP toolsets under per-tool service accounts — each tool its own IAM principal
  • Apigee fronting tool APIs — authZ, quotas, schema enforcement on every tool call
  • VPC-SC conditional access on MCP attributes — perimeter rules aware of which MCP server/tool is in play
  • Model Armor tool-poisoning screening on tool descriptions and responses

Best-of-Breed

  • MCP security triage (OWASP MCP Top 10-aligned scanning à la mcp-triage) — score servers for injection surface, secret handling, update integrity before onboarding
  • MCP gateways (Kong, Lasso, Prompt Security) — allowlisting, schema pinning, response sanitization
  • Snyk / Socket / Endor — supply-chain scanning of tool + MCP server dependencies
  • Pin server versions — checksum/signature verification to kill rug-pull updates
Maps toOWASP MCP Top 10OWASP LLM: supply chainATLAS: ExecutionDASF: tool plane
L7

Data Plane — RAG, Memory & Knowledge

Objective: the agent can retrieve only what the calling user could read directly, memory never becomes a cross-user leak or a poisoning vector, and everything at rest sits under customer-managed keys with classification labels that survive into the index.

RAG data leakageindex poisoningmemory poisoningembedding inversionoversharing via retrieval

Azure AI Foundry

  • Azure AI Search security trimming — document-level ACLs enforced at query time per user
  • Microsoft Purview — sensitivity labels + DLP flowing into AI interactions; DSPM for AI
  • CMK encryption across Foundry, Storage, Cosmos (threads), AI Search
  • Ingestion hygiene — sanitize/label documents before indexing; treat all retrieved text as untrusted (feeds L3 Prompt Shields)

AWS Bedrock AgentCore

  • KB metadata filtering — per-user entitlement filters on every Bedrock Knowledge Base query
  • AgentCore Memory fine-grained access control — scoped read/write on memory records
  • KMS CMKs everywhere; S3 Block Public Access + bucket policies on corpora
  • Macie — discover/classify sensitive data before it enters the RAG corpus

GCP Vertex AI

  • Vertex AI Search ACL-aware retrieval — results trimmed to the calling user's entitlements
  • CMEK on Agent Engine sessions/memory and indexes; VPC-SC keeps data inside the perimeter
  • Sensitive Data Protection — classify/de-identify the corpus before indexing
  • Dataplex + BigQuery row/column-level security behind RAG sources

Best-of-Breed

  • Cyera / BigID / Securiti — DSPM: know what sensitive data feeds agents, across all three clouds
  • Protect AI / HiddenLayer — scan datasets + embeddings pipelines for poisoning
  • Immuta / Privacera — policy-based access enforcement on lakehouse data behind RAG
Maps toOWASP LLM: data poisoningOWASP LLM: disclosureATLAS: PoisoningDASF: data plane
§3

Cross-Cutting Planes

Three capabilities that don't sit at any single hop but decide whether the layered controls actually hold: knowing when something got through, surviving it, and finding the agents nobody registered.

Plane A

Detection & Incident Response

  • Agent-aware IR runbooks — contain: revoke the agent's identity + cut its gateway; eradicate: rotate credentials, purge poisoned memory and indexes; recover: restore last-known-good prompt/tool config
  • Forensics from traces — full prompt + tool-call replay from OTel spans; retention set for investigation, not just debugging
  • Native detections into SOAR — Defender XDR, GuardDuty, SCC AI Protection findings drive automated containment
  • Kill-switch drill — tabletop and execute the revocation path quarterly; an untested kill switch is a hope
Plane B

Resilience & Cost Control

  • Denial-of-wallet defenses — per-consumer token quotas and rate limits at the AI gateway; budget anomaly alerts
  • Loop circuit breakers — max iterations / max tool calls per task so a manipulated agent can't run away
  • Model failover routing — provider or region outage degrades gracefully instead of failing open
  • Restorable state — versioned memory and vector indexes with tested restore; poisoning recovery is a rollback, not a rebuild
Plane C

Posture & Discovery (AI-SPM)

  • Shadow-agent discovery — continuously find unregistered agents, models, and MCP servers across all three clouds (Wiz AI-SPM, Prisma AIRS, Noma)
  • Maker-built agents — Copilot Studio inventory via M365 admin center / Copilot Control System + Zenity; the canonical shadow-agent population
  • Drift detection — SCC posture controls, Defender CSPM: alert when an agent's config departs from the approved baseline (public IP appears, CMK removed, guardrail disabled)
  • Registry reconciliation — discovered inventory diffed against the governance registry; anything unregistered is blocked, not backlogged
§4

Deployment-Time Pipeline

Runtime controls assume the artifact that shipped was clean. These gates run in CI/CD before an agent version ever reaches L4 — fail any gate, no deploy.

Gate 1

Supply Chain

  • Model provenance — pull only from registry; signed weights, HiddenLayer/Protect AI Guardian scan for backdoors
  • AIBOM — models, datasets, prompts, tools, MCP servers inventoried per release
  • Dependency + container scanning (Snyk, Wiz, Defender for Cloud)
Gate 2

Config & IaC

  • IaC policy-as-code — Terraform/Bicep checked: private networking on, public access off, CMK/CMEK on, per-tool roles present
  • Prompt & tool-schema versioning — system prompts and tool definitions in git, peer-reviewed like code
  • Secrets scan (GitGuardian) on everything the agent ships with
Gate 3

Adversarial Testing

  • Automated red-team — injection, jailbreak, tool-abuse, and exfiltration scenarios vs. the real agent (Foundry AI Red Teaming Agent, PyRIT, Gauntlet-style CI gate)
  • Safety + groundedness evals with release thresholds
  • Agentic abuse cases — excessive-agency and cross-agent propagation scenarios
Gate 4

Approval & Registration

  • Threat model refreshed — MAESTRO / agentic STRIDE pass over any new tool, data source, or peer agent
  • Use-case risk review — NIST AI RMF-mapped intake; EU AI Act tiering where applicable
  • Agent registered — Entra Agent ID / AgentCore / GCP Agent Identity created with owner, scope, expiry
  • Rollback + kill switch verified before traffic
§5

Framework Crosswalk

How the seven layers land against the frameworks auditors and customers will ask about.

LayerOWASP (LLM / Agentic / MCP / NHI)MITRE ATLAS tacticsNIST AI RMFDASF 3.0
L1 NetworkLLM Top 10: supply chain, DoSExfiltration, ImpactManage 2.4Runtime plane risks
L2 IdentityNHI Top 10 (all); Agentic: excessive agencyCredential Access, Priv. Esc.Govern 1.3, ManageServing & ops controls
L3 GuardrailsLLM01 injection, LLM02 insecure outputPrompt Injection, EvasionMeasure 2.xInference plane risks
L4 RuntimeAgentic: memory poisoning, rogue agentsPersistence, Defense EvasionManage 1.xModel plane risks
L5 Multi-agentAgentic Top 10 (comms, impersonation)Lateral MovementGovern 5, Managev3.0 agent risks
L6 Tools/MCPMCP Top 10 (all); LLM: plugins/supply chainExecution, CollectionMap 3.x, ManageTool integration risks
L7 DataLLM: data poisoning, sensitive disclosurePoisoning, CollectionMap 1.x, MeasureData plane risks
Planes A–CAgentic: rogue agents, resource abuseDiscovery, ImpactGovern 6, Manage 4.xOps & governance controls
§6

Build Order — First Ten Moves

If you implement nothing else this quarter, do these, in this order. Each is cheap relative to the class of incident it removes.

  1. Private networking on day one. Foundry Standard Setup w/ BYO VNet, AgentCore behind PrivateLink + gateway-only invocation, or Agent Engine inside a VPC-SC perimeter. Retrofitting is 10× harder.
  2. No secrets in the agent's reach. Managed identity / AgentCore token vault / Workload Identity Federation only; run a secrets scan to prove it.
  3. Guardrails on both directions of every model call — Prompt Shields, Bedrock Guardrails, or Model Armor floor settings — before the first user touches it.
  4. Per-tool least privilege. One IAM role / OBO scope / service account per tool, not one fat role per agent.
  5. Security-trimmed retrieval. Doc-level ACLs in AI Search / KB metadata filters / Vertex ACL-aware search — the #1 real-world agent leak is oversharing via RAG.
  6. Register every agent as an NHI with an owner and an expiry; wire the inventory (Entra Agent ID / AgentCore / GCP Agent Identity + NHI platform) before agent #10 exists.
  7. MCP gateway + allowlist. No direct agent→tool paths; vet and pin every MCP server version.
  8. Adversarial CI gate. Injection/jailbreak/tool-abuse regression suite that blocks deploys — automated, not annual.
  9. Trace everything to the SIEM. OTel spans per step + tool call into Sentinel / Security Lake / Google SecOps; alert on tool-call anomalies and token-spend spikes.
  10. Human gate + kill switch. Approval step for consequential actions; one revocation (Conditional Access block / gateway cut / IAM disable) that stops the agent in seconds — and drill it quarterly.
§7

Acronym Legend

Every abbreviation used in the diagram and control matrix, in one place.

A2AAgent-to-Agent protocol — Google-originated standard for inter-agent communication
ACLAccess Control List
ADKAgent Development Kit (Google)
AIBOMAI Bill of Materials — inventory of models, datasets, prompts, and tools per release
AI-SPMAI Security Posture Management
AOAIAzure OpenAI
APIMAzure API Management
ATLASMITRE Adversarial Threat Landscape for Artificial-Intelligence Systems
authN/Zauthentication / authorization
BYOBring Your Own (network, storage, keys)
C2Command and Control (attacker infrastructure)
CI/CDContinuous Integration / Continuous Deployment
CMK / CMEKCustomer-Managed (Encryption) Key — Azure/AWS and GCP terms for the same control
CSACloud Security Alliance
CSPMCloud Security Posture Management
DASFDatabricks AI Security Framework
DLPData Loss Prevention
DoSDenial of Service
DSPMData Security Posture Management
FGACFine-Grained Access Control
FQDNFully Qualified Domain Name
GAGenerally Available
HIPAAHealth Insurance Portability and Accountability Act
HITLHuman-in-the-Loop
IaCInfrastructure as Code
IAMIdentity and Access Management
IdPIdentity Provider
IRIncident Response
JITJust-in-Time (access elevation)
JWTJSON Web Token
KBKnowledge Base (Bedrock)
KMSKey Management Service (AWS)
LLMLarge Language Model
M365Microsoft 365
MAESTROMulti-Agent Environment, Security, Threat, Risk & Outcome — agentic-AI threat-modeling framework
MCPModel Context Protocol — standard connecting agents to tools and data
MCRAMicrosoft Cybersecurity Reference Architectures
mTLSmutual TLS — both sides authenticate with certificates
NGFWNext-Generation Firewall
NHINon-Human Identity — service accounts, workload identities, agents
NIST AI RMFNIST AI Risk Management Framework (Govern / Map / Measure / Manage)
NSGNetwork Security Group (Azure)
OAuthopen standard for delegated authorization
OBOOn-Behalf-Of — delegated flow carrying the end-user's entitlements downstream
OTelOpenTelemetry — open standard for traces, metrics, and logs
OWASPOpen Worldwide Application Security Project
PIIPersonally Identifiable Information
PIMPrivileged Identity Management (Microsoft Entra)
PyRITPython Risk Identification Toolkit — Microsoft's open-source AI red-team tool
RAGRetrieval-Augmented Generation
RBACRole-Based Access Control
SaaSSoftware as a Service
SAGASecurity Architecture for Governing Agentic systems (research framework)
SAIFSecure AI Framework (Google)
SCCSecurity Command Center (Google Cloud)
SIEMSecurity Information and Event Management
SigV4AWS Signature Version 4 — request-signing scheme
SOARSecurity Orchestration, Automation and Response
SSESecurity Service Edge (Zscaler, Netskope)
STRIDESpoofing, Tampering, Repudiation, Information disclosure, DoS, Elevation — threat-model taxonomy
TLSTransport Layer Security
UEBAUser and Entity Behavior Analytics
VNetVirtual Network (Azure)
VPCVirtual Private Cloud (AWS / GCP)
VPC-SCVPC Service Controls — GCP data-exfiltration perimeter
WAFWeb Application Firewall
XDRExtended Detection and Response