GAISSF to CIS Controls Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to CIS Controls, with scope, method, limitations and traceability.
1. Executive Summary
This crosswalk contains 194 outcome-based mapping records covering all 59 GAISSF controls and all 18 CIS Control families. It supports cybersecurity control rationalization and evidence reuse. It does not establish implementation of the underlying CIS Safeguards or any CIS assessment result.
2. Source Baseline
CIS Controls v8.1 is the current official version verified on 29 June 2026. CIS describes the Controls as a prioritized set of Safeguards against prevalent cyber attacks. The framework contains 18 Controls and 153 Safeguards, with Implementation Groups used to prioritize adoption.
3. Scope and Method
The crosswalk compares GAISSF control outcomes with the 18 CIS Control families. Safeguard-level obligations, IG assignments, asset classes, frequencies and assessment evidence remain governed by official CIS materials. Relationship and confidence ratings are analytical judgments, not equivalence findings.
4. High-Alignment Areas
Asset, software and supplier inventory
Data protection, secure configuration and access control
Vulnerability, logging, monitoring and malware defense
Secure software development and penetration testing
Incident response, recovery and workforce training
5. Material Residual Work
Select IG1, IG2 or IG3 based on enterprise risk and resources
Assess every applicable Safeguard rather than relying on Control-family coverage
Define enterprise asset classes, implementation frequencies and ownership
Collect CIS-specific evidence and evaluate operating effectiveness
Address enterprise IT controls outside GAISSF AI-system scope
6. Notably Absent
No basis was found to claim CIS certification, accreditation, SecureSuite conformance, implementation of all 153 Safeguards, correct IG selection, or CIS endorsement.
7. CIS Control Coverage Register
| Control | Title | Mapped GAISSF controls | Coverage |
|---|---|---|---|
| 1 | Inventory and Control of Enterprise Assets | 10 | Substantially Addressed |
| 2 | Inventory and Control of Software Assets | 6 | Partially Addressed |
| 3 | Data Protection | 21 | Substantially Addressed |
| 4 | Secure Configuration of Enterprise Assets and Software | 7 | Partially Addressed |
| 5 | Account Management | 14 | Substantially Addressed |
| 6 | Access Control Management | 9 | Substantially Addressed |
| 7 | Continuous Vulnerability Management | 12 | Substantially Addressed |
| 8 | Audit Log Management | 21 | Substantially Addressed |
| 9 | Email and Web Browser Protections | 9 | Substantially Addressed |
| 10 | Malware Defenses | 14 | Substantially Addressed |
| 11 | Data Recovery | 1 | Indirectly Supported |
| 12 | Network Infrastructure Management | 3 | Partially Addressed |
| 13 | Network Monitoring and Defense | 13 | Substantially Addressed |
| 14 | Security Awareness and Skills Training | 10 | Substantially Addressed |
| 15 | Service Provider Management | 8 | Substantially Addressed |
| 16 | Application Software Security | 11 | Substantially Addressed |
| 17 | Incident Response Management | 5 | Partially Addressed |
| 18 | Penetration Testing | 20 | Substantially Addressed |
Annex A — Complete Mapping Register
| Record | GAISSF | CIS Control | Rel. | Confidence | Rationale / Gap |
|---|---|---|---|---|---|
| CRO033-MAP-0001 | D1-CTL-01 | 8 — Audit Log Management | P | Medium | GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials. |
| CRO033-MAP-0002 | D1-CTL-01 | 3 — Data Protection | S | Medium | GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials. |
| CRO033-MAP-0003 | D1-CTL-01 | 18 — Penetration Testing | S | Medium | GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials. |
| CRO033-MAP-0004 | D1-CTL-01 | 13 — Network Monitoring and Defense | S | Medium | GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials. |
| CRO033-MAP-0005 | D1-CTL-02 | 13 — Network Monitoring and Defense | P | Medium | GAISSF D1-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials. |
| CRO033-MAP-0006 | D1-CTL-02 | 7 — Continuous Vulnerability Management | S | Medium | GAISSF D1-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards. The organization must validate the applicable CIS v8.1 Safeguards, Implementation Group, asset classes, frequencies, enterprise scope, evidence and operating effectiveness using the official CIS materials. |
Annex B — Source Register
| Source | Role | Status |
|---|---|---|
| GAISSF-NOR-001 v1.0 | Framework and conformance baseline | Normative |
| GAISSF-NOR-004 v1.0 | Authoritative control catalogue | Normative |
| CIS Controls v8.1 | Primary external baseline | Current official version |
| CIS Implementation Groups | Safeguard prioritization | Separate implementation layer |
| CIS CSAT / SecureSuite | Assessment and tooling | Separate assessment layer |
Limitations and Reliance Notice
Mapping is not CIS certification, accreditation, assessment, SecureSuite conformance, or proof of implementation effectiveness.
CIS Controls v8.1 contains 153 Safeguards assigned across Implementation Groups; this publication maps at the 18-Control family level and does not reproduce the full licensed Safeguard text.
Implementation Group selection is risk- and resource-dependent and must be determined by the implementing enterprise.
CIS Benchmarks, CIS RAM, CIS CSAT and CIS SecureSuite are separate resources and are not substituted by this crosswalk.
Similar terminology does not establish equivalence; enterprise IT outcomes and AI-specific security outcomes may differ materially.
Future CIS revisions require revalidation.
© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. CIS, CIS Controls, CIS Safeguards, CIS Benchmarks and related marks and materials remain the property of Center for Internet Security, Inc. No endorsement or affiliation is implied.