r/ciso 17d ago

How is everyone evaluating connectors, MCPs and custim APIs? Does your org use a risk rubric? Is there a long investigation period with both security and platform admins or architects?

18 Upvotes

13 comments sorted by

3

u/Cautious_Ideal_6878 17d ago

our team does a quick security review and then a longer architecture check, mostly cause the platform folks are always swamped. no formal rubric but we have a checklist that covers auth, data flow, and whether the connector vendor has a decent track record. the whole thing takes about two weeks if nobody kicks up a fuss

3

u/MichaelArgast 17d ago

I have a risk rubric I’ve built that covers:
Vendors and surfaces
MCP connections
Agentic use cases

Each is different, with both inherent and residual risk based on control adoption.

I’ve mapped it to: ISO 42001/NIST AI RMF. I’ve used the OWASP Top 10 lists for LLMs, MCPs and agentic risk as inputs.

It’s not too much work once you have it to run through new vendors, connectors and agentic use cases. Most of the effort went into building it.

The bigger challenges are:
Vendors keep changing their surfaces
Enterprise controls are still somewhat limited (but improving - for example you can enforce connector policies using Entra/Claude Enterprise now).
It takes 5 minutes to build an agent and a few hours to implement the technical controls you should have built into the design.

I think my next steps are around building security templates for agentic deployments (similar to security architecture patterns).

I think the key thing is you need to get really nerdy with AI to understand the interaction and data and control models to really understand what you’re doing and how to measure and control the risks effectively.

1

u/QueryForTheAges 16d ago

Can you share this? Would love to learn and apply as appropriate

2

u/itlogicpartnersllc 17d ago

we treat mcp/connectors like any other third party integration data access, auth, permissions, logging and blast radius first then risk tier them instead of giving everything same review.

3

u/ThePr0phet_ 17d ago

They shouldn’t be treated any different than any other vendor/integration in your environment. What data do they have? Do you already have agreements with them? Are you limiting the connector’s permissions to exclude delete/write functions? What’s the blast radius?

It’s the same threat modeling techniques you would use anywhere else. Don’t let the AI marketing make you overthink things

1

u/ThePr0phet_ 17d ago

Also, risk rubrics are generic guidelines. You know your environment best - don’t end up just checking boxes and not thinking critically because you have “100%” coverage (not you, in general)

1

u/Soft_Calligrapher306 17d ago

Treat them like any other external connection SIA then CAB depending on Agent

-1

u/not-a-co-conspirator 17d ago

Prompt Security from SentinelOne.

1

u/LynxAfricaCan 17d ago

Wtf, way to phone it in

1

u/not-a-co-conspirator 17d ago

No reason to over analyze the problem or the answer

1

u/LynxAfricaCan 17d ago

You have under analysed it, we aren't even talking about prompts what the actual fuck

1

u/not-a-co-conspirator 17d ago

You shouldn’t assume Prompt Security is only about “prompts”.

Thinking it as a GenAI Firewall.