GAISSF DOCUMENTATION

Bibliography

Public GAISSF v1.0 publication reproduced as accessible HTML from the final source document.

GAISSF™ v1.0

Bibliography

Controlled References, Citations and Source-Transparency Register

FieldValue
Document IDGAISSF-NOR-006
Version1.0
StatusFinal Publication v1.0
ClassificationNormative reference register; bibliographic annotations informative
PublisherODA3 Institute
Legal entityODA3 Pvt Ltd
Authoritative framework sourceGAISSF-NOR-001
Control baseline59 controls across nine domains
Publication date1 July 2026

This document controls source identification and citation practice for the GAISSF v1.0 ecosystem. It does not reproduce third-party standards and does not imply endorsement, equivalence, adoption or affiliation.

Document Control

AttributeControlled value
TitleGAISSF™ v1.0 Bibliography
Document IDGAISSF-NOR-006
Version1.0
Primary purposeSource transparency, citation consistency and reference traceability
Applies toGAISSF-NOR-001 through NOR-005 and downstream GAISSF artifacts
Normative authorityThis document is normative for GAISSF citation identifiers, source tiers and reference-record maintenance. Third-party publications remain authoritative for their own content.
PrecedenceGAISSF-NOR-001 governs framework requirements. Where a citation description conflicts with a source publication, the source publication prevails.
Review triggersGAISSF release change; cited-source revision; withdrawal or supersession; material legal change; identified citation defect.
DistributionPublic — Website and GitHub

Foreword

GAISSF relies on transparent, controlled use of external standards, threat knowledge, regulatory instruments and technical guidance. This bibliography provides a single register for those sources, defines how GAISSF documents shall cite them, and distinguishes authoritative source material from contextual or implementation-oriented references.

1. Purpose and Scope

This document establishes the controlled bibliography for GAISSF v1.0. It applies to normative, informative, technical, regulatory, sector, threat-intelligence, assurance and implementation references used across the GAISSF ecosystem.

It is not a crosswalk and does not assert one-to-one equivalence between GAISSF controls and external provisions. Detailed mappings shall be maintained in separately controlled crosswalk artifacts.

2. Conformance Language

SHALL, SHALL NOT, SHOULD, SHOULD NOT, MAY and RECOMMENDED have the meanings established in GAISSF-NOR-005. Normative requirements in this document govern citation management and reference maintenance, not the substantive obligations of third-party publications.

3. Source Classification Model

TierSource classUse in GAISSFMinimum handling
T1Primary authoritativeLaw, regulation, official standard, official government or standards-body publicationUse exact title, identifier, issuer, edition/date and official location.
T2Primary technical authorityOfficial threat framework, security project, regulator guidance, official technical specificationRecord version/date and scope; avoid implying legal or certification equivalence.
T3Peer-reviewed or institutional researchAcademic paper, recognized research institute, intergovernmental reportRecord authors, venue, year and DOI or stable identifier where available.
T4Implementation referenceTool documentation, vendor-neutral practice guide, open-source projectUse for implementation examples only; do not elevate to normative authority.
T5Contextual evidenceIndustry survey, incident report, market or loss dataState methodology and limitations; time-bound quantitative claims.

4. Citation and Reference Requirements

  1. Each externally derived normative proposition SHALL identify a controlled source or be explicitly labelled as an ODA3 Institute requirement.
  2. Citations SHALL use the reference identifier assigned in this document where one exists.
  3. References SHALL identify the edition, version, publication date or access date needed to disambiguate the source.
  4. Withdrawn or superseded sources SHALL NOT be silently cited as current.
  5. References to laws and regulations SHALL identify jurisdiction and instrument number where available.
  6. Cross-framework mappings SHALL distinguish alignment, partial coverage, dependency and non-equivalence.
  7. Internet locations SHOULD use persistent official pages rather than third-party mirrors.
  8. Quantitative claims SHALL state the reporting period and source limitations.
  9. Where no source supports a claim, the document SHALL record that absence rather than infer authority.

5. Reference-Identifier Syntax

The controlled format is GAISSF-REF-[CLASS]-NNN, where CLASS identifies the source family.

ClassMeaningExample
ISOISO or ISO/IEC publicationGAISSF-REF-ISO-001
IECIEC publicationGAISSF-REF-IEC-001
NISTNIST publicationGAISSF-REF-NIST-001
OWASPOWASP project or publicationGAISSF-REF-OWASP-001
MITREMITRE publication or knowledge baseGAISSF-REF-MITRE-001
CISCenter for Internet Security publicationGAISSF-REF-CIS-001
REGLaw or regulationGAISSF-REF-REG-001
GOVGovernment or regulator guidanceGAISSF-REF-GOV-001
RESResearch or institutional reportGAISSF-REF-RES-001
TOOLImplementation or open-source referenceGAISSF-REF-TOOL-001

6. Controlled Bibliography

ISO and ISO/IEC standards

GAISSF-REF-ISO-001. ISO/IEC 42001:2023. Information technology — Artificial intelligence — Management system. Source tier: T1. GAISSF use: D6, D8; governance and management-system context.

GAISSF-REF-ISO-002. ISO/IEC 23894:2023. Information technology — Artificial intelligence — Guidance on risk management. Source tier: T1. GAISSF use: D6, D8; AI risk management.

GAISSF-REF-ISO-003. ISO/IEC 22989:2022. Artificial intelligence — Artificial intelligence concepts and terminology. Source tier: T1. GAISSF use: NOR-005 terminology support.

GAISSF-REF-ISO-004. ISO/IEC 23053:2022. Framework for Artificial Intelligence systems using machine learning. Source tier: T1. GAISSF use: Architecture and lifecycle context.

GAISSF-REF-ISO-005. ISO/IEC 24027:2021. Bias in AI systems and AI aided decision making. Source tier: T1. GAISSF use: D7; bias and harmful-output assurance.

GAISSF-REF-ISO-006. ISO/IEC TR 24028:2020. Overview of trustworthiness in artificial intelligence. Source tier: T1. GAISSF use: Cross-domain trustworthiness context.

GAISSF-REF-ISO-007. ISO/IEC 24029-1:2021. Assessment of the robustness of neural networks — Part 1: Overview. Source tier: T1. GAISSF use: D1, D2, D7; robustness validation.

GAISSF-REF-ISO-008. ISO/IEC 27001:2022. Information security management systems — Requirements. Source tier: T1. GAISSF use: D1-D6, D8; ISMS integration.

GAISSF-REF-ISO-009. ISO/IEC 27002:2022. Information security controls. Source tier: T1. GAISSF use: Security-control implementation context.

GAISSF-REF-ISO-010. ISO/IEC 27005:2022. Guidance on managing information security risks. Source tier: T1. GAISSF use: D8; risk assessment and treatment.

GAISSF-REF-ISO-011. ISO/IEC 27017:2015. Information security controls for cloud services. Source tier: T1. GAISSF use: D3, D5; cloud and supplier controls.

GAISSF-REF-ISO-012. ISO/IEC 27018:2019. Protection of personally identifiable information in public clouds. Source tier: T1. GAISSF use: D5; privacy and cloud processing.

GAISSF-REF-ISO-013. ISO/IEC 27701:2019. Privacy information management — Extension to ISO/IEC 27001 and ISO/IEC 27002. Source tier: T1. GAISSF use: D5; privacy governance.

GAISSF-REF-ISO-014. ISO/IEC 38507:2022. Governance implications of the use of artificial intelligence by organizations. Source tier: T1. GAISSF use: D6; governing-body oversight.

GAISSF-REF-ISO-015. ISO/IEC 42005:2025. Artificial intelligence system impact assessment. Source tier: T1. GAISSF use: D6-D8; impact-assessment context.

GAISSF-REF-ISO-016. ISO/IEC 42006:2025. Requirements for bodies providing audit and certification of artificial intelligence management systems. Source tier: T1. GAISSF use: Certification-scheme design context.

GAISSF-REF-ISO-017. ISO/IEC 5259 series. Data quality for analytics and machine learning. Source tier: T1. GAISSF use: D1, D4, D5; data quality and provenance.

GAISSF-REF-ISO-018. ISO/IEC 5338:2023. AI system life cycle processes. Source tier: T1. GAISSF use: framework lifecycle governance.

GAISSF-REF-ISO-019. ISO 31000:2018. Risk management — Guidelines. Source tier: T1. GAISSF use: Enterprise risk integration.

GAISSF-REF-ISO-020. ISO 19011:2018. Guidelines for auditing management systems. Source tier: T1. GAISSF use: Assessment methodology.

GAISSF-REF-ISO-021. ISO/IEC 17021-1:2015. Requirements for bodies providing audit and certification of management systems. Source tier: T1. GAISSF use: Certification governance context.

GAISSF-REF-ISO-022. ISO/IEC 17065:2012. Requirements for bodies certifying products, processes and services. Source tier: T1. GAISSF use: Product/process certification boundary.

GAISSF-REF-ISO-023. ISO/IEC 17025:2017. General requirements for competence of testing and calibration laboratories. Source tier: T1. GAISSF use: Testing competence context.

IEC and safety standards

GAISSF-REF-IEC-001. IEC 61508 series. Functional safety of electrical/electronic/programmable electronic safety-related systems. Source tier: T1. GAISSF use: D9; physical-AI functional safety.

GAISSF-REF-IEC-002. IEC 62443 series. Security for industrial automation and control systems. Source tier: T1. GAISSF use: D3, D9; OT and cyber-physical security.

GAISSF-REF-IEC-003. IEC 62304:2006+A1:2015. Medical device software — Software life cycle processes. Source tier: T1. GAISSF use: Healthcare sector tailoring.

GAISSF-REF-IEC-004. IEC 62061:2021. Safety of machinery — Functional safety of safety-related control systems. Source tier: T1. GAISSF use: D9; machinery safety.

GAISSF-REF-IEC-005. IEC 60601-1. Medical electrical equipment — General requirements for basic safety and essential performance. Source tier: T1. GAISSF use: Healthcare physical-AI context.

GAISSF-REF-IEC-006. IEC 60601-1-8. Alarm systems in medical electrical equipment and systems. Source tier: T1. GAISSF use: Human oversight and alerting context.

GAISSF-REF-ISO-024. ISO 26262 series. Road vehicles — Functional safety. Source tier: T1. GAISSF use: Automotive sector tailoring.

GAISSF-REF-ISO-025. ISO 21448:2022. Road vehicles — Safety of the intended functionality. Source tier: T1. GAISSF use: Autonomous and assisted-driving context.

GAISSF-REF-ISO-026. ISO 14971:2019. Medical devices — Application of risk management to medical devices. Source tier: T1. GAISSF use: Healthcare risk management.

NIST publications

GAISSF-REF-NIST-001. NIST AI 100-1. Artificial Intelligence Risk Management Framework (AI RMF 1.0), 2023. Source tier: T1. GAISSF use: AI risk-management crosswalk.

GAISSF-REF-NIST-002. NIST AI 600-1. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, 2024. Source tier: T1. GAISSF use: Generative-AI risk context.

GAISSF-REF-NIST-003. NIST Cybersecurity Framework 2.0. The NIST Cybersecurity Framework (CSF) 2.0, 2024. Source tier: T1. GAISSF use: Cybersecurity governance and outcomes.

GAISSF-REF-NIST-004. NIST SP 800-53 Rev. 5. Security and Privacy Controls for Information Systems and Organizations. Source tier: T1. GAISSF use: Control mapping and assurance.

GAISSF-REF-NIST-005. NIST SP 800-218. Secure Software Development Framework (SSDF). Source tier: T1. GAISSF use: D1-D4; secure development.

GAISSF-REF-NIST-006. NIST SP 800-218A. Secure Software Development Practices for Generative AI and Dual-Use Foundation Models. Source tier: T1. GAISSF use: AI-specific software development.

GAISSF-REF-NIST-007. NIST SP 800-161 Rev. 1. Cybersecurity Supply Chain Risk Management Practices. Source tier: T1. GAISSF use: D3; supply-chain risk.

GAISSF-REF-NIST-008. NIST SP 800-61 Rev. 2. Computer Security Incident Handling Guide. Source tier: T1. GAISSF use: D6; incident response.

GAISSF-REF-NIST-009. NIST SP 800-207. Zero Trust Architecture. Source tier: T1. GAISSF use: D3, D5; access architecture.

GAISSF-REF-NIST-010. NIST SP 800-30 Rev. 1. Guide for Conducting Risk Assessments. Source tier: T1. GAISSF use: D8; assessment methodology.

GAISSF-REF-NIST-011. NIST SP 800-37 Rev. 2. Risk Management Framework for Information Systems and Organizations. Source tier: T1. GAISSF use: Governance and authorization.

GAISSF-REF-NIST-012. NIST SP 800-115. Technical Guide to Information Security Testing and Assessment. Source tier: T1. GAISSF use: Assessment and testing.

GAISSF-REF-NIST-013. NIST SP 800-88 Rev. 1. Guidelines for Media Sanitization. Source tier: T1. GAISSF use: D5; data disposal.

GAISSF-REF-NIST-014. NISTIR 8286 series. Integrating Cybersecurity and Enterprise Risk Management. Source tier: T1. GAISSF use: Enterprise risk integration.

GAISSF-REF-NIST-015. NIST OSCAL. Open Security Controls Assessment Language. Source tier: T2. GAISSF use: Machine-readable control and evidence exchange.

Threat and security frameworks

GAISSF-REF-MITRE-001. MITRE ATLAS. Adversarial Threat Landscape for Artificial-Intelligence Systems knowledge base. Source tier: T2. GAISSF use: Related threats across D1-D9.

GAISSF-REF-MITRE-002. MITRE ATT&CK. Enterprise adversary tactics and techniques knowledge base. Source tier: T2. GAISSF use: Enterprise threat context.

GAISSF-REF-OWASP-001. OWASP Top 10 for Large Language Model Applications. Current controlled edition used by the applicable GAISSF crosswalk. Source tier: T2. GAISSF use: LLM application risks.

GAISSF-REF-OWASP-002. OWASP Top 10 for Agentic Applications. Current controlled edition used by the applicable GAISSF crosswalk. Source tier: T2. GAISSF use: Agentic-AI risks.

GAISSF-REF-OWASP-003. OWASP AI Security and Privacy Guide. Community guidance for AI security and privacy engineering. Source tier: T2. GAISSF use: Implementation context.

GAISSF-REF-OWASP-004. OWASP Application Security Verification Standard. Application-security verification requirements. Source tier: T2. GAISSF use: D1-D4; application assurance.

GAISSF-REF-OWASP-005. OWASP Software Assurance Maturity Model. Software-assurance maturity practices. Source tier: T2. GAISSF use: Maturity guidance.

GAISSF-REF-CIS-001. CIS Critical Security Controls v8.1. Prioritized cybersecurity safeguards. Source tier: T2. GAISSF use: Baseline cybersecurity mapping.

GAISSF-REF-CIS-002. CIS Benchmarks. Technology-specific secure-configuration guidance. Source tier: T2. GAISSF use: Implementation and hardening.

GAISSF-REF-RES-001. Cloud Security Alliance AI Controls Matrix. AI-focused cloud control mapping and assurance guidance. Source tier: T2. GAISSF use: Cloud-AI assurance context.

European Union legal and regulatory instruments

GAISSF-REF-REG-001. Regulation (EU) 2024/1689. Artificial Intelligence Act. Source tier: T1. GAISSF use: Cross-domain regulatory context.

GAISSF-REF-REG-002. Regulation (EU) 2016/679. General Data Protection Regulation (GDPR). Source tier: T1. GAISSF use: D5, D6, D8.

GAISSF-REF-REG-003. Regulation (EU) 2022/2554. Digital Operational Resilience Act (DORA). Source tier: T1. GAISSF use: Financial-sector resilience.

GAISSF-REF-REG-004. Directive (EU) 2022/2555. NIS 2 Directive. Source tier: T1. GAISSF use: Cybersecurity governance and reporting.

GAISSF-REF-REG-005. Regulation (EU) 2024/2847. Cyber Resilience Act. Source tier: T1. GAISSF use: Products with digital elements.

GAISSF-REF-REG-006. Regulation (EU) 2023/2854. Data Act. Source tier: T1. GAISSF use: Data access and use.

GAISSF-REF-REG-007. Regulation (EU) 2022/868. Data Governance Act. Source tier: T1. GAISSF use: Data governance.

GAISSF-REF-REG-008. Regulation (EU) 2019/881. EU Cybersecurity Act. Source tier: T1. GAISSF use: Cybersecurity certification context.

GAISSF-REF-REG-009. Regulation (EU) 2017/745. Medical Device Regulation. Source tier: T1. GAISSF use: Healthcare sector.

GAISSF-REF-REG-010. Directive 2002/58/EC. ePrivacy Directive, as amended. Source tier: T1. GAISSF use: Privacy and communications.

Selected national and sector sources

GAISSF-REF-GOV-001. United States Executive Order 14110. Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, 2023. Source tier: T1. GAISSF use: US federal policy context.

GAISSF-REF-GOV-002. OMB Memorandum M-24-10. Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence. Source tier: T1. GAISSF use: US federal implementation.

GAISSF-REF-GOV-003. U.S. FDA guidance and action plans for AI/ML-enabled medical devices. Official FDA materials applicable to the assessed product and date. Source tier: T1. GAISSF use: Healthcare sector.

GAISSF-REF-GOV-004. UK AI Regulation White Paper and regulator guidance. Official UK government and regulator publications applicable to the assessed context. Source tier: T1. GAISSF use: UK cross-jurisdictional context.

GAISSF-REF-GOV-005. Singapore Model AI Governance Framework. Official IMDA/PDPC framework and implementation guidance. Source tier: T1. GAISSF use: APAC governance context.

GAISSF-REF-GOV-006. ASEAN Guide on AI Governance and Ethics. Regional AI governance guidance. Source tier: T1. GAISSF use: Southeast Asia context.

GAISSF-REF-GOV-007. OECD Recommendation of the Council on Artificial Intelligence. OECD/LEGAL/0449, as amended. Source tier: T1. GAISSF use: International principles.

GAISSF-REF-GOV-008. UNESCO Recommendation on the Ethics of Artificial Intelligence. Adopted 2021. Source tier: T1. GAISSF use: International ethics context.

GAISSF-REF-GOV-009. Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law. CETS No. 225, 2024. Source tier: T1. GAISSF use: International legal context.

Internal GAISSF controlled sources

GAISSF-REF-INT-001. GAISSF-NOR-001. GAISSF™ v1.0 — Global AI Security & Safety Framework. Source tier: T1. GAISSF use: Authoritative normative source.

GAISSF-REF-INT-002. GAISSF-NOR-002. GAISSF™ v1.0 Executive Summary. Source tier: T1. GAISSF use: Executive interpretation.

GAISSF-REF-INT-003. GAISSF-NOR-003. GAISSF™ v1.0 Quick Start Guide. Source tier: T1. GAISSF use: Implementation onboarding.

GAISSF-REF-INT-004. GAISSF-NOR-004. GAISSF™ v1.0 Control Catalogue. Source tier: T1. GAISSF use: 59-control library.

GAISSF-REF-INT-005. GAISSF-NOR-005. GAISSF™ v1.0 Glossary. Source tier: T1. GAISSF use: Controlled terminology.

GAISSF-REF-INT-006. GAISSF VTS v1.0. Validation Test Suite and associated controlled schemas. Source tier: T1. GAISSF use: Machine-executable validation.

GAISSF-REF-INT-007. GAISSF Editorial Decision Log MTH-GOV-034. Foundational-tier reconciliation and preservation of the 59-control baseline. Source tier: T1. GAISSF use: Editorial provenance.

7. Citation Forms

Use caseRequired formExample
First citationReference ID + issuer/title + edition/dateGAISSF-REF-NIST-001, NIST AI RMF 1.0 (2023)
Subsequent citationReference IDGAISSF-REF-NIST-001
Specific provisionReference ID + clause/article/page or controlGAISSF-REF-REG-001, Article 15
Framework mappingGAISSF control + relationship + source locationD3-CTL-03 — partial alignment — GAISSF-REF-NIST-007
Web-only sourceIssuer, page title, publication/update date and access dateUse only where no stable publication identifier exists

8. Reference-to-Domain Index

GAISSF domainPrimary reference familiesNotably absent
D1 — Model and Data IntegrityISO/IEC 5259, ISO/IEC 24029-1, NIST SSDF, MITRE ATLASNo source is treated as a universal robustness threshold.
D2 — Adversarial RobustnessMITRE ATLAS, OWASP LLM/Agentic, NIST testing guidanceThreat catalogues do not prove control effectiveness.
D3 — Secure Architecture and Supply ChainNIST SP 800-161, IEC 62443, CIS, OWASPMappings do not establish supplier compliance.
D4 — Secure Development and DeploymentNIST SSDF, ISO/IEC 5338, OWASP ASVS/SAMMTool use alone is not conformance evidence.
D5 — Data Protection and PrivacyGDPR, ISO/IEC 27701, ISO/IEC 27018No universal lawful basis or retention period is prescribed.
D6 — Governance, Oversight and Incident ManagementISO/IEC 42001, ISO/IEC 38507, NIST AI RMFCertification does not transfer accountability.
D7 — Transparency, Human Factors and Content SafetyISO/IEC 24027, UNESCO, OECD, OWASPNo universal fairness or content-safety metric is asserted.
D8 — Risk, Assurance and Continuous ImprovementISO 31000, ISO 19011, NIST RMF/ERM guidanceMaturity does not substitute for conformance.
D9 — Physical AI SafetyIEC 61508, IEC 62443, ISO 26262, ISO 21448GAISSF does not replace sector safety approval.

9. Reference Maintenance and Change Control

  1. The Bibliography Custodian SHALL review reference status at least annually and before each major GAISSF release.
  2. A source revision SHALL be assessed for semantic impact before the controlled edition is changed.
  3. Superseded references MAY remain listed for historical traceability but SHALL be marked superseded.
  4. Broken links SHALL be replaced with an official persistent location where available.
  5. Changes affecting mappings, controls, certification criteria or legal interpretation SHALL trigger downstream impact analysis.
  6. Reference identifiers SHALL NOT be reassigned to unrelated publications.

10. Limitations

This bibliography is a controlled source register, not a legal opinion, exhaustive literature review or declaration of formal equivalence. Standards and regulatory instruments evolve. Access restrictions may prevent public reproduction of source text. Language translations, national adoptions and consolidated legal texts may differ.

11. Notably Absent

  • No claim that any cited organization endorses or recognizes GAISSF.
  • No claim that GAISSF certification satisfies a cited certification, accreditation or conformity-assessment scheme.
  • No automatic one-to-one equivalence between a GAISSF control and an external clause.
  • No reproduction of complete copyrighted standards.
  • No universal jurisdictional applicability determination.
  • No guarantee that the list is exhaustive for every sector, technology or deployment.
  • No reliance on unsourced market claims as normative authority.

Annex A — Reference Record Template

FieldRequired content
Reference IDPermanent GAISSF identifier
IssuerOfficial issuing body
TitleExact publication title
IdentifierStandard, report, regulation or instrument number
Edition/versionControlled edition or revision
Publication dateOfficial date
StatusCurrent, superseded, withdrawn or historical
Source tierT1-T5
Official locationPersistent official URL or catalogue location
GAISSF useDomains, controls or artifact purposes
Mapping statusNone, contextual, partial, substantial or dependency
LimitationsKnown scope, access, edition or evidentiary limitations
Last verifiedDate and verifier

Annex B — Citation Review Checklist

☐ Source is official or its authority is explicitly qualified.

☐ Exact identifier and edition are recorded.

☐ Publication status has been checked.

☐ Claim does not exceed what the source supports.

☐ Legal applicability is not inferred from citation alone.

☐ Mapping type and limitations are stated.

☐ Third-party marks are used for identification only.

☐ Quantitative data includes period and methodology limits.

☐ Superseded references are labelled.

☐ Downstream documents use the same reference identifier.

Annex C — Publication Record

VersionDateChangeApproval status
1.01 July 2026Initial controlled bibliography for the GAISSF v1.0, 59-control ecosystem.Final Publication v1.0

Controlled Profile Reconciliation Notice

The Foundational profile comprises the 52 canonical controls in D1-D8. The seven D9 controls are additional mandatory controls whenever physical AI or cyber-physical actuation is within the assessed scope.

Any earlier wording that described the Foundational profile as spanning all nine domains, or that treated D9 as universally mandatory or universally excluded, is superseded by this statement. D9 applicability shall be determined and justified for every assessed scope.

Source Verification Procedure

  • Verify title, issuer, edition and publication status against an official source.
  • Record access restrictions and whether the source is normative, informative or contextual.
  • Check that the claim made in GAISSF does not exceed the source.
  • Reverify time-sensitive legal and regulatory sources before each release.

Citation Quality Controls

RiskRequired control
Superseded editionRecord status and migration impact.
Copyright overreachCite without reproducing protected text.
False equivalenceDescribe relationship and limitations.
Broken linkUse persistent official location or catalogue identifier.
Unsupported quantitative claimState period, methodology and limitations.

Publication Completeness and Intended Use

This full publication edition of GAISSF-NOR-006 is designed to stand on its own for its stated role: controlled bibliography, citation method and source-transparency register. It includes purpose, scope, governance, operating guidance, evidence expectations, limitations, decision criteria and reusable records appropriate to that role.

Completeness does not mean that the document replaces the normative control statements, applicable law, sector-specific engineering, organizational procedures or professional judgement. Cross-referenced GAISSF documents remain part of the controlled document system.

Completeness dimensionTreatment in this edition
Normative alignmentReconciled to the authoritative 59-control baseline and controlled profile structure.
Operational usabilityIncludes roles, workflows, gates, evidence, metrics, escalation and examples where relevant.
TraceabilityIdentifies dependencies and preserves the distinction between requirements, guidance and examples.
LimitationsStates what the document does not establish or guarantee.
MaintenanceIncludes review triggers, change control and publication status.

Source-Tier Distinction and Selected India Sources

The T1-T5 source tiers in this bibliography classify the authority and proximity of external and controlled references. They do not classify the sufficiency, reliability, independence, or operating effectiveness of evidence submitted for assessment.

GAISSF-REF-IND-001. Government of India, The Digital Personal Data Protection Act, 2023, Act No. 22 of 2023, as published through India Code and subsequent official notifications. GAISSF use: Indian digital-personal-data legal context. Current commencement and implementing instruments shall be verified before reliance.

GAISSF-REF-IND-002. Indian Computer Emergency Response Team (CERT-In), Directions relating to information security practices, procedure, prevention, response and reporting of cyber incidents, issued under section 70B of the Information Technology Act, 2000, 28 April 2022, including applicable official updates and FAQs. GAISSF use: Indian incident reporting, logging, time synchronization, and service-provider context.

GAISSF-REF-IND-003. Bureau of Indian Standards, official standards catalogue and Artificial Intelligence standardization work programme. GAISSF use: discovery and verification of published Indian Standards relevant to AI; no unpublished, draft, or unspecified BIS item is treated as a normative GAISSF source.