AI Security · Runtime · Supply Chain
Postura de segurança das tecnologias de IA
Avaliação dos quinze vetores de ataque de IA, dos nove controles de runtime governance, da descoberta contínua de AI-SPM e da exposição da cadeia de suprimentos de modelos, MCPs e agentes.
Cobertura AI Security
21%
15 vetores avaliados
Cobertura Runtime
32%
9 controles de runtime
Exposição cibernética máx.
10/10
Tecnologias com privilégio excessivo
11
controle ausente
Lacunas — AI Security (OWASP Top 10 LLM / SANS)
Cobertura do controle no portfólio, do menor para o maior.
Lacunas — AI Runtime Governance
Cobertura do controle no portfólio, do menor para o maior.
Exposição de segurança por tecnologia
| Tecnologia | Exp. segurança | Security ctrl. | Runtime ctrl. | Supply chain | Prioridade |
|---|---|---|---|---|---|
| Agentes autônomos de back-office | 10.0 | 7% | 11% | 7.0 | Auditoria imediata |
| MCP Gateway corporativo | 9.5 | 13% | 22% | 9.0 | Próximo ciclo |
| Microsoft 365 Copilot | 9.0 | 27% | 33% | 4.0 | Monitoramento contínuo |
| Azure OpenAI Service | 8.0 | 33% | 44% | 7.0 | Próximo ciclo |
| GitHub Copilot / Cursor | 8.0 | 20% | 22% | 8.0 | Monitoramento contínuo |
| Glean (AI Search corporativa) | 8.0 | 13% | 22% | 6.0 | Monitoramento contínuo |
| ServiceNow AI Agents | 8.0 | 13% | 22% | 7.0 | Monitoramento contínuo |
| ChatGPT Enterprise | 8.0 | 20% | 11% | 6.0 | Monitoramento contínuo |
| UiPath / Automation Anywhere Agentic | 8.0 | 13% | 33% | 7.0 | Próximo ciclo |
| Amazon Bedrock | 7.0 | 27% | 56% | 8.0 | Monitoramento contínuo |
| Salesforce Agentforce | 7.0 | 20% | 33% | 6.0 | Monitoramento contínuo |
| Google Gemini / Vertex AI | 7.0 | 20% | 33% | 7.0 | Monitoramento contínuo |
| AI Security Posture (Palo Alto / CrowdStrike) | 7.0 | 40% | 44% | 6.0 | Observação |
| Copiloto de crédito (motor de decisão) | 6.5 | 27% | 44% | 6.0 | Próximo ciclo |
| Databricks Mosaic AI | 6.0 | 27% | 56% | 6.0 | Monitoramento contínuo |
| AI Observability (Arize / LangSmith) | 6.0 | 13% | 33% | 5.0 | Observação |
Context Engineering
- Context Management
- Context Lineage
- Context Security
- Context Classification
- Context Leakage
- Context Poisoning
- Retrieval Context Quality
AI-SPM
- Model Discovery
- Agent Discovery
- MCP Discovery
- Attack Surface Mapping
- Vulnerability Identification
- Security Drift
- Exposure Mapping
AI Supply Chain
- Open Source Models
- Marketplace Models
- Third Party Providers
- External Dependencies
- External APIs
- MCP Marketplaces
- Agent Marketplaces
Agentes autônomos de back-office
Fornecedores e dependências: LangGraph · MCP marketplace público · APIs transacionais internas
Vetores de ataque cobertos
1/15 · 7%- Prompt Injection
- Indirect Prompt Injection
- Jailbreak
- Hallucination
- Data Leakage
- Data Exfiltration
- RAG Poisoning
- Model Poisoning
- Adversarial Attacks
- Supply Chain Attack
- Secrets Exposure
- Excessive Permissions
- Agent Takeover
- Privilege Escalation
- Lateral Movement
Runtime governance
1/9 · 11%- Runtime Security
- Runtime Observability
- Runtime Resilience
- Runtime Monitoring
- Runtime Logging
- Runtime Segregation
- Runtime Enforcement
- Runtime Policy Controls
- Runtime Platform Risk
MCP Gateway corporativo
Fornecedores e dependências: MCP registries públicos · Servidores MCP de terceiros · Conectores comunitários
Vetores de ataque cobertos
2/15 · 13%- Prompt Injection
- Indirect Prompt Injection
- Jailbreak
- Hallucination
- Data Leakage
- Data Exfiltration
- RAG Poisoning
- Model Poisoning
- Adversarial Attacks
- Supply Chain Attack
- Secrets Exposure
- Excessive Permissions
- Agent Takeover
- Privilege Escalation
- Lateral Movement
Runtime governance
2/9 · 22%- Runtime Security
- Runtime Observability
- Runtime Resilience
- Runtime Monitoring
- Runtime Logging
- Runtime Segregation
- Runtime Enforcement
- Runtime Policy Controls
- Runtime Platform Risk
Microsoft 365 Copilot
Fornecedores e dependências: OpenAI (via Azure) · Microsoft Graph · Marketplace de agentes
Vetores de ataque cobertos
4/15 · 27%- Prompt Injection
- Indirect Prompt Injection
- Jailbreak
- Hallucination
- Data Leakage
- Data Exfiltration
- RAG Poisoning
- Model Poisoning
- Adversarial Attacks
- Supply Chain Attack
- Secrets Exposure
- Excessive Permissions
- Agent Takeover
- Privilege Escalation
- Lateral Movement
Runtime governance
3/9 · 33%- Runtime Security
- Runtime Observability
- Runtime Resilience
- Runtime Monitoring
- Runtime Logging
- Runtime Segregation
- Runtime Enforcement
- Runtime Policy Controls
- Runtime Platform Risk