feat(ms-ai-architect): #8b currency M-items — Defender AI threat protection + OWASP LLM04/06/08/09 + M365 E7/Agent 365 + Foundry Local air-gapped

Phase B (M-items) av #8 currency-rest. Nytt innhold, verifisert mot
Microsoft Learn + OWASP GenAI 2026-06-18 (tre research-subagenter).
Begge nye KB-filer wiret i SKILL.md (de-orphan bekreftet: kb-integrity
115/115, orphan-warnings uendret 262).

Nye KB-filer (ms-ai-security/references/ai-security-engineering/):
- owasp-llm-top10-azure-mitigations.md — konsolidert dekning av de fire
  OWASP 2025-kategoriene som manglet referanse i SKILL.md-mappingen
  (LLM04 Data/Model Poisoning, LLM06 Excessive Agency, LLM08 Vector/
  Embedding Weaknesses, LLM09 Misinformation) med verifiserte Azure-tiltak.
  OWASP-side 404 for LLM06/08/09 → definisjoner kryssverifisert, merket.
- defender-threat-protection-ai-services.md — Defender for Cloud «AI threat
  protection» (gjeldende navn; plan «Defender for AI Services»). GA for
  AI applications, Preview for AI agents (fra 2026-02-02). Varselliste m/
  Alert ID + MITRE-taktikk, Prompt Shields-integrasjon, prising (75B-token
  trial). KRITISK: ikke tilgjengelig i Azure Government (norsk off. sektor).

SKILL.md (ms-ai-security):
- Fylte de 4 «—»-radene LLM04/06/08/09 → owasp-llm-top10-azure-mitigations.md.
- La til Defender-referanse (kjøretids-trusseldeteksjon) + Government-forbehold.
- Fil-telling ai-security-engineering 17→22 (17 var stale; faktisk 20 + 2 nye).

licensing-matrix.md (ms-ai-advisor):
- Ny rad «Microsoft 365 E7» i master-matrisen + dedikert E7/Agent 365-seksjon.
  E7 (GA 2026-05-01) bundler E5 + M365 Copilot + Agent 365 + Entra Suite.
  Agent 365 = IT-admin kontrollplan (registry/Entra Agent ID/Defender/Purview).
  VERIFISERT at begge er reelle SKU-er. Priser (~$99 E7 / ~$15 Agent 365) er
  community-/partnerkilder → eksplisitt merket uverifisert.

disconnected-ai-scenarios.md (ms-ai-infrastructure):
- Ny seksjon «Foundry Local — generativt lokalt og air-gapped». To produkter:
  on-device (offline etter nedlasting, ingen Azure-sub) + on Azure Local
  (Arc/Kubernetes, Preview). Air-gapped/disconnected støttet fra juni 2026
  (Preview): edgeartifacts-registry, expansion packs, lokal AD, ingen
  telemetri. Del av Microsoft Sovereign Private Cloud — relevant for norsk
  suverenitet.

Tester: validate-plugin 239 PASS / 0 FAIL / 0 WARN · kb-integrity 115/115
(262 pre-eksisterende orphan-warnings, uendret) · run-e2e alle suiter PASS.

#8 nå komplett (S-bannere #8a + M-items #8b). Neste: #9 v1.16.0 release.
FLAGG: `/architect:kb-update` apply forblir UTSATT (krever egen bekreftelse).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REiKFhP4w6xGXXqWKpPCJJ
This commit is contained in:
Kjell Tore Guttormsen 2026-06-18 20:32:43 +02:00
commit e406ef395e
5 changed files with 247 additions and 6 deletions

View file

@ -79,15 +79,17 @@ Map each threat to the solution under assessment. Use the reference files for de
| LLM01 | Prompt Injection | Content Safety Prompt Shields, system message hardening, Groundedness Detection | `prompt-injection-defense-patterns.md` |
| LLM02 | Sensitive Information Disclosure | PII-filter, Purview DLP, output-filtrering | `data-leakage-prevention-ai.md`, `pii-detection-norwegian-context.md` |
| LLM03 | Supply Chain Vulnerabilities | AI Foundry curated models, signed models, DLP for connectors | `supply-chain-security-ai-models.md` |
| LLM04 | Data and Model Poisoning | Azure ML data lineage, isolated fine-tuning, Purview validation | — |
| LLM04 | Data and Model Poisoning | Azure ML data lineage, isolated fine-tuning, Purview validation | `owasp-llm-top10-azure-mitigations.md` |
| LLM05 | Improper Output Handling | Grounding Detection API, Content Safety output-filtre, Structured Outputs | `output-validation-grounding-verification.md` |
| LLM06 | Excessive Agency | Copilot Studio scoped tools, RBAC per project, human-in-the-loop, budget caps | — |
| LLM06 | Excessive Agency | Copilot Studio scoped tools, RBAC per project, human-in-the-loop, budget caps | `owasp-llm-top10-azure-mitigations.md` |
| LLM07 | System Prompt Leakage | Metaprompt patterns, Prompt Shields, output monitoring | `jailbreak-prevention-production.md` |
| LLM08 | Vector and Embedding Weaknesses | AI Search managed identities, index-level security filters, Private Endpoints | — |
| LLM09 | Misinformation | RAG grounding, Groundedness Detection, citation patterns, confidence scoring | — |
| LLM08 | Vector and Embedding Weaknesses | AI Search managed identities, index-level security filters, Private Endpoints | `owasp-llm-top10-azure-mitigations.md` |
| LLM09 | Misinformation | RAG grounding, Groundedness Detection, citation patterns, confidence scoring | `owasp-llm-top10-azure-mitigations.md` |
| LLM10 | Unbounded Consumption | Rate limits, token budgets, PTU for capacity, Cost Management alerts | — |
All reference files are in `references/ai-security-engineering/`.
All reference files are in `references/ai-security-engineering/`. LLM04/06/08/09 deler den konsoliderte filen `owasp-llm-top10-azure-mitigations.md`; LLM10 dekkes av rate-limit-/kostnadsfiler.
Kjøretids-trusseldeteksjon for AI-endepunkter dekkes av `defender-threat-protection-ai-services.md` (Defender for Cloud AI threat protection — GA for AI applications, Preview for AI agents; merk: **ikke** tilgjengelig i Azure Government).
### Azure AI-spesifikke sikkerhetskontroller
@ -167,7 +169,7 @@ For detailed implementation guidance, see specific files in `references/performa
| Katalog | Filer | Innhold |
|---------|-------|---------|
| `references/ai-security-engineering/` | 17 | Forsvar, testing, scoring, hendelseshåndtering, Zero Trust, STRIDE-AI, prompt injection, content safety |
| `references/ai-security-engineering/` | 22 | Forsvar, testing, scoring, hendelseshåndtering, Zero Trust, STRIDE-AI, prompt injection, content safety, OWASP LLM-tiltak, Defender AI threat protection |
| `references/cost-optimization/` | 21 | Kostnadsmodellering, FinOps, token-optimalisering, PTU/PAYG, caching, right-sizing, SLM-økonomi |
| `references/performance-scalability/` | 18 | Latency, skalering, streaming, batch API, rate limits, benchmarking, GPU-dimensjonering |