Inventory every AI assistant, model gateway, agent platform, MCP server, and coding assistant in use.
CISO checklist
AI security checklist for CISOs and security leaders.
Use this checklist to move from vague AI concern to concrete controls: inventory, identity, data boundaries, model gateways, agent permissions, MCP review, logging, and incident response.

Checklist
Ten controls to establish first.
Classify workflows by data sensitivity: public, internal, confidential, regulated, source code, and production operations.
Route enterprise AI usage through approved providers or model gateways where possible.
Give agents distinct identities instead of shared human accounts or broad service accounts.
Separate read-only analysis from write-capable automation and destructive actions.
Block secrets, customer data, and regulated data from unapproved prompts, uploads, logs, and connectors.
Review MCP servers, browser tools, shell tools, file access, network access, and OAuth flows before use.
Log model, user, agent, repository, tool call, policy decision, cost, and outcome metadata.
Require human approval for production changes, credential rotation, package publishing, and customer-impacting actions.
Add AI-specific scenarios to incident response, tabletop exercises, vendor reviews, and board reporting.