Bibliography
Public GAISSF v1.0 publication reproduced as accessible HTML from the final source document.
GAISSF™ v1.0
Bibliography
Controlled References, Citations and Source-Transparency Register
| Field | Value |
|---|---|
| Document ID | GAISSF-NOR-006 |
| Version | 1.0 |
| Status | Final Publication v1.0 |
| Classification | Normative reference register; bibliographic annotations informative |
| Publisher | ODA3 Institute |
| Legal entity | ODA3 Pvt Ltd |
| Authoritative framework source | GAISSF-NOR-001 |
| Control baseline | 59 controls across nine domains |
| Publication date | 1 July 2026 |
This document controls source identification and citation practice for the GAISSF v1.0 ecosystem. It does not reproduce third-party standards and does not imply endorsement, equivalence, adoption or affiliation.
Document Control
| Attribute | Controlled value |
|---|---|
| Title | GAISSF™ v1.0 Bibliography |
| Document ID | GAISSF-NOR-006 |
| Version | 1.0 |
| Primary purpose | Source transparency, citation consistency and reference traceability |
| Applies to | GAISSF-NOR-001 through NOR-005 and downstream GAISSF artifacts |
| Normative authority | This document is normative for GAISSF citation identifiers, source tiers and reference-record maintenance. Third-party publications remain authoritative for their own content. |
| Precedence | GAISSF-NOR-001 governs framework requirements. Where a citation description conflicts with a source publication, the source publication prevails. |
| Review triggers | GAISSF release change; cited-source revision; withdrawal or supersession; material legal change; identified citation defect. |
| Distribution | Public — Website and GitHub |
Copyright, Licensing and Legal Notices
© 2026 ODA3 Pvt Ltd. Published market-facing by ODA3 Institute.
GAISSF™ is used as a framework mark. Third-party names, marks, publication titles and identifiers are the property of their respective owners and are referenced only for identification, analysis and interoperability.
No reference in this bibliography constitutes endorsement of GAISSF by a cited organization, regulator, standards body or publisher.
Many standards are copyright-protected and may require purchase or licensed access. This bibliography identifies sources but does not reproduce protected text beyond what is permitted by applicable law or licence.
Regulatory references are not legal advice. Users shall verify current applicability, consolidated text, effective dates, territorial scope and sector-specific obligations.
Foreword
GAISSF relies on transparent, controlled use of external standards, threat knowledge, regulatory instruments and technical guidance. This bibliography provides a single register for those sources, defines how GAISSF documents shall cite them, and distinguishes authoritative source material from contextual or implementation-oriented references.
1. Purpose and Scope
This document establishes the controlled bibliography for GAISSF v1.0. It applies to normative, informative, technical, regulatory, sector, threat-intelligence, assurance and implementation references used across the GAISSF ecosystem.
It is not a crosswalk and does not assert one-to-one equivalence between GAISSF controls and external provisions. Detailed mappings shall be maintained in separately controlled crosswalk artifacts.
2. Conformance Language
SHALL, SHALL NOT, SHOULD, SHOULD NOT, MAY and RECOMMENDED have the meanings established in GAISSF-NOR-005. Normative requirements in this document govern citation management and reference maintenance, not the substantive obligations of third-party publications.
3. Source Classification Model
| Tier | Source class | Use in GAISSF | Minimum handling |
|---|---|---|---|
| T1 | Primary authoritative | Law, regulation, official standard, official government or standards-body publication | Use exact title, identifier, issuer, edition/date and official location. |
| T2 | Primary technical authority | Official threat framework, security project, regulator guidance, official technical specification | Record version/date and scope; avoid implying legal or certification equivalence. |
| T3 | Peer-reviewed or institutional research | Academic paper, recognized research institute, intergovernmental report | Record authors, venue, year and DOI or stable identifier where available. |
| T4 | Implementation reference | Tool documentation, vendor-neutral practice guide, open-source project | Use for implementation examples only; do not elevate to normative authority. |
| T5 | Contextual evidence | Industry survey, incident report, market or loss data | State methodology and limitations; time-bound quantitative claims. |
4. Citation and Reference Requirements
- Each externally derived normative proposition SHALL identify a controlled source or be explicitly labelled as an ODA3 Institute requirement.
- Citations SHALL use the reference identifier assigned in this document where one exists.
- References SHALL identify the edition, version, publication date or access date needed to disambiguate the source.
- Withdrawn or superseded sources SHALL NOT be silently cited as current.
- References to laws and regulations SHALL identify jurisdiction and instrument number where available.
- Cross-framework mappings SHALL distinguish alignment, partial coverage, dependency and non-equivalence.
- Internet locations SHOULD use persistent official pages rather than third-party mirrors.
- Quantitative claims SHALL state the reporting period and source limitations.
- Where no source supports a claim, the document SHALL record that absence rather than infer authority.
5. Reference-Identifier Syntax
The controlled format is GAISSF-REF-[CLASS]-NNN, where CLASS identifies the source family.
| Class | Meaning | Example |
|---|---|---|
| ISO | ISO or ISO/IEC publication | GAISSF-REF-ISO-001 |
| IEC | IEC publication | GAISSF-REF-IEC-001 |
| NIST | NIST publication | GAISSF-REF-NIST-001 |
| OWASP | OWASP project or publication | GAISSF-REF-OWASP-001 |
| MITRE | MITRE publication or knowledge base | GAISSF-REF-MITRE-001 |
| CIS | Center for Internet Security publication | GAISSF-REF-CIS-001 |
| REG | Law or regulation | GAISSF-REF-REG-001 |
| GOV | Government or regulator guidance | GAISSF-REF-GOV-001 |
| RES | Research or institutional report | GAISSF-REF-RES-001 |
| TOOL | Implementation or open-source reference | GAISSF-REF-TOOL-001 |
6. Controlled Bibliography
ISO and ISO/IEC standards
GAISSF-REF-ISO-001. ISO/IEC 42001:2023. Information technology — Artificial intelligence — Management system. Source tier: T1. GAISSF use: D6, D8; governance and management-system context.
GAISSF-REF-ISO-002. ISO/IEC 23894:2023. Information technology — Artificial intelligence — Guidance on risk management. Source tier: T1. GAISSF use: D6, D8; AI risk management.
GAISSF-REF-ISO-003. ISO/IEC 22989:2022. Artificial intelligence — Artificial intelligence concepts and terminology. Source tier: T1. GAISSF use: NOR-005 terminology support.
GAISSF-REF-ISO-004. ISO/IEC 23053:2022. Framework for Artificial Intelligence systems using machine learning. Source tier: T1. GAISSF use: Architecture and lifecycle context.
GAISSF-REF-ISO-005. ISO/IEC 24027:2021. Bias in AI systems and AI aided decision making. Source tier: T1. GAISSF use: D7; bias and harmful-output assurance.
GAISSF-REF-ISO-006. ISO/IEC TR 24028:2020. Overview of trustworthiness in artificial intelligence. Source tier: T1. GAISSF use: Cross-domain trustworthiness context.
GAISSF-REF-ISO-007. ISO/IEC 24029-1:2021. Assessment of the robustness of neural networks — Part 1: Overview. Source tier: T1. GAISSF use: D1, D2, D7; robustness validation.
GAISSF-REF-ISO-008. ISO/IEC 27001:2022. Information security management systems — Requirements. Source tier: T1. GAISSF use: D1-D6, D8; ISMS integration.
GAISSF-REF-ISO-009. ISO/IEC 27002:2022. Information security controls. Source tier: T1. GAISSF use: Security-control implementation context.
GAISSF-REF-ISO-010. ISO/IEC 27005:2022. Guidance on managing information security risks. Source tier: T1. GAISSF use: D8; risk assessment and treatment.
GAISSF-REF-ISO-011. ISO/IEC 27017:2015. Information security controls for cloud services. Source tier: T1. GAISSF use: D3, D5; cloud and supplier controls.
GAISSF-REF-ISO-012. ISO/IEC 27018:2019. Protection of personally identifiable information in public clouds. Source tier: T1. GAISSF use: D5; privacy and cloud processing.
GAISSF-REF-ISO-013. ISO/IEC 27701:2019. Privacy information management — Extension to ISO/IEC 27001 and ISO/IEC 27002. Source tier: T1. GAISSF use: D5; privacy governance.
GAISSF-REF-ISO-014. ISO/IEC 38507:2022. Governance implications of the use of artificial intelligence by organizations. Source tier: T1. GAISSF use: D6; governing-body oversight.
GAISSF-REF-ISO-015. ISO/IEC 42005:2025. Artificial intelligence system impact assessment. Source tier: T1. GAISSF use: D6-D8; impact-assessment context.
GAISSF-REF-ISO-016. ISO/IEC 42006:2025. Requirements for bodies providing audit and certification of artificial intelligence management systems. Source tier: T1. GAISSF use: Certification-scheme design context.
GAISSF-REF-ISO-017. ISO/IEC 5259 series. Data quality for analytics and machine learning. Source tier: T1. GAISSF use: D1, D4, D5; data quality and provenance.
GAISSF-REF-ISO-018. ISO/IEC 5338:2023. AI system life cycle processes. Source tier: T1. GAISSF use: framework lifecycle governance.
GAISSF-REF-ISO-019. ISO 31000:2018. Risk management — Guidelines. Source tier: T1. GAISSF use: Enterprise risk integration.
GAISSF-REF-ISO-020. ISO 19011:2018. Guidelines for auditing management systems. Source tier: T1. GAISSF use: Assessment methodology.
GAISSF-REF-ISO-021. ISO/IEC 17021-1:2015. Requirements for bodies providing audit and certification of management systems. Source tier: T1. GAISSF use: Certification governance context.
GAISSF-REF-ISO-022. ISO/IEC 17065:2012. Requirements for bodies certifying products, processes and services. Source tier: T1. GAISSF use: Product/process certification boundary.
GAISSF-REF-ISO-023. ISO/IEC 17025:2017. General requirements for competence of testing and calibration laboratories. Source tier: T1. GAISSF use: Testing competence context.
IEC and safety standards
GAISSF-REF-IEC-001. IEC 61508 series. Functional safety of electrical/electronic/programmable electronic safety-related systems. Source tier: T1. GAISSF use: D9; physical-AI functional safety.
GAISSF-REF-IEC-002. IEC 62443 series. Security for industrial automation and control systems. Source tier: T1. GAISSF use: D3, D9; OT and cyber-physical security.
GAISSF-REF-IEC-003. IEC 62304:2006+A1:2015. Medical device software — Software life cycle processes. Source tier: T1. GAISSF use: Healthcare sector tailoring.
GAISSF-REF-IEC-004. IEC 62061:2021. Safety of machinery — Functional safety of safety-related control systems. Source tier: T1. GAISSF use: D9; machinery safety.
GAISSF-REF-IEC-005. IEC 60601-1. Medical electrical equipment — General requirements for basic safety and essential performance. Source tier: T1. GAISSF use: Healthcare physical-AI context.
GAISSF-REF-IEC-006. IEC 60601-1-8. Alarm systems in medical electrical equipment and systems. Source tier: T1. GAISSF use: Human oversight and alerting context.
GAISSF-REF-ISO-024. ISO 26262 series. Road vehicles — Functional safety. Source tier: T1. GAISSF use: Automotive sector tailoring.
GAISSF-REF-ISO-025. ISO 21448:2022. Road vehicles — Safety of the intended functionality. Source tier: T1. GAISSF use: Autonomous and assisted-driving context.
GAISSF-REF-ISO-026. ISO 14971:2019. Medical devices — Application of risk management to medical devices. Source tier: T1. GAISSF use: Healthcare risk management.
NIST publications
GAISSF-REF-NIST-001. NIST AI 100-1. Artificial Intelligence Risk Management Framework (AI RMF 1.0), 2023. Source tier: T1. GAISSF use: AI risk-management crosswalk.
GAISSF-REF-NIST-002. NIST AI 600-1. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, 2024. Source tier: T1. GAISSF use: Generative-AI risk context.
GAISSF-REF-NIST-003. NIST Cybersecurity Framework 2.0. The NIST Cybersecurity Framework (CSF) 2.0, 2024. Source tier: T1. GAISSF use: Cybersecurity governance and outcomes.
GAISSF-REF-NIST-004. NIST SP 800-53 Rev. 5. Security and Privacy Controls for Information Systems and Organizations. Source tier: T1. GAISSF use: Control mapping and assurance.
GAISSF-REF-NIST-005. NIST SP 800-218. Secure Software Development Framework (SSDF). Source tier: T1. GAISSF use: D1-D4; secure development.
GAISSF-REF-NIST-006. NIST SP 800-218A. Secure Software Development Practices for Generative AI and Dual-Use Foundation Models. Source tier: T1. GAISSF use: AI-specific software development.
GAISSF-REF-NIST-007. NIST SP 800-161 Rev. 1. Cybersecurity Supply Chain Risk Management Practices. Source tier: T1. GAISSF use: D3; supply-chain risk.
GAISSF-REF-NIST-008. NIST SP 800-61 Rev. 2. Computer Security Incident Handling Guide. Source tier: T1. GAISSF use: D6; incident response.
GAISSF-REF-NIST-009. NIST SP 800-207. Zero Trust Architecture. Source tier: T1. GAISSF use: D3, D5; access architecture.
GAISSF-REF-NIST-010. NIST SP 800-30 Rev. 1. Guide for Conducting Risk Assessments. Source tier: T1. GAISSF use: D8; assessment methodology.
GAISSF-REF-NIST-011. NIST SP 800-37 Rev. 2. Risk Management Framework for Information Systems and Organizations. Source tier: T1. GAISSF use: Governance and authorization.
GAISSF-REF-NIST-012. NIST SP 800-115. Technical Guide to Information Security Testing and Assessment. Source tier: T1. GAISSF use: Assessment and testing.
GAISSF-REF-NIST-013. NIST SP 800-88 Rev. 1. Guidelines for Media Sanitization. Source tier: T1. GAISSF use: D5; data disposal.
GAISSF-REF-NIST-014. NISTIR 8286 series. Integrating Cybersecurity and Enterprise Risk Management. Source tier: T1. GAISSF use: Enterprise risk integration.
GAISSF-REF-NIST-015. NIST OSCAL. Open Security Controls Assessment Language. Source tier: T2. GAISSF use: Machine-readable control and evidence exchange.
Threat and security frameworks
GAISSF-REF-MITRE-001. MITRE ATLAS. Adversarial Threat Landscape for Artificial-Intelligence Systems knowledge base. Source tier: T2. GAISSF use: Related threats across D1-D9.
GAISSF-REF-MITRE-002. MITRE ATT&CK. Enterprise adversary tactics and techniques knowledge base. Source tier: T2. GAISSF use: Enterprise threat context.
GAISSF-REF-OWASP-001. OWASP Top 10 for Large Language Model Applications. Current controlled edition used by the applicable GAISSF crosswalk. Source tier: T2. GAISSF use: LLM application risks.
GAISSF-REF-OWASP-002. OWASP Top 10 for Agentic Applications. Current controlled edition used by the applicable GAISSF crosswalk. Source tier: T2. GAISSF use: Agentic-AI risks.
GAISSF-REF-OWASP-003. OWASP AI Security and Privacy Guide. Community guidance for AI security and privacy engineering. Source tier: T2. GAISSF use: Implementation context.
GAISSF-REF-OWASP-004. OWASP Application Security Verification Standard. Application-security verification requirements. Source tier: T2. GAISSF use: D1-D4; application assurance.
GAISSF-REF-OWASP-005. OWASP Software Assurance Maturity Model. Software-assurance maturity practices. Source tier: T2. GAISSF use: Maturity guidance.
GAISSF-REF-CIS-001. CIS Critical Security Controls v8.1. Prioritized cybersecurity safeguards. Source tier: T2. GAISSF use: Baseline cybersecurity mapping.
GAISSF-REF-CIS-002. CIS Benchmarks. Technology-specific secure-configuration guidance. Source tier: T2. GAISSF use: Implementation and hardening.
GAISSF-REF-RES-001. Cloud Security Alliance AI Controls Matrix. AI-focused cloud control mapping and assurance guidance. Source tier: T2. GAISSF use: Cloud-AI assurance context.
European Union legal and regulatory instruments
GAISSF-REF-REG-001. Regulation (EU) 2024/1689. Artificial Intelligence Act. Source tier: T1. GAISSF use: Cross-domain regulatory context.
GAISSF-REF-REG-002. Regulation (EU) 2016/679. General Data Protection Regulation (GDPR). Source tier: T1. GAISSF use: D5, D6, D8.
GAISSF-REF-REG-003. Regulation (EU) 2022/2554. Digital Operational Resilience Act (DORA). Source tier: T1. GAISSF use: Financial-sector resilience.
GAISSF-REF-REG-004. Directive (EU) 2022/2555. NIS 2 Directive. Source tier: T1. GAISSF use: Cybersecurity governance and reporting.
GAISSF-REF-REG-005. Regulation (EU) 2024/2847. Cyber Resilience Act. Source tier: T1. GAISSF use: Products with digital elements.
GAISSF-REF-REG-006. Regulation (EU) 2023/2854. Data Act. Source tier: T1. GAISSF use: Data access and use.
GAISSF-REF-REG-007. Regulation (EU) 2022/868. Data Governance Act. Source tier: T1. GAISSF use: Data governance.
GAISSF-REF-REG-008. Regulation (EU) 2019/881. EU Cybersecurity Act. Source tier: T1. GAISSF use: Cybersecurity certification context.
GAISSF-REF-REG-009. Regulation (EU) 2017/745. Medical Device Regulation. Source tier: T1. GAISSF use: Healthcare sector.
GAISSF-REF-REG-010. Directive 2002/58/EC. ePrivacy Directive, as amended. Source tier: T1. GAISSF use: Privacy and communications.
Selected national and sector sources
GAISSF-REF-GOV-001. United States Executive Order 14110. Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, 2023. Source tier: T1. GAISSF use: US federal policy context.
GAISSF-REF-GOV-002. OMB Memorandum M-24-10. Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence. Source tier: T1. GAISSF use: US federal implementation.
GAISSF-REF-GOV-003. U.S. FDA guidance and action plans for AI/ML-enabled medical devices. Official FDA materials applicable to the assessed product and date. Source tier: T1. GAISSF use: Healthcare sector.
GAISSF-REF-GOV-004. UK AI Regulation White Paper and regulator guidance. Official UK government and regulator publications applicable to the assessed context. Source tier: T1. GAISSF use: UK cross-jurisdictional context.
GAISSF-REF-GOV-005. Singapore Model AI Governance Framework. Official IMDA/PDPC framework and implementation guidance. Source tier: T1. GAISSF use: APAC governance context.
GAISSF-REF-GOV-006. ASEAN Guide on AI Governance and Ethics. Regional AI governance guidance. Source tier: T1. GAISSF use: Southeast Asia context.
GAISSF-REF-GOV-007. OECD Recommendation of the Council on Artificial Intelligence. OECD/LEGAL/0449, as amended. Source tier: T1. GAISSF use: International principles.
GAISSF-REF-GOV-008. UNESCO Recommendation on the Ethics of Artificial Intelligence. Adopted 2021. Source tier: T1. GAISSF use: International ethics context.
GAISSF-REF-GOV-009. Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law. CETS No. 225, 2024. Source tier: T1. GAISSF use: International legal context.
Internal GAISSF controlled sources
GAISSF-REF-INT-001. GAISSF-NOR-001. GAISSF™ v1.0 — Global AI Security & Safety Framework. Source tier: T1. GAISSF use: Authoritative normative source.
GAISSF-REF-INT-002. GAISSF-NOR-002. GAISSF™ v1.0 Executive Summary. Source tier: T1. GAISSF use: Executive interpretation.
GAISSF-REF-INT-003. GAISSF-NOR-003. GAISSF™ v1.0 Quick Start Guide. Source tier: T1. GAISSF use: Implementation onboarding.
GAISSF-REF-INT-004. GAISSF-NOR-004. GAISSF™ v1.0 Control Catalogue. Source tier: T1. GAISSF use: 59-control library.
GAISSF-REF-INT-005. GAISSF-NOR-005. GAISSF™ v1.0 Glossary. Source tier: T1. GAISSF use: Controlled terminology.
GAISSF-REF-INT-006. GAISSF VTS v1.0. Validation Test Suite and associated controlled schemas. Source tier: T1. GAISSF use: Machine-executable validation.
GAISSF-REF-INT-007. GAISSF Editorial Decision Log MTH-GOV-034. Foundational-tier reconciliation and preservation of the 59-control baseline. Source tier: T1. GAISSF use: Editorial provenance.
7. Citation Forms
| Use case | Required form | Example |
|---|---|---|
| First citation | Reference ID + issuer/title + edition/date | GAISSF-REF-NIST-001, NIST AI RMF 1.0 (2023) |
| Subsequent citation | Reference ID | GAISSF-REF-NIST-001 |
| Specific provision | Reference ID + clause/article/page or control | GAISSF-REF-REG-001, Article 15 |
| Framework mapping | GAISSF control + relationship + source location | D3-CTL-03 — partial alignment — GAISSF-REF-NIST-007 |
| Web-only source | Issuer, page title, publication/update date and access date | Use only where no stable publication identifier exists |
8. Reference-to-Domain Index
| GAISSF domain | Primary reference families | Notably absent |
|---|---|---|
| D1 — Model and Data Integrity | ISO/IEC 5259, ISO/IEC 24029-1, NIST SSDF, MITRE ATLAS | No source is treated as a universal robustness threshold. |
| D2 — Adversarial Robustness | MITRE ATLAS, OWASP LLM/Agentic, NIST testing guidance | Threat catalogues do not prove control effectiveness. |
| D3 — Secure Architecture and Supply Chain | NIST SP 800-161, IEC 62443, CIS, OWASP | Mappings do not establish supplier compliance. |
| D4 — Secure Development and Deployment | NIST SSDF, ISO/IEC 5338, OWASP ASVS/SAMM | Tool use alone is not conformance evidence. |
| D5 — Data Protection and Privacy | GDPR, ISO/IEC 27701, ISO/IEC 27018 | No universal lawful basis or retention period is prescribed. |
| D6 — Governance, Oversight and Incident Management | ISO/IEC 42001, ISO/IEC 38507, NIST AI RMF | Certification does not transfer accountability. |
| D7 — Transparency, Human Factors and Content Safety | ISO/IEC 24027, UNESCO, OECD, OWASP | No universal fairness or content-safety metric is asserted. |
| D8 — Risk, Assurance and Continuous Improvement | ISO 31000, ISO 19011, NIST RMF/ERM guidance | Maturity does not substitute for conformance. |
| D9 — Physical AI Safety | IEC 61508, IEC 62443, ISO 26262, ISO 21448 | GAISSF does not replace sector safety approval. |
9. Reference Maintenance and Change Control
- The Bibliography Custodian SHALL review reference status at least annually and before each major GAISSF release.
- A source revision SHALL be assessed for semantic impact before the controlled edition is changed.
- Superseded references MAY remain listed for historical traceability but SHALL be marked superseded.
- Broken links SHALL be replaced with an official persistent location where available.
- Changes affecting mappings, controls, certification criteria or legal interpretation SHALL trigger downstream impact analysis.
- Reference identifiers SHALL NOT be reassigned to unrelated publications.
10. Limitations
This bibliography is a controlled source register, not a legal opinion, exhaustive literature review or declaration of formal equivalence. Standards and regulatory instruments evolve. Access restrictions may prevent public reproduction of source text. Language translations, national adoptions and consolidated legal texts may differ.
11. Notably Absent
- No claim that any cited organization endorses or recognizes GAISSF.
- No claim that GAISSF certification satisfies a cited certification, accreditation or conformity-assessment scheme.
- No automatic one-to-one equivalence between a GAISSF control and an external clause.
- No reproduction of complete copyrighted standards.
- No universal jurisdictional applicability determination.
- No guarantee that the list is exhaustive for every sector, technology or deployment.
- No reliance on unsourced market claims as normative authority.
Annex A — Reference Record Template
| Field | Required content |
|---|---|
| Reference ID | Permanent GAISSF identifier |
| Issuer | Official issuing body |
| Title | Exact publication title |
| Identifier | Standard, report, regulation or instrument number |
| Edition/version | Controlled edition or revision |
| Publication date | Official date |
| Status | Current, superseded, withdrawn or historical |
| Source tier | T1-T5 |
| Official location | Persistent official URL or catalogue location |
| GAISSF use | Domains, controls or artifact purposes |
| Mapping status | None, contextual, partial, substantial or dependency |
| Limitations | Known scope, access, edition or evidentiary limitations |
| Last verified | Date and verifier |
Annex B — Citation Review Checklist
☐ Source is official or its authority is explicitly qualified.
☐ Exact identifier and edition are recorded.
☐ Publication status has been checked.
☐ Claim does not exceed what the source supports.
☐ Legal applicability is not inferred from citation alone.
☐ Mapping type and limitations are stated.
☐ Third-party marks are used for identification only.
☐ Quantitative data includes period and methodology limits.
☐ Superseded references are labelled.
☐ Downstream documents use the same reference identifier.
Annex C — Publication Record
| Version | Date | Change | Approval status |
|---|---|---|---|
| 1.0 | 1 July 2026 | Initial controlled bibliography for the GAISSF v1.0, 59-control ecosystem. | Final Publication v1.0 |
Controlled Profile Reconciliation Notice
The Foundational profile comprises the 52 canonical controls in D1-D8. The seven D9 controls are additional mandatory controls whenever physical AI or cyber-physical actuation is within the assessed scope.
Any earlier wording that described the Foundational profile as spanning all nine domains, or that treated D9 as universally mandatory or universally excluded, is superseded by this statement. D9 applicability shall be determined and justified for every assessed scope.
Source Verification Procedure
- Verify title, issuer, edition and publication status against an official source.
- Record access restrictions and whether the source is normative, informative or contextual.
- Check that the claim made in GAISSF does not exceed the source.
- Reverify time-sensitive legal and regulatory sources before each release.
Citation Quality Controls
| Risk | Required control |
|---|---|
| Superseded edition | Record status and migration impact. |
| Copyright overreach | Cite without reproducing protected text. |
| False equivalence | Describe relationship and limitations. |
| Broken link | Use persistent official location or catalogue identifier. |
| Unsupported quantitative claim | State period, methodology and limitations. |
Publication Completeness and Intended Use
This full publication edition of GAISSF-NOR-006 is designed to stand on its own for its stated role: controlled bibliography, citation method and source-transparency register. It includes purpose, scope, governance, operating guidance, evidence expectations, limitations, decision criteria and reusable records appropriate to that role.
Completeness does not mean that the document replaces the normative control statements, applicable law, sector-specific engineering, organizational procedures or professional judgement. Cross-referenced GAISSF documents remain part of the controlled document system.
| Completeness dimension | Treatment in this edition |
|---|---|
| Normative alignment | Reconciled to the authoritative 59-control baseline and controlled profile structure. |
| Operational usability | Includes roles, workflows, gates, evidence, metrics, escalation and examples where relevant. |
| Traceability | Identifies dependencies and preserves the distinction between requirements, guidance and examples. |
| Limitations | States what the document does not establish or guarantee. |
| Maintenance | Includes review triggers, change control and publication status. |
Source-Tier Distinction and Selected India Sources
The T1-T5 source tiers in this bibliography classify the authority and proximity of external and controlled references. They do not classify the sufficiency, reliability, independence, or operating effectiveness of evidence submitted for assessment.
GAISSF-REF-IND-001. Government of India, The Digital Personal Data Protection Act, 2023, Act No. 22 of 2023, as published through India Code and subsequent official notifications. GAISSF use: Indian digital-personal-data legal context. Current commencement and implementing instruments shall be verified before reliance.
GAISSF-REF-IND-002. Indian Computer Emergency Response Team (CERT-In), Directions relating to information security practices, procedure, prevention, response and reporting of cyber incidents, issued under section 70B of the Information Technology Act, 2000, 28 April 2022, including applicable official updates and FAQs. GAISSF use: Indian incident reporting, logging, time synchronization, and service-provider context.
GAISSF-REF-IND-003. Bureau of Indian Standards, official standards catalogue and Artificial Intelligence standardization work programme. GAISSF use: discovery and verification of published Indian Standards relevant to AI; no unpublished, draft, or unspecified BIS item is treated as a normative GAISSF source.