GAISSF to MITRE ATLAS Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to MITRE ATLAS, with scope, method, limitations and traceability.
1. Executive summary
CRO-025 maps all 59 GAISSF v1.0 controls to MITRE ATLAS adversary tactics and 82 priority AI-threat techniques. The official 2026.05 ATLAS baseline contains 16 tactics and reports 170 techniques including sub-techniques. This crosswalk supports threat-informed control selection, red-team planning, evidence reuse, detection-gap analysis, and assurance scoping.
The crosswalk does not demonstrate that a technique is prevented or detected. ATLAS describes adversary behavior; GAISSF establishes control and evidence expectations. Operating effectiveness must be tested in the relevant architecture and threat context.
2. Source baseline and scope
| Source | Version / status | Role |
|---|---|---|
| GAISSF-NOR-001 | v1.0 Final Publication v1.0 | Normative framework and conformance baseline |
| GAISSF-NOR-004 | v1.0 Full Final | Authoritative 59-control catalogue |
| MITRE ATLAS | Content 2026.05; format 6.0.0 | Adversary tactics, techniques, mitigations, and case-study knowledge base |
| ATLAS website | Verified 29 June 2026 | Live matrix and reported object counts |
The crosswalk maps all GAISSF controls to materially relevant ATLAS tactics and a source-verified priority technique set. It does not claim exhaustive procedure coverage or detection validation for every ATLAS technique.
3. Mapping method
Normalize each GAISSF control into its preventive, detective, corrective, governance, and evidence outcomes.
Compare those outcomes with the objective and operational effect of ATLAS tactics and techniques.
Classify the relationship as Strong Partial, Partial, or Supporting; do not infer equivalence from shared terminology.
Record residual detection, telemetry, adversary-emulation, and validation work.
Perform a reverse review at tactic level to identify thin or absent GAISSF coverage.
4. ATLAS tactic inventory
| Tactic ID | Tactic |
|---|---|
| AML.TA0002 | Reconnaissance |
| AML.TA0003 | Resource Development |
| AML.TA0004 | Initial Access |
| AML.TA0000 | AI Model Access |
| AML.TA0005 | Execution |
| AML.TA0006 | Persistence |
| AML.TA0012 | Privilege Escalation |
| AML.TA0007 | Defense Evasion |
| AML.TA0013 | Credential Access |
| AML.TA0008 | Discovery |
| AML.TA0015 | Lateral Movement |
| AML.TA0009 | Collection |
| AML.TA0001 | AI Attack Staging |
| AML.TA0014 | Command and Control |
| AML.TA0010 | Exfiltration |
| AML.TA0011 | Impact |
5. Priority technique inventory
| Technique ID | Technique | Tactic |
|---|---|---|
| AML.T0064 | Gather RAG-Indexed Targets | Reconnaissance |
| AML.T0087 | Gather Victim Identity Information | Reconnaissance |
| AML.T0004 | Search Application Repositories | Reconnaissance |
| AML.T0001 | Search Open AI Vulnerability Analysis | Reconnaissance |
| AML.T0000 | Search Open Technical Databases | Reconnaissance |
| AML.T0003 | Search Victim-Owned Websites | Reconnaissance |
| AML.T0008 | Acquire Infrastructure | Resource Development |
| AML.T0002 | Acquire Public AI Artifacts | Resource Development |
| AML.T0017 | Develop Capabilities | Resource Development |
| AML.T0021 | Establish Accounts | Resource Development |
| AML.T0065 | LLM Prompt Crafting | Resource Development |
| AML.T0016 | Obtain Capabilities | Resource Development |
| AML.T0020 | Poison Training Data | Resource Development |
| AML.T0060 | Publish Hallucinated Entities | Resource Development |
| AML.T0104 | Publish Poisoned AI Agent Tool | Resource Development |
| AML.T0019 | Publish Poisoned Datasets | Resource Development |
| AML.T0058 | Publish Poisoned Models | Resource Development |
| AML.T0066 | Retrieval Content Crafting | Resource Development |
| AML.T0079 | Stage Capabilities | Resource Development |
| AML.T0010 | AI Supply Chain Compromise | Initial Access |
| AML.T0015 | Evade AI Model | Initial Access |
| AML.T0049 | Exploit Public-Facing Application | Initial Access |
| AML.T0052 | Phishing | Initial Access |
| AML.T0093 | Prompt Infiltration via Public-Facing Application | Initial Access |
| AML.T0012 | Valid Accounts | Initial Access |
| AML.T0040 | AI Model Inference API Access | AI Model Access |
| AML.T0047 | AI-Enabled Product or Service | AI Model Access |
| AML.T0044 | Full AI Model Access | AI Model Access |
| AML.T0041 | Physical Environment Access | AI Model Access |
| AML.T0100 | AI Agent Clickbait | Execution |
| AML.T0053 | AI Agent Tool Invocation | Execution |
| AML.T0050 | Command and Scripting Interpreter | Execution |
| AML.T0103 | Deploy AI Agent | Execution |
| AML.T0051 | LLM Prompt Injection | Execution |
| AML.T0011 | User Execution | Execution |
| AML.T0110 | AI Agent Context Poisoning | Persistence |
| AML.T0105 | AI Agent Tool Data Poisoning | Persistence |
| AML.T0111 | AI Agent Tool Poisoning | Persistence |
| AML.T0061 | LLM Prompt Self-Replication | Persistence |
| AML.T0018 | Manipulate AI Model | Persistence |
| AML.T0081 | RAG Poisoning | Persistence |
| AML.T0070 | Escape to Host | Privilege Escalation |
| AML.T0054 | LLM Jailbreak | Privilege Escalation |
| AML.T0109 | AI Supply Chain Reputation Inflation | Defense Evasion |
| AML.T0076 | AI Supply Chain Rug Pull | Defense Evasion |
| AML.T0094 | Corrupt AI Model | Defense Evasion |
| AML.T0107 | Delay Execution of LLM Instructions | Defense Evasion |
| AML.T0071 | False RAG Entry Injection | Defense Evasion |
| AML.T0073 | LLM Prompt Obfuscation | Defense Evasion |
| AML.T0068 | Manipulate User LLM Chat History | Defense Evasion |
| AML.T0092 | Modify AI Agent Configuration | Defense Evasion |
| AML.T0097 | AI Agent Tool Credential Harvesting | Credential Access |
| AML.T0098 | Credentials from AI Agent Configuration | Credential Access |
| AML.T0083 | RAG Credential Harvesting | Credential Access |
| AML.T0055 | Unsecured Credentials | Credential Access |
| AML.T0106 | Discover AI Agent Configuration | Discovery |
| AML.T0007 | Discover AI Artifacts | Discovery |
| AML.T0014 | Discover AI Model Family | Discovery |
| AML.T0013 | Discover AI Model Ontology | Discovery |
| AML.T0063 | Discover AI Model Outputs | Discovery |
| AML.T0062 | Discover LLM Hallucinations | Discovery |
| AML.T0069 | Discover LLM System Information | Discovery |
| AML.T0089 | AI Artifact Collection | Collection |
| AML.T0091 | Data from AI Services | Collection |
| AML.T0005 | Create Proxy AI Model | AI Attack Staging |
| AML.T0043 | Craft Adversarial Data | AI Attack Staging |
| AML.T0099 | Generate Deepfakes | AI Attack Staging |
| AML.T0080 | Generate Malicious Commands | AI Attack Staging |
| AML.T0042 | Verify Attack | AI Attack Staging |
| AML.T0108 | AI Agent | Command and Control |
| AML.T0102 | AI Service API | Command and Control |
| AML.T0101 | Exfiltration via AI Agent Tool Invocation | Exfiltration |
| AML.T0024 | Exfiltration via AI Inference API | Exfiltration |
| AML.T0025 | Exfiltration via Cyber Means | Exfiltration |
| AML.T0056 | Extract LLM System Prompt | Exfiltration |
| AML.T0057 | LLM Data Leakage | Exfiltration |
| AML.T0090 | LLM Response Rendering | Exfiltration |
| AML.T0029 | Denial of AI Service | Impact |
| AML.T0031 | Erode AI Model Integrity | Impact |
| AML.T0046 | Spamming AI System with Chaff Data | Impact |
| AML.T0048 | External Harms | Impact |
| AML.T0059 | Erode Dataset Integrity | Impact |
6. Reverse tactic coverage
| Tactic | Mapped GAISSF controls | Priority techniques represented | Coverage | Residual limitation |
|---|---|---|---|---|
| AML.TA0002 Reconnaissance | D5-CTL-05, D5-CTL-06, D6-CTL-01, D6-CTL-02, D6-CTL-04, D7-CTL-H01, D7-CTL-H03, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-05 | AML.T0087 Gather Victim Identity Information; AML.T0064 Gather RAG-Indexed Targets; AML.T0001 Search Open AI Vulnerability Analysis; AML.T0000 Search Open Technical Databases | Substantially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0003 Resource Development | D1-CTL-01, D1-CTL-04, D2-CTL-02, D2-CTL-06, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D7-CTL-H01, D7-CTL-H02, D8-CTL-03, D8-CTL-05 | AML.T0020 Poison Training Data; AML.T0058 Publish Poisoned Models; AML.T0065 LLM Prompt Crafting; AML.T0104 Publish Poisoned AI Agent Tool; AML.T0017 Develop Capabilities | Substantially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0004 Initial Access | D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D2-CTL-04, D2-CTL-05, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06, D7-CTL-H05 | AML.T0015 Evade AI Model; AML.T0010 AI Supply Chain Compromise; AML.T0052 Phishing | Substantially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0000 AI Model Access | D3-CTL-01, D3-CTL-04, D4-CTL-04, D5-CTL-02, D6-CTL-03, D6-CTL-05, D9-CTL-02, D9-CTL-03, D9-CTL-05, D9-CTL-06 | AML.T0040 AI Model Inference API Access; AML.T0041 Physical Environment Access; AML.T0044 Full AI Model Access | Substantially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0005 Execution | D2-CTL-01, D2-CTL-02, D3-CTL-02, D3-CTL-05, D3-CTL-07 | AML.T0051 LLM Prompt Injection; AML.T0100 AI Agent Clickbait | Partially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0006 Persistence | D9-CTL-02 | AML.T0110 AI Agent Context Poisoning | Partially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0012 Privilege Escalation | Not Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. | ||
| AML.TA0007 Defense Evasion | D1-CTL-06, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06 | AML.T0109 AI Supply Chain Reputation Inflation | Substantially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0013 Credential Access | Not Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. | ||
| AML.TA0008 Discovery | D5-CTL-01, D5-CTL-03, D5-CTL-04, D5-CTL-05, D8-CTL-04, D9-CTL-01, D9-CTL-05, D9-CTL-07 | AML.T0062 Discover LLM Hallucinations; AML.T0106 Discover AI Agent Configuration; AML.T0007 Discover AI Artifacts; AML.T0069 Discover LLM System Information | Substantially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0015 Lateral Movement | Not Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. | ||
| AML.TA0009 Collection | Not Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. | ||
| AML.TA0001 AI Attack Staging | D1-CTL-02, D1-CTL-03, D1-CTL-05, D1-CTL-07, D1-CTL-08, D1-CTL-09, D2-CTL-03, D2-CTL-04, D2-CTL-05, D5-CTL-01, D5-CTL-03, D5-CTL-04, D7-CTL-H02, D7-CTL-H04, D9-CTL-01 | AML.T0042 Verify Attack; AML.T0005 Create Proxy AI Model; AML.T0043 Craft Adversarial Data; AML.T0099 Generate Deepfakes | Substantially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0014 Command and Control | Not Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. | ||
| AML.TA0010 Exfiltration | D2-CTL-01, D2-CTL-06, D3-CTL-03, D3-CTL-06, D5-CTL-06, D6-CTL-04, D7-CTL-H04 | AML.T0056 Extract LLM System Prompt; AML.T0101 Exfiltration via AI Agent Tool Invocation; AML.T0024 Exfiltration via AI Inference API; AML.T0090 LLM Response Rendering | Partially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
| AML.TA0011 Impact | D1-CTL-01, D6-CTL-07, D7-CTL-H03, D7-CTL-H05 | AML.T0059 Erode Dataset Integrity; AML.T0046 Spamming AI System with Chaff Data; AML.T0029 Denial of AI Service; AML.T0048 External Harms | Partially Addressed | ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic. |
7. Implementation and evidence reuse
AI-system and model threat models linked to ATLAS tactic and technique IDs
Adversary-emulation plans and red-team test cases
Model, dataset, agent-tool, RAG, and supply-chain inventories
Prompt-injection, poisoning, evasion, extraction, and jailbreak test results
IAM, secrets, least-privilege, tool-authorization, and human-approval records
Telemetry design, detection logic, alerts, investigations, and incident records
Model integrity, provenance, signing, and deployment-gate evidence
Residual-risk decisions and management approvals
8. Limitations
Mapping is not MITRE endorsement, certification, equivalence, or proof of defensive effectiveness.
ATLAS describes adversary behavior; GAISSF defines control and evidence expectations. A relationship does not prove prevention or detection.
The priority technique register is deliberately focused on techniques with direct AI-system relevance to GAISSF controls; the official ATLAS dataset remains authoritative for the complete 170-object technique inventory.
Environment-specific threat modelling, telemetry, detection engineering, adversary emulation, and validation remain necessary.
ATLAS publishes monthly content updates; revalidation is required after a source release changes.
9. Notably absent
No MITRE certification, approval, endorsement, or conformance declaration is established.
No claim is made that GAISSF implementation prevents or detects every ATLAS technique.
No universal technique-coverage percentage or maturity score is asserted.
No assumption is made that control documentation proves operating effectiveness.
No claim is made that ATLAS replaces ATT&CK, application threat modelling, or environment-specific incident intelligence.
Annex A - GAISSF-to-ATLAS mapping register
| Record | GAISSF control | ATLAS tactic / technique | Rel. | Confidence | Rationale | Residual gap |
|---|---|---|---|---|---|---|
| CRO025-MAP-0001 | D1-CTL-01 Dataset Provenance & Poisoning Prevention | Resource Development | AML.T0020 Poison Training Data | S | Low | GAISSF D1-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Poison Training Data. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. | Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary. |
| CRO025-MAP-0002 | D1-CTL-01 Dataset Provenance & Poisoning Prevention | Impact | AML.T0059 Erode Dataset Integrity | S | Low | GAISSF D1-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0059 Erode Dataset Integrity. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. | Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary. |
| CRO025-MAP-0003 | D1-CTL-02 Model Extraction Resistance | AI Attack Staging | AML.T0042 Verify Attack | P | Medium | GAISSF D1-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. | Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary. |
| CRO025-MAP-0004 | D1-CTL-03 Behavioral Drift Detection | AI Attack Staging | AML.T0042 Verify Attack | P | Medium | GAISSF D1-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. | Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary. |
| CRO025-MAP-0005 | D1-CTL-04 Federated Learning Poisoning Prevention | Resource Development | AML.T0020 Poison Training Data | S | Low | GAISSF D1-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Poison Training Data. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. | Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary. |
| CRO025-MAP-0006 | D1-CTL-04 Federated Learning Poisoning Prevention | Resource Development | AML.T0058 Publish Poisoned Models | S | Low | GAISSF D1-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0058 Publish Poisoned Models. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. | Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary. |
Annex B - QA and change record
| Check | Result |
|---|---|
| GAISSF controls inventoried | 59 |
| ATLAS tactics inventoried | 16 |
| Official ATLAS reported technique count | 170 |
| Priority techniques mapped | 82 |
| Forward mapping records | 112 |
| Monthly source revalidation required | Yes |
| Independent threat-informed-defense review | Required before final publication |