CROSSWALKS

GAISSF to CSA CCM Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to CSA CCM, with scope, method, limitations and traceability.

Document Control

Field Controlled Value
Document ID CRO-034
Title GAISSF–CSA Cloud Controls Matrix Mapping
Version 1.0
Classification Crosswalk — informative
Publisher ODA3 Institute
GAISSF baseline GAISSF v1.0; 59 controls across nine domains
External baseline CSA CCM v4.1 and CAIQ v4.1; released 27 January 2026
Mapping unit GAISSF control to CCM security domain
Publication status Publication Candidate
Verification date 29 June 2026
Distribution Website and GitHub

Reliance and Attribution Notice

This crosswalk is an interpretive mapping aid. It does not establish CSA endorsement, STAR listing, STAR certification or attestation, CAIQ acceptance, control implementation, operating effectiveness, or equivalence between GAISSF and CCM. Cloud Security Alliance, CCM, CAIQ and STAR names and marks remain the property of their respective owners.

Executive Summary

CRO-034 maps 59 GAISSF v1.0 controls to the 17 security domains of CSA Cloud Controls Matrix v4.1. The register contains 281 domain-level mapping records. CCM v4.1 contains 207 control specifications, while CAIQ v4.1 contains 283 assessment questions. This release intentionally does not reproduce those licensed control specifications or claim that a domain-level relationship covers every control or question.

The strongest relationships occur in Governance, Risk Management & Compliance; Data Security & Privacy; Application & Interface Security; Logging & Monitoring; Security Incident Management; Supply Chain Management; and Threat & Vulnerability Management. The most material residual gaps concern cloud shared responsibility, cloud service model and deployment model, infrastructure configuration, provider inheritance, contractual assurance, CAIQ responses, and STAR-specific evidence.

1. Purpose and Intended Use

• Support cloud-security gap analysis for AI systems and AI-enabled cloud services.

• Identify where GAISSF evidence may support CCM implementation activities.

• Help allocate control ownership among cloud service providers, customers and other supply-chain actors.

• Provide a controlled starting point for a future control-specification-level crosswalk.

2. Scope and Baseline

The authoritative GAISSF source is GAISSF-NOR-001 and GAISSF-NOR-004 v1.0. The external baseline is CSA CCM v4.1, released 27 January 2026. CSA describes CCM v4.1 as containing 207 controls across 17 domains and CAIQ v4.1 as the associated assessment questionnaire. The mapping is frozen to the verification date and must be revalidated after either framework changes.

3. Mapping Methodology

Each GAISSF control was decomposed by intended outcome and mapped to materially related CCM domains. Relationship classifications are Strong Partial, Partial or Supporting unless a stronger conclusion is directly defensible. Confidence is assigned separately. The reverse register checks whether every CCM domain has at least one relevant GAISSF relationship. This method identifies thematic and operational alignment; it does not substitute for analysis of the 207 CCM control specifications.

Code Meaning
SP Strong partial: substantial shared outcome but material cloud-specific elements remain.
P Partial: meaningful overlap with narrower or different scope.
S Supporting: assists implementation but does not directly satisfy the domain.
C Contextual only.
N No material mapping.
O Outside scope.
U Unable to determine.

4. CCM Domain Coverage

Domain Title Mapped GAISSF controls Mapping records Coverage
A&A Audit & Assurance 12 12 Partially Addressed
AIS Application & Interface Security 28 28 Partially Addressed
BCR Business Continuity Management & Operational Resilience 14 14 Partially Addressed
CCC Change Control & Configuration Management 9 9 Partially Addressed
CEK Cryptography, Encryption & Key Management 0 0 Not Addressed
DCS Datacenter Security 7 7 Partially Addressed
DSP Data Security & Privacy 22 22 Partially Addressed
GRC Governance, Risk Management & Compliance 37 37 Partially Addressed
HRS Human Resources Security 5 5 Partially Addressed
IAM Identity & Access Management 18 18 Partially Addressed
IPY Interoperability & Portability 7 7 Partially Addressed
IVS Infrastructure & Virtualization Security 13 13 Partially Addressed
LOG Logging & Monitoring 43 43 Partially Addressed
SEF Security Incident Management, E-Discovery & Cloud Forensics 27 27 Partially Addressed
STA Supply Chain Management, Transparency & Accountability 12 12 Partially Addressed
TVM Threat & Vulnerability Management 27 27 Partially Addressed
UEM Universal Endpoint Management 0 0 Not Addressed

5. Domain-Level Analysis

A&A — Audit & Assurance

Independent assessment, audit planning, evidence, control effectiveness and assurance.

GAISSF linkage: 12 controls across 12 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

AIS — Application & Interface Security

Secure application lifecycle, interfaces, APIs and application-layer protections.

GAISSF linkage: 28 controls across 28 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

BCR — Business Continuity Management & Operational Resilience

Continuity, recovery, resilience, backup and service restoration.

GAISSF linkage: 14 controls across 14 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

CCC — Change Control & Configuration Management

Controlled changes, configuration baselines, approvals and integrity.

GAISSF linkage: 9 controls across 9 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

CEK — Cryptography, Encryption & Key Management

Cryptographic controls, key lifecycle, secrets and protected communications.

GAISSF linkage: 0 controls across 0 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

DCS — Datacenter Security

Physical facilities, environmental safeguards and infrastructure protection.

GAISSF linkage: 7 controls across 7 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

DSP — Data Security & Privacy

Data governance, classification, privacy, retention, protection and secure disposal.

GAISSF linkage: 22 controls across 22 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

GRC — Governance, Risk Management & Compliance

Policies, accountability, risk management, legal obligations and oversight.

GAISSF linkage: 37 controls across 37 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

HRS — Human Resources Security

Personnel screening, awareness, responsibilities and workforce lifecycle.

GAISSF linkage: 5 controls across 5 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

IAM — Identity & Access Management

Identity lifecycle, authentication, authorization, privileged access and segregation.

GAISSF linkage: 18 controls across 18 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

IPY — Interoperability & Portability

Portability, interoperability, exit planning and dependency management.

GAISSF linkage: 7 controls across 7 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

IVS — Infrastructure & Virtualization Security

Cloud infrastructure, compute, network, containers, virtualization and hardening.

GAISSF linkage: 13 controls across 13 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

LOG — Logging & Monitoring

Security logging, monitoring, alerting, time synchronization and evidence.

GAISSF linkage: 43 controls across 43 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

SEF — Security Incident Management, E-Discovery & Cloud Forensics

Incident preparation, response, investigation, evidence and forensics.

GAISSF linkage: 27 controls across 27 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

STA — Supply Chain Management, Transparency & Accountability

Third-party risk, supply chain, contracts, transparency and shared responsibility.

GAISSF linkage: 12 controls across 12 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

TVM — Threat & Vulnerability Management

Threat intelligence, vulnerability discovery, remediation, testing and exposure management.

GAISSF linkage: 27 controls across 27 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

UEM — Universal Endpoint Management

Endpoint inventory, configuration, protection and lifecycle management.

GAISSF linkage: 0 controls across 0 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.

6. Shared Responsibility and Cloud Context

CCM is designed for cloud environments and explicitly supports responsibility allocation across the cloud supply chain. GAISSF control implementation must therefore be evaluated against the selected service model, deployment model, provider architecture, regions, managed services, inherited controls, customer configuration responsibilities, subcontractors and exit strategy. A mapping record alone does not identify the responsible actor or prove that inherited controls are effective.

7. CAIQ and STAR Treatment

CAIQ is an assessment questionnaire aligned to CCM. STAR Level 1 is a self-assessment route, while STAR Level 2 involves certification or third-party attestation. Neither a GAISSF mapping nor GAISSF conformance automatically completes CAIQ, authorizes a STAR submission, or meets certification and attestation requirements. Current CSA program rules and applicable assessor requirements must be followed separately.

8. Evidence Reuse

Evidence class Potential reuse Important limitation
Governance and risk Policies, risk registers, ownership records, exception approvals Must be scoped to cloud service and shared-responsibility allocation.
Technical security Threat models, test reports, access records, configuration evidence Provider-specific configuration and inherited controls require separate validation.
Monitoring and incidents Logs, alerts, incident records, forensic procedures Cloud log sources, retention and provider access must be confirmed.
Supply chain Vendor assessments, contracts, model provenance records Cloud subcontractors, locations, portability and exit obligations remain separate.
Assurance Control narratives, evidence indexes, internal reviews Does not replace CCM auditing guidelines, CAIQ responses or STAR assessment.

9. Gap Register Summary

Every CCM domain retains a control-specification-level gap because this release maps to domains rather than reproducing the complete CCM control set. Implementers must perform a licensed, control-by-control review of CCM v4.1, allocate responsibilities, document applicability and gather operating evidence.

10. Limitations

• Domain-level mapping is not a substitute for the 207 CCM v4.1 control specifications.

• CAIQ questions and answers are not reproduced or pre-completed.

• The crosswalk does not determine cloud-provider or customer responsibility.

• The crosswalk does not establish STAR Level 1 or Level 2 eligibility.

• No claim of CSA endorsement, certification, attestation or validation is made.

• Cloud-provider-specific services, configurations, regions and evidence require independent assessment.

11. Notably Absent

• CSA endorsement or affiliation

• STAR listing, certification or attestation

• CAIQ submission or validation

• Proof of implementation or operating effectiveness

• Control-specification-level mapping to all 207 CCM controls

• Cloud-provider-specific configuration evidence

• Automatic assignment of shared responsibility

12. Conclusion

GAISSF provides substantial AI-specific security, governance, supply-chain, monitoring and incident-response capabilities that can support cloud-security programs using CCM v4.1. The crosswalk is most useful as a triage and evidence-reuse instrument. It must not be interpreted as complete CCM coverage or cloud assurance without control-specification-level analysis and verified operating evidence.

Annex A — Complete GAISSF-to-CCM Domain Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 281 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF control Control title CCM domain Relationship Confidence Rationale Residual gap
CRO034-0001 D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION DSP SP Medium-High Dataset Provenance & Poisoning Prevention contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment. CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone.
CRO034-0002 D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION TVM P Medium Dataset Provenance & Poisoning Prevention contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment. CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone.
CRO034-0003 D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION AIS P Medium Dataset Provenance & Poisoning Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment. CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone.
CRO034-0004 D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION LOG S Medium Dataset Provenance & Poisoning Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment. CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone.
CRO034-0005 D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION CCC S Medium Dataset Provenance & Poisoning Prevention contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment. CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone.
CRO034-0006 D1-CTL-02 MODEL EXTRACTION RESISTANCE DSP SP Medium-High Model Extraction Resistance contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment. CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone.

Annex B — Source Register

Source Version/status Role Official location
GAISSF Framework Standard GAISSF-NOR-001 v1.0 Normative framework baseline Controlled ODA3 Institute source
GAISSF Control Catalogue GAISSF-NOR-004 v1.0 Normative control source Controlled ODA3 Institute source
CSA Cloud Controls Matrix and CAIQ v4.1, released 27 January 2026 External cloud-control baseline https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1
CCM Implementation and Auditing Guidelines v4.1 Supplementary implementation and assessment guidance Included with official CCM v4.1 release
STAR Program Current program Separate assurance and registry layer https://cloudsecurityalliance.org/star