OWASP Top 10 for LLM Applications 2025
Prompt Security

OWASP Top 10 for LLM Applications 2025 OWASPLLM-1: Prompt Injection and System Prompt Leakage (LLM01 + LLM07)

Address OWASP LLM01:2025 Prompt Injection + LLM07:2025 System Prompt Leakage. Prompt Injection occurs when attacker input causes the LLM to act outside intended boundaries via direct injection (user-supplied) or indirect injection (through retrieved data + documents + tools + multi-modal inputs). System Prompt Leakage occurs when the system prompt + instructions + sensitive data embedded therein become disclosed to users or attackers. Mitigations include (a) treat all user input + retrieved content as untrusted + (b) maintain clear instruction-data separation + privilege boundaries in prompts + (c) use input + output filtering for known injection patterns + (d) implement least-privilege access for LLM-invoked tools + APIs + (e) avoid embedding secrets + credentials + sensitive instructions in system prompts + (f) implement output classification + filtering against jailbreak + leakage + (g) maintain monitoring + detection for injection + leakage attempts.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 103 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

OWASP Top 10:2025 · 4 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats

MARS-E · 3 controls

BSI IT-Grundschutz · 2 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO 27799:2025 · 2 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-12 Unique user identification and authentication

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management

ISO/SAE 21434 · 2 controls

  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

MDS2 (Medical Device) · 2 controls

  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS
  • MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management
  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-03 Authentication Mechanisms
  • AMLCTF-35 Identity Verification Standard
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • 62351-8 Role-based access control (RBAC)

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

MITRE ATT&CK · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • ACE-CR-4 Cargo Release Authorization
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.