ConductorOne
CISO Guide to Agentic AI and Security Governance
Pages
6
Time to read
8 mins
Publication
Language
English
Pages
6
Time to read
8 mins
Publication
Language
English
This guide details the challenges and strategies associated with the emergence of agentic AI in security governance. Agentic AI systems are defined as autonomous entities that act on behalf of users or organizations, capable of making decisions and executing tasks without human intervention. The guide outlines types of agentic AI, including company AI agents, employee AI agents, and agent-to-agent interactions, each with unique governance needs. It discusses the limitations of traditional identity and access management (IAM) systems in handling these rapid, ephemeral AI identities and the associated risks, such as expanded attack surfaces and compliance challenges. The guide suggests governance frameworks and strategies for CISOs, including developing clear AI strategies, discovering and classifying AI agents, implementing task-based authorization, and ensuring real-time monitoring and oversight. It emphasizes the importance of collaboration across organizational functions for effective agentic AI adoption and governance.