The Operating Discipline for AI Library™

The AI IT Security Implementation & Strategy™

Running the Program the Audit Proved You Needed

Available now

Get it on Amazon, Kindle $24.99, paperback $46.99, hardback $99.99. 404 pages, published August 2026. Book 06 of 9 in The Operating Discipline for AI Library™, and Volume VI of Pillar II, AI Risk Governance & Security™. Volume V proved the posture. This Volume operates it. Across the four domains a CISO is accountable for, Security Governance and Risk Management, Security Operations, Third-Party and Supply Chain Risk, and Data Protection and Privacy, it converts the audit's evidence into a running program: the AI Security Operating System™, ratified decision rights, living artifacts with owners and cadences, and a 1-Year Target Operating Model for each domain that answers the question every board is now asking. Thirteen chapters, a twenty-two instrument Implementation Toolkit, and a first-ninety-days sequence that puts authority before tooling. The complete set of figures from the book is available below, free to download and use within your organization, alongside the twenty-two operating instruments of the Consulting Toolkit, editable and ready to run.

Buy on Amazon Hardback, paperback, and Kindle editions.
Editions

Hardback, 404 pages, $99.99, ISBN 979-8-9969402-7-1. Paperback, $46.99, ISBN 979-8-9969402-5-7. Kindle edition, $24.99, ISBN 979-8-9969402-6-4.

The AI IT Security Implementation & Strategy™ book cover
Executive Briefing
The AI IT Security Implementation & Strategy™
PDF · 26 Slides
Read the Briefing

The executive briefing, in one page at a time.

A condensed visual companion to the program. The four domains held as one, the Agent Authority Chain™, the claim-versus-capability distinction the auditor and the carrier are testing for, and the twelve-month operating model that ends in installed capability. Built for board distribution and leadership team review.

You proved it. Now run it. The binder was true on the date it was printed.

The audit is done. The board saw the slides, asked reasonable questions, and nodded at the right moments. The findings were real, the risk register was honest, and the regulatory crosswalk held up under scrutiny. Then Tuesday morning arrived, and nothing in the security program actually governs what AI is doing in the enterprise right now. Not the inventory that has been sitting static for four months. Not the vendor questionnaires that went out last quarter to partners who have since quietly enabled AI features nobody reviewed. The binder proved the posture at a point in time. The enterprise kept moving. The gap between those two things grows every single day, and that gap is not a failure of effort. It is a failure of operating model.

Static evidence ages, and it ages into liability. A regulator who picks up the binder six months from now will not see a thorough organization that completed a rigorous assessment. They will see an organization that completed a rigorous assessment and then stopped, a paper trail that shows exactly when attention ended. This Volume picks up exactly where the audit left off. Not to re-prove the posture. To run it, every day, in a way that keeps the evidence current, keeps the board answered, and keeps the security function relevant in an enterprise where machine reasoning now makes consequential decisions alongside human ones.

What the audit handed over, and the condition it arrives in

Ten artifacts cross over from Volume V: the four-layer AI inventory, the Non-Human Identity Inventory, the Agent Boundary Matrix, the AI Vendor Tier Map, the AI Data Flow Map, the Regulatory Crosswalk, the Defensible AI Security Baseline™, the Four-Page Board Pack, the risk register entries, and the compliance gap analysis. Each arrives stale, and they arrive stale at different rates. The crosswalk decays slowly because regulations publish on a schedule. The inventory decays weekly because business units adopt tools continuously. The identity inventory decays whenever an integration is built. The vendor map decays whenever a vendor ships an AI feature, which requires no contract change and generates no notification the security organization reads. That differential decay is the first thing this Volume teaches you to measure, because a control built on a stale population produces a coverage claim that is wrong by an unmeasured margin. The second thing the audit could not hand over is authority. Every artifact describes a state, none of them assigns a right, and instrumentation without authority produces a program that can see everything and stop nothing.

The fourth attack surface

Security programs have organized themselves around three attack surfaces for twenty years: infrastructure, applications, and data. There is now a fourth. Decisions are an attack surface. An AI system that approves a credit application, adjudicates a claim, prices a contract, or authorizes a payment has become the point at which a business outcome is determined, and an attacker who influences that determination has achieved the objective without touching the other three surfaces. No server compromised. No application exploited. No data exfiltrated. The enterprise simply made a decision it would not otherwise have made, acted on it, and generated no alert in doing so. The three established surfaces each have a mature detection discipline. The fourth has almost none, and every unfamiliar instrument in this Volume exists to give it one.

The Agent Authority Chain

The security question for AI systems is no longer whether an attacker can compromise the model. It is whether an attacker can manipulate a system that already holds legitimate authority. Six elements have to be answerable for every consequential machine action, and this Volume calls them the Agent Authority Chain: identity, which system acted. Intent, what objective it was pursuing. Authority, who delegated the right to pursue it, with what scope and what expiry. Context, what information influenced the reasoning. Action, what the system actually did. Impact, what changed in the enterprise as a result. Most organizations can currently answer two of the six. The other four are the ones a regulator, a plaintiff, or a board will ask about after something goes wrong, and each Part of this Volume carries one link of the chain as its primary responsibility.

Four domains. One arc. Twelve chapters that install four operating models.

Each domain receives three chapters in the same sequence. The first names what AI is breaking in that domain, working from the specific artifacts Volume V handed over. The second names how AI rebuilds the domain's capability, because the same technology creating the exposure is the only thing operating at the speed required to govern it. The third is the operating model chapter: the solution categories that matter, described with no vendor names anywhere, whether the department survives in its current form, and the 1-Year Target Operating Model with owners, cadences, and budget lines.

In Security Governance and Risk Management, the shift is from sampling compliance to running continuous compliance, because quarterly reviews governing daily AI behavior is a structural mismatch that creates documented gaps. In Security Operations, the shift is from detecting breaches to supervising machine reasoning, because reasoning can be corrupted without triggering a single traditional alert. In Third-Party and Supply Chain Risk, the shift is from annual questionnaires to continuous monitoring, because a supply chain that mutates weekly cannot be governed by a process that samples annually. In Data Protection and Privacy, the shift is from protecting databases to governing enterprise memory, the persistent context agents accumulate that no erasure request was designed to reach. Chapter 13 then sequences the first ninety days, and it puts the ratification session before the tooling on purpose.

The instruments this Volume adds to the Library

The AI Security Operating System™ is the umbrella that holds the four domains in one program rather than four parallel projects, a governance rhythm across five horizons, daily, weekly, monthly, quarterly, and annual, matched to the speed of the asset it governs. The Decision Rights RACI answers, before deployment, who approves an AI system, who can suspend it without a committee meeting, and who is accountable when it acts. The Human Supervision Matrix™ documents which actions machines may take alone and which require human confirmation. The Red-Button Protocol™ makes suspension a rehearsed capability with a measured time-to-stop rather than a paragraph in a policy. The Shadow AI Sanctioning Pathway™ converts rogue demand into governed capability instead of driving it underground. Adaptive AI Trust Scores™ make vendor trust a managed variable rather than a binary annual assessment. The Non-Human Identity Pyramid™ tiers the identity population that now outnumbers the human one. The AI Decision Provenance Chain™ answers the accountability question when no human decided. Every artifact carries the same discipline: a named owner, a set cadence, and the executive decision it feeds. An artifact missing any of the three is a record, not a governance tool.

A one-year horizon, on purpose

Multi-year transformation plans get written, presented, funded in year one, and defunded in year two when the sponsoring executive changes roles or the threat picture moves. Every target operating model in this Volume is scoped to four quarters, with the milestone the CISO will name to the board at the end of each one. Where a capability genuinely requires longer to mature, the Volume says what Year One makes possible rather than pretending the work compresses.

More security, or less? The answer, delivered four times, with the reasoning shown.

The board's question is always some version of the same thing: now that we have deployed AI, do we need more security or less, and what exactly are we funding? It sounds like a budget question. It is an accountability question. This Volume answers it once per domain, and the short version is more, in every domain, but transformed. Not more of the same controls. A fundamentally different function, one that governs machine judgment instead of operating manual controls, supervises autonomous reasoning instead of monitoring human behavior, and treats accuracy and accountability as security properties alongside confidentiality and integrity. Enterprise security is no longer protecting information. It is governing organizational intelligence, and the security leader who builds that function becomes the executive who makes AI governable.

The Implementation Toolkit

Twenty-two operating instruments ship with the book as its appendix set, from the AI Security Operating System One-Page Map and the Decision Rights RACI through the Five-Horizon Governance Rhythm, the Red-Button Protocol Runbook, the Living Risk Register entry, the AI Clause Library, the AI Bill of Materials Requirement, the Erasure Engineering Register, the AI Security Scorecard, the AI Security Debt Register, and the Continuous Adversarial Evaluation Test Set. Every figure behind them, and every framework diagram from all thirteen chapters, is in the Chapter Graphics Library below, free to download and use within your organization today, while the manuscript completes.

How the book and the AI IT Security Implementation & Strategy engagement work together

The book is the operating manual, written for security leaders who want to run the post-audit program themselves across all four domains. The AI IT Security Implementation & Strategy™ engagement is the execution of its governance core, designed for organizations that want the AI governance framework ratified, the risk register integrated, the regulatory crosswalk mapped, and the board and audit committee reporting built inside a defined timeline, not learned, drafted, and refined over two quarters of internal effort.

Teams that want the discipline in book form work from the book. Teams that want the framework ratified against their own decision rights, the crosswalk mapped to their own regulatory footprint, and the reporting written for their own audit committee, work directly with the firm.

Free downloads for this book

The worksheets and templates that ship with this book are free. Enter your email once, click the confirmation link we send you, and every book's downloads unlock across the site, forever.

The Consulting Toolkit

Every operating instrument, editable and ready to run.

The twenty-two operating instruments from the book, free and editable, ready to use in a live AI security program. These are the working material of the first ninety days and the year that follows, not reading material. Works in Microsoft Excel, Google Sheets, Apple Numbers, and LibreOffice Calc.

Recommended Starting Point
The AI Security Operating System One-Page Map

The book's central artifact. The entire program, four domains, the governance rhythm, and the decision rights, on a single page an executive can hold. Fill it in first. It will tell you in an afternoon which parts of the operating model you already have and which exist only as intentions.

Download the One-Page Map
Chapter Graphics Library

Visual frameworks, ready for your presentations.

Every diagram, framework, and chart from the book is available here as an individual file. Use them in your slide decks, internal memos, board presentations, or training sessions. Free to use within your organization. Browse by chapter, click any image to download.

Publication details

Series
The Operating Discipline for AI Library™, Volume 6
Published
August 24, 2026
Length
404 pages
Publisher
SRJ Consulting & Services Publishing
Editions, ISBNs, and list prices
EditionISBN-13List price
Hardcover979-8-9969402-7-1$99.99
Paperback979-8-9969402-5-7$46.99
Kindle979-8-9969402-6-4$24.99

Buy on Amazon List prices shown. Retailer pricing varies.