What happened
ISACA published a white paper providing a controls-based framework, a secure-by-default checklist, and a data classification/handling guide for securing AI agents against prompt injection, tool misuse, excessive agency, memory leakage, and model/supply-chain compromise (governance & asset inventory, secure development & change management, strong identity/auth/authz, network segmentation/isolation, and more). Publication date is not shown on the page; independent coverage (CSO Online, 8 September 2026) suggests publication in the surrounding window — surfaced at Tier C with date uncertainty for QA adjudication.
Why it matters
ISACA is a recognized professional body; this is a practitioner-oriented control set that complements OWASP and MITRE ATLAS for the dominant agent-threat categories, useful for mapping existing enterprise agent controls and audit expectations.
Action needed
Map existing AI-agent controls to the paper's checklist and secure-by-default guidance; use for audit/assurance alignment.