GAISSF to NIST CSF 2.0 Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to NIST CSF 2.0, with scope, method, limitations and traceability.
Document Control and Authority
This publication candidate maps the authoritative GAISSF v1.0 59-control baseline to the NIST Cybersecurity Framework 2.0 Core. GAISSF-NOR-001 governs framework architecture and conformance; GAISSF-NOR-004 is the authoritative control catalogue. NIST CSWP 29 Appendix A is the primary external mapping source.
1. Executive Summary
The analysis assessed all 59 GAISSF controls against all 106 NIST CSF 2.0 Core subcategories and produced 182 forward mapping records plus a complete reverse coverage register. The crosswalk is designed for control rationalization, AI-security integration, evidence reuse, profile development, and gap analysis.
The strongest alignment appears in cybersecurity governance, third-party and supply-chain risk, vulnerability and threat assessment, access control, platform and data security, continuous monitoring, incident analysis and mitigation, and resilience. The principal structural limitation is scope: NIST CSF 2.0 addresses cybersecurity risk across the whole organization and all ICT, whereas GAISSF is an AI-security and safety framework focused on AI systems, their supporting infrastructure, suppliers, data, models, agents, and physical-AI components.
2. Purpose and Intended Use
Develop an AI-focused overlay for a CSF Current or Target Profile.
Identify GAISSF evidence that may support selected CSF outcomes.
Locate organization-wide or non-AI cybersecurity gaps that GAISSF does not address.
Support internal assurance and control rationalization without asserting equivalence.
3. Source Baseline
| Source | Identifier | Status | Role |
|---|---|---|---|
| GAISSF Framework Standard | GAISSF-NOR-001 v1.0 | Normative, corrected final publication edition | Framework and conformance baseline |
| GAISSF Control Catalogue | GAISSF-NOR-004 v1.0 | Normative, full final | Authoritative 59-control catalogue |
| NIST Cybersecurity Framework 2.0 | NIST CSWP 29, 26 Feb 2024 | Voluntary cybersecurity framework | Primary Core mapping target |
| CSF Implementation Examples | Online, dynamically maintained | Informative and non-exhaustive | Supplementary interpretation only |
4. Methodology
Mappings were assigned at GAISSF-control-to-CSF-subcategory level using shared outcome, scope, lifecycle, actor, evidence, and implementation-effect criteria. Similar terminology alone was insufficient. One-to-many and many-to-one relationships were retained. Each mapping has a relationship classification, coverage status, confidence rating, rationale, and residual gap. Reverse coverage was then assessed for every CSF subcategory.
| Code | Meaning |
|---|---|
| SP | Strong partial: substantial support, but material elements remain unmatched |
| P | Partial: meaningful overlap with narrower or different scope |
| S | Supporting: assists implementation but does not directly achieve the complete outcome |
| N | No material mapping |
| O | Outside scope |
| U | Unable to determine |
5. Quantitative Overview
| Metric | Result |
|---|---|
| GAISSF controls assessed | 59 |
| NIST CSF Core subcategories assessed | 106 |
| Forward mapping records | 182 |
| Reverse coverage records | 106 |
6. Function-Level Findings
GOVERN
31 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.
IDENTIFY
21 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.
PROTECT
22 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.
DETECT
11 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.
RESPOND
13 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.
RECOVER
8 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.
7. Reverse Coverage Register
| NIST ID | Function | Category | Outcome | Mapped GAISSF controls | Coverage | Confidence | Residual gap |
|---|---|---|---|---|---|---|---|
| GV.OC-01 | GOVERN | Organizational Context | The organizational mission is understood and informs cybersecurity risk management | D2-CTL-06 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.OC-02 | GOVERN | Organizational Context | Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered | D2-CTL-06 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.OC-03 | GOVERN | Organizational Context | Legal, regulatory, and contractual requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed | D5-CTL-05, D8-CTL-05 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.OC-04 | GOVERN | Organizational Context | Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.OC-05 | GOVERN | Organizational Context | Outcomes, capabilities, and services that the organization depends on are understood and communicated | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RM-01 | GOVERN | Risk Management Strategy | Risk management objectives are established and agreed to by organizational stakeholders | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RM-02 | GOVERN | Risk Management Strategy | Risk appetite and risk tolerance statements are established, communicated, and maintained | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RM-03 | GOVERN | Risk Management Strategy | Cybersecurity risk management activities and outcomes are included in enterprise risk management processes | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RM-04 | GOVERN | Risk Management Strategy | Strategic direction that describes appropriate risk response options is established and communicated | D7-CTL-H05 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.RM-05 | GOVERN | Risk Management Strategy | Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RM-06 | GOVERN | Risk Management Strategy | A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RM-07 | GOVERN | Risk Management Strategy | Strategic opportunities, or positive risks, are characterized and included in organizational cybersecurity risk discussions | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RR-01 | GOVERN | Roles, Responsibilities, and Authorities | Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RR-02 | GOVERN | Roles, Responsibilities, and Authorities | Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RR-03 | GOVERN | Roles, Responsibilities, and Authorities | Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.RR-04 | GOVERN | Roles, Responsibilities, and Authorities | Cybersecurity is included in human resources practices | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.PO-01 | GOVERN | Policy | Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.PO-02 | GOVERN | Policy | Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission | D6-CTL-03 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.OV-01 | GOVERN | Oversight | Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.OV-02 | GOVERN | Oversight | The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks | D8-CTL-01 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.OV-03 | GOVERN | Oversight | Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.SC-01 | GOVERN | Cybersecurity Supply Chain Risk Management | A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| GV.SC-02 | GOVERN | Cybersecurity Supply Chain Risk Management | Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally | D6-CTL-06, D1-CTL-01, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.SC-03 | GOVERN | Cybersecurity Supply Chain Risk Management | Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes | D8-CTL-01 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.SC-04 | GOVERN | Cybersecurity Supply Chain Risk Management | Suppliers are known and prioritized by criticality | D1-CTL-06, D1-CTL-07 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.SC-05 | GOVERN | Cybersecurity Supply Chain Risk Management | Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and agreements with suppliers and other relevant third parties | D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-04, D4-CTL-05, D4-CTL-06 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.SC-06 | GOVERN | Cybersecurity Supply Chain Risk Management | Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships | D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D3-CTL-05, D4-CTL-02, D4-CTL-04, D4-CTL-05 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.SC-07 | GOVERN | Cybersecurity Supply Chain Risk Management | The risks posed by suppliers, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the relationship | D1-CTL-01, D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-04, D4-CTL-05 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.SC-08 | GOVERN | Cybersecurity Supply Chain Risk Management | Relevant suppliers and other third parties are included in incident planning, response, and recovery activities | D1-CTL-01, D4-CTL-01, D6-CTL-06, D4-CTL-03, D9-CTL-04, D1-CTL-03, D1-CTL-05, D3-CTL-07 | Substantially Addressed | Medium-High | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.SC-09 | GOVERN | Cybersecurity Supply Chain Risk Management | Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and performance is monitored throughout the technology product and service life cycle | D2-CTL-04, D3-CTL-03 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| GV.SC-10 | GOVERN | Cybersecurity Supply Chain Risk Management | Cybersecurity supply chain risk management plans include provisions for activities after the conclusion of a partnership or service agreement | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.AM-01 | IDENTIFY | Asset Management | Inventories of hardware managed by the organization are maintained | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.AM-02 | IDENTIFY | Asset Management | Inventories of software, services, and systems managed by the organization are maintained | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.AM-03 | IDENTIFY | Asset Management | Representations of the organization's authorized network communication and internal and external network data flows are maintained | D2-CTL-02 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| ID.AM-04 | IDENTIFY | Asset Management | Inventories of services provided by suppliers are maintained | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.AM-05 | IDENTIFY | Asset Management | Assets are prioritized based on classification, criticality, resources, and impact on the mission | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.AM-07 | IDENTIFY | Asset Management | Inventories of data and corresponding metadata for designated data types are maintained | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.AM-08 | IDENTIFY | Asset Management | Systems, hardware, software, services, and data are managed throughout their life cycles | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-01 | IDENTIFY | Risk Assessment | Vulnerabilities in assets are identified, validated, and recorded | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-02 | IDENTIFY | Risk Assessment | Cyber threat intelligence is received from information sharing forums and sources | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-03 | IDENTIFY | Risk Assessment | Internal and external threats to the organization are identified and recorded | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-04 | IDENTIFY | Risk Assessment | Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-05 | IDENTIFY | Risk Assessment | Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-06 | IDENTIFY | Risk Assessment | Risk responses are chosen, prioritized, planned, tracked, and communicated | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-07 | IDENTIFY | Risk Assessment | Changes and exceptions are managed, assessed for risk impact, recorded, and tracked | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-08 | IDENTIFY | Risk Assessment | Processes for receiving, analyzing, and responding to vulnerability disclosures are established | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.RA-09 | IDENTIFY | Risk Assessment | The authenticity and integrity of hardware and software are assessed prior to acquisition and use | D1-CTL-04, D1-CTL-08, D1-CTL-09, D2-CTL-02, D3-CTL-04, D3-CTL-06, D5-CTL-01 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| ID.RA-10 | IDENTIFY | Risk Assessment | Critical suppliers are assessed prior to acquisition | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.IM-01 | IDENTIFY | Improvement | Improvements are identified from evaluations | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.IM-02 | IDENTIFY | Improvement | Improvements are identified from security tests and exercises, including those coordinated with suppliers and relevant third parties | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.IM-03 | IDENTIFY | Improvement | Improvements are identified from execution of operational processes, procedures, and activities | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| ID.IM-04 | IDENTIFY | Improvement | Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.AA-01 | PROTECT | Identity Management, Authentication, and Access Control | Identities and credentials for authorized users, services, and hardware are managed by the organization | D7-CTL-H03 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.AA-02 | PROTECT | Identity Management, Authentication, and Access Control | Identities are proofed and bound to credentials based on the context of interactions | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.AA-03 | PROTECT | Identity Management, Authentication, and Access Control | Users, services, and hardware are authenticated | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.AA-04 | PROTECT | Identity Management, Authentication, and Access Control | Identity assertions are protected, conveyed, and verified | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.AA-05 | PROTECT | Identity Management, Authentication, and Access Control | Access permissions, entitlements, and authorizations are defined in policy, managed, enforced, and reviewed, incorporating least privilege and separation of duties | D3-CTL-01, D6-CTL-05, D7-CTL-H03 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.AA-06 | PROTECT | Identity Management, Authentication, and Access Control | Physical access to assets is managed, monitored, and enforced commensurate with risk | D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-07, D1-CTL-04, D1-CTL-08 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.AT-01 | PROTECT | Awareness and Training | Personnel receive awareness and training to possess the knowledge and skills to perform general tasks with cybersecurity risks in mind | D1-CTL-02, D2-CTL-03, D5-CTL-06, D7-CTL-H01, D8-CTL-03 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.AT-02 | PROTECT | Awareness and Training | Individuals in specialized roles receive awareness and training to possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind | D1-CTL-02, D2-CTL-03, D5-CTL-06, D7-CTL-H01, D8-CTL-03 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.DS-01 | PROTECT | Data Security | The confidentiality, integrity, and availability of data at rest are protected | D2-CTL-05, D5-CTL-05, D6-CTL-07 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.DS-02 | PROTECT | Data Security | The confidentiality, integrity, and availability of data in transit are protected | D2-CTL-05 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.DS-10 | PROTECT | Data Security | The confidentiality, integrity, and availability of data in use are protected | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.DS-11 | PROTECT | Data Security | Backups of data are created, protected, maintained, and tested | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.PS-01 | PROTECT | Platform Security | Configuration management practices are established and applied | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.PS-02 | PROTECT | Platform Security | Software is maintained, replaced, and removed commensurate with risk | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.PS-03 | PROTECT | Platform Security | Hardware is maintained, replaced, and removed commensurate with risk | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.PS-04 | PROTECT | Platform Security | Log records are generated and made available for continuous monitoring | D2-CTL-04 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.PS-05 | PROTECT | Platform Security | Installation and execution of unauthorized software are prevented | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.PS-06 | PROTECT | Platform Security | Secure software development practices are integrated, and performance is monitored throughout the software development life cycle | D8-CTL-05 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.IR-01 | PROTECT | Technology Infrastructure Resilience | Networks and environments are protected from unauthorized logical access and usage | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.IR-02 | PROTECT | Technology Infrastructure Resilience | Technology assets are protected from environmental threats | D3-CTL-02 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| PR.IR-03 | PROTECT | Technology Infrastructure Resilience | Mechanisms are implemented to achieve resilience requirements in normal and adverse situations | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| PR.IR-04 | PROTECT | Technology Infrastructure Resilience | Adequate resource capacity to ensure availability is maintained | D6-CTL-07 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| DE.CM-01 | DETECT | Continuous Monitoring | Networks and network services are monitored to find potentially adverse events | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.CM-02 | DETECT | Continuous Monitoring | The physical environment is monitored to find potentially adverse events | D9-CTL-05, D9-CTL-07, D5-CTL-02, D5-CTL-03, D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| DE.CM-03 | DETECT | Continuous Monitoring | Personnel activity and technology usage are monitored to find potentially adverse events | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.CM-06 | DETECT | Continuous Monitoring | External service provider activities and services are monitored to find potentially adverse events | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.CM-09 | DETECT | Continuous Monitoring | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.AE-02 | DETECT | Adverse Event Analysis | Potentially adverse events are analyzed to better understand associated activities | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.AE-03 | DETECT | Adverse Event Analysis | Information is correlated from multiple sources | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.AE-04 | DETECT | Adverse Event Analysis | The estimated impact and scope of adverse events are understood | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.AE-06 | DETECT | Adverse Event Analysis | Information on adverse events is provided to authorized staff and tools | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.AE-07 | DETECT | Adverse Event Analysis | Cyber threat intelligence and other contextual information are integrated into analysis | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| DE.AE-08 | DETECT | Adverse Event Analysis | Incidents are declared when adverse events meet defined incident criteria | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RS.MA-01 | RESPOND | Incident Management | The incident response plan is executed in coordination with relevant third parties once an incident is declared | D7-CTL-H04 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RS.MA-02 | RESPOND | Incident Management | Incident reports are triaged and validated | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RS.MA-03 | RESPOND | Incident Management | Incidents are categorized and prioritized | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RS.MA-04 | RESPOND | Incident Management | Incidents are escalated or elevated as needed | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RS.MA-05 | RESPOND | Incident Management | Criteria for initiating incident recovery are applied | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RS.AN-03 | RESPOND | Incident Analysis | Analysis is performed to establish what occurred during an incident and its root cause | D9-CTL-04 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RS.AN-06 | RESPOND | Incident Analysis | Actions performed during an investigation are recorded, and record integrity and provenance are preserved | D1-CTL-01, D4-CTL-01, D9-CTL-07, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RS.AN-07 | RESPOND | Incident Analysis | Incident data and metadata are collected, and their integrity and provenance are preserved | D1-CTL-01, D4-CTL-01, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01, D6-CTL-04 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RS.AN-08 | RESPOND | Incident Analysis | An incident's magnitude is estimated and validated | D2-CTL-01, D5-CTL-04 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RS.CO-02 | RESPOND | Incident Response Reporting and Communication | Internal and external stakeholders are notified of incidents | D8-CTL-04 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RS.CO-03 | RESPOND | Incident Response Reporting and Communication | Information is shared with designated internal and external stakeholders | D8-CTL-04 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RS.MI-01 | RESPOND | Incident Mitigation | Incidents are contained | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RS.MI-02 | RESPOND | Incident Mitigation | Incidents are eradicated | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RC.RP-01 | RECOVER | Incident Recovery Plan Execution | The recovery portion of the incident response plan is executed once initiated from the incident response process | D7-CTL-H04 | Indirectly Supported | Low | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RC.RP-02 | RECOVER | Incident Recovery Plan Execution | Recovery actions are selected, scoped, prioritized, and performed | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RC.RP-03 | RECOVER | Incident Recovery Plan Execution | The integrity of backups and other restoration assets is verified before use | D4-CTL-01, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01, D6-CTL-04, D7-CTL-H02 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RC.RP-04 | RECOVER | Incident Recovery Plan Execution | Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms | D9-CTL-04, D9-CTL-07, D1-CTL-03, D3-CTL-07, D6-CTL-01, D6-CTL-04, D9-CTL-01 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RC.RP-05 | RECOVER | Incident Recovery Plan Execution | The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed | D4-CTL-01, D1-CTL-05, D2-CTL-01, D5-CTL-04, D7-CTL-H02, D9-CTL-01, D9-CTL-05 | Partially Addressed | Medium | GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls. |
| RC.RP-06 | RECOVER | Incident Recovery Plan Execution | The end of incident recovery is declared based on criteria, and incident-related documentation is completed | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RC.CO-03 | RECOVER | Incident Recovery Communication | Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
| RC.CO-04 | RECOVER | Incident Recovery Communication | Public updates on incident recovery are shared using approved methods and messaging | None | Not Addressed | Not Rated | No sufficiently direct GAISSF control was identified. |
8. GAISSF-to-NIST Mapping Register
| Record | GAISSF ID | GAISSF control | NIST ID | Function | Rel. | Confidence | Rationale | Residual gap |
|---|---|---|---|---|---|---|---|---|
| CRO023-MAP-0001 | D1-CTL-01 | Dataset Provenance & Poisoning Prevention | GV.SC-08 | GOVERN | SP | Medium-High | GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in GV.SC-08. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. | Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence. |
| CRO023-MAP-0002 | D1-CTL-01 | Dataset Provenance & Poisoning Prevention | RS.AN-07 | RESPOND | P | Medium | GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in RS.AN-07. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. | Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence. |
| CRO023-MAP-0003 | D1-CTL-01 | Dataset Provenance & Poisoning Prevention | GV.SC-07 | GOVERN | P | Medium | GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in GV.SC-07. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. | Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence. |
| CRO023-MAP-0004 | D1-CTL-01 | Dataset Provenance & Poisoning Prevention | RS.AN-06 | RESPOND | P | Medium | GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in RS.AN-06. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. | Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence. |
| CRO023-MAP-0005 | D1-CTL-01 | Dataset Provenance & Poisoning Prevention | GV.SC-02 | GOVERN | S | Low | GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in GV.SC-02. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. | Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence. |
| CRO023-MAP-0006 | D1-CTL-02 | Model Extraction Resistance | PR.AT-01 | PROTECT | S | Low | GAISSF D1-CTL-02 provides AI-system-specific controls and evidence that support the cybersecurity outcome in PR.AT-01. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. | Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence. |
9. Evidence Reuse Guidance
Potentially reusable evidence includes AI system inventories, model and data provenance records, supplier assessments, threat models, vulnerability records, access-control configurations, security test reports, red-team reports, monitoring telemetry, incident records, recovery tests, risk-treatment decisions, and governance approvals. Reuse is valid only after scope, currency, ownership, and operating effectiveness are confirmed.
10. Limitations
Mapping does not establish NIST endorsement, certification, equivalence, or regulatory compliance.
GAISSF focuses on AI systems; NIST CSF 2.0 applies across organizational ICT, including non-AI assets.
Relationship classifications describe textual and operational support, not operating effectiveness.
Profiles, Tiers, and organization-specific risk tolerances must be developed by the implementing organization.
Revalidate mappings when either source baseline changes.
11. Notably Absent
No NIST certification or endorsement of GAISSF.
No finding that GAISSF conformance automatically achieves a CSF Organizational Profile.
No treatment of CSF Implementation Examples as mandatory requirements.
No organization-independent compliance percentage or universal risk-tolerance threshold.
No automatic coverage of non-AI enterprise assets, workforce processes, or broader ICT operations.
12. Conclusion
GAISSF can operate as an AI-security specialization layer within a broader NIST CSF 2.0 cybersecurity risk program. The mapping supports evidence reuse and gap identification, but it does not replace organization-wide cybersecurity governance, CSF Profile development, or verification of operating effectiveness.