CROSSWALKS

GAISSF to NIST CSF 2.0 Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to NIST CSF 2.0, with scope, method, limitations and traceability.

Document Control and Authority

This publication candidate maps the authoritative GAISSF v1.0 59-control baseline to the NIST Cybersecurity Framework 2.0 Core. GAISSF-NOR-001 governs framework architecture and conformance; GAISSF-NOR-004 is the authoritative control catalogue. NIST CSWP 29 Appendix A is the primary external mapping source.

1. Executive Summary

The analysis assessed all 59 GAISSF controls against all 106 NIST CSF 2.0 Core subcategories and produced 182 forward mapping records plus a complete reverse coverage register. The crosswalk is designed for control rationalization, AI-security integration, evidence reuse, profile development, and gap analysis.

The strongest alignment appears in cybersecurity governance, third-party and supply-chain risk, vulnerability and threat assessment, access control, platform and data security, continuous monitoring, incident analysis and mitigation, and resilience. The principal structural limitation is scope: NIST CSF 2.0 addresses cybersecurity risk across the whole organization and all ICT, whereas GAISSF is an AI-security and safety framework focused on AI systems, their supporting infrastructure, suppliers, data, models, agents, and physical-AI components.

2. Purpose and Intended Use

  • Develop an AI-focused overlay for a CSF Current or Target Profile.

  • Identify GAISSF evidence that may support selected CSF outcomes.

  • Locate organization-wide or non-AI cybersecurity gaps that GAISSF does not address.

  • Support internal assurance and control rationalization without asserting equivalence.

3. Source Baseline

Source Identifier Status Role
GAISSF Framework Standard GAISSF-NOR-001 v1.0 Normative, corrected final publication edition Framework and conformance baseline
GAISSF Control Catalogue GAISSF-NOR-004 v1.0 Normative, full final Authoritative 59-control catalogue
NIST Cybersecurity Framework 2.0 NIST CSWP 29, 26 Feb 2024 Voluntary cybersecurity framework Primary Core mapping target
CSF Implementation Examples Online, dynamically maintained Informative and non-exhaustive Supplementary interpretation only

4. Methodology

Mappings were assigned at GAISSF-control-to-CSF-subcategory level using shared outcome, scope, lifecycle, actor, evidence, and implementation-effect criteria. Similar terminology alone was insufficient. One-to-many and many-to-one relationships were retained. Each mapping has a relationship classification, coverage status, confidence rating, rationale, and residual gap. Reverse coverage was then assessed for every CSF subcategory.

Code Meaning
SP Strong partial: substantial support, but material elements remain unmatched
P Partial: meaningful overlap with narrower or different scope
S Supporting: assists implementation but does not directly achieve the complete outcome
N No material mapping
O Outside scope
U Unable to determine

5. Quantitative Overview

Metric Result
GAISSF controls assessed 59
NIST CSF Core subcategories assessed 106
Forward mapping records 182
Reverse coverage records 106

6. Function-Level Findings

GOVERN

31 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.

IDENTIFY

21 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.

PROTECT

22 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.

DETECT

11 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.

RESPOND

13 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.

RECOVER

8 NIST CSF subcategories were assessed. GAISSF evidence can support selected AI-system outcomes; enterprise-wide application, non-AI asset coverage, and organization-specific profile prioritization remain separate implementation responsibilities.

7. Reverse Coverage Register

NIST ID Function Category Outcome Mapped GAISSF controls Coverage Confidence Residual gap
GV.OC-01 GOVERN Organizational Context The organizational mission is understood and informs cybersecurity risk management D2-CTL-06 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.OC-02 GOVERN Organizational Context Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered D2-CTL-06 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.OC-03 GOVERN Organizational Context Legal, regulatory, and contractual requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed D5-CTL-05, D8-CTL-05 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.OC-04 GOVERN Organizational Context Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.OC-05 GOVERN Organizational Context Outcomes, capabilities, and services that the organization depends on are understood and communicated None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RM-01 GOVERN Risk Management Strategy Risk management objectives are established and agreed to by organizational stakeholders None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RM-02 GOVERN Risk Management Strategy Risk appetite and risk tolerance statements are established, communicated, and maintained None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RM-03 GOVERN Risk Management Strategy Cybersecurity risk management activities and outcomes are included in enterprise risk management processes None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RM-04 GOVERN Risk Management Strategy Strategic direction that describes appropriate risk response options is established and communicated D7-CTL-H05 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.RM-05 GOVERN Risk Management Strategy Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RM-06 GOVERN Risk Management Strategy A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RM-07 GOVERN Risk Management Strategy Strategic opportunities, or positive risks, are characterized and included in organizational cybersecurity risk discussions None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RR-01 GOVERN Roles, Responsibilities, and Authorities Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RR-02 GOVERN Roles, Responsibilities, and Authorities Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RR-03 GOVERN Roles, Responsibilities, and Authorities Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.RR-04 GOVERN Roles, Responsibilities, and Authorities Cybersecurity is included in human resources practices None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.PO-01 GOVERN Policy Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.PO-02 GOVERN Policy Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission D6-CTL-03 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.OV-01 GOVERN Oversight Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.OV-02 GOVERN Oversight The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks D8-CTL-01 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.OV-03 GOVERN Oversight Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.SC-01 GOVERN Cybersecurity Supply Chain Risk Management A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
GV.SC-02 GOVERN Cybersecurity Supply Chain Risk Management Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally D6-CTL-06, D1-CTL-01, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.SC-03 GOVERN Cybersecurity Supply Chain Risk Management Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes D8-CTL-01 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.SC-04 GOVERN Cybersecurity Supply Chain Risk Management Suppliers are known and prioritized by criticality D1-CTL-06, D1-CTL-07 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.SC-05 GOVERN Cybersecurity Supply Chain Risk Management Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and agreements with suppliers and other relevant third parties D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-04, D4-CTL-05, D4-CTL-06 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.SC-06 GOVERN Cybersecurity Supply Chain Risk Management Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D3-CTL-05, D4-CTL-02, D4-CTL-04, D4-CTL-05 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.SC-07 GOVERN Cybersecurity Supply Chain Risk Management The risks posed by suppliers, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the relationship D1-CTL-01, D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-04, D4-CTL-05 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.SC-08 GOVERN Cybersecurity Supply Chain Risk Management Relevant suppliers and other third parties are included in incident planning, response, and recovery activities D1-CTL-01, D4-CTL-01, D6-CTL-06, D4-CTL-03, D9-CTL-04, D1-CTL-03, D1-CTL-05, D3-CTL-07 Substantially Addressed Medium-High GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.SC-09 GOVERN Cybersecurity Supply Chain Risk Management Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and performance is monitored throughout the technology product and service life cycle D2-CTL-04, D3-CTL-03 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
GV.SC-10 GOVERN Cybersecurity Supply Chain Risk Management Cybersecurity supply chain risk management plans include provisions for activities after the conclusion of a partnership or service agreement None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.AM-01 IDENTIFY Asset Management Inventories of hardware managed by the organization are maintained None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.AM-02 IDENTIFY Asset Management Inventories of software, services, and systems managed by the organization are maintained None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.AM-03 IDENTIFY Asset Management Representations of the organization's authorized network communication and internal and external network data flows are maintained D2-CTL-02 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
ID.AM-04 IDENTIFY Asset Management Inventories of services provided by suppliers are maintained None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.AM-05 IDENTIFY Asset Management Assets are prioritized based on classification, criticality, resources, and impact on the mission None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.AM-07 IDENTIFY Asset Management Inventories of data and corresponding metadata for designated data types are maintained None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.AM-08 IDENTIFY Asset Management Systems, hardware, software, services, and data are managed throughout their life cycles None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-01 IDENTIFY Risk Assessment Vulnerabilities in assets are identified, validated, and recorded None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-02 IDENTIFY Risk Assessment Cyber threat intelligence is received from information sharing forums and sources None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-03 IDENTIFY Risk Assessment Internal and external threats to the organization are identified and recorded None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-04 IDENTIFY Risk Assessment Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-05 IDENTIFY Risk Assessment Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-06 IDENTIFY Risk Assessment Risk responses are chosen, prioritized, planned, tracked, and communicated None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-07 IDENTIFY Risk Assessment Changes and exceptions are managed, assessed for risk impact, recorded, and tracked None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-08 IDENTIFY Risk Assessment Processes for receiving, analyzing, and responding to vulnerability disclosures are established None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.RA-09 IDENTIFY Risk Assessment The authenticity and integrity of hardware and software are assessed prior to acquisition and use D1-CTL-04, D1-CTL-08, D1-CTL-09, D2-CTL-02, D3-CTL-04, D3-CTL-06, D5-CTL-01 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
ID.RA-10 IDENTIFY Risk Assessment Critical suppliers are assessed prior to acquisition None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.IM-01 IDENTIFY Improvement Improvements are identified from evaluations None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.IM-02 IDENTIFY Improvement Improvements are identified from security tests and exercises, including those coordinated with suppliers and relevant third parties None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.IM-03 IDENTIFY Improvement Improvements are identified from execution of operational processes, procedures, and activities None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
ID.IM-04 IDENTIFY Improvement Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.AA-01 PROTECT Identity Management, Authentication, and Access Control Identities and credentials for authorized users, services, and hardware are managed by the organization D7-CTL-H03 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.AA-02 PROTECT Identity Management, Authentication, and Access Control Identities are proofed and bound to credentials based on the context of interactions None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.AA-03 PROTECT Identity Management, Authentication, and Access Control Users, services, and hardware are authenticated None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.AA-04 PROTECT Identity Management, Authentication, and Access Control Identity assertions are protected, conveyed, and verified None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.AA-05 PROTECT Identity Management, Authentication, and Access Control Access permissions, entitlements, and authorizations are defined in policy, managed, enforced, and reviewed, incorporating least privilege and separation of duties D3-CTL-01, D6-CTL-05, D7-CTL-H03 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.AA-06 PROTECT Identity Management, Authentication, and Access Control Physical access to assets is managed, monitored, and enforced commensurate with risk D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-07, D1-CTL-04, D1-CTL-08 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.AT-01 PROTECT Awareness and Training Personnel receive awareness and training to possess the knowledge and skills to perform general tasks with cybersecurity risks in mind D1-CTL-02, D2-CTL-03, D5-CTL-06, D7-CTL-H01, D8-CTL-03 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.AT-02 PROTECT Awareness and Training Individuals in specialized roles receive awareness and training to possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind D1-CTL-02, D2-CTL-03, D5-CTL-06, D7-CTL-H01, D8-CTL-03 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.DS-01 PROTECT Data Security The confidentiality, integrity, and availability of data at rest are protected D2-CTL-05, D5-CTL-05, D6-CTL-07 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.DS-02 PROTECT Data Security The confidentiality, integrity, and availability of data in transit are protected D2-CTL-05 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.DS-10 PROTECT Data Security The confidentiality, integrity, and availability of data in use are protected None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.DS-11 PROTECT Data Security Backups of data are created, protected, maintained, and tested None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.PS-01 PROTECT Platform Security Configuration management practices are established and applied None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.PS-02 PROTECT Platform Security Software is maintained, replaced, and removed commensurate with risk None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.PS-03 PROTECT Platform Security Hardware is maintained, replaced, and removed commensurate with risk None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.PS-04 PROTECT Platform Security Log records are generated and made available for continuous monitoring D2-CTL-04 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.PS-05 PROTECT Platform Security Installation and execution of unauthorized software are prevented None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.PS-06 PROTECT Platform Security Secure software development practices are integrated, and performance is monitored throughout the software development life cycle D8-CTL-05 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.IR-01 PROTECT Technology Infrastructure Resilience Networks and environments are protected from unauthorized logical access and usage None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.IR-02 PROTECT Technology Infrastructure Resilience Technology assets are protected from environmental threats D3-CTL-02 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
PR.IR-03 PROTECT Technology Infrastructure Resilience Mechanisms are implemented to achieve resilience requirements in normal and adverse situations None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
PR.IR-04 PROTECT Technology Infrastructure Resilience Adequate resource capacity to ensure availability is maintained D6-CTL-07 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
DE.CM-01 DETECT Continuous Monitoring Networks and network services are monitored to find potentially adverse events None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.CM-02 DETECT Continuous Monitoring The physical environment is monitored to find potentially adverse events D9-CTL-05, D9-CTL-07, D5-CTL-02, D5-CTL-03, D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
DE.CM-03 DETECT Continuous Monitoring Personnel activity and technology usage are monitored to find potentially adverse events None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.CM-06 DETECT Continuous Monitoring External service provider activities and services are monitored to find potentially adverse events None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.CM-09 DETECT Continuous Monitoring Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.AE-02 DETECT Adverse Event Analysis Potentially adverse events are analyzed to better understand associated activities None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.AE-03 DETECT Adverse Event Analysis Information is correlated from multiple sources None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.AE-04 DETECT Adverse Event Analysis The estimated impact and scope of adverse events are understood None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.AE-06 DETECT Adverse Event Analysis Information on adverse events is provided to authorized staff and tools None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.AE-07 DETECT Adverse Event Analysis Cyber threat intelligence and other contextual information are integrated into analysis None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
DE.AE-08 DETECT Adverse Event Analysis Incidents are declared when adverse events meet defined incident criteria None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RS.MA-01 RESPOND Incident Management The incident response plan is executed in coordination with relevant third parties once an incident is declared D7-CTL-H04 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RS.MA-02 RESPOND Incident Management Incident reports are triaged and validated None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RS.MA-03 RESPOND Incident Management Incidents are categorized and prioritized None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RS.MA-04 RESPOND Incident Management Incidents are escalated or elevated as needed None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RS.MA-05 RESPOND Incident Management Criteria for initiating incident recovery are applied None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RS.AN-03 RESPOND Incident Analysis Analysis is performed to establish what occurred during an incident and its root cause D9-CTL-04 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RS.AN-06 RESPOND Incident Analysis Actions performed during an investigation are recorded, and record integrity and provenance are preserved D1-CTL-01, D4-CTL-01, D9-CTL-07, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RS.AN-07 RESPOND Incident Analysis Incident data and metadata are collected, and their integrity and provenance are preserved D1-CTL-01, D4-CTL-01, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01, D6-CTL-04 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RS.AN-08 RESPOND Incident Analysis An incident's magnitude is estimated and validated D2-CTL-01, D5-CTL-04 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RS.CO-02 RESPOND Incident Response Reporting and Communication Internal and external stakeholders are notified of incidents D8-CTL-04 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RS.CO-03 RESPOND Incident Response Reporting and Communication Information is shared with designated internal and external stakeholders D8-CTL-04 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RS.MI-01 RESPOND Incident Mitigation Incidents are contained None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RS.MI-02 RESPOND Incident Mitigation Incidents are eradicated None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RC.RP-01 RECOVER Incident Recovery Plan Execution The recovery portion of the incident response plan is executed once initiated from the incident response process D7-CTL-H04 Indirectly Supported Low GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RC.RP-02 RECOVER Incident Recovery Plan Execution Recovery actions are selected, scoped, prioritized, and performed None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RC.RP-03 RECOVER Incident Recovery Plan Execution The integrity of backups and other restoration assets is verified before use D4-CTL-01, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01, D6-CTL-04, D7-CTL-H02 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RC.RP-04 RECOVER Incident Recovery Plan Execution Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms D9-CTL-04, D9-CTL-07, D1-CTL-03, D3-CTL-07, D6-CTL-01, D6-CTL-04, D9-CTL-01 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RC.RP-05 RECOVER Incident Recovery Plan Execution The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed D4-CTL-01, D1-CTL-05, D2-CTL-01, D5-CTL-04, D7-CTL-H02, D9-CTL-01, D9-CTL-05 Partially Addressed Medium GAISSF is AI-system-focused; organization-wide cybersecurity outcomes and non-AI ICT assets require additional controls.
RC.RP-06 RECOVER Incident Recovery Plan Execution The end of incident recovery is declared based on criteria, and incident-related documentation is completed None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RC.CO-03 RECOVER Incident Recovery Communication Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.
RC.CO-04 RECOVER Incident Recovery Communication Public updates on incident recovery are shared using approved methods and messaging None Not Addressed Not Rated No sufficiently direct GAISSF control was identified.

8. GAISSF-to-NIST Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 182 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF ID GAISSF control NIST ID Function Rel. Confidence Rationale Residual gap
CRO023-MAP-0001 D1-CTL-01 Dataset Provenance & Poisoning Prevention GV.SC-08 GOVERN SP Medium-High GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in GV.SC-08. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence.
CRO023-MAP-0002 D1-CTL-01 Dataset Provenance & Poisoning Prevention RS.AN-07 RESPOND P Medium GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in RS.AN-07. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence.
CRO023-MAP-0003 D1-CTL-01 Dataset Provenance & Poisoning Prevention GV.SC-07 GOVERN P Medium GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in GV.SC-07. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence.
CRO023-MAP-0004 D1-CTL-01 Dataset Provenance & Poisoning Prevention RS.AN-06 RESPOND P Medium GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in RS.AN-06. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence.
CRO023-MAP-0005 D1-CTL-01 Dataset Provenance & Poisoning Prevention GV.SC-02 GOVERN S Low GAISSF D1-CTL-01 provides AI-system-specific controls and evidence that support the cybersecurity outcome in GV.SC-02. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence.
CRO023-MAP-0006 D1-CTL-02 Model Extraction Resistance PR.AT-01 PROTECT S Low GAISSF D1-CTL-02 provides AI-system-specific controls and evidence that support the cybersecurity outcome in PR.AT-01. The relationship is outcome-based; NIST CSF 2.0 remains broader and technology-neutral. Organization-wide ICT scope, enterprise context, and non-AI assets remain outside the direct GAISSF control scope and require separate implementation evidence.

9. Evidence Reuse Guidance

Potentially reusable evidence includes AI system inventories, model and data provenance records, supplier assessments, threat models, vulnerability records, access-control configurations, security test reports, red-team reports, monitoring telemetry, incident records, recovery tests, risk-treatment decisions, and governance approvals. Reuse is valid only after scope, currency, ownership, and operating effectiveness are confirmed.

10. Limitations

  • Mapping does not establish NIST endorsement, certification, equivalence, or regulatory compliance.

  • GAISSF focuses on AI systems; NIST CSF 2.0 applies across organizational ICT, including non-AI assets.

  • Relationship classifications describe textual and operational support, not operating effectiveness.

  • Profiles, Tiers, and organization-specific risk tolerances must be developed by the implementing organization.

  • Revalidate mappings when either source baseline changes.

11. Notably Absent

  • No NIST certification or endorsement of GAISSF.

  • No finding that GAISSF conformance automatically achieves a CSF Organizational Profile.

  • No treatment of CSF Implementation Examples as mandatory requirements.

  • No organization-independent compliance percentage or universal risk-tolerance threshold.

  • No automatic coverage of non-AI enterprise assets, workforce processes, or broader ICT operations.

12. Conclusion

GAISSF can operate as an AI-security specialization layer within a broader NIST CSF 2.0 cybersecurity risk program. The mapping supports evidence reuse and gap identification, but it does not replace organization-wide cybersecurity governance, CSF Profile development, or verification of operating effectiveness.