OWASP Top 10 for LLM Applications 2025
Agency and Resource Bounds

OWASP Top 10 for LLM Applications 2025 OWASPLLM-6: Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

Address OWASP LLM06:2025 Excessive Agency + LLM10:2025 Unbounded Consumption. Excessive Agency occurs when an LLM is granted too much functionality (excessive functions + permissions + autonomy) such that compromise causes outsized impact including unauthorised actions + data modification + resource consumption + financial impact. Unbounded Consumption occurs when LLM systems consume excessive resources (compute + tokens + external API calls + cost) enabling DoS + cost amplification + denial of wallet attacks. Mitigations for Excessive Agency include (a) limit LLM functions + permissions to minimum necessary + (b) implement human-in-the-loop approval for sensitive operations + (c) implement strict allowlists for LLM-callable tools + APIs + (d) avoid open-ended autonomous action chains + (e) implement audit logging for LLM-initiated actions. Mitigations for Unbounded Consumption include (a) implement rate limiting + quota management + (b) implement cost monitoring + alerting + (c) implement timeout + resource limits + (d) implement circuit breakers + bulkheads.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 64 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.3 Account Management
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)

BSI IT-Grundschutz · 2 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-12 User access management and provisioning
  • ISO27043-14 Privileged access management

ISO/SAE 21434 · 2 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

OWASP Top 10:2025 · 2 controls

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-02 User Account Management
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics
  • 62351-8 Role-based access control (RBAC)

ISO 27799:2025 · 1 control

  • ISO27799-01 ePHI access controls and authorization

ISO/IEC 27010:2015 · 1 control

  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

MARS-E · 1 control

  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS

MITRE ATT&CK · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe
  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • ACE-CR-4 Cargo Release Authorization

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.