CROSSWALKS

GAISSF to CIS Controls Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to CIS Controls, with scope, method, limitations and traceability.

1. Executive Summary

This crosswalk contains 194 outcome-based mapping records covering all 59 GAISSF controls and all 18 CIS Control families. It supports cybersecurity control rationalization and evidence reuse. It does not establish implementation of the underlying CIS Safeguards or any CIS assessment result.

2. Source Baseline

CIS Controls v8.1 is the current official version verified on 29 June 2026. CIS describes the Controls as a prioritized set of Safeguards against prevalent cyber attacks. The framework contains 18 Controls and 153 Safeguards, with Implementation Groups used to prioritize adoption.

3. Scope and Method

The crosswalk compares GAISSF control outcomes with the 18 CIS Control families. Safeguard-level obligations, IG assignments, asset classes, frequencies and assessment evidence remain governed by official CIS materials. Relationship and confidence ratings are analytical judgments, not equivalence findings.

4. High-Alignment Areas

  • Asset, software and supplier inventory

  • Data protection, secure configuration and access control

  • Vulnerability, logging, monitoring and malware defense

  • Secure software development and penetration testing

  • Incident response, recovery and workforce training

5. Material Residual Work

  • Select IG1, IG2 or IG3 based on enterprise risk and resources

  • Assess every applicable Safeguard rather than relying on Control-family coverage

  • Define enterprise asset classes, implementation frequencies and ownership

  • Collect CIS-specific evidence and evaluate operating effectiveness

  • Address enterprise IT controls outside GAISSF AI-system scope

6. Notably Absent

No basis was found to claim CIS certification, accreditation, SecureSuite conformance, implementation of all 153 Safeguards, correct IG selection, or CIS endorsement.

7. CIS Control Coverage Register

Control Title Mapped GAISSF controls Coverage
1 Inventory and Control of Enterprise Assets 10 Substantially Addressed
2 Inventory and Control of Software Assets 6 Partially Addressed
3 Data Protection 21 Substantially Addressed
4 Secure Configuration of Enterprise Assets and Software 7 Partially Addressed
5 Account Management 14 Substantially Addressed
6 Access Control Management 9 Substantially Addressed
7 Continuous Vulnerability Management 12 Substantially Addressed
8 Audit Log Management 21 Substantially Addressed
9 Email and Web Browser Protections 9 Substantially Addressed
10 Malware Defenses 14 Substantially Addressed
11 Data Recovery 1 Indirectly Supported
12 Network Infrastructure Management 3 Partially Addressed
13 Network Monitoring and Defense 13 Substantially Addressed
14 Security Awareness and Skills Training 10 Substantially Addressed
15 Service Provider Management 8 Substantially Addressed
16 Application Software Security 11 Substantially Addressed
17 Incident Response Management 5 Partially Addressed
18 Penetration Testing 20 Substantially Addressed

Annex A — Complete Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 194 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF CIS Control Rel. Confidence Rationale / Gap
CRO033-MAP-0001 D1-CTL-01 8 — Audit Log Management P Medium GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials.
CRO033-MAP-0002 D1-CTL-01 3 — Data Protection S Medium GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials.
CRO033-MAP-0003 D1-CTL-01 18 — Penetration Testing S Medium GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials.
CRO033-MAP-0004 D1-CTL-01 13 — Network Monitoring and Defense S Medium GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials.
CRO033-MAP-0005 D1-CTL-02 13 — Network Monitoring and Defense P Medium GAISSF D1-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials.
CRO033-MAP-0006 D1-CTL-02 7 — Continuous Vulnerability Management S Medium GAISSF D1-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials.

Annex B — Source Register

Source Role Status
GAISSF-NOR-001 v1.0 Framework and conformance baseline Normative
GAISSF-NOR-004 v1.0 Authoritative control catalogue Normative
CIS Controls v8.1 Primary external baseline Current official version
CIS Implementation Groups Safeguard prioritization Separate implementation layer
CIS CSAT / SecureSuite Assessment and tooling Separate assessment layer

Limitations and Reliance Notice

  • Mapping is not CIS certification, accreditation, assessment, SecureSuite conformance, or proof of implementation effectiveness.

  • CIS Controls v8.1 contains 153 Safeguards assigned across Implementation Groups; this publication maps at the 18-Control family level and does not reproduce the full licensed Safeguard text.

  • Implementation Group selection is risk- and resource-dependent and must be determined by the implementing enterprise.

  • CIS Benchmarks, CIS RAM, CIS CSAT and CIS SecureSuite are separate resources and are not substituted by this crosswalk.

  • Similar terminology does not establish equivalence; enterprise IT outcomes and AI-specific security outcomes may differ materially.

  • Future CIS revisions require revalidation.

© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. CIS, CIS Controls, CIS Safeguards, CIS Benchmarks and related marks and materials remain the property of Center for Internet Security, Inc. No endorsement or affiliation is implied.