Frameworks / OWASP Top 10 for LLM Applications 2025 / OWASPLLM-1 OWASP Top 10 for LLM Applications 2025
Prompt Security
OWASP Top 10 for LLM Applications 2025 OWASPLLM-1: Prompt Injection and System Prompt Leakage (LLM01 + LLM07) Address OWASP LLM01:2025 Prompt Injection + LLM07:2025 System Prompt Leakage. Prompt Injection occurs when attacker input causes the LLM to act outside intended boundaries via direct injection (user-supplied) or indirect injection (through retrieved data + documents + tools + multi-modal inputs). System Prompt Leakage occurs when the system prompt + instructions + sensitive data embedded therein become disclosed to users or attackers. Mitigations include (a) treat all user input + retrieved content as untrusted + (b) maintain clear instruction-data separation + privilege boundaries in prompts + (c) use input + output filtering for known injection patterns + (d) implement least-privilege access for LLM-invoked tools + APIs + (e) avoid embedding secrets + credentials + sensitive instructions in system prompts + (f) implement output classification + filtering against jailbreak + leakage + (g) maintain monitoring + detection for injection + leakage attempts.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 103 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) ISO27799-01 ePHI access controls and authorization ISO27799-12 Unique user identification and authentication ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO21434-13 Authentication and password management ISO21434-14 Privileged access management BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access ISMSP-AC-01 Access Control Policy ISMSP-AC-03 Authentication Mechanisms AMLCTF-35 Identity Verification Standard DSO-3 Data Access Management CAT-IRP-4 Organizational characteristics FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery 23837-1.7.3 Authentication and classical post-processing 27011-8.1 User Endpoint Devices 27400-6.1 Secure Device Design MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice TEFCAREC-1 Common Agreement Conformance and Onboarding ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.