GAISSF / D2
Runtime Security & Adversarial Defense
Domain purpose
Controls and requirements
D2-CTL-01Direct Prompt Injection Prevention
Prevent unauthorized system prompt override or instruction hijacking.
D2-CTL-02Indirect Prompt Injection Prevention
Block malicious instructions injected via RAG, APIs, or external data sources.
D2-CTL-03Jailbreak Resistance Testing
Validate safety guardrails against evolving adversarial prompt techniques.
D2-CTL-04Multi-Modal Injection Defense
Prevent hidden commands embedded in images, audio, or video from executing.
D2-CTL-05Function Call/Tool Call Injection Prevention
Secure structured tool/function parameters from adversarial manipulation.
D2-CTL-06Cross-Context Hijacking Mitigation
Prevent system prompt dilution or override in long-context windows.
Implementation use
Determine applicability using the framework scope and system context. Implementation should be proportionate to risk and supported by evidence sufficient to validate the intended outcome.