Research

Research and knowledge context

A connected reference layer behind the blog: definitions, sources, standards, projects, papers, related concepts and evidence links.

Research topics

Browse the knowledge layer

A compact catalogue of concepts, technologies, regulations and methodologies behind the blog.

Showing 25 of 25 entries

Advanced tag filters
Methodologymaintained

AI Governance

Governance methodology for assigning responsibility, oversight, risk controls, audit evidence and accountability around artificial intelligence systems, AI-assisted development and AI-enabled business processes.

Methodologymaintained

AI Red Teaming

Methodology profile for structured AI red-team and abuse-case testing, focused on adversarial scenarios, prompt injection, data leakage, model misuse, RAG/agent workflows, control validation and evidence-based reporting.

Methodologymaintained

AI Security Architecture

Security architecture methodology for designing, reviewing and governing AI systems, LLM applications, RAG workflows and AI-assisted services through threat modeling, identity, data, application, monitoring and audit controls.

Methodologymaintained

AI Threat Modeling

Methodology for identifying, documenting and reviewing threats against AI-enabled systems, LLM applications, RAG workflows and AI agents before they are deployed or changed in production.

Conceptmaintained

AI Transparency

Concept covering disclosure, provenance, labelling, traceability and review evidence for AI-generated, AI-modified or AI-assisted content and decisions.

Regulationmaintained

Artificial Intelligence Act

Legal-technical research profile of Regulation (EU) 2024/1689, the European Union Artificial Intelligence Act, focused on AI governance, risk categories, transparency, oversight and compliance relevance.

Conceptmaintained

Audit Evidence

Evidence retained to support governance, compliance, security and operational claims, including logs, records, approvals, configuration snapshots, test results, provenance data and review trails.

Methodologymaintained

Data Governance for AI

Methodology profile for governing data used by AI systems, including source ownership, classification, consent or legal basis, retention, quality, retrieval boundaries, privacy, provenance, access control and audit evidence.

Regulationmaintained

General Data Protection Regulation

Legal-technical research profile of the European Union General Data Protection Regulation, focused on personal data protection, accountability, security of processing, data protection by design, personal data breach handling, DPIA, governance and cybersecurity relevance.

Technologymaintained

GLPI

Version-aware technical profile of GLPI as an open-source IT asset management, CMDB, inventory and IT service management platform, with focus on architecture, data model, agent-based inventory, repositories, integrations, security considerations and operational risks.

Technologymaintained

Hyper-V

Technical profile of Microsoft Hyper-V as a Windows virtualization technology and migration source platform, with focus on guest hardware assumptions, backups, drivers, restore planning and operational risk.

Methodologymaintained

IAM for AI systems

Identity and access-management methodology for AI systems, LLM applications, agents and RAG workflows, covering users, service accounts, tools, datasets, model providers, retrieval permissions and audit evidence.

Methodologymaintained

MITRE ATLAS

Public adversary-knowledge framework for understanding tactics, techniques and case studies against AI-enabled systems, useful for AI threat modeling, AI security architecture and executive risk communication.

Conceptmaintained

Model Supply Chain Security

Security concept for AI and machine-learning supply chains, covering models, datasets, embeddings, packages, prompts, pipelines, SBOM evidence, provenance, vulnerability management and deployment governance.

Technologymaintained

NetXMS

Version-aware technical profile of NetXMS as an open-source network and infrastructure monitoring platform, including architecture, data collection, discovery, event processing, security considerations, integrations and operational risks.

Standardmaintained

OWASP Top 10 for LLM Applications

Community security guidance for identifying common risk classes in applications that use large language models, including prompt injection, data leakage, insecure output handling, excessive agency and supply-chain exposure.

Conceptmaintained

Prompt Injection

Security concept for instructions embedded in user input, documents, tools or retrieved context that attempt to override system intent, bypass policy, exfiltrate data or manipulate AI-enabled workflows.

Technologymaintained

Proxmox Backup Server

Technical profile of Proxmox Backup Server as a dedicated backup and restore platform for Proxmox environments, with focus on retention, deduplication, encryption, integrity, restore testing and recovery evidence.

Technologymaintained

Proxmox Mail Gateway

Technical profile of Proxmox Mail Gateway as an email security gateway, with focus on mail perimeter filtering, spam and malware controls, quarantine, routing, logs, identity-adjacent risks and operational evidence.

Technologymaintained

Proxmox VE

Technical profile of Proxmox VE as an open-source virtualization platform for KVM virtual machines and containers, with focus on migration, storage, networking, backup, restore and operational risk.

Conceptmaintained

RAG Security

Security concept for retrieval-augmented generation systems, focusing on data boundaries, source governance, access control, retrieval poisoning, prompt injection through documents, logging and audit evidence.

Methodologymaintained

Secure AI-Assisted Development

Engineering methodology for using AI coding assistants, code generators and agentic development workflows while preserving security review, traceability, testing, dependency control and deployment accountability.

Conceptmaintained

Software Bill of Materials

Technical and governance profile of Software Bill of Materials as a structured inventory of software components used for transparency, vulnerability management, supply-chain security, procurement, incident response and audit evidence.

Technologymaintained

Veeam Backup & Replication

Technical profile of Veeam Backup & Replication as a backup, restore and migration tool for virtualized workloads, with emphasis on restore verification, rollback and cross-platform recovery assumptions.

Methodologymaintained

Zero Trust

Technical and governance profile of Zero Trust as a security architecture methodology based on explicit verification, least privilege, continuous evaluation and the assumption that network location alone should not imply trust.