CROSSWALKS

GAISSF to FedRAMP Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to FedRAMP, with scope, method, limitations and traceability.

Document Control

Attribute Controlled value
Purpose Map GAISSF v1.0 controls to FedRAMP/NIST SP 800-53 Rev. 5 control families for planning and gap analysis.
Normative GAISSF sources GAISSF-NOR-001 and GAISSF-NOR-004, version 1.0.
External baseline FedRAMP Consolidated Rules for 2026; FedRAMP Rev5/Class D; FedRAMP 20x Classes A–C; NIST SP 800-53 Rev. 5.
Mapping granularity Control-family level; not individual FedRAMP control or assessment-objective level.
Review trigger Any change to GAISSF, FedRAMP rules, certification classes, Rev5 baselines, 20x requirements, NIST SP 800-53 or agency requirements.
Distribution Public — Website and GitHub.

1. Executive Summary

CRO-036 maps all 59 GAISSF v1.0 controls to the 20 NIST SP 800-53 Revision 5 control families used in the FedRAMP Rev5 security model. The register contains 258 forward relationships and a complete reverse family coverage view.

The mapping supports preliminary federal-cloud readiness analysis, control ownership, evidence rationalization and identification of AI-specific security capabilities. It is not a FedRAMP assessment and cannot substitute for a defined cloud service offering boundary, applicable certification class, Security Decision Record, security package, independent assessment, continuous monitoring, agency risk acceptance or Marketplace action.

2. Current FedRAMP Baseline

As verified on 29 June 2026, FedRAMP operates under the Consolidated Rules for 2026, officially launched on 24 June 2026. The current program includes the traditional Rev5 path and the FedRAMP 20x pathway. Rev5 program and agency certifications are Class D and use NIST SP 800-53 Rev. 5 controls. FedRAMP 20x Classes A, B and C are available; a 20x Class D path remains planned.

The crosswalk therefore treats the NIST/FedRAMP control families as the stable common organizing layer while preserving separate conclusions for Rev5 controls, FedRAMP-defined parameters, 20x security decisions and indicators, certification class, authorization path and agency-specific risk decisions.

3. Purpose and Intended Use

  • Identify candidate overlap between AI security controls and federal cloud security outcome areas.

  • Support preliminary gap analysis before a formal FedRAMP readiness or certification engagement.

  • Structure evidence reuse while preserving cloud service boundary and shared-responsibility constraints.

  • Assist CISOs, cloud security architects, AI governance leads and compliance teams in assigning ownership.

This document must not be used as proof of FedRAMP Certification, authorization, ATO, control implementation, assessment completion or agency acceptance.

4. Scope and Exclusions

In scope Out of scope
GAISSF v1.0 — 59 authoritative controls Individual Rev5 control and enhancement determinations
Twenty NIST SP 800-53 Rev. 5 control families FedRAMP-defined parameters and control-specific guidance
Family-level forward and reverse mapping FedRAMP 20x KSI implementation and automated validation
Current Rev5 and 20x pathway context SSP, SAP, SAR, POA&M, Security Decision Record or ConMon completion
Evidence and residual-gap guidance 3PAO/FedRAMP Recognized assessment, FedRAMP Certification, Marketplace listing or agency ATO

5. Source Register

Source Role Status Verified
GAISSF-NOR-001 v1.0 Framework and conformance baseline Normative GAISSF 29 Jun 2026
GAISSF-NOR-004 v1.0 Authoritative 59-control catalogue Normative GAISSF 29 Jun 2026
FedRAMP Consolidated Rules for 2026 Current program rules and terminology Official FedRAMP 29 Jun 2026
NIST SP 800-53 Revision 5 Rev5 control-family and control baseline Official NIST 29 Jun 2026
OMB Memorandum M-24-15 Authorization policy and responsibilities Binding federal policy 29 Jun 2026
FedRAMP 20x documentation Current classes and phased implementation Official FedRAMP 29 Jun 2026

6. Mapping Methodology

Mappings compare intended security outcome, lifecycle relevance, cloud implementation context, evidence expectations and shared-responsibility implications. A relationship is assigned only where a substantive operational connection exists. Similar terminology alone is insufficient.

Code Meaning
SP Strong partial: the GAISSF control materially supports the family outcome but leaves FedRAMP-specific requirements.
P Partial: meaningful overlap exists but the GAISSF control addresses only part of the family scope.
S Supporting: the control contributes evidence or capability without directly satisfying the family outcome.
N/O/U No material mapping, outside scope or unable to determine.

7. Coverage Summary by Control Family

Family Title GAISSF controls Records Coverage status
AC Access Control 14 14 Substantially Addressed
AT Awareness and Training 5 5 Substantially Addressed
AU Audit and Accountability 9 9 Substantially Addressed
CA Assessment, Authorization and Monitoring 13 13 Substantially Addressed
CM Configuration Management 9 9 Substantially Addressed
CP Contingency Planning 9 9 Substantially Addressed
IA Identification and Authentication 12 12 Substantially Addressed
IR Incident Response 15 15 Substantially Addressed
MA Maintenance 0 0 Not Addressed
MP Media Protection 3 3 Partially Addressed
PE Physical and Environmental Protection 7 7 Substantially Addressed
PL Planning 12 12 Substantially Addressed
PM Program Management 12 12 Substantially Addressed
PS Personnel Security 0 0 Not Addressed
PT Personally Identifiable Information Processing and Transparency 6 6 Substantially Addressed
RA Risk Assessment 27 27 Substantially Addressed
SA System and Services Acquisition 25 25 Substantially Addressed
SC System and Communications Protection 20 20 Substantially Addressed
SI System and Information Integrity 43 43 Substantially Addressed
SR Supply Chain Risk Management 17 17 Substantially Addressed

8. GAISSF-to-FedRAMP Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 258 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
GAISSF ID GAISSF control FedRAMP family Relationship Confidence Residual gap
D1-CTL-01 Dataset Provenance & Poisoning Prevention RA — Risk Assessment P Medium FedRAMP requires cloud-service-boundary-specific implementation statements, inherited/shared controls, FedRAMP-defined parameters, evidence, testing and authorization/certification records beyond this GAISSF control.
D1-CTL-01 Dataset Provenance & Poisoning Prevention SI — System and Information Integrity P Medium FedRAMP requires cloud-service-boundary-specific implementation statements, inherited/shared controls, FedRAMP-defined parameters, evidence, testing and authorization/certification records beyond this GAISSF control.
D1-CTL-01 Dataset Provenance & Poisoning Prevention SA — System and Services Acquisition P Medium FedRAMP requires cloud-service-boundary-specific implementation statements, inherited/shared controls, FedRAMP-defined parameters, evidence, testing and authorization/certification records beyond this GAISSF control.
D1-CTL-01 Dataset Provenance & Poisoning Prevention SR — Supply Chain Risk Management S Medium FedRAMP requires cloud-service-boundary-specific implementation statements, inherited/shared controls, FedRAMP-defined parameters, evidence, testing and authorization/certification records beyond this GAISSF control.
D1-CTL-02 Model Extraction Resistance RA — Risk Assessment P Medium FedRAMP requires cloud-service-boundary-specific implementation statements, inherited/shared controls, FedRAMP-defined parameters, evidence, testing and authorization/certification records beyond this GAISSF control.
D1-CTL-02 Model Extraction Resistance SI — System and Information Integrity P Medium FedRAMP requires cloud-service-boundary-specific implementation statements, inherited/shared controls, FedRAMP-defined parameters, evidence, testing and authorization/certification records beyond this GAISSF control.

9. FedRAMP-to-GAISSF Reverse Coverage

Family Title Mapped GAISSF controls Coverage Residual gap
AC Access Control D2-CTL-01, D2-CTL-02, D2-CTL-03, D2-CTL-04, D2-CTL-05, D2-CTL-06, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D7-CTL-H03 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
AT Awareness and Training D7-CTL-H01, D7-CTL-H02, D7-CTL-H03, D7-CTL-H04, D7-CTL-H05 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
AU Audit and Accountability D6-CTL-01, D6-CTL-02, D6-CTL-03, D6-CTL-04, D6-CTL-05, D6-CTL-06, D6-CTL-07, D8-CTL-04, D9-CTL-07 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
CA Assessment, Authorization and Monitoring D6-CTL-01, D6-CTL-02, D6-CTL-03, D6-CTL-04, D6-CTL-05, D6-CTL-06, D6-CTL-07, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-04, D8-CTL-05, D9-CTL-07 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
CM Configuration Management D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-05, D8-CTL-05 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
CP Contingency Planning D6-CTL-07, D8-CTL-04, D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-06, D9-CTL-07 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
IA Identification and Authentication D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D7-CTL-H01, D7-CTL-H02, D7-CTL-H03, D7-CTL-H04, D7-CTL-H05 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
IR Incident Response D6-CTL-04, D6-CTL-07, D7-CTL-H01, D7-CTL-H02, D7-CTL-H03, D7-CTL-H04, D7-CTL-H05, D8-CTL-04, D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-06, D9-CTL-07 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
MA Maintenance Not Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
MP Media Protection D3-CTL-06, D3-CTL-07, D6-CTL-05 Partially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
PE Physical and Environmental Protection D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-06, D9-CTL-07 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
PL Planning D6-CTL-01, D6-CTL-02, D6-CTL-03, D6-CTL-04, D6-CTL-05, D6-CTL-06, D6-CTL-07, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-04, D8-CTL-05 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
PM Program Management D6-CTL-01, D6-CTL-02, D6-CTL-03, D6-CTL-04, D6-CTL-05, D6-CTL-06, D6-CTL-07, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-04, D8-CTL-05 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
PS Personnel Security Not Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
PT Personally Identifiable Information Processing and Transparency D5-CTL-01, D5-CTL-02, D5-CTL-03, D5-CTL-04, D5-CTL-05, D5-CTL-06 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
RA Risk Assessment D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D1-CTL-09, D2-CTL-01, D2-CTL-02, D2-CTL-03, D2-CTL-04, D2-CTL-05, D2-CTL-06, D3-CTL-03, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D5-CTL-03, D7-CTL-H02, D9-CTL-04, D9-CTL-05 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
SA System and Services Acquisition D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D1-CTL-09, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06, D8-CTL-05 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
SC System and Communications Protection D1-CTL-06, D2-CTL-01, D2-CTL-02, D2-CTL-03, D2-CTL-04, D2-CTL-05, D2-CTL-06, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D5-CTL-01, D5-CTL-02, D5-CTL-03, D5-CTL-04, D5-CTL-05, D5-CTL-06 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
SI System and Information Integrity D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D1-CTL-09, D2-CTL-01, D2-CTL-02, D2-CTL-03, D2-CTL-04, D2-CTL-05, D2-CTL-06, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D4-CTL-02, D4-CTL-04, D5-CTL-01, D5-CTL-02, D5-CTL-03, D5-CTL-04, D5-CTL-05, D5-CTL-06, D7-CTL-H01, D7-CTL-H02, D7-CTL-H03, D7-CTL-H04, D7-CTL-H05, D8-CTL-05, D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-06, D9-CTL-07 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.
SR Supply Chain Risk Management D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D1-CTL-09, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06 Substantially Addressed Family-level mapping does not establish implementation of every Rev5 control or enhancement. A Class/impact-specific control baseline, FedRAMP parameters, shared-responsibility allocation, assessment procedures and authorization/certification evidence remain necessary.

10. FedRAMP Readiness Implications

Cloud Service Offering boundary

The organization must define the exact service, components, deployment model, data flows, external services and inherited controls. GAISSF does not establish this boundary.

Certification class and pathway

The provider must select the applicable current FedRAMP class and Rev5 or 20x pathway. The crosswalk does not make that selection.

Shared responsibility

Each relevant control must be allocated among the provider, federal customer, underlying infrastructure provider and other external services.

Assessment and evidence

FedRAMP requires current implementation evidence, independent verification where applicable, findings management and continuous reporting.

Agency decision

An agency authorizing official remains responsible for the agency's ATO and may require additional controls based on mission and risk.

11. Evidence Reuse Guidance

GAISSF evidence type Potential FedRAMP use Required validation
AI asset inventory and AI BOM Support CM, PM, RA, SA and SR inventories Confirm complete CSO boundary, ownership, currency and inherited components.
Threat models and adversarial test reports Support RA, CA, SI and SC analysis Align to FedRAMP control objectives, system architecture and current deployed version.
Audit logs and monitoring records Support AU, CA, IR and SI Validate required events, retention, protection, review cadence and incident integration.
Vendor and model-provider assessments Support SA and SR Document contracts, service dependencies, flow-down requirements and ongoing monitoring.
Incident response and continuity records Support IR and CP Integrate agency/FedRAMP reporting, exercises, recovery objectives and lessons learned.
Privacy and PII controls Support PT and SC Complete federal privacy analysis, authority, notices, minimization and records.

12. Limitations

  • This is an interpretive control-family crosswalk, not a control-by-control FedRAMP gap assessment.

  • FedRAMP requirements are cloud-service-offering-specific and depend on certification class, pathway, agency use, architecture and information impact.

  • A mapped GAISSF control may support several FedRAMP controls but does not satisfy their complete statements, parameters or assessment objectives.

  • Current FedRAMP rules are evolving rapidly; this mapping must be revalidated after program or baseline changes.

  • The mapping does not address classified information or agency-specific requirements outside the FedRAMP package.

13. Notably Absent

  • No FedRAMP Certification, authorization or agency ATO is created by this mapping.

  • No individual FedRAMP control is deemed implemented solely because a GAISSF control maps to its family.

  • No FedRAMP-recognized independent assessment has been performed.

  • No cloud-service boundary, data-impact class, inherited-control model or agency use case is established.

  • No SSP, SAP, SAR, POA&M, Security Decision Record or continuous-monitoring package is completed.

  • No endorsement, acceptance or recognition by GSA, FedRAMP, OMB, NIST or any federal agency is implied.

14. Conclusion

GAISSF provides material AI-security capabilities across all FedRAMP/NIST control families, particularly risk assessment, system integrity, system acquisition, communications protection, supply-chain risk, incident response and governance. The relationship is complementary rather than substitutive. Formal FedRAMP readiness requires a complete, class-specific and pathway-specific assessment against the controlling FedRAMP rules.