PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

DEF-03

Remediation Operating Model

Security, product, platform, and engineering teams need explicit ownership for control design, implementation, and proof.

operating model

Shared Foundation
  • Security
    • Interpret evidence and consequence
    • Prioritize control opportunities
    • Define security acceptance criteria
  • Platform
    • Own identity, policy, and shared controls
    • Provide reusable guardrails
    • Instrument shared control evidence
  • Product
    • Own user and workflow impact
    • Approve product tradeoffs
    • Set rollout and exception policy
  • Engineering
    • Implement the system change
    • Add test and evidence hooks
    • Preserve regression coverage

About this figure

A remediation operating model only works when control design, implementation, and proof have explicit owners. Security interprets evidence, sets acceptance criteria, and prioritizes control opportunities; product owns user and workflow impact, approves tradeoffs, and sets rollout and exception policy; platform provides reusable guardrails, shared identity and policy controls, and instrumentation for evidence; engineering implements system changes, adds test and evidence hooks, and preserves regression coverage; and an evidence owner runs the agreed retest and updates residual risk and closure state. This split creates clear accountability from finding to fix to verification, reducing ambiguity, slowing drift, and making remediation measurable end to end.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/platform/defend.dsl.md" figureId="DEF-03" />

Citation

Remediation Operating Model (DEF-03). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/DEF-03