Perform threat modelling of agentic workflows
Is this legally binding?
Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
Map out agentic workflows to identify where security risks might occur and where threat actors could exploit vulnerabilities; threat modelling identifies areas of interest for control placement.
From the source
“Threat modelling identifies where security risks might occur in the system’s workflows.”
Addendum, Section 4.1 Step 1
What this connects to
1 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Maps across to1
- External frameworkFunction: MAPGuidanceGAGE analysis, not official
Agentic workflow threat modelling operationalises the MAP function
Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.