Framework & Regulatory Knowledge
Security and AI-governance frameworks applied in professional work, graduate study, and governance analysis -- each labeled by depth, with the specific evidence behind it.
Security
OWASP Top 10
AppliedWeb application security risk categories, applied directly to structure secure code review and remediation guidance in professional AppSec work.
CWE/SANS Top 25
AppliedCommon weakness enumeration, used alongside OWASP Top 10 in professional code review.
NIST Cybersecurity Framework (CSF)
Working knowledgeCybersecurity risk-management framework, part of CompTIA Security+ domain knowledge.
MITRE ATT&CK
Working knowledgeAdversary tactics/techniques taxonomy, applied in red-team and threat-intel work.
Defense-in-depth
AppliedLayered-controls security design principle, applied and measured directly in the LLM Data Leakage Lab and the Three-Layer Defense Framework.
Zero Trust
AppliedNever-trust-by-default access model, applied through server-side identity resolution and least-privilege IAM provisioning across professional roles.
Adaptive Moving Target Defense (AMTD)
Graduate-level exposureA defense strategy that changes system behavior to reduce attacker predictability -- the subject of Amalachukwu's MSc research at the University of Guelph.
AI Governance & Regulation
NIST AI Risk Management Framework (AI RMF)
Governance analysisUS framework for managing AI risk across the Map/Measure/Manage/Govern functions -- applied in the Attack → Defend → Govern Lab's governance workbench and in published analysis of AI transparency in customer service.
ISO/IEC 42001
Governance analysisInternational standard for AI management systems, referenced in AI governance analysis and coursework.
OECD AI Principles
Governance analysisIntergovernmental principles for trustworthy AI, referenced in AI governance analysis and coursework.
EU AI Act
Governance analysisEU regulation for AI systems, risk-tiered by use case -- referenced as emerging regulatory direction in AI governance analysis.
Privacy by design
Graduate-level exposureBuilding privacy protection into systems from the outset, covered in the University of Guelph Data Privacy, Security and Governance micro-credential.
This is not legal advice.