{
  "document": {
    "id": "GAISSF-CRO-024",
    "title": "GAISSF™–OWASP Top 10 for LLM Applications 2025 Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "classification": "Informative crosswalk / public",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "candidate_date": "2026-06-29",
    "updated": "2026-10-05"
  },
  "source_baseline": {
    "gaissf": {
      "framework": "GAISSF-NOR-001 v1.0",
      "control_catalogue": "GAISSF-NOR-004 v1.0",
      "controls": 59,
      "domains": 9,
      "applicable_control_baseline": "52 D1-D8 + applicable D9"
    },
    "owasp": {
      "title": "OWASP Top 10 for LLM Applications",
      "edition": "2025",
      "publication_date": "2024-11-17",
      "note": "Edition-bound crosswalk. OWASP released a 2026 edition in August 2026; separate revalidation is required."
    },
    "scope_note": "Correspondence only; no endorsement, equivalence, evidence sufficiency, vulnerability absence, automatic conformance, legal compliance, certification, or operating-effectiveness conclusion."
  },
  "controlled_vocabulary": {
    "relationship": {
      "SP": "Strong partial",
      "P": "Partial",
      "S": "Supporting",
      "N": "No material relationship",
      "O": "Outside scope",
      "U": "Unable to determine"
    },
    "confidence": [
      "High",
      "Medium-High",
      "Medium",
      "Medium-Low",
      "Low",
      "Not Rated"
    ]
  },
  "statistics": {
    "gaissf_controls": 59,
    "owasp_risks": 10,
    "control_assessment_records": 59,
    "positive_relationships": 44,
    "no_material_relationships": 3,
    "outside_scope": 12,
    "reverse_records": 10
  },
  "limitations": [
    "Mapping is not OWASP endorsement, certification, equivalence, evidence sufficiency, vulnerability absence, automatic conformance, legal compliance, or proof of secure implementation.",
    "OWASP Top 10 is a prioritized risk-awareness resource, not a complete security standard or exhaustive threat catalogue.",
    "GAISSF controls can support multiple risks; actual mitigation depends on architecture, implementation, testing, monitoring, and evidence.",
    "D9 mappings are additional/conditional and apply only where Physical AI or cyber-physical actuation is in scope.",
    "The 2025 OWASP edition is frozen as the mapping target for this document; the 2026 edition requires separate revalidation."
  ],
  "gaissf_controls": [
    {
      "id": "D1-CTL-01",
      "title": "Dataset Provenance & Poisoning Prevention",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D1-CTL-02",
      "title": "Model Extraction Resistance",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D1-CTL-03",
      "title": "Behavioral Drift Detection",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D1-CTL-04",
      "title": "Federated Learning Poisoning Prevention",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D1-CTL-05",
      "title": "Embedding Space Robustness",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D1-CTL-06",
      "title": "Post-Quantum Model Signing & Crypto Hardening",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D1-CTL-07",
      "title": "Lora/Adapter Integrity Verification",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D1-CTL-08",
      "title": "Model Merge Attack Detection",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D1-CTL-09",
      "title": "Quantization Backdoor Screening",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D2-CTL-01",
      "title": "Direct Prompt Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D2-CTL-02",
      "title": "Indirect Prompt Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D2-CTL-03",
      "title": "Jailbreak Resistance Testing",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D2-CTL-04",
      "title": "Multi-Modal Injection Defense",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D2-CTL-05",
      "title": "Function Call/Tool Call Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D2-CTL-06",
      "title": "Cross-Context Hijacking Mitigation",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D3-CTL-01",
      "title": "Least Agency Enforcement",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D3-CTL-02",
      "title": "Inter-Agent Communication Security",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D3-CTL-03",
      "title": "Agentic Prompt Chaining Detection",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D3-CTL-04",
      "title": "Embodied Ai Safety Controls",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D3-CTL-05",
      "title": "Multi-Agent Trust Chain Attestation",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D3-CTL-06",
      "title": "Persistent Memory Exfiltration Prevention",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D3-CTL-07",
      "title": "Secure Memory Lifecycle Management",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D4-CTL-01",
      "title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D4-CTL-02",
      "title": "Model File & Artifact Scanning",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D4-CTL-03",
      "title": "Model Hub & Registry Vetting",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D4-CTL-04",
      "title": "Mcp Server Behavioral Monitoring",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D4-CTL-05",
      "title": "Third-Party Ai Api Security Assessment",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D4-CTL-06",
      "title": "Shadow Ai Discovery & Governance",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D4-CTL-07",
      "title": "Ai Software Composition Analysis (Sca)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D5-CTL-01",
      "title": "Harmful Content Blocking",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D5-CTL-02",
      "title": "Pii Leakage Prevention",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D5-CTL-03",
      "title": "Copyright Detection",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D5-CTL-04",
      "title": "Ai Watermarking Robustness",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D5-CTL-05",
      "title": "Privacy-By-Design Verification",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D5-CTL-06",
      "title": "Privacy-Preserving Ml Validation",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D6-CTL-01",
      "title": "Human-In-The-Loop For High-Risk Actions",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D6-CTL-02",
      "title": "Audit Trail Completeness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D6-CTL-03",
      "title": "Ai Model Card Completeness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D6-CTL-04",
      "title": "Ai Incident Response Readiness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D6-CTL-05",
      "title": "Model Deprecation & Decommissioning",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D6-CTL-06",
      "title": "Third-Party Ai Vendor Governance",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D6-CTL-07",
      "title": "Ai Resilience & Business Continuity",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D7-CTL-H01",
      "title": "Ai-Generated Phishing Simulation",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D7-CTL-H02",
      "title": "Deepfake Detection Training",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D7-CTL-H03",
      "title": "Out-Of-Band Authentication",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D7-CTL-H04",
      "title": "Ai Social Engineering Ir",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D7-CTL-H05",
      "title": "Ai-Enhanced External Attack Defense",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D8-CTL-01",
      "title": "Eu Ai Act Risk Tier Mapping",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D8-CTL-02",
      "title": "Iso 42001 Gap Analysis",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D8-CTL-03",
      "title": "Gpai Technical Documentation Verification",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D8-CTL-04",
      "title": "Dora Ict Incident Reporting (Financial Sector)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D8-CTL-05",
      "title": "Nist Sp 800-218A Compliance Check",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "baseline_membership": "Canonical D1-D8 baseline",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D9-CTL-01",
      "title": "Physical Harm Boundary Enforcement",
      "domain": "D9: PHYSICAL AI SAFETY",
      "baseline_membership": "Additional / conditional",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D9-CTL-02",
      "title": "Safe State And Graceful Degradation",
      "domain": "D9: PHYSICAL AI SAFETY",
      "baseline_membership": "Additional / conditional",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D9-CTL-03",
      "title": "Human Override And Emergency Stop",
      "domain": "D9: PHYSICAL AI SAFETY",
      "baseline_membership": "Additional / conditional",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D9-CTL-04",
      "title": "Cyber-Physical Attack Detection",
      "domain": "D9: PHYSICAL AI SAFETY",
      "baseline_membership": "Additional / conditional",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D9-CTL-05",
      "title": "Physical Environment Integrity Monitoring",
      "domain": "D9: PHYSICAL AI SAFETY",
      "baseline_membership": "Additional / conditional",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D9-CTL-06",
      "title": "Actuator Command Verification",
      "domain": "D9: PHYSICAL AI SAFETY",
      "baseline_membership": "Additional / conditional",
      "source": "GAISSF-NOR-004 v1.0"
    },
    {
      "id": "D9-CTL-07",
      "title": "Physical Incident Evidence Preservation",
      "domain": "D9: PHYSICAL AI SAFETY",
      "baseline_membership": "Additional / conditional",
      "source": "GAISSF-NOR-004 v1.0"
    }
  ],
  "owasp_llm_top_10_2025": [
    {
      "id": "LLM01:2025",
      "title": "Prompt Injection",
      "summary": "Crafted direct or indirect inputs can alter model behavior, bypass instructions, expose data, or trigger unauthorized actions."
    },
    {
      "id": "LLM02:2025",
      "title": "Sensitive Information Disclosure",
      "summary": "Models and applications can reveal confidential, personal, proprietary, credential, or otherwise sensitive information."
    },
    {
      "id": "LLM03:2025",
      "title": "Supply Chain",
      "summary": "Compromised models, datasets, components, services, dependencies, or provenance can undermine application security and integrity."
    },
    {
      "id": "LLM04:2025",
      "title": "Data and Model Poisoning",
      "summary": "Manipulated pre-training, fine-tuning, retrieval, embedding, or model data can introduce backdoors, bias, unsafe behavior, or integrity failures."
    },
    {
      "id": "LLM05:2025",
      "title": "Improper Output Handling",
      "summary": "Insufficient validation, sanitization, encoding, or contextual handling of model outputs can create downstream exploits."
    },
    {
      "id": "LLM06:2025",
      "title": "Excessive Agency",
      "summary": "Excessive functionality, permissions, autonomy, or insufficient human approval can allow harmful or unintended actions."
    },
    {
      "id": "LLM07:2025",
      "title": "System Prompt Leakage",
      "summary": "System prompts or embedded instructions may be exposed and reveal sensitive logic, controls, or operational context."
    },
    {
      "id": "LLM08:2025",
      "title": "Vector and Embedding Weaknesses",
      "summary": "Weaknesses in retrieval, vector stores, embeddings, access controls, segmentation, and data provenance can cause disclosure or manipulation."
    },
    {
      "id": "LLM09:2025",
      "title": "Misinformation",
      "summary": "Incorrect, fabricated, misleading, or insufficiently verified model outputs can undermine decisions and safety."
    },
    {
      "id": "LLM10:2025",
      "title": "Unbounded Consumption",
      "summary": "Uncontrolled model, token, tool, compute, or service consumption can cause denial of service, cost escalation, degradation, or theft-related abuse."
    }
  ],
  "gaissf_to_owasp_mappings": [
    {
      "record_id": "GAISSF-CRO-024-MAP-0001",
      "gaissf_control_id": "D1-CTL-01",
      "gaissf_control_title": "Dataset Provenance & Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM04:2025",
      "owasp_risk_title": "Data and Model Poisoning",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D1-CTL-01 Dataset Provenance & Poisoning Prevention has an outcome-level relationship to LLM04:2025 Data and Model Poisoning. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0002",
      "gaissf_control_id": "D1-CTL-02",
      "gaissf_control_title": "Model Extraction Resistance",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM10:2025",
      "owasp_risk_title": "Unbounded Consumption",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Low",
      "rationale": "D1-CTL-02 Model Extraction Resistance has an outcome-level relationship to LLM10:2025 Unbounded Consumption. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0003",
      "gaissf_control_id": "D1-CTL-03",
      "gaissf_control_title": "Behavioral Drift Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM09:2025",
      "owasp_risk_title": "Misinformation",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Medium-Low",
      "rationale": "D1-CTL-03 Behavioral Drift Detection has an outcome-level relationship to LLM09:2025 Misinformation. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0004",
      "gaissf_control_id": "D1-CTL-04",
      "gaissf_control_title": "Federated Learning Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM04:2025",
      "owasp_risk_title": "Data and Model Poisoning",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D1-CTL-04 Federated Learning Poisoning Prevention has an outcome-level relationship to LLM04:2025 Data and Model Poisoning. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0005",
      "gaissf_control_id": "D1-CTL-05",
      "gaissf_control_title": "Embedding Space Robustness",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM08:2025",
      "owasp_risk_title": "Vector and Embedding Weaknesses",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D1-CTL-05 Embedding Space Robustness has an outcome-level relationship to LLM08:2025 Vector and Embedding Weaknesses. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0006",
      "gaissf_control_id": "D1-CTL-06",
      "gaissf_control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Medium",
      "rationale": "D1-CTL-06 Post-Quantum Model Signing & Crypto Hardening has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0007",
      "gaissf_control_id": "D1-CTL-07",
      "gaissf_control_title": "Lora/Adapter Integrity Verification",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM04:2025",
      "owasp_risk_title": "Data and Model Poisoning",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-07 Lora/Adapter Integrity Verification has an outcome-level relationship to LLM04:2025 Data and Model Poisoning. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0008",
      "gaissf_control_id": "D1-CTL-08",
      "gaissf_control_title": "Model Merge Attack Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM04:2025",
      "owasp_risk_title": "Data and Model Poisoning",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium",
      "rationale": "D1-CTL-08 Model Merge Attack Detection has an outcome-level relationship to LLM04:2025 Data and Model Poisoning. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0009",
      "gaissf_control_id": "D1-CTL-09",
      "gaissf_control_title": "Quantization Backdoor Screening",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "owasp_risk_id": "LLM04:2025",
      "owasp_risk_title": "Data and Model Poisoning",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-09 Quantization Backdoor Screening has an outcome-level relationship to LLM04:2025 Data and Model Poisoning. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0010",
      "gaissf_control_id": "D2-CTL-01",
      "gaissf_control_title": "Direct Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "owasp_risk_id": "LLM01:2025",
      "owasp_risk_title": "Prompt Injection",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D2-CTL-01 Direct Prompt Injection Prevention has an outcome-level relationship to LLM01:2025 Prompt Injection. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0011",
      "gaissf_control_id": "D2-CTL-02",
      "gaissf_control_title": "Indirect Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "owasp_risk_id": "LLM01:2025",
      "owasp_risk_title": "Prompt Injection",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D2-CTL-02 Indirect Prompt Injection Prevention has an outcome-level relationship to LLM01:2025 Prompt Injection. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0012",
      "gaissf_control_id": "D2-CTL-03",
      "gaissf_control_title": "Jailbreak Resistance Testing",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "owasp_risk_id": "LLM01:2025",
      "owasp_risk_title": "Prompt Injection",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-03 Jailbreak Resistance Testing has an outcome-level relationship to LLM01:2025 Prompt Injection. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0013",
      "gaissf_control_id": "D2-CTL-04",
      "gaissf_control_title": "Multi-Modal Injection Defense",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "owasp_risk_id": "LLM01:2025",
      "owasp_risk_title": "Prompt Injection",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-04 Multi-Modal Injection Defense has an outcome-level relationship to LLM01:2025 Prompt Injection. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0014",
      "gaissf_control_id": "D2-CTL-05",
      "gaissf_control_title": "Function Call/Tool Call Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "owasp_risk_id": "LLM01:2025",
      "owasp_risk_title": "Prompt Injection",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-05 Function Call/Tool Call Injection Prevention has an outcome-level relationship to LLM01:2025 Prompt Injection. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0015",
      "gaissf_control_id": "D2-CTL-06",
      "gaissf_control_title": "Cross-Context Hijacking Mitigation",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "owasp_risk_id": "LLM07:2025",
      "owasp_risk_title": "System Prompt Leakage",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Medium-Low",
      "rationale": "D2-CTL-06 Cross-Context Hijacking Mitigation has an outcome-level relationship to LLM07:2025 System Prompt Leakage. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0016",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D3-CTL-01 Least Agency Enforcement has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0017",
      "gaissf_control_id": "D3-CTL-02",
      "gaissf_control_title": "Inter-Agent Communication Security",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium",
      "rationale": "D3-CTL-02 Inter-Agent Communication Security has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0018",
      "gaissf_control_id": "D3-CTL-03",
      "gaissf_control_title": "Agentic Prompt Chaining Detection",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-03 Agentic Prompt Chaining Detection has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0019",
      "gaissf_control_id": "D3-CTL-04",
      "gaissf_control_title": "Embodied Ai Safety Controls",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Medium-Low",
      "rationale": "D3-CTL-04 Embodied Ai Safety Controls has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0020",
      "gaissf_control_id": "D3-CTL-05",
      "gaissf_control_title": "Multi-Agent Trust Chain Attestation",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium",
      "rationale": "D3-CTL-05 Multi-Agent Trust Chain Attestation has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0021",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "owasp_risk_id": "LLM02:2025",
      "owasp_risk_title": "Sensitive Information Disclosure",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-06 Persistent Memory Exfiltration Prevention has an outcome-level relationship to LLM02:2025 Sensitive Information Disclosure. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0022",
      "gaissf_control_id": "D3-CTL-07",
      "gaissf_control_title": "Secure Memory Lifecycle Management",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "owasp_risk_id": "LLM02:2025",
      "owasp_risk_title": "Sensitive Information Disclosure",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Medium",
      "rationale": "D3-CTL-07 Secure Memory Lifecycle Management has an outcome-level relationship to LLM02:2025 Sensitive Information Disclosure. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0023",
      "gaissf_control_id": "D4-CTL-01",
      "gaissf_control_title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D4-CTL-01 Ai Bill Of Materials (Ai Bom) Maintenance has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0024",
      "gaissf_control_id": "D4-CTL-02",
      "gaissf_control_title": "Model File & Artifact Scanning",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D4-CTL-02 Model File & Artifact Scanning has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0025",
      "gaissf_control_id": "D4-CTL-03",
      "gaissf_control_title": "Model Hub & Registry Vetting",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D4-CTL-03 Model Hub & Registry Vetting has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0026",
      "gaissf_control_id": "D4-CTL-04",
      "gaissf_control_title": "Mcp Server Behavioral Monitoring",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium",
      "rationale": "D4-CTL-04 Mcp Server Behavioral Monitoring has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0027",
      "gaissf_control_id": "D4-CTL-05",
      "gaissf_control_title": "Third-Party Ai Api Security Assessment",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D4-CTL-05 Third-Party Ai Api Security Assessment has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0028",
      "gaissf_control_id": "D4-CTL-06",
      "gaissf_control_title": "Shadow Ai Discovery & Governance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-06 Shadow Ai Discovery & Governance has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0029",
      "gaissf_control_id": "D4-CTL-07",
      "gaissf_control_title": "Ai Software Composition Analysis (Sca)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D4-CTL-07 Ai Software Composition Analysis (Sca) has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0030",
      "gaissf_control_id": "D5-CTL-01",
      "gaissf_control_title": "Harmful Content Blocking",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "owasp_risk_id": "LLM05:2025",
      "owasp_risk_title": "Improper Output Handling",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Low",
      "rationale": "D5-CTL-01 Harmful Content Blocking has an outcome-level relationship to LLM05:2025 Improper Output Handling. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0031",
      "gaissf_control_id": "D5-CTL-02",
      "gaissf_control_title": "Pii Leakage Prevention",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "owasp_risk_id": "LLM02:2025",
      "owasp_risk_title": "Sensitive Information Disclosure",
      "relationship": "SP",
      "coverage_status": "Strong partial",
      "confidence": "High",
      "rationale": "D5-CTL-02 Pii Leakage Prevention has an outcome-level relationship to LLM02:2025 Sensitive Information Disclosure. The relationship is classified SP because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0032",
      "gaissf_control_id": "D5-CTL-03",
      "gaissf_control_title": "Copyright Detection",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "N",
      "coverage_status": "No material relationship",
      "confidence": "Not Rated",
      "rationale": "D5-CTL-03 Copyright Detection does not have a sufficiently direct outcome-level relationship to a specific OWASP Top 10 for LLM Applications 2025 risk category for this edition-bound crosswalk.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0033",
      "gaissf_control_id": "D5-CTL-04",
      "gaissf_control_title": "Ai Watermarking Robustness",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "N",
      "coverage_status": "No material relationship",
      "confidence": "Not Rated",
      "rationale": "D5-CTL-04 Ai Watermarking Robustness does not have a sufficiently direct outcome-level relationship to a specific OWASP Top 10 for LLM Applications 2025 risk category for this edition-bound crosswalk.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0034",
      "gaissf_control_id": "D5-CTL-05",
      "gaissf_control_title": "Privacy-By-Design Verification",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "owasp_risk_id": "LLM02:2025",
      "owasp_risk_title": "Sensitive Information Disclosure",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-05 Privacy-By-Design Verification has an outcome-level relationship to LLM02:2025 Sensitive Information Disclosure. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0035",
      "gaissf_control_id": "D5-CTL-06",
      "gaissf_control_title": "Privacy-Preserving Ml Validation",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "owasp_risk_id": "LLM02:2025",
      "owasp_risk_title": "Sensitive Information Disclosure",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Medium",
      "rationale": "D5-CTL-06 Privacy-Preserving Ml Validation has an outcome-level relationship to LLM02:2025 Sensitive Information Disclosure. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0036",
      "gaissf_control_id": "D6-CTL-01",
      "gaissf_control_title": "Human-In-The-Loop For High-Risk Actions",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-01 Human-In-The-Loop For High-Risk Actions has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0037",
      "gaissf_control_id": "D6-CTL-02",
      "gaissf_control_title": "Audit Trail Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "owasp_risk_id": "LLM01:2025",
      "owasp_risk_title": "Prompt Injection",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Low",
      "rationale": "D6-CTL-02 Audit Trail Completeness has an outcome-level relationship to LLM01:2025 Prompt Injection. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0038",
      "gaissf_control_id": "D6-CTL-03",
      "gaissf_control_title": "Ai Model Card Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "N",
      "coverage_status": "No material relationship",
      "confidence": "Not Rated",
      "rationale": "D6-CTL-03 Ai Model Card Completeness does not have a sufficiently direct outcome-level relationship to a specific OWASP Top 10 for LLM Applications 2025 risk category for this edition-bound crosswalk.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0039",
      "gaissf_control_id": "D6-CTL-04",
      "gaissf_control_title": "Ai Incident Response Readiness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "owasp_risk_id": "LLM10:2025",
      "owasp_risk_title": "Unbounded Consumption",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Low",
      "rationale": "D6-CTL-04 Ai Incident Response Readiness has an outcome-level relationship to LLM10:2025 Unbounded Consumption. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0040",
      "gaissf_control_id": "D6-CTL-05",
      "gaissf_control_title": "Model Deprecation & Decommissioning",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Low",
      "rationale": "D6-CTL-05 Model Deprecation & Decommissioning has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0041",
      "gaissf_control_id": "D6-CTL-06",
      "gaissf_control_title": "Third-Party Ai Vendor Governance",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-06 Third-Party Ai Vendor Governance has an outcome-level relationship to LLM03:2025 Supply Chain. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0042",
      "gaissf_control_id": "D6-CTL-07",
      "gaissf_control_title": "Ai Resilience & Business Continuity",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "owasp_risk_id": "LLM10:2025",
      "owasp_risk_title": "Unbounded Consumption",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-07 Ai Resilience & Business Continuity has an outcome-level relationship to LLM10:2025 Unbounded Consumption. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0043",
      "gaissf_control_id": "D7-CTL-H01",
      "gaissf_control_title": "Ai-Generated Phishing Simulation",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D7-CTL-H01 Ai-Generated Phishing Simulation addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0044",
      "gaissf_control_id": "D7-CTL-H02",
      "gaissf_control_title": "Deepfake Detection Training",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D7-CTL-H02 Deepfake Detection Training addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0045",
      "gaissf_control_id": "D7-CTL-H03",
      "gaissf_control_title": "Out-Of-Band Authentication",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D7-CTL-H03 Out-Of-Band Authentication addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0046",
      "gaissf_control_id": "D7-CTL-H04",
      "gaissf_control_title": "Ai Social Engineering Ir",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D7-CTL-H04 Ai Social Engineering Ir addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0047",
      "gaissf_control_id": "D7-CTL-H05",
      "gaissf_control_title": "Ai-Enhanced External Attack Defense",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D7-CTL-H05 Ai-Enhanced External Attack Defense addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0048",
      "gaissf_control_id": "D8-CTL-01",
      "gaissf_control_title": "Eu Ai Act Risk Tier Mapping",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D8-CTL-01 Eu Ai Act Risk Tier Mapping addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0049",
      "gaissf_control_id": "D8-CTL-02",
      "gaissf_control_title": "Iso 42001 Gap Analysis",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D8-CTL-02 Iso 42001 Gap Analysis addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0050",
      "gaissf_control_id": "D8-CTL-03",
      "gaissf_control_title": "Gpai Technical Documentation Verification",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D8-CTL-03 Gpai Technical Documentation Verification addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0051",
      "gaissf_control_id": "D8-CTL-04",
      "gaissf_control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D8-CTL-04 Dora Ict Incident Reporting (Financial Sector) addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0052",
      "gaissf_control_id": "D8-CTL-05",
      "gaissf_control_title": "Nist Sp 800-218A Compliance Check",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D8-CTL-05 Nist Sp 800-218A Compliance Check addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0053",
      "gaissf_control_id": "D9-CTL-01",
      "gaissf_control_title": "Physical Harm Boundary Enforcement",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Low",
      "rationale": "D9-CTL-01 Physical Harm Boundary Enforcement has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation. For D9, this relationship is relevant only where the D9 control is in the Applicable-Control Baseline.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0054",
      "gaissf_control_id": "D9-CTL-02",
      "gaissf_control_title": "Safe State And Graceful Degradation",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium",
      "rationale": "D9-CTL-02 Safe State And Graceful Degradation has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation. For D9, this relationship is relevant only where the D9 control is in the Applicable-Control Baseline.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0055",
      "gaissf_control_id": "D9-CTL-03",
      "gaissf_control_title": "Human Override And Emergency Stop",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium",
      "rationale": "D9-CTL-03 Human Override And Emergency Stop has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation. For D9, this relationship is relevant only where the D9 control is in the Applicable-Control Baseline.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0056",
      "gaissf_control_id": "D9-CTL-04",
      "gaissf_control_title": "Cyber-Physical Attack Detection",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "owasp_risk_id": "LLM01:2025",
      "owasp_risk_title": "Prompt Injection",
      "relationship": "S",
      "coverage_status": "Supporting",
      "confidence": "Low",
      "rationale": "D9-CTL-04 Cyber-Physical Attack Detection has an outcome-level relationship to LLM01:2025 Prompt Injection. The relationship is classified S because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation. For D9, this relationship is relevant only where the D9 control is in the Applicable-Control Baseline.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0057",
      "gaissf_control_id": "D9-CTL-05",
      "gaissf_control_title": "Physical Environment Integrity Monitoring",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D9-CTL-05 Physical Environment Integrity Monitoring addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0058",
      "gaissf_control_id": "D9-CTL-06",
      "gaissf_control_title": "Actuator Command Verification",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "relationship": "P",
      "coverage_status": "Partial",
      "confidence": "Medium",
      "rationale": "D9-CTL-06 Actuator Command Verification has an outcome-level relationship to LLM06:2025 Excessive Agency. The relationship is classified P because the GAISSF control can reduce or evidence part of the OWASP risk but does not, by itself, demonstrate complete mitigation. For D9, this relationship is relevant only where the D9 control is in the Applicable-Control Baseline.",
      "residual_gap": "Application-specific threat modelling, adversarial testing, implementation verification, and operating-effectiveness evidence remain necessary; documentary mapping is not evidence sufficiency or automatic conformance."
    },
    {
      "record_id": "GAISSF-CRO-024-MAP-0059",
      "gaissf_control_id": "D9-CTL-07",
      "gaissf_control_title": "Physical Incident Evidence Preservation",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "owasp_risk_id": null,
      "owasp_risk_title": null,
      "relationship": "O",
      "coverage_status": "Outside scope",
      "confidence": "Not Rated",
      "rationale": "D9-CTL-07 Physical Incident Evidence Preservation addresses a GAISSF concern that is materially outside the scope of the OWASP Top 10 for LLM Applications 2025 risk inventory.",
      "residual_gap": "Do not infer absence of security relevance. Address the GAISSF control on its own terms where it is in the Applicable-Control Baseline; use other threat models or standards for concerns outside the OWASP Top 10 scope."
    }
  ],
  "owasp_to_gaissf_reverse_coverage": [
    {
      "owasp_risk_id": "LLM01:2025",
      "owasp_risk_title": "Prompt Injection",
      "owasp_risk_summary": "Crafted direct or indirect inputs can alter model behavior, bypass instructions, expose data, or trigger unauthorized actions.",
      "gaissf_control_ids": "D2-CTL-01, D2-CTL-02, D2-CTL-03, D2-CTL-04, D2-CTL-05, D6-CTL-02, D9-CTL-04",
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "High",
      "residual_gap": "Application-specific architecture, threat modelling, testing depth, and operating-effectiveness evidence remain necessary. Mapping alone does not demonstrate mitigation."
    },
    {
      "owasp_risk_id": "LLM02:2025",
      "owasp_risk_title": "Sensitive Information Disclosure",
      "owasp_risk_summary": "Models and applications can reveal confidential, personal, proprietary, credential, or otherwise sensitive information.",
      "gaissf_control_ids": "D3-CTL-06, D3-CTL-07, D5-CTL-02, D5-CTL-05, D5-CTL-06",
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "High",
      "residual_gap": "Application-specific architecture, threat modelling, testing depth, and operating-effectiveness evidence remain necessary. Mapping alone does not demonstrate mitigation."
    },
    {
      "owasp_risk_id": "LLM03:2025",
      "owasp_risk_title": "Supply Chain",
      "owasp_risk_summary": "Compromised models, datasets, components, services, dependencies, or provenance can undermine application security and integrity.",
      "gaissf_control_ids": "D1-CTL-06, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-05, D6-CTL-06",
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "High",
      "residual_gap": "Application-specific architecture, threat modelling, testing depth, and operating-effectiveness evidence remain necessary. Mapping alone does not demonstrate mitigation."
    },
    {
      "owasp_risk_id": "LLM04:2025",
      "owasp_risk_title": "Data and Model Poisoning",
      "owasp_risk_summary": "Manipulated pre-training, fine-tuning, retrieval, embedding, or model data can introduce backdoors, bias, unsafe behavior, or integrity failures.",
      "gaissf_control_ids": "D1-CTL-01, D1-CTL-04, D1-CTL-07, D1-CTL-08, D1-CTL-09",
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "High",
      "residual_gap": "Application-specific architecture, threat modelling, testing depth, and operating-effectiveness evidence remain necessary. Mapping alone does not demonstrate mitigation."
    },
    {
      "owasp_risk_id": "LLM05:2025",
      "owasp_risk_title": "Improper Output Handling",
      "owasp_risk_summary": "Insufficient validation, sanitization, encoding, or contextual handling of model outputs can create downstream exploits.",
      "gaissf_control_ids": "D5-CTL-01",
      "coverage_status": "Supporting only",
      "relationship": "S",
      "confidence": "Low",
      "residual_gap": "GAISSF content/output controls do not substitute for application-layer encoding, sanitization, sink controls, downstream interpreter security or secure software engineering."
    },
    {
      "owasp_risk_id": "LLM06:2025",
      "owasp_risk_title": "Excessive Agency",
      "owasp_risk_summary": "Excessive functionality, permissions, autonomy, or insufficient human approval can allow harmful or unintended actions.",
      "gaissf_control_ids": "D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D6-CTL-01, D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-06",
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "High",
      "residual_gap": "Agent permissions, tool design, human approval, and application-specific authorization remain necessary; D9 mappings are conditional when Physical AI is in scope."
    },
    {
      "owasp_risk_id": "LLM07:2025",
      "owasp_risk_title": "System Prompt Leakage",
      "owasp_risk_summary": "System prompts or embedded instructions may be exposed and reveal sensitive logic, controls, or operational context.",
      "gaissf_control_ids": "D2-CTL-06",
      "coverage_status": "Supporting only",
      "relationship": "S",
      "confidence": "Low-Medium",
      "residual_gap": "GAISSF provides supporting context-isolation and disclosure controls, but does not contain a dedicated system-prompt-secrecy control in this baseline."
    },
    {
      "owasp_risk_id": "LLM08:2025",
      "owasp_risk_title": "Vector and Embedding Weaknesses",
      "owasp_risk_summary": "Weaknesses in retrieval, vector stores, embeddings, access controls, segmentation, and data provenance can cause disclosure or manipulation.",
      "gaissf_control_ids": "D1-CTL-05",
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "High",
      "residual_gap": "Application-specific architecture, threat modelling, testing depth, and operating-effectiveness evidence remain necessary. Mapping alone does not demonstrate mitigation."
    },
    {
      "owasp_risk_id": "LLM09:2025",
      "owasp_risk_title": "Misinformation",
      "owasp_risk_summary": "Incorrect, fabricated, misleading, or insufficiently verified model outputs can undermine decisions and safety.",
      "gaissf_control_ids": "D1-CTL-03",
      "coverage_status": "Supporting only",
      "relationship": "S",
      "confidence": "Medium-Low",
      "residual_gap": "GAISSF includes supporting drift/content controls, but the source control set does not directly implement the full application-specific misinformation and grounding problem."
    },
    {
      "owasp_risk_id": "LLM10:2025",
      "owasp_risk_title": "Unbounded Consumption",
      "owasp_risk_summary": "Uncontrolled model, token, tool, compute, or service consumption can cause denial of service, cost escalation, degradation, or theft-related abuse.",
      "gaissf_control_ids": "D1-CTL-02, D6-CTL-04, D6-CTL-07",
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "Application-specific architecture, threat modelling, testing depth, and operating-effectiveness evidence remain necessary. Mapping alone does not demonstrate mitigation."
    }
  ]
}