{"slug": "mlsecops-practical-guide-open-source-handbook-for-securing-ai-systems", "title": "MLSecOps Practical Guide – open-source handbook for securing AI systems", "summary": "The MLSecOps Practical Reference Guide, an open-source handbook for securing AI systems, has been released in version 1.1.3 by maintainer MHaghighian, providing a practitioner reference for AI security, LLM/RAG security, and secure MLOps. The guide synthesizes OWASP AI Exchange, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, OpenSSF Secure MLOps, and CSA MAESTRO, and introduces ten lifecycle control points, explicit release decisions, and an Evidence Pack for auditable output bundles. It is available on GitHub with a DOI of 10.5281/zenodo.21206781.", "body_md": "Open-source MLSecOps handbook for AI security, LLM/RAG, and secure MLOps.\n\n**MLSecOps Practical Reference Guide** is an open-source handbook for **AI security**, **machine learning security**, and **secure MLOps** across the full ML lifecycle — from data and training through deployment, runtime monitoring, SOC, and governance.\n\nIt covers **LLM security**, **RAG security**, **agentic AI**, **MCP**, **AI supply chain security**, and **DevSecOps** patterns for production AI systems. Use it as a practitioner reference — not a product manual or an official OWASP, NIST, or ISO standard.\n\nRead online (recommended) |\n|\n\n**Source repository**[github.com/MHaghighian/MLSecOps](https://github.com/MHaghighian/MLSecOps)** Maintainer site**[mhsec.me](https://mhsec.me)** Latest release**[v1.1.3](https://github.com/MHaghighian/MLSecOps/releases/tag/v1.1.3)** Cite (DOI)**[10.5281/zenodo.21206781](https://doi.org/10.5281/zenodo.21206781)Security engineers, ML/MLOps teams, architects, and risk owners who need a **practical MLSecOps** reference aligned with OWASP AI Exchange, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, OpenSSF Secure MLOps, and CSA MAESTRO — with operational controls, evidence, and rollout guidance.\n\nThis guide **synthesizes** OWASP, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, OpenSSF Secure MLOps, and CSA MAESTRO. Its operational additions are:\n\n**Ten lifecycle control points**— one thread from change initiation through monitoring** Explicit release decisions**— separate evidence-producing steps from blocking gates (control points 4, 7, 8) and integrity at 9— auditable output bundle per release`Evidence Pack`\n\n— architecture cards, decision matrix, templates, playbooks[Implementation Reference](/MHaghighian/MLSecOps/blob/main/chapters-en/17-appendix-e-implementation-reference.md)\n\nLearn more: [Chapter 1 — What this guide adds](/MHaghighian/MLSecOps/blob/main/chapters-en/01-intro.md#what-this-guide-adds-beyond-owasp-openssf-and-nist).\n\n| Area | Chapters / focus |\n|---|---|\nMLSecOps & threat modeling |\nScope, risk, autonomous AI threats |\nData security & privacy |\nTraining data, PII, augmentation confidentiality |\nAI / ML supply chain |\nModel artifacts, provenance, signing |\nSecure ML pipeline |\nTen control points, CI/CD gates, Evidence Pack |\nLLM security & RAG |\nGateway, guardrails, prompt injection, retrieval ACL |\nAgentic AI & MCP |\nTool policy, Intent Gate, scoped execution |\nRuntime & SOC |\nMonitoring, detection, incident response |\nGovernance & compliance |\nEvidence, maturity roadmap, Kubernetes patterns |\n\nTraditional DevSecOps does not fully address model artifacts, training data, LLMs, RAG, agents, or runtime AI risks.\n\n**MLSecOps** extends existing security practices with lifecycle-specific controls, evidence generation, and AI-focused governance — without replacing your CI/CD or MLOps platform.\n\n- Ten-point\n**lifecycle control model** and release decision points methodology per release`Evidence Pack`\n\n— architecture cards, templates, playbooks[Implementation Reference](/MHaghighian/MLSecOps/blob/main/chapters-en/17-appendix-e-implementation-reference.md)**Threat / control / tool mapping**([Ch.12](/MHaghighian/MLSecOps/blob/main/chapters-en/12-threat-control-tools-map.md))** LLM, RAG, Agent, and MCP**security ([Ch.7](/MHaghighian/MLSecOps/blob/main/chapters-en/07-llm-rag-security.md)·[Ch.8](/MHaghighian/MLSecOps/blob/main/chapters-en/08-agentic-ai-security.md))**AI supply chain** and model artifact security ([Ch.5](/MHaghighian/MLSecOps/blob/main/chapters-en/05-model-artifact-supply-chain.md))**Kubernetes** reference patterns ([Ch.16](/MHaghighian/MLSecOps/blob/main/chapters-en/16-kubernetes-deployment-reference.md))- SOC integration, governance, case studies, and maturity roadmap\n\nRead online |\n|\n\n**Markdown**[Table of Contents](/MHaghighian/MLSecOps/blob/main/chapters-en/TABLE-OF-CONTENTS.md)·[Chapter 1](/MHaghighian/MLSecOps/blob/main/chapters-en/01-intro.md)**Role-based paths**[GETTING-STARTED.md](/MHaghighian/MLSecOps/blob/main/GETTING-STARTED.md)** Contribute**[CONTRIBUTING.md](/MHaghighian/MLSecOps/blob/main/CONTRIBUTING.md)·[Issues](https://github.com/MHaghighian/MLSecOps/issues)·[Discussions](https://github.com/MHaghighian/MLSecOps/discussions)| Role | Start here |\n|---|---|\n| Executive / risk |\n|\n\n[Ch.2](/MHaghighian/MLSecOps/blob/main/chapters-en/02-scope-risk-threat-model.md)→[Ch.6](/MHaghighian/MLSecOps/blob/main/chapters-en/06-pipeline.md)→[Ch.12](/MHaghighian/MLSecOps/blob/main/chapters-en/12-threat-control-tools-map.md)[Ch.6](/MHaghighian/MLSecOps/blob/main/chapters-en/06-pipeline.md)→[Ch.5](/MHaghighian/MLSecOps/blob/main/chapters-en/05-model-artifact-supply-chain.md)[Ch.7](/MHaghighian/MLSecOps/blob/main/chapters-en/07-llm-rag-security.md)→[Ch.8](/MHaghighian/MLSecOps/blob/main/chapters-en/08-agentic-ai-security.md)[Appendix E](/MHaghighian/MLSecOps/blob/main/chapters-en/17-appendix-e-implementation-reference.md)→[Ch.6](/MHaghighian/MLSecOps/blob/main/chapters-en/06-pipeline.md)Project status, roadmap, and governance: [GOVERNANCE.md](/MHaghighian/MLSecOps/blob/main/GOVERNANCE.md) · [CHANGELOG.md](/MHaghighian/MLSecOps/blob/main/CHANGELOG.md).\n\nExecutive lifecycle (detail in [Chapter 6](/MHaghighian/MLSecOps/blob/main/chapters-en/06-pipeline.md)):\n\n**Coverage:** classic ML · LLM · RAG · managed AI APIs · agents · MCP · Shadow AI · supply chain · runtime · SOC · governance · Kubernetes patterns.\n\n**Latest release:** **v1.1.3** · [Zenodo DOI](https://doi.org/10.5281/zenodo.21206781)\n\n| Format | Link |\n|---|---|\nDocumentation site |\n|\n\n**Markdown**`chapters-en/`\n\nin this repository**Source (ZIP)**[v1.1.3 archive](https://github.com/MHaghighian/MLSecOps/archive/refs/tags/v1.1.3.zip)All releases: [GitHub Releases](https://github.com/MHaghighian/MLSecOps/releases). Pre-built PDF/DOCX are **not** published with releases; build Word locally if you need a printable copy (below).\n\nGenerate the printable Word edition from the markdown sources:\n\n```\npip install -r scripts/requirements-docx.txt\npython scripts/build-docx.py --render-mermaid\n```\n\n**Output:** `dist/MLSecOps-Practical-Reference-Guide-v{version}.docx`\n\n(version read from [CITATION.cff](/MHaghighian/MLSecOps/blob/main/CITATION.cff)). Export PDF from Word (or Pandoc) if needed.\n\n| Option | Purpose |\n|---|---|\n`--render-mermaid` |\nRender missing diagram PNGs from `assets/diagrams/source/*.mmd` (uses system Chrome or Edge) |\n`--reference path/to/file.docx` |\nOverride the Word style template |\n`--output path/to/file.docx` |\nCustom output path |\n`--skip-validate` |\nSkip post-build content checks |\n\nThe build uses **Pandoc** with the project Word template (`scripts/templates/reference.docx`\n\n, or auto-download from the [v1.0.0 Release DOCX](https://github.com/MHaghighian/MLSecOps/releases/download/v1.0.0/MLSecOps-Practical-Reference-Guide-v1.0.0.docx) on first run). Template details: [scripts/templates/README.md](/MHaghighian/MLSecOps/blob/main/scripts/templates/README.md). Maintainer checklist: [RELEASING.md](/MHaghighian/MLSecOps/blob/main/RELEASING.md).\n\n| Question | Answer |\n|---|---|\nWhat is MLSecOps? |\nSecurity practices for the ML/AI lifecycle — extending DevSecOps with model, data, LLM, RAG, agent, and runtime controls. |\nIs this an official OWASP or NIST document? |\nNo. It references those frameworks but is an independent open-source guide (CC BY-SA 4.0). |\nWhere should I start reading? |\n|\n\n**How do I cite this work?**[Zenodo DOI](https://doi.org/10.5281/zenodo.21206781)or[CITATION.cff](/MHaghighian/MLSecOps/blob/main/CITATION.cff).\n\n```\nMLSecOps/\n├── chapters-en/          # Guide chapters (English)\n├── assets/diagrams/      # Diagram PNGs and Mermaid source (.mmd)\n├── scripts/              # DOCX build (build-docx.py, mermaid_to_png.py)\n├── dist/                 # Local DOCX output (gitignored)\n├── GETTING-STARTED.md    # Role-based reading paths\n├── CITATION.cff          # Citation metadata (DOI)\n├── CHANGELOG.md\n└── .github/workflows/    # Pages deploy, releases\n```\n\nWe welcome review from practitioners.\n\n**Bug or typo:**[Open an issue](https://github.com/MHaghighian/MLSecOps/issues)** Suggestion / discussion:**[GitHub Discussions](https://github.com/MHaghighian/MLSecOps/discussions)** Pull request:**see[CONTRIBUTING.md](/MHaghighian/MLSecOps/blob/main/CONTRIBUTING.md)\n\nIf you review the guide and agree to be listed, we can add your name under **Community reviewers** (with your permission only).\n\n**Share this project:** linking from LinkedIn, blog posts, OWASP community threads, Dev.to, or internal security wikis helps others discover the guide and improves search visibility for `MLSecOps`\n\nand `MLSecOps Practical Reference Guide`\n\n.\n\nSee [CITATION.cff](/MHaghighian/MLSecOps/blob/main/CITATION.cff) for machine-readable metadata.\n\n```\nHaghighian, M. (2026). MLSecOps Practical Reference Guide (v1.1.3).\nZenodo. https://doi.org/10.5281/zenodo.21206781\n```\n\n- OWASP AI Exchange (\n[https://owaspai.org/](https://owaspai.org/)) - OWASP LLM Top 10 (2025)\n- OWASP ML Top 10 (draft)\n- OWASP Agentic / MCP\n- MITRE ATLAS\n- NIST AI RMF\n- ISO/IEC 42001 · ISO/IEC 23894\n- EU AI Act\n- OpenSSF MLSecOps Whitepaper\n- CSA MAESTRO\n- CSA AARM —\n[AARM Alignment](/MHaghighian/MLSecOps/blob/main/references/AARM-ALIGNMENT.md)(agentic runtime; complementary mapping)\n\n|\n\n[LICENSE](/MHaghighian/MLSecOps/blob/main/LICENSE)[SECURITY.md](/MHaghighian/MLSecOps/blob/main/SECURITY.md)[CODE_OF_CONDUCT.md](/MHaghighian/MLSecOps/blob/main/CODE_OF_CONDUCT.md)Questions: [Issues](https://github.com/MHaghighian/MLSecOps/issues) · [Discussions](https://github.com/MHaghighian/MLSecOps/discussions).", "url": "https://wpnews.pro/news/mlsecops-practical-guide-open-source-handbook-for-securing-ai-systems", "canonical_source": "https://github.com/MHaghighian/MLSecOps", "published_at": "2026-08-14 02:33:32+00:00", "updated_at": "2026-08-14 03:11:03.132827+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-infrastructure", "ai-ethics"], "entities": ["MHaghighian", "OWASP", "MITRE ATLAS", "NIST", "ISO/IEC 42001", "OpenSSF", "CSA MAESTRO", "GitHub"], "alternates": {"html": "https://wpnews.pro/news/mlsecops-practical-guide-open-source-handbook-for-securing-ai-systems", "markdown": "https://wpnews.pro/news/mlsecops-practical-guide-open-source-handbook-for-securing-ai-systems.md", "text": "https://wpnews.pro/news/mlsecops-practical-guide-open-source-handbook-for-securing-ai-systems.txt", "jsonld": "https://wpnews.pro/news/mlsecops-practical-guide-open-source-handbook-for-securing-ai-systems.jsonld"}}