CROSSWALKS

GAISSF to MITRE ATLAS Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to MITRE ATLAS, with scope, method, limitations and traceability.

1. Executive summary

CRO-025 maps all 59 GAISSF v1.0 controls to MITRE ATLAS adversary tactics and 82 priority AI-threat techniques. The official 2026.05 ATLAS baseline contains 16 tactics and reports 170 techniques including sub-techniques. This crosswalk supports threat-informed control selection, red-team planning, evidence reuse, detection-gap analysis, and assurance scoping.

The crosswalk does not demonstrate that a technique is prevented or detected. ATLAS describes adversary behavior; GAISSF establishes control and evidence expectations. Operating effectiveness must be tested in the relevant architecture and threat context.

2. Source baseline and scope

Source Version / status Role
GAISSF-NOR-001 v1.0 Final Publication v1.0 Normative framework and conformance baseline
GAISSF-NOR-004 v1.0 Full Final Authoritative 59-control catalogue
MITRE ATLAS Content 2026.05; format 6.0.0 Adversary tactics, techniques, mitigations, and case-study knowledge base
ATLAS website Verified 29 June 2026 Live matrix and reported object counts

The crosswalk maps all GAISSF controls to materially relevant ATLAS tactics and a source-verified priority technique set. It does not claim exhaustive procedure coverage or detection validation for every ATLAS technique.

3. Mapping method

  1. Normalize each GAISSF control into its preventive, detective, corrective, governance, and evidence outcomes.

  2. Compare those outcomes with the objective and operational effect of ATLAS tactics and techniques.

  3. Classify the relationship as Strong Partial, Partial, or Supporting; do not infer equivalence from shared terminology.

  4. Record residual detection, telemetry, adversary-emulation, and validation work.

  5. Perform a reverse review at tactic level to identify thin or absent GAISSF coverage.

4. ATLAS tactic inventory

Tactic ID Tactic
AML.TA0002 Reconnaissance
AML.TA0003 Resource Development
AML.TA0004 Initial Access
AML.TA0000 AI Model Access
AML.TA0005 Execution
AML.TA0006 Persistence
AML.TA0012 Privilege Escalation
AML.TA0007 Defense Evasion
AML.TA0013 Credential Access
AML.TA0008 Discovery
AML.TA0015 Lateral Movement
AML.TA0009 Collection
AML.TA0001 AI Attack Staging
AML.TA0014 Command and Control
AML.TA0010 Exfiltration
AML.TA0011 Impact

5. Priority technique inventory

Technique ID Technique Tactic
AML.T0064 Gather RAG-Indexed Targets Reconnaissance
AML.T0087 Gather Victim Identity Information Reconnaissance
AML.T0004 Search Application Repositories Reconnaissance
AML.T0001 Search Open AI Vulnerability Analysis Reconnaissance
AML.T0000 Search Open Technical Databases Reconnaissance
AML.T0003 Search Victim-Owned Websites Reconnaissance
AML.T0008 Acquire Infrastructure Resource Development
AML.T0002 Acquire Public AI Artifacts Resource Development
AML.T0017 Develop Capabilities Resource Development
AML.T0021 Establish Accounts Resource Development
AML.T0065 LLM Prompt Crafting Resource Development
AML.T0016 Obtain Capabilities Resource Development
AML.T0020 Poison Training Data Resource Development
AML.T0060 Publish Hallucinated Entities Resource Development
AML.T0104 Publish Poisoned AI Agent Tool Resource Development
AML.T0019 Publish Poisoned Datasets Resource Development
AML.T0058 Publish Poisoned Models Resource Development
AML.T0066 Retrieval Content Crafting Resource Development
AML.T0079 Stage Capabilities Resource Development
AML.T0010 AI Supply Chain Compromise Initial Access
AML.T0015 Evade AI Model Initial Access
AML.T0049 Exploit Public-Facing Application Initial Access
AML.T0052 Phishing Initial Access
AML.T0093 Prompt Infiltration via Public-Facing Application Initial Access
AML.T0012 Valid Accounts Initial Access
AML.T0040 AI Model Inference API Access AI Model Access
AML.T0047 AI-Enabled Product or Service AI Model Access
AML.T0044 Full AI Model Access AI Model Access
AML.T0041 Physical Environment Access AI Model Access
AML.T0100 AI Agent Clickbait Execution
AML.T0053 AI Agent Tool Invocation Execution
AML.T0050 Command and Scripting Interpreter Execution
AML.T0103 Deploy AI Agent Execution
AML.T0051 LLM Prompt Injection Execution
AML.T0011 User Execution Execution
AML.T0110 AI Agent Context Poisoning Persistence
AML.T0105 AI Agent Tool Data Poisoning Persistence
AML.T0111 AI Agent Tool Poisoning Persistence
AML.T0061 LLM Prompt Self-Replication Persistence
AML.T0018 Manipulate AI Model Persistence
AML.T0081 RAG Poisoning Persistence
AML.T0070 Escape to Host Privilege Escalation
AML.T0054 LLM Jailbreak Privilege Escalation
AML.T0109 AI Supply Chain Reputation Inflation Defense Evasion
AML.T0076 AI Supply Chain Rug Pull Defense Evasion
AML.T0094 Corrupt AI Model Defense Evasion
AML.T0107 Delay Execution of LLM Instructions Defense Evasion
AML.T0071 False RAG Entry Injection Defense Evasion
AML.T0073 LLM Prompt Obfuscation Defense Evasion
AML.T0068 Manipulate User LLM Chat History Defense Evasion
AML.T0092 Modify AI Agent Configuration Defense Evasion
AML.T0097 AI Agent Tool Credential Harvesting Credential Access
AML.T0098 Credentials from AI Agent Configuration Credential Access
AML.T0083 RAG Credential Harvesting Credential Access
AML.T0055 Unsecured Credentials Credential Access
AML.T0106 Discover AI Agent Configuration Discovery
AML.T0007 Discover AI Artifacts Discovery
AML.T0014 Discover AI Model Family Discovery
AML.T0013 Discover AI Model Ontology Discovery
AML.T0063 Discover AI Model Outputs Discovery
AML.T0062 Discover LLM Hallucinations Discovery
AML.T0069 Discover LLM System Information Discovery
AML.T0089 AI Artifact Collection Collection
AML.T0091 Data from AI Services Collection
AML.T0005 Create Proxy AI Model AI Attack Staging
AML.T0043 Craft Adversarial Data AI Attack Staging
AML.T0099 Generate Deepfakes AI Attack Staging
AML.T0080 Generate Malicious Commands AI Attack Staging
AML.T0042 Verify Attack AI Attack Staging
AML.T0108 AI Agent Command and Control
AML.T0102 AI Service API Command and Control
AML.T0101 Exfiltration via AI Agent Tool Invocation Exfiltration
AML.T0024 Exfiltration via AI Inference API Exfiltration
AML.T0025 Exfiltration via Cyber Means Exfiltration
AML.T0056 Extract LLM System Prompt Exfiltration
AML.T0057 LLM Data Leakage Exfiltration
AML.T0090 LLM Response Rendering Exfiltration
AML.T0029 Denial of AI Service Impact
AML.T0031 Erode AI Model Integrity Impact
AML.T0046 Spamming AI System with Chaff Data Impact
AML.T0048 External Harms Impact
AML.T0059 Erode Dataset Integrity Impact

6. Reverse tactic coverage

Tactic Mapped GAISSF controls Priority techniques represented Coverage Residual limitation
AML.TA0002 Reconnaissance D5-CTL-05, D5-CTL-06, D6-CTL-01, D6-CTL-02, D6-CTL-04, D7-CTL-H01, D7-CTL-H03, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-05 AML.T0087 Gather Victim Identity Information; AML.T0064 Gather RAG-Indexed Targets; AML.T0001 Search Open AI Vulnerability Analysis; AML.T0000 Search Open Technical Databases Substantially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0003 Resource Development D1-CTL-01, D1-CTL-04, D2-CTL-02, D2-CTL-06, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D7-CTL-H01, D7-CTL-H02, D8-CTL-03, D8-CTL-05 AML.T0020 Poison Training Data; AML.T0058 Publish Poisoned Models; AML.T0065 LLM Prompt Crafting; AML.T0104 Publish Poisoned AI Agent Tool; AML.T0017 Develop Capabilities Substantially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0004 Initial Access D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D2-CTL-04, D2-CTL-05, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06, D7-CTL-H05 AML.T0015 Evade AI Model; AML.T0010 AI Supply Chain Compromise; AML.T0052 Phishing Substantially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0000 AI Model Access D3-CTL-01, D3-CTL-04, D4-CTL-04, D5-CTL-02, D6-CTL-03, D6-CTL-05, D9-CTL-02, D9-CTL-03, D9-CTL-05, D9-CTL-06 AML.T0040 AI Model Inference API Access; AML.T0041 Physical Environment Access; AML.T0044 Full AI Model Access Substantially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0005 Execution D2-CTL-01, D2-CTL-02, D3-CTL-02, D3-CTL-05, D3-CTL-07 AML.T0051 LLM Prompt Injection; AML.T0100 AI Agent Clickbait Partially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0006 Persistence D9-CTL-02 AML.T0110 AI Agent Context Poisoning Partially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0012 Privilege Escalation Not Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0007 Defense Evasion D1-CTL-06, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06 AML.T0109 AI Supply Chain Reputation Inflation Substantially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0013 Credential Access Not Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0008 Discovery D5-CTL-01, D5-CTL-03, D5-CTL-04, D5-CTL-05, D8-CTL-04, D9-CTL-01, D9-CTL-05, D9-CTL-07 AML.T0062 Discover LLM Hallucinations; AML.T0106 Discover AI Agent Configuration; AML.T0007 Discover AI Artifacts; AML.T0069 Discover LLM System Information Substantially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0015 Lateral Movement Not Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0009 Collection Not Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0001 AI Attack Staging D1-CTL-02, D1-CTL-03, D1-CTL-05, D1-CTL-07, D1-CTL-08, D1-CTL-09, D2-CTL-03, D2-CTL-04, D2-CTL-05, D5-CTL-01, D5-CTL-03, D5-CTL-04, D7-CTL-H02, D7-CTL-H04, D9-CTL-01 AML.T0042 Verify Attack; AML.T0005 Create Proxy AI Model; AML.T0043 Craft Adversarial Data; AML.T0099 Generate Deepfakes Substantially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0014 Command and Control Not Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0010 Exfiltration D2-CTL-01, D2-CTL-06, D3-CTL-03, D3-CTL-06, D5-CTL-06, D6-CTL-04, D7-CTL-H04 AML.T0056 Extract LLM System Prompt; AML.T0101 Exfiltration via AI Agent Tool Invocation; AML.T0024 Exfiltration via AI Inference API; AML.T0090 LLM Response Rendering Partially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.
AML.TA0011 Impact D1-CTL-01, D6-CTL-07, D7-CTL-H03, D7-CTL-H05 AML.T0059 Erode Dataset Integrity; AML.T0046 Spamming AI System with Chaff Data; AML.T0029 Denial of AI Service; AML.T0048 External Harms Partially Addressed ATLAS is an adversary-behavior knowledge base; control mapping does not establish detection coverage, prevention, or resilience against every procedure under the tactic.

7. Implementation and evidence reuse

  • AI-system and model threat models linked to ATLAS tactic and technique IDs

  • Adversary-emulation plans and red-team test cases

  • Model, dataset, agent-tool, RAG, and supply-chain inventories

  • Prompt-injection, poisoning, evasion, extraction, and jailbreak test results

  • IAM, secrets, least-privilege, tool-authorization, and human-approval records

  • Telemetry design, detection logic, alerts, investigations, and incident records

  • Model integrity, provenance, signing, and deployment-gate evidence

  • Residual-risk decisions and management approvals

8. Limitations

  • Mapping is not MITRE endorsement, certification, equivalence, or proof of defensive effectiveness.

  • ATLAS describes adversary behavior; GAISSF defines control and evidence expectations. A relationship does not prove prevention or detection.

  • The priority technique register is deliberately focused on techniques with direct AI-system relevance to GAISSF controls; the official ATLAS dataset remains authoritative for the complete 170-object technique inventory.

  • Environment-specific threat modelling, telemetry, detection engineering, adversary emulation, and validation remain necessary.

  • ATLAS publishes monthly content updates; revalidation is required after a source release changes.

9. Notably absent

  • No MITRE certification, approval, endorsement, or conformance declaration is established.

  • No claim is made that GAISSF implementation prevents or detects every ATLAS technique.

  • No universal technique-coverage percentage or maturity score is asserted.

  • No assumption is made that control documentation proves operating effectiveness.

  • No claim is made that ATLAS replaces ATT&CK, application threat modelling, or environment-specific incident intelligence.

Annex A - GAISSF-to-ATLAS mapping register

Controlled Publication. The table below shows a representative sample (6 of 112 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF control ATLAS tactic / technique Rel. Confidence Rationale Residual gap
CRO025-MAP-0001 D1-CTL-01 Dataset Provenance & Poisoning Prevention Resource Development | AML.T0020 Poison Training Data S Low GAISSF D1-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Poison Training Data. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary.
CRO025-MAP-0002 D1-CTL-01 Dataset Provenance & Poisoning Prevention Impact | AML.T0059 Erode Dataset Integrity S Low GAISSF D1-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0059 Erode Dataset Integrity. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary.
CRO025-MAP-0003 D1-CTL-02 Model Extraction Resistance AI Attack Staging | AML.T0042 Verify Attack P Medium GAISSF D1-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary.
CRO025-MAP-0004 D1-CTL-03 Behavioral Drift Detection AI Attack Staging | AML.T0042 Verify Attack P Medium GAISSF D1-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary.
CRO025-MAP-0005 D1-CTL-04 Federated Learning Poisoning Prevention Resource Development | AML.T0020 Poison Training Data S Low GAISSF D1-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Poison Training Data. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary.
CRO025-MAP-0006 D1-CTL-04 Federated Learning Poisoning Prevention Resource Development | AML.T0058 Publish Poisoned Models S Low GAISSF D1-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0058 Publish Poisoned Models. The mapping records defensive relevance, not technique elimination or verified operating effectiveness. Threat modelling, environment-specific telemetry, adversary emulation, detection engineering, and operating-effectiveness testing remain necessary.

Annex B - QA and change record

Check Result
GAISSF controls inventoried 59
ATLAS tactics inventoried 16
Official ATLAS reported technique count 170
Priority techniques mapped 82
Forward mapping records 112
Monthly source revalidation required Yes
Independent threat-informed-defense review Required before final publication