TemplateCopy-ready

AI Acceptable Use Policy

A starter policy for approved tools, sensitive data, model use, human review, and prohibited workflows.

TemplateCopy-ready

AI Incident Response Playbook

A response checklist for prompt injection, exposed model keys, runaway agents, unsafe tool calls, and data leakage.

TemplateCopy-ready

MCP Server Security Review

A review checklist for local MCP servers, tokens, filesystem access, network access, and tool permissions.

TemplateCopy-ready

CISO Board Memo for AI Risk

A concise board-ready structure for AI adoption, control maturity, risk scenarios, and investment requests.

TemplateCopy-ready

Secure AI Coding Assistant Rollout

A practical rollout checklist for Claude Code, Codex, Cursor, and other coding assistants in security-sensitive teams.

TemplateCopy-ready

Vendor AI Security Questionnaire

Questions for vendors handling prompts, customer data, model logs, subprocessors, training data, retention, and incident disclosure.

AI Acceptable Use Policy

Use this template to define which AI systems are approved, what data may be used, what actions require human review, and which workflows are prohibited.

  • Approved AI tools and model gateways must have named business and technical owners.
  • Secrets, regulated data, customer data, and unpublished source code require explicit approval before model exposure.
  • Agents may not deploy, publish packages, rotate production credentials, or change access without human approval.
  • Teams must retain enough logs to reconstruct prompts, model responses, tool calls, and resulting changes.

AI Incident Response Playbook

Use this when an AI tool leaks data, executes unintended actions, follows malicious instructions, or exposes credentials.

  1. Identify the affected model, gateway, user, app, repository, tool, and environment.
  2. Disable risky tool access and revoke exposed model keys or virtual keys.
  3. Preserve prompts, responses, logs, file changes, shell commands, and network traces.
  4. Determine whether customer data, secrets, source code, or production systems were exposed.
  5. Rotate credentials, redeploy cleanly, and document detection gaps before restoring access.

MCP Server Security Review

  • List every MCP server, owner, data source, tool action, credential, and network dependency.
  • Run local MCP servers with minimal filesystem, process, and network permissions.
  • Separate read-only tools from write-capable tools and destructive actions.
  • Log tool calls with user, agent, source prompt, target system, and result.
  • Review prompt injection paths from issues, docs, tickets, webpages, and repositories.

CISO Board Memo for AI Risk

Use this structure for a one-page executive update: current AI adoption, top risk scenarios, control maturity, incidents or near misses, investment needs, and 90-day milestones.

Secure AI Coding Assistant Rollout

  • Start with approved repositories, non-production branches, and clear reviewer ownership.
  • Require tests, security checks, and human approval before merge.
  • Prevent assistants from reading secrets, private tokens, production logs, or unnecessary customer data.
  • Define allowed shell, network, browser, package manager, and commit actions.

Vendor AI Security Questionnaire

  • What customer data is sent to models, subprocessors, logs, or training pipelines?
  • How are prompts, responses, embeddings, files, and tool outputs retained and deleted?
  • Which controls prevent prompt injection, data exfiltration, and unsafe tool execution?
  • How quickly will the vendor disclose AI-related security incidents?