Objective
Submit the implementation-neutral CAEP requirement language to the OWASP AISVS AI Incident Response discussion and the Agentic Security Initiative working group.
Contribution artifact
Primary targets
- Existing OWASP/AISVS discussion:
OWASP/AISVS#1083 — AI Incident Response.
- OWASP GenAI Security Project Slack:
#team-genai-agentic-security-initiative.
- Agentic Security Initiative open working-group meeting if maintainers request a walkthrough.
Message
Use the ready-to-post text in:
protocols/caep/OWASP_AISVS_IR_PROPOSAL.md#ready-to-post-working-group-message
Submission checklist
Access note
The connected GitHub integration can write to this repository but previously received HTTP 403 when attempting to comment in OWASP/AISVS. If that restriction remains, the external GitHub comment and Slack post require an authenticated human account. No claim of external submission should be made until the message is visible in the target community.
Success criteria
At least one AISVS or Agentic Security maintainer responds with one of:
- already covered, with exact control references;
- accepted gap, with requested chapter/appendix placement;
- request for narrower requirement language;
- request for a reference implementation or test corpus walkthrough.
Objective
Submit the implementation-neutral CAEP requirement language to the OWASP AISVS AI Incident Response discussion and the Agentic Security Initiative working group.
Contribution artifact
Primary targets
OWASP/AISVS#1083— AI Incident Response.#team-genai-agentic-security-initiative.Message
Use the ready-to-post text in:
protocols/caep/OWASP_AISVS_IR_PROPOSAL.md#ready-to-post-working-group-messageSubmission checklist
#team-genai-agentic-security-initiative.OWASP/AISVS#1083without duplicating the entire document.Access note
The connected GitHub integration can write to this repository but previously received HTTP 403 when attempting to comment in
OWASP/AISVS. If that restriction remains, the external GitHub comment and Slack post require an authenticated human account. No claim of external submission should be made until the message is visible in the target community.Success criteria
At least one AISVS or Agentic Security maintainer responds with one of: