GAISSF to CSA CCM Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to CSA CCM, with scope, method, limitations and traceability.
Document Control
| Field | Controlled Value |
|---|---|
| Document ID | CRO-034 |
| Title | GAISSF–CSA Cloud Controls Matrix Mapping |
| Version | 1.0 |
| Classification | Crosswalk — informative |
| Publisher | ODA3 Institute |
| GAISSF baseline | GAISSF v1.0; 59 controls across nine domains |
| External baseline | CSA CCM v4.1 and CAIQ v4.1; released 27 January 2026 |
| Mapping unit | GAISSF control to CCM security domain |
| Publication status | Publication Candidate |
| Verification date | 29 June 2026 |
| Distribution | Website and GitHub |
Reliance and Attribution Notice
This crosswalk is an interpretive mapping aid. It does not establish CSA endorsement, STAR listing, STAR certification or attestation, CAIQ acceptance, control implementation, operating effectiveness, or equivalence between GAISSF and CCM. Cloud Security Alliance, CCM, CAIQ and STAR names and marks remain the property of their respective owners.
Executive Summary
CRO-034 maps 59 GAISSF v1.0 controls to the 17 security domains of CSA Cloud Controls Matrix v4.1. The register contains 281 domain-level mapping records. CCM v4.1 contains 207 control specifications, while CAIQ v4.1 contains 283 assessment questions. This release intentionally does not reproduce those licensed control specifications or claim that a domain-level relationship covers every control or question.
The strongest relationships occur in Governance, Risk Management & Compliance; Data Security & Privacy; Application & Interface Security; Logging & Monitoring; Security Incident Management; Supply Chain Management; and Threat & Vulnerability Management. The most material residual gaps concern cloud shared responsibility, cloud service model and deployment model, infrastructure configuration, provider inheritance, contractual assurance, CAIQ responses, and STAR-specific evidence.
1. Purpose and Intended Use
• Support cloud-security gap analysis for AI systems and AI-enabled cloud services.
• Identify where GAISSF evidence may support CCM implementation activities.
• Help allocate control ownership among cloud service providers, customers and other supply-chain actors.
• Provide a controlled starting point for a future control-specification-level crosswalk.
2. Scope and Baseline
The authoritative GAISSF source is GAISSF-NOR-001 and GAISSF-NOR-004 v1.0. The external baseline is CSA CCM v4.1, released 27 January 2026. CSA describes CCM v4.1 as containing 207 controls across 17 domains and CAIQ v4.1 as the associated assessment questionnaire. The mapping is frozen to the verification date and must be revalidated after either framework changes.
3. Mapping Methodology
Each GAISSF control was decomposed by intended outcome and mapped to materially related CCM domains. Relationship classifications are Strong Partial, Partial or Supporting unless a stronger conclusion is directly defensible. Confidence is assigned separately. The reverse register checks whether every CCM domain has at least one relevant GAISSF relationship. This method identifies thematic and operational alignment; it does not substitute for analysis of the 207 CCM control specifications.
| Code | Meaning |
|---|---|
| SP | Strong partial: substantial shared outcome but material cloud-specific elements remain. |
| P | Partial: meaningful overlap with narrower or different scope. |
| S | Supporting: assists implementation but does not directly satisfy the domain. |
| C | Contextual only. |
| N | No material mapping. |
| O | Outside scope. |
| U | Unable to determine. |
4. CCM Domain Coverage
| Domain | Title | Mapped GAISSF controls | Mapping records | Coverage |
|---|---|---|---|---|
| A&A | Audit & Assurance | 12 | 12 | Partially Addressed |
| AIS | Application & Interface Security | 28 | 28 | Partially Addressed |
| BCR | Business Continuity Management & Operational Resilience | 14 | 14 | Partially Addressed |
| CCC | Change Control & Configuration Management | 9 | 9 | Partially Addressed |
| CEK | Cryptography, Encryption & Key Management | 0 | 0 | Not Addressed |
| DCS | Datacenter Security | 7 | 7 | Partially Addressed |
| DSP | Data Security & Privacy | 22 | 22 | Partially Addressed |
| GRC | Governance, Risk Management & Compliance | 37 | 37 | Partially Addressed |
| HRS | Human Resources Security | 5 | 5 | Partially Addressed |
| IAM | Identity & Access Management | 18 | 18 | Partially Addressed |
| IPY | Interoperability & Portability | 7 | 7 | Partially Addressed |
| IVS | Infrastructure & Virtualization Security | 13 | 13 | Partially Addressed |
| LOG | Logging & Monitoring | 43 | 43 | Partially Addressed |
| SEF | Security Incident Management, E-Discovery & Cloud Forensics | 27 | 27 | Partially Addressed |
| STA | Supply Chain Management, Transparency & Accountability | 12 | 12 | Partially Addressed |
| TVM | Threat & Vulnerability Management | 27 | 27 | Partially Addressed |
| UEM | Universal Endpoint Management | 0 | 0 | Not Addressed |
5. Domain-Level Analysis
A&A — Audit & Assurance
Independent assessment, audit planning, evidence, control effectiveness and assurance.
GAISSF linkage: 12 controls across 12 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
AIS — Application & Interface Security
Secure application lifecycle, interfaces, APIs and application-layer protections.
GAISSF linkage: 28 controls across 28 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
BCR — Business Continuity Management & Operational Resilience
Continuity, recovery, resilience, backup and service restoration.
GAISSF linkage: 14 controls across 14 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
CCC — Change Control & Configuration Management
Controlled changes, configuration baselines, approvals and integrity.
GAISSF linkage: 9 controls across 9 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
CEK — Cryptography, Encryption & Key Management
Cryptographic controls, key lifecycle, secrets and protected communications.
GAISSF linkage: 0 controls across 0 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
DCS — Datacenter Security
Physical facilities, environmental safeguards and infrastructure protection.
GAISSF linkage: 7 controls across 7 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
DSP — Data Security & Privacy
Data governance, classification, privacy, retention, protection and secure disposal.
GAISSF linkage: 22 controls across 22 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
GRC — Governance, Risk Management & Compliance
Policies, accountability, risk management, legal obligations and oversight.
GAISSF linkage: 37 controls across 37 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
HRS — Human Resources Security
Personnel screening, awareness, responsibilities and workforce lifecycle.
GAISSF linkage: 5 controls across 5 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
IAM — Identity & Access Management
Identity lifecycle, authentication, authorization, privileged access and segregation.
GAISSF linkage: 18 controls across 18 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
IPY — Interoperability & Portability
Portability, interoperability, exit planning and dependency management.
GAISSF linkage: 7 controls across 7 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
IVS — Infrastructure & Virtualization Security
Cloud infrastructure, compute, network, containers, virtualization and hardening.
GAISSF linkage: 13 controls across 13 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
LOG — Logging & Monitoring
Security logging, monitoring, alerting, time synchronization and evidence.
GAISSF linkage: 43 controls across 43 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
SEF — Security Incident Management, E-Discovery & Cloud Forensics
Incident preparation, response, investigation, evidence and forensics.
GAISSF linkage: 27 controls across 27 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
STA — Supply Chain Management, Transparency & Accountability
Third-party risk, supply chain, contracts, transparency and shared responsibility.
GAISSF linkage: 12 controls across 12 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
TVM — Threat & Vulnerability Management
Threat intelligence, vulnerability discovery, remediation, testing and exposure management.
GAISSF linkage: 27 controls across 27 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
UEM — Universal Endpoint Management
Endpoint inventory, configuration, protection and lifecycle management.
GAISSF linkage: 0 controls across 0 mapping records. A domain-level relationship does not establish coverage of all 207 CCM v4.1 control specifications, CAIQ questions, shared-responsibility assignments, auditing guidelines or STAR assurance requirements.
7. CAIQ and STAR Treatment
CAIQ is an assessment questionnaire aligned to CCM. STAR Level 1 is a self-assessment route, while STAR Level 2 involves certification or third-party attestation. Neither a GAISSF mapping nor GAISSF conformance automatically completes CAIQ, authorizes a STAR submission, or meets certification and attestation requirements. Current CSA program rules and applicable assessor requirements must be followed separately.
8. Evidence Reuse
| Evidence class | Potential reuse | Important limitation |
|---|---|---|
| Governance and risk | Policies, risk registers, ownership records, exception approvals | Must be scoped to cloud service and shared-responsibility allocation. |
| Technical security | Threat models, test reports, access records, configuration evidence | Provider-specific configuration and inherited controls require separate validation. |
| Monitoring and incidents | Logs, alerts, incident records, forensic procedures | Cloud log sources, retention and provider access must be confirmed. |
| Supply chain | Vendor assessments, contracts, model provenance records | Cloud subcontractors, locations, portability and exit obligations remain separate. |
| Assurance | Control narratives, evidence indexes, internal reviews | Does not replace CCM auditing guidelines, CAIQ responses or STAR assessment. |
9. Gap Register Summary
Every CCM domain retains a control-specification-level gap because this release maps to domains rather than reproducing the complete CCM control set. Implementers must perform a licensed, control-by-control review of CCM v4.1, allocate responsibilities, document applicability and gather operating evidence.
10. Limitations
• Domain-level mapping is not a substitute for the 207 CCM v4.1 control specifications.
• CAIQ questions and answers are not reproduced or pre-completed.
• The crosswalk does not determine cloud-provider or customer responsibility.
• The crosswalk does not establish STAR Level 1 or Level 2 eligibility.
• No claim of CSA endorsement, certification, attestation or validation is made.
• Cloud-provider-specific services, configurations, regions and evidence require independent assessment.
11. Notably Absent
• CSA endorsement or affiliation
• STAR listing, certification or attestation
• CAIQ submission or validation
• Proof of implementation or operating effectiveness
• Control-specification-level mapping to all 207 CCM controls
• Cloud-provider-specific configuration evidence
• Automatic assignment of shared responsibility
12. Conclusion
GAISSF provides substantial AI-specific security, governance, supply-chain, monitoring and incident-response capabilities that can support cloud-security programs using CCM v4.1. The crosswalk is most useful as a triage and evidence-reuse instrument. It must not be interpreted as complete CCM coverage or cloud assurance without control-specification-level analysis and verified operating evidence.
Annex A — Complete GAISSF-to-CCM Domain Mapping Register
| Record | GAISSF control | Control title | CCM domain | Relationship | Confidence | Rationale | Residual gap |
|---|---|---|---|---|---|---|---|
| CRO034-0001 | D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | DSP | SP | Medium-High | Dataset Provenance & Poisoning Prevention contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment. | CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone. |
| CRO034-0002 | D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | TVM | P | Medium | Dataset Provenance & Poisoning Prevention contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment. | CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone. |
| CRO034-0003 | D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | AIS | P | Medium | Dataset Provenance & Poisoning Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment. | CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone. |
| CRO034-0004 | D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | LOG | S | Medium | Dataset Provenance & Poisoning Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment. | CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone. |
| CRO034-0005 | D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | CCC | S | Medium | Dataset Provenance & Poisoning Prevention contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment. | CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone. |
| CRO034-0006 | D1-CTL-02 | MODEL EXTRACTION RESISTANCE | DSP | SP | Medium-High | Model Extraction Resistance contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment. | CCM v4.1 includes cloud-provider/customer responsibility allocation and detailed control specifications not established by this GAISSF control alone. |
Annex B — Source Register
| Source | Version/status | Role | Official location |
|---|---|---|---|
| GAISSF Framework Standard | GAISSF-NOR-001 v1.0 | Normative framework baseline | Controlled ODA3 Institute source |
| GAISSF Control Catalogue | GAISSF-NOR-004 v1.0 | Normative control source | Controlled ODA3 Institute source |
| CSA Cloud Controls Matrix and CAIQ | v4.1, released 27 January 2026 | External cloud-control baseline | https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1 |
| CCM Implementation and Auditing Guidelines | v4.1 | Supplementary implementation and assessment guidance | Included with official CCM v4.1 release |
| STAR Program | Current program | Separate assurance and registry layer | https://cloudsecurityalliance.org/star |