{
  "document": {
    "id": "GAISSF-CRO-025",
    "title": "GAISSF-MITRE ATLAS Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "classification": "Informative threat-alignment crosswalk / public",
    "publisher": "ODA3 Institute",
    "publication_date": "2026-06-29",
    "updated": "2026-10-06"
  },
  "source_baseline": {
    "gaissf": [
      "GAISSF-NOR-001 v1.0; published 2026-07-01; updated 2026-10-04",
      "GAISSF-NOR-004 v1.0; published 2026-07-01; updated 2026-10-04"
    ],
    "atlas": {
      "content_version": "2026.09",
      "release_date": "2026-09-15",
      "format_version": "6.x",
      "official_site": "https://atlas.mitre.org/",
      "official_data": "https://github.com/mitre-atlas/atlas-data",
      "verified_date": "2026-10-06",
      "reported_counts": {
        "tactics": 16,
        "techniques": 120,
        "subtechniques": 88,
        "technique_objects_total": 208,
        "mitigations": 40,
        "case_studies": 73
      }
    },
    "scope_note": "The crosswalk maps all GAISSF controls to materially relevant ATLAS tactics and a bounded priority technique/sub-technique set. It does not claim exhaustive ATLAS coverage, prevention/detection validation, evidence sufficiency, or operating effectiveness."
  },
  "controlled_vocabulary": {
    "relationship": {
      "E": "Equivalent or near-equivalent",
      "SP": "Strong partial",
      "P": "Partial",
      "S": "Supporting",
      "C": "Contextual",
      "N": "No material mapping",
      "O": "Outside scope",
      "U": "Unable to determine"
    },
    "coverage_status": [
      "Addressed",
      "Substantially Addressed",
      "Partially Addressed",
      "Indirectly Supported",
      "Not Addressed",
      "Outside Scope",
      "Unable to Determine"
    ],
    "confidence": [
      "High",
      "Medium-High",
      "Medium",
      "Low",
      "Not Rated"
    ]
  },
  "limitations": [
    "Mapping is not MITRE endorsement, certification, equivalence, evidence sufficiency, verified prevention/detection coverage, or proof of defensive operating effectiveness.",
    "The priority technique register is a bounded subset and is not a substitute for the complete ATLAS v2026.09 knowledge base.",
    "ATLAS publishes monthly content updates; tactic/technique names, identifiers, hierarchy and scope must be revalidated before material reuse.",
    "Environment-specific threat modelling, telemetry, detection engineering, adversary emulation and validation remain necessary.",
    "D9 is additional/conditional. Where Physical AI is in scope, PAI-SF™ v1.0 may be used alongside GAISSF; CSX-PAISF-004 is mapping only.",
    "Independent ATT&CK/ATLAS crosswalk review and explicit publication approval remain open."
  ],
  "statistics": {
    "gaissf_controls": 59,
    "atlas_tactics": 16,
    "atlas_reported_techniques": 208,
    "priority_techniques_mapped": 82,
    "forward_mapping_records": 112,
    "reverse_tactic_records": 16
  },
  "gaissf_controls": [
    {
      "id": "D1-CTL-01",
      "title": "Dataset Provenance & Poisoning Prevention",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-02",
      "title": "Model Extraction Resistance",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-03",
      "title": "Behavioral Drift Detection",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-04",
      "title": "Federated Learning Poisoning Prevention",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-05",
      "title": "Embedding Space Robustness",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-06",
      "title": "Post-Quantum Model Signing & Crypto Hardening",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-07",
      "title": "Lora/Adapter Integrity Verification",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-08",
      "title": "Model Merge Attack Detection",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-09",
      "title": "Quantization Backdoor Screening",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-01",
      "title": "Direct Prompt Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-02",
      "title": "Indirect Prompt Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-03",
      "title": "Jailbreak Resistance Testing",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-04",
      "title": "Multi-Modal Injection Defense",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-05",
      "title": "Function Call/Tool Call Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-06",
      "title": "Cross-Context Hijacking Mitigation",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-01",
      "title": "Least Agency Enforcement",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-02",
      "title": "Inter-Agent Communication Security",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-03",
      "title": "Agentic Prompt Chaining Detection",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-04",
      "title": "Embodied Ai Safety Controls",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-05",
      "title": "Multi-Agent Trust Chain Attestation",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-06",
      "title": "Persistent Memory Exfiltration Prevention",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-07",
      "title": "Secure Memory Lifecycle Management",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-01",
      "title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-02",
      "title": "Model File & Artifact Scanning",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-03",
      "title": "Model Hub & Registry Vetting",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-04",
      "title": "Mcp Server Behavioral Monitoring",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-05",
      "title": "Third-Party Ai Api Security Assessment",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-06",
      "title": "Shadow Ai Discovery & Governance",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-07",
      "title": "Ai Software Composition Analysis (Sca)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-01",
      "title": "Harmful Content Blocking",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-02",
      "title": "Pii Leakage Prevention",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-03",
      "title": "Copyright Detection",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-04",
      "title": "Ai Watermarking Robustness",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-05",
      "title": "Privacy-By-Design Verification",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-06",
      "title": "Privacy-Preserving Ml Validation",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-01",
      "title": "Human-In-The-Loop For High-Risk Actions",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-02",
      "title": "Audit Trail Completeness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-03",
      "title": "Ai Model Card Completeness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-04",
      "title": "Ai Incident Response Readiness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-05",
      "title": "Model Deprecation & Decommissioning",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-06",
      "title": "Third-Party Ai Vendor Governance",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-07",
      "title": "Ai Resilience & Business Continuity",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H01",
      "title": "Ai-Generated Phishing Simulation",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H02",
      "title": "Deepfake Detection Training",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H03",
      "title": "Out-Of-Band Authentication",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H04",
      "title": "Ai Social Engineering Ir",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H05",
      "title": "Ai-Enhanced External Attack Defense",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-01",
      "title": "Eu Ai Act Risk Tier Mapping",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-02",
      "title": "Iso 42001 Gap Analysis",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-03",
      "title": "Gpai Technical Documentation Verification",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-04",
      "title": "Dora Ict Incident Reporting (Financial Sector)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-05",
      "title": "Nist Sp 800-218A Compliance Check",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D9-CTL-01",
      "title": "Physical Harm Boundary Enforcement",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-02",
      "title": "Safe State And Graceful Degradation",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-03",
      "title": "Human Override And Emergency Stop",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-04",
      "title": "Cyber-Physical Attack Detection",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-05",
      "title": "Physical Environment Integrity Monitoring",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-06",
      "title": "Actuator Command Verification",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-07",
      "title": "Physical Incident Evidence Preservation",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    }
  ],
  "atlas_tactics": [
    {
      "id": "AML.TA0002",
      "name": "Reconnaissance"
    },
    {
      "id": "AML.TA0003",
      "name": "Resource Development"
    },
    {
      "id": "AML.TA0004",
      "name": "Initial Access"
    },
    {
      "id": "AML.TA0000",
      "name": "AI Model Access"
    },
    {
      "id": "AML.TA0005",
      "name": "Execution"
    },
    {
      "id": "AML.TA0006",
      "name": "Persistence"
    },
    {
      "id": "AML.TA0012",
      "name": "Privilege Escalation"
    },
    {
      "id": "AML.TA0007",
      "name": "Defense Evasion"
    },
    {
      "id": "AML.TA0013",
      "name": "Credential Access"
    },
    {
      "id": "AML.TA0008",
      "name": "Discovery"
    },
    {
      "id": "AML.TA0015",
      "name": "Lateral Movement"
    },
    {
      "id": "AML.TA0009",
      "name": "Collection"
    },
    {
      "id": "AML.TA0001",
      "name": "AI Attack Adaptation"
    },
    {
      "id": "AML.TA0014",
      "name": "Command and Control"
    },
    {
      "id": "AML.TA0010",
      "name": "Exfiltration"
    },
    {
      "id": "AML.TA0011",
      "name": "Impact"
    }
  ],
  "atlas_priority_techniques": [
    {
      "id": "AML.T0064",
      "name": "Gather RAG-Indexed Targets",
      "tactic": "Reconnaissance"
    },
    {
      "id": "AML.T0087",
      "name": "Gather Victim Identity Information",
      "tactic": "Reconnaissance"
    },
    {
      "id": "AML.T0004",
      "name": "Search Application Repositories",
      "tactic": "Reconnaissance"
    },
    {
      "id": "AML.T0001",
      "name": "Search Open AI Vulnerability Analysis",
      "tactic": "Reconnaissance"
    },
    {
      "id": "AML.T0000",
      "name": "Search Open Technical Databases",
      "tactic": "Reconnaissance"
    },
    {
      "id": "AML.T0003",
      "name": "Search Victim-Owned Websites",
      "tactic": "Reconnaissance"
    },
    {
      "id": "AML.T0008",
      "name": "Acquire Infrastructure",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0002",
      "name": "Acquire Public AI Artifacts",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0017",
      "name": "Develop Capabilities",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0021",
      "name": "Establish Accounts",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0065",
      "name": "LLM Prompt Crafting",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0016",
      "name": "Obtain Capabilities",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0020",
      "name": "Training Data Poisoning",
      "tactic": "Resource Development",
      "source_note": "Name reconciled to current ATLAS taxonomy; stable identifier retained."
    },
    {
      "id": "AML.T0060",
      "name": "Publish Hallucinated Entities",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0104",
      "name": "Publish Poisoned AI Artifacts: AI Agent Tools",
      "tactic": "Resource Development",
      "source_note": "Name reconciled to current ATLAS taxonomy; stable identifier retained."
    },
    {
      "id": "AML.T0019",
      "name": "Publish Poisoned AI Artifacts: Datasets",
      "tactic": "Resource Development",
      "source_note": "Name reconciled to current ATLAS taxonomy; stable identifier retained."
    },
    {
      "id": "AML.T0058",
      "name": "Publish Poisoned AI Artifacts: Models",
      "tactic": "Resource Development",
      "source_note": "Name reconciled to current ATLAS taxonomy; stable identifier retained."
    },
    {
      "id": "AML.T0066",
      "name": "Retrieval Content Crafting",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0079",
      "name": "Stage Capabilities",
      "tactic": "Resource Development"
    },
    {
      "id": "AML.T0010",
      "name": "AI Supply Chain Compromise",
      "tactic": "Initial Access"
    },
    {
      "id": "AML.T0015",
      "name": "Evade AI Model",
      "tactic": "Initial Access"
    },
    {
      "id": "AML.T0049",
      "name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "id": "AML.T0052",
      "name": "Phishing",
      "tactic": "Initial Access"
    },
    {
      "id": "AML.T0093",
      "name": "Prompt Infiltration via Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "id": "AML.T0012",
      "name": "Valid Accounts",
      "tactic": "Initial Access"
    },
    {
      "id": "AML.T0040",
      "name": "AI Model Inference API Access",
      "tactic": "AI Model Access"
    },
    {
      "id": "AML.T0047",
      "name": "AI-Enabled Product or Service",
      "tactic": "AI Model Access"
    },
    {
      "id": "AML.T0044",
      "name": "Full AI Model Access",
      "tactic": "AI Model Access"
    },
    {
      "id": "AML.T0041",
      "name": "Physical Environment Access",
      "tactic": "AI Model Access"
    },
    {
      "id": "AML.T0100",
      "name": "AI Agent Clickbait",
      "tactic": "Execution"
    },
    {
      "id": "AML.T0053",
      "name": "AI Agent Tool Invocation",
      "tactic": "Execution"
    },
    {
      "id": "AML.T0050",
      "name": "Command and Scripting Interpreter",
      "tactic": "Execution"
    },
    {
      "id": "AML.T0103",
      "name": "Deploy AI Agent",
      "tactic": "Execution"
    },
    {
      "id": "AML.T0051",
      "name": "LLM Prompt Injection",
      "tactic": "Execution"
    },
    {
      "id": "AML.T0011",
      "name": "User Execution",
      "tactic": "Execution"
    },
    {
      "id": "AML.T0110",
      "name": "AI Agent Context Poisoning",
      "tactic": "Persistence"
    },
    {
      "id": "AML.T0105",
      "name": "AI Agent Tool Data Poisoning",
      "tactic": "Persistence"
    },
    {
      "id": "AML.T0111",
      "name": "AI Agent Tool Poisoning",
      "tactic": "Persistence"
    },
    {
      "id": "AML.T0061",
      "name": "LLM Prompt Self-Replication",
      "tactic": "Persistence"
    },
    {
      "id": "AML.T0018",
      "name": "Manipulate AI Model",
      "tactic": "Persistence"
    },
    {
      "id": "AML.T0081",
      "name": "RAG Poisoning",
      "tactic": "Persistence"
    },
    {
      "id": "AML.T0070",
      "name": "Escape to Host",
      "tactic": "Privilege Escalation"
    },
    {
      "id": "AML.T0054",
      "name": "LLM Jailbreak",
      "tactic": "Privilege Escalation"
    },
    {
      "id": "AML.T0109",
      "name": "AI Supply Chain Reputation Inflation",
      "tactic": "Defense Evasion"
    },
    {
      "id": "AML.T0076",
      "name": "AI Supply Chain Rug Pull",
      "tactic": "Defense Evasion"
    },
    {
      "id": "AML.T0094",
      "name": "Corrupt AI Model",
      "tactic": "Defense Evasion"
    },
    {
      "id": "AML.T0107",
      "name": "Delay Execution of LLM Instructions",
      "tactic": "Defense Evasion"
    },
    {
      "id": "AML.T0071",
      "name": "False RAG Entry Injection",
      "tactic": "Defense Evasion"
    },
    {
      "id": "AML.T0073",
      "name": "LLM Prompt Obfuscation",
      "tactic": "Defense Evasion"
    },
    {
      "id": "AML.T0068",
      "name": "Manipulate User LLM Chat History",
      "tactic": "Defense Evasion"
    },
    {
      "id": "AML.T0092",
      "name": "Modify AI Agent Configuration",
      "tactic": "Defense Evasion"
    },
    {
      "id": "AML.T0097",
      "name": "AI Agent Tool Credential Harvesting",
      "tactic": "Credential Access"
    },
    {
      "id": "AML.T0098",
      "name": "Credentials from AI Agent Configuration",
      "tactic": "Credential Access"
    },
    {
      "id": "AML.T0083",
      "name": "RAG Credential Harvesting",
      "tactic": "Credential Access"
    },
    {
      "id": "AML.T0055",
      "name": "Unsecured Credentials",
      "tactic": "Credential Access"
    },
    {
      "id": "AML.T0106",
      "name": "Discover AI Agent Configuration",
      "tactic": "Discovery"
    },
    {
      "id": "AML.T0007",
      "name": "Discover AI Artifacts",
      "tactic": "Discovery"
    },
    {
      "id": "AML.T0014",
      "name": "Discover AI Model Family",
      "tactic": "Discovery"
    },
    {
      "id": "AML.T0013",
      "name": "Discover AI Model Ontology",
      "tactic": "Discovery"
    },
    {
      "id": "AML.T0063",
      "name": "Discover AI Model Outputs",
      "tactic": "Discovery"
    },
    {
      "id": "AML.T0062",
      "name": "Discover LLM Hallucinations",
      "tactic": "Discovery"
    },
    {
      "id": "AML.T0069",
      "name": "Discover LLM System Information",
      "tactic": "Discovery"
    },
    {
      "id": "AML.T0089",
      "name": "AI Artifact Collection",
      "tactic": "Collection"
    },
    {
      "id": "AML.T0091",
      "name": "Data from AI Services",
      "tactic": "Collection"
    },
    {
      "id": "AML.T0005",
      "name": "Create Proxy AI Model",
      "tactic": "AI Attack Adaptation"
    },
    {
      "id": "AML.T0043",
      "name": "Craft Adversarial Data",
      "tactic": "AI Attack Adaptation"
    },
    {
      "id": "AML.T0099",
      "name": "Generate Deepfakes",
      "tactic": "AI Attack Adaptation"
    },
    {
      "id": "AML.T0080",
      "name": "Generate Malicious Commands",
      "tactic": "AI Attack Adaptation"
    },
    {
      "id": "AML.T0042",
      "name": "Verify Attack",
      "tactic": "AI Attack Adaptation"
    },
    {
      "id": "AML.T0108",
      "name": "AI Agent",
      "tactic": "Command and Control"
    },
    {
      "id": "AML.T0102",
      "name": "AI Service API",
      "tactic": "Command and Control"
    },
    {
      "id": "AML.T0101",
      "name": "Exfiltration via AI Agent Tool Invocation",
      "tactic": "Exfiltration"
    },
    {
      "id": "AML.T0024",
      "name": "Exfiltration via AI Inference API",
      "tactic": "Exfiltration"
    },
    {
      "id": "AML.T0025",
      "name": "Exfiltration via Cyber Means",
      "tactic": "Exfiltration"
    },
    {
      "id": "AML.T0056",
      "name": "Extract LLM System Prompt",
      "tactic": "Exfiltration"
    },
    {
      "id": "AML.T0057",
      "name": "LLM Data Leakage",
      "tactic": "Exfiltration"
    },
    {
      "id": "AML.T0090",
      "name": "LLM Response Rendering",
      "tactic": "Exfiltration"
    },
    {
      "id": "AML.T0029",
      "name": "Denial of AI Service",
      "tactic": "Impact"
    },
    {
      "id": "AML.T0031",
      "name": "Erode AI Model Integrity",
      "tactic": "Impact"
    },
    {
      "id": "AML.T0046",
      "name": "Spamming AI System with Chaff Data",
      "tactic": "Impact"
    },
    {
      "id": "AML.T0048",
      "name": "External Harms",
      "tactic": "Impact"
    },
    {
      "id": "AML.T0059",
      "name": "Erode Dataset Integrity",
      "tactic": "Impact"
    }
  ],
  "gaissf_to_atlas_mappings": [
    {
      "record_id": "GAISSF-CRO-025-MAP-0001",
      "gaissf_control_id": "D1-CTL-01",
      "gaissf_control_title": "Dataset Provenance & Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0020",
      "atlas_technique_name": "Training Data Poisoning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Training Data Poisoning. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0002",
      "gaissf_control_id": "D1-CTL-01",
      "gaissf_control_title": "Dataset Provenance & Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Impact",
      "atlas_technique_id": "AML.T0059",
      "atlas_technique_name": "Erode Dataset Integrity",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0059 Erode Dataset Integrity. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0003",
      "gaissf_control_id": "D1-CTL-02",
      "gaissf_control_title": "Model Extraction Resistance",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0042",
      "atlas_technique_name": "Verify Attack",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0004",
      "gaissf_control_id": "D1-CTL-03",
      "gaissf_control_title": "Behavioral Drift Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0042",
      "atlas_technique_name": "Verify Attack",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0005",
      "gaissf_control_id": "D1-CTL-04",
      "gaissf_control_title": "Federated Learning Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0020",
      "atlas_technique_name": "Training Data Poisoning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Training Data Poisoning. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0006",
      "gaissf_control_id": "D1-CTL-04",
      "gaissf_control_title": "Federated Learning Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0058",
      "atlas_technique_name": "Publish Poisoned AI Artifacts: Models",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0058 Publish Poisoned AI Artifacts: Models. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0007",
      "gaissf_control_id": "D1-CTL-05",
      "gaissf_control_title": "Embedding Space Robustness",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0015",
      "atlas_technique_name": "Evade AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0015 Evade AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0008",
      "gaissf_control_id": "D1-CTL-05",
      "gaissf_control_title": "Embedding Space Robustness",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0005",
      "atlas_technique_name": "Create Proxy AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0005 Create Proxy AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0009",
      "gaissf_control_id": "D1-CTL-06",
      "gaissf_control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0010",
      "gaissf_control_id": "D1-CTL-06",
      "gaissf_control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Defense Evasion",
      "atlas_technique_id": "AML.T0109",
      "atlas_technique_name": "AI Supply Chain Reputation Inflation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0109 AI Supply Chain Reputation Inflation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0011",
      "gaissf_control_id": "D1-CTL-07",
      "gaissf_control_title": "Lora/Adapter Integrity Verification",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0015",
      "atlas_technique_name": "Evade AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0015 Evade AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0012",
      "gaissf_control_id": "D1-CTL-07",
      "gaissf_control_title": "Lora/Adapter Integrity Verification",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0005",
      "atlas_technique_name": "Create Proxy AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0005 Create Proxy AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0013",
      "gaissf_control_id": "D1-CTL-08",
      "gaissf_control_title": "Model Merge Attack Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0015",
      "atlas_technique_name": "Evade AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-08 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0015 Evade AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0014",
      "gaissf_control_id": "D1-CTL-08",
      "gaissf_control_title": "Model Merge Attack Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0005",
      "atlas_technique_name": "Create Proxy AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-08 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0005 Create Proxy AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0015",
      "gaissf_control_id": "D1-CTL-09",
      "gaissf_control_title": "Quantization Backdoor Screening",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0042",
      "atlas_technique_name": "Verify Attack",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0016",
      "gaissf_control_id": "D2-CTL-01",
      "gaissf_control_title": "Direct Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "Execution",
      "atlas_technique_id": "AML.T0051",
      "atlas_technique_name": "LLM Prompt Injection",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0051 LLM Prompt Injection. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0017",
      "gaissf_control_id": "D2-CTL-01",
      "gaissf_control_title": "Direct Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "Exfiltration",
      "atlas_technique_id": "AML.T0056",
      "atlas_technique_name": "Extract LLM System Prompt",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0056 Extract LLM System Prompt. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0018",
      "gaissf_control_id": "D2-CTL-02",
      "gaissf_control_title": "Indirect Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "Execution",
      "atlas_technique_id": "AML.T0051",
      "atlas_technique_name": "LLM Prompt Injection",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0051 LLM Prompt Injection. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0019",
      "gaissf_control_id": "D2-CTL-02",
      "gaissf_control_title": "Indirect Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0065",
      "atlas_technique_name": "LLM Prompt Crafting",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0065 LLM Prompt Crafting. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0020",
      "gaissf_control_id": "D2-CTL-03",
      "gaissf_control_title": "Jailbreak Resistance Testing",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0042",
      "atlas_technique_name": "Verify Attack",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0021",
      "gaissf_control_id": "D2-CTL-04",
      "gaissf_control_title": "Multi-Modal Injection Defense",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0043",
      "atlas_technique_name": "Craft Adversarial Data",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0043 Craft Adversarial Data. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0022",
      "gaissf_control_id": "D2-CTL-04",
      "gaissf_control_title": "Multi-Modal Injection Defense",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0015",
      "atlas_technique_name": "Evade AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0015 Evade AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0023",
      "gaissf_control_id": "D2-CTL-05",
      "gaissf_control_title": "Function Call/Tool Call Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0043",
      "atlas_technique_name": "Craft Adversarial Data",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0043 Craft Adversarial Data. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0024",
      "gaissf_control_id": "D2-CTL-05",
      "gaissf_control_title": "Function Call/Tool Call Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0015",
      "atlas_technique_name": "Evade AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0015 Evade AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0025",
      "gaissf_control_id": "D2-CTL-06",
      "gaissf_control_title": "Cross-Context Hijacking Mitigation",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "Exfiltration",
      "atlas_technique_id": "AML.T0056",
      "atlas_technique_name": "Extract LLM System Prompt",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0056 Extract LLM System Prompt. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0026",
      "gaissf_control_id": "D2-CTL-06",
      "gaissf_control_title": "Cross-Context Hijacking Mitigation",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0065",
      "atlas_technique_name": "LLM Prompt Crafting",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0065 LLM Prompt Crafting. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0027",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0104",
      "atlas_technique_name": "Publish Poisoned AI Artifacts: AI Agent Tools",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0104 Publish Poisoned AI Artifacts: AI Agent Tools. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0028",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0040",
      "atlas_technique_name": "AI Model Inference API Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0040 AI Model Inference API Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0029",
      "gaissf_control_id": "D3-CTL-02",
      "gaissf_control_title": "Inter-Agent Communication Security",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0104",
      "atlas_technique_name": "Publish Poisoned AI Artifacts: AI Agent Tools",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0104 Publish Poisoned AI Artifacts: AI Agent Tools. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0030",
      "gaissf_control_id": "D3-CTL-02",
      "gaissf_control_title": "Inter-Agent Communication Security",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Execution",
      "atlas_technique_id": "AML.T0100",
      "atlas_technique_name": "AI Agent Clickbait",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0100 AI Agent Clickbait. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0031",
      "gaissf_control_id": "D3-CTL-03",
      "gaissf_control_title": "Agentic Prompt Chaining Detection",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Exfiltration",
      "atlas_technique_id": "AML.T0056",
      "atlas_technique_name": "Extract LLM System Prompt",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0056 Extract LLM System Prompt. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0032",
      "gaissf_control_id": "D3-CTL-03",
      "gaissf_control_title": "Agentic Prompt Chaining Detection",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0065",
      "atlas_technique_name": "LLM Prompt Crafting",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0065 LLM Prompt Crafting. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0033",
      "gaissf_control_id": "D3-CTL-04",
      "gaissf_control_title": "Embodied Ai Safety Controls",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0104",
      "atlas_technique_name": "Publish Poisoned AI Artifacts: AI Agent Tools",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0104 Publish Poisoned AI Artifacts: AI Agent Tools. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0034",
      "gaissf_control_id": "D3-CTL-04",
      "gaissf_control_title": "Embodied Ai Safety Controls",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0041",
      "atlas_technique_name": "Physical Environment Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0041 Physical Environment Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0035",
      "gaissf_control_id": "D3-CTL-05",
      "gaissf_control_title": "Multi-Agent Trust Chain Attestation",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0104",
      "atlas_technique_name": "Publish Poisoned AI Artifacts: AI Agent Tools",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0104 Publish Poisoned AI Artifacts: AI Agent Tools. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0036",
      "gaissf_control_id": "D3-CTL-05",
      "gaissf_control_title": "Multi-Agent Trust Chain Attestation",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Execution",
      "atlas_technique_id": "AML.T0100",
      "atlas_technique_name": "AI Agent Clickbait",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0100 AI Agent Clickbait. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0037",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Exfiltration",
      "atlas_technique_id": "AML.T0101",
      "atlas_technique_name": "Exfiltration via AI Agent Tool Invocation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0101 Exfiltration via AI Agent Tool Invocation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0038",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0104",
      "atlas_technique_name": "Publish Poisoned AI Artifacts: AI Agent Tools",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0104 Publish Poisoned AI Artifacts: AI Agent Tools. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0039",
      "gaissf_control_id": "D3-CTL-07",
      "gaissf_control_title": "Secure Memory Lifecycle Management",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0104",
      "atlas_technique_name": "Publish Poisoned AI Artifacts: AI Agent Tools",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0104 Publish Poisoned AI Artifacts: AI Agent Tools. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0040",
      "gaissf_control_id": "D3-CTL-07",
      "gaissf_control_title": "Secure Memory Lifecycle Management",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "atlas_tactic": "Execution",
      "atlas_technique_id": "AML.T0100",
      "atlas_technique_name": "AI Agent Clickbait",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0100 AI Agent Clickbait. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0041",
      "gaissf_control_id": "D4-CTL-01",
      "gaissf_control_title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0042",
      "gaissf_control_id": "D4-CTL-01",
      "gaissf_control_title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Defense Evasion",
      "atlas_technique_id": "AML.T0109",
      "atlas_technique_name": "AI Supply Chain Reputation Inflation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0109 AI Supply Chain Reputation Inflation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0043",
      "gaissf_control_id": "D4-CTL-02",
      "gaissf_control_title": "Model File & Artifact Scanning",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0044",
      "gaissf_control_id": "D4-CTL-02",
      "gaissf_control_title": "Model File & Artifact Scanning",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Defense Evasion",
      "atlas_technique_id": "AML.T0109",
      "atlas_technique_name": "AI Supply Chain Reputation Inflation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0109 AI Supply Chain Reputation Inflation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0045",
      "gaissf_control_id": "D4-CTL-03",
      "gaissf_control_title": "Model Hub & Registry Vetting",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0046",
      "gaissf_control_id": "D4-CTL-03",
      "gaissf_control_title": "Model Hub & Registry Vetting",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Defense Evasion",
      "atlas_technique_id": "AML.T0109",
      "atlas_technique_name": "AI Supply Chain Reputation Inflation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0109 AI Supply Chain Reputation Inflation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0047",
      "gaissf_control_id": "D4-CTL-04",
      "gaissf_control_title": "Mcp Server Behavioral Monitoring",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0048",
      "gaissf_control_id": "D4-CTL-04",
      "gaissf_control_title": "Mcp Server Behavioral Monitoring",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0040",
      "atlas_technique_name": "AI Model Inference API Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0040 AI Model Inference API Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0049",
      "gaissf_control_id": "D4-CTL-05",
      "gaissf_control_title": "Third-Party Ai Api Security Assessment",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0050",
      "gaissf_control_id": "D4-CTL-05",
      "gaissf_control_title": "Third-Party Ai Api Security Assessment",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Defense Evasion",
      "atlas_technique_id": "AML.T0109",
      "atlas_technique_name": "AI Supply Chain Reputation Inflation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0109 AI Supply Chain Reputation Inflation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0051",
      "gaissf_control_id": "D4-CTL-06",
      "gaissf_control_title": "Shadow Ai Discovery & Governance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0052",
      "gaissf_control_id": "D4-CTL-06",
      "gaissf_control_title": "Shadow Ai Discovery & Governance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Defense Evasion",
      "atlas_technique_id": "AML.T0109",
      "atlas_technique_name": "AI Supply Chain Reputation Inflation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0109 AI Supply Chain Reputation Inflation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0053",
      "gaissf_control_id": "D4-CTL-07",
      "gaissf_control_title": "Ai Software Composition Analysis (Sca)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0054",
      "gaissf_control_id": "D4-CTL-07",
      "gaissf_control_title": "Ai Software Composition Analysis (Sca)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "atlas_tactic": "Defense Evasion",
      "atlas_technique_id": "AML.T0109",
      "atlas_technique_name": "AI Supply Chain Reputation Inflation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0109 AI Supply Chain Reputation Inflation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0055",
      "gaissf_control_id": "D5-CTL-01",
      "gaissf_control_title": "Harmful Content Blocking",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0062",
      "atlas_technique_name": "Discover LLM Hallucinations",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0062 Discover LLM Hallucinations. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0056",
      "gaissf_control_id": "D5-CTL-01",
      "gaissf_control_title": "Harmful Content Blocking",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0099",
      "atlas_technique_name": "Generate Deepfakes",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0099 Generate Deepfakes. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0057",
      "gaissf_control_id": "D5-CTL-02",
      "gaissf_control_title": "Pii Leakage Prevention",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0040",
      "atlas_technique_name": "AI Model Inference API Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0040 AI Model Inference API Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0058",
      "gaissf_control_id": "D5-CTL-02",
      "gaissf_control_title": "Pii Leakage Prevention",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0044",
      "atlas_technique_name": "Full AI Model Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0044 Full AI Model Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0059",
      "gaissf_control_id": "D5-CTL-03",
      "gaissf_control_title": "Copyright Detection",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0062",
      "atlas_technique_name": "Discover LLM Hallucinations",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0062 Discover LLM Hallucinations. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0060",
      "gaissf_control_id": "D5-CTL-03",
      "gaissf_control_title": "Copyright Detection",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0099",
      "atlas_technique_name": "Generate Deepfakes",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0099 Generate Deepfakes. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0061",
      "gaissf_control_id": "D5-CTL-04",
      "gaissf_control_title": "Ai Watermarking Robustness",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0062",
      "atlas_technique_name": "Discover LLM Hallucinations",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0062 Discover LLM Hallucinations. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0062",
      "gaissf_control_id": "D5-CTL-04",
      "gaissf_control_title": "Ai Watermarking Robustness",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0099",
      "atlas_technique_name": "Generate Deepfakes",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0099 Generate Deepfakes. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0063",
      "gaissf_control_id": "D5-CTL-05",
      "gaissf_control_title": "Privacy-By-Design Verification",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0087",
      "atlas_technique_name": "Gather Victim Identity Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0087 Gather Victim Identity Information. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0064",
      "gaissf_control_id": "D5-CTL-05",
      "gaissf_control_title": "Privacy-By-Design Verification",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0062",
      "atlas_technique_name": "Discover LLM Hallucinations",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0062 Discover LLM Hallucinations. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0065",
      "gaissf_control_id": "D5-CTL-06",
      "gaissf_control_title": "Privacy-Preserving Ml Validation",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "Exfiltration",
      "atlas_technique_id": "AML.T0024",
      "atlas_technique_name": "Exfiltration via AI Inference API",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0024 Exfiltration via AI Inference API. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0066",
      "gaissf_control_id": "D5-CTL-06",
      "gaissf_control_title": "Privacy-Preserving Ml Validation",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0087",
      "atlas_technique_name": "Gather Victim Identity Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D5-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0087 Gather Victim Identity Information. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0067",
      "gaissf_control_id": "D6-CTL-01",
      "gaissf_control_title": "Human-In-The-Loop For High-Risk Actions",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0064",
      "atlas_technique_name": "Gather RAG-Indexed Targets",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0064 Gather RAG-Indexed Targets. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0068",
      "gaissf_control_id": "D6-CTL-01",
      "gaissf_control_title": "Human-In-The-Loop For High-Risk Actions",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0087",
      "atlas_technique_name": "Gather Victim Identity Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0087 Gather Victim Identity Information. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0069",
      "gaissf_control_id": "D6-CTL-02",
      "gaissf_control_title": "Audit Trail Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0064",
      "atlas_technique_name": "Gather RAG-Indexed Targets",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0064 Gather RAG-Indexed Targets. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0070",
      "gaissf_control_id": "D6-CTL-02",
      "gaissf_control_title": "Audit Trail Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0087",
      "atlas_technique_name": "Gather Victim Identity Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0087 Gather Victim Identity Information. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0071",
      "gaissf_control_id": "D6-CTL-03",
      "gaissf_control_title": "Ai Model Card Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0040",
      "atlas_technique_name": "AI Model Inference API Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0040 AI Model Inference API Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0072",
      "gaissf_control_id": "D6-CTL-03",
      "gaissf_control_title": "Ai Model Card Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0044",
      "atlas_technique_name": "Full AI Model Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0044 Full AI Model Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0073",
      "gaissf_control_id": "D6-CTL-04",
      "gaissf_control_title": "Ai Incident Response Readiness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Exfiltration",
      "atlas_technique_id": "AML.T0090",
      "atlas_technique_name": "LLM Response Rendering",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0090 LLM Response Rendering. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0074",
      "gaissf_control_id": "D6-CTL-04",
      "gaissf_control_title": "Ai Incident Response Readiness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0064",
      "atlas_technique_name": "Gather RAG-Indexed Targets",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0064 Gather RAG-Indexed Targets. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0075",
      "gaissf_control_id": "D6-CTL-05",
      "gaissf_control_title": "Model Deprecation & Decommissioning",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0040",
      "atlas_technique_name": "AI Model Inference API Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0040 AI Model Inference API Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0076",
      "gaissf_control_id": "D6-CTL-05",
      "gaissf_control_title": "Model Deprecation & Decommissioning",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0044",
      "atlas_technique_name": "Full AI Model Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0044 Full AI Model Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0077",
      "gaissf_control_id": "D6-CTL-06",
      "gaissf_control_title": "Third-Party Ai Vendor Governance",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0010",
      "atlas_technique_name": "AI Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0010 AI Supply Chain Compromise. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0078",
      "gaissf_control_id": "D6-CTL-06",
      "gaissf_control_title": "Third-Party Ai Vendor Governance",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Defense Evasion",
      "atlas_technique_id": "AML.T0109",
      "atlas_technique_name": "AI Supply Chain Reputation Inflation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0109 AI Supply Chain Reputation Inflation. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0079",
      "gaissf_control_id": "D6-CTL-07",
      "gaissf_control_title": "Ai Resilience & Business Continuity",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Impact",
      "atlas_technique_id": "AML.T0046",
      "atlas_technique_name": "Spamming AI System with Chaff Data",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0046 Spamming AI System with Chaff Data. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0080",
      "gaissf_control_id": "D6-CTL-07",
      "gaissf_control_title": "Ai Resilience & Business Continuity",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "atlas_tactic": "Impact",
      "atlas_technique_id": "AML.T0029",
      "atlas_technique_name": "Denial of AI Service",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0029 Denial of AI Service. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0081",
      "gaissf_control_id": "D7-CTL-H01",
      "gaissf_control_title": "Ai-Generated Phishing Simulation",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0001",
      "atlas_technique_name": "Search Open AI Vulnerability Analysis",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0001 Search Open AI Vulnerability Analysis. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0082",
      "gaissf_control_id": "D7-CTL-H01",
      "gaissf_control_title": "Ai-Generated Phishing Simulation",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0020",
      "atlas_technique_name": "Training Data Poisoning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Training Data Poisoning. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0083",
      "gaissf_control_id": "D7-CTL-H02",
      "gaissf_control_title": "Deepfake Detection Training",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0020",
      "atlas_technique_name": "Training Data Poisoning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Training Data Poisoning. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0084",
      "gaissf_control_id": "D7-CTL-H02",
      "gaissf_control_title": "Deepfake Detection Training",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0042",
      "atlas_technique_name": "Verify Attack",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0085",
      "gaissf_control_id": "D7-CTL-H03",
      "gaissf_control_title": "Out-Of-Band Authentication",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "Impact",
      "atlas_technique_id": "AML.T0048",
      "atlas_technique_name": "External Harms",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0048 External Harms. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0086",
      "gaissf_control_id": "D7-CTL-H03",
      "gaissf_control_title": "Out-Of-Band Authentication",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0064",
      "atlas_technique_name": "Gather RAG-Indexed Targets",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0064 Gather RAG-Indexed Targets. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0087",
      "gaissf_control_id": "D7-CTL-H04",
      "gaissf_control_title": "Ai Social Engineering Ir",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0042",
      "atlas_technique_name": "Verify Attack",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0088",
      "gaissf_control_id": "D7-CTL-H04",
      "gaissf_control_title": "Ai Social Engineering Ir",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "Exfiltration",
      "atlas_technique_id": "AML.T0090",
      "atlas_technique_name": "LLM Response Rendering",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0090 LLM Response Rendering. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0089",
      "gaissf_control_id": "D7-CTL-H05",
      "gaissf_control_title": "Ai-Enhanced External Attack Defense",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "Impact",
      "atlas_technique_id": "AML.T0048",
      "atlas_technique_name": "External Harms",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0048 External Harms. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0090",
      "gaissf_control_id": "D7-CTL-H05",
      "gaissf_control_title": "Ai-Enhanced External Attack Defense",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0052",
      "atlas_technique_name": "Phishing",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0052 Phishing. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0091",
      "gaissf_control_id": "D8-CTL-01",
      "gaissf_control_title": "Eu Ai Act Risk Tier Mapping",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0064",
      "atlas_technique_name": "Gather RAG-Indexed Targets",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0064 Gather RAG-Indexed Targets. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0092",
      "gaissf_control_id": "D8-CTL-01",
      "gaissf_control_title": "Eu Ai Act Risk Tier Mapping",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0087",
      "atlas_technique_name": "Gather Victim Identity Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0087 Gather Victim Identity Information. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0093",
      "gaissf_control_id": "D8-CTL-02",
      "gaissf_control_title": "Iso 42001 Gap Analysis",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0001",
      "atlas_technique_name": "Search Open AI Vulnerability Analysis",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0001 Search Open AI Vulnerability Analysis. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0094",
      "gaissf_control_id": "D8-CTL-02",
      "gaissf_control_title": "Iso 42001 Gap Analysis",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0064",
      "atlas_technique_name": "Gather RAG-Indexed Targets",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0064 Gather RAG-Indexed Targets. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0095",
      "gaissf_control_id": "D8-CTL-03",
      "gaissf_control_title": "Gpai Technical Documentation Verification",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0000",
      "atlas_technique_name": "Search Open Technical Databases",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0000 Search Open Technical Databases. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0096",
      "gaissf_control_id": "D8-CTL-03",
      "gaissf_control_title": "Gpai Technical Documentation Verification",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0020",
      "atlas_technique_name": "Training Data Poisoning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0020 Training Data Poisoning. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0097",
      "gaissf_control_id": "D8-CTL-04",
      "gaissf_control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0106",
      "atlas_technique_name": "Discover AI Agent Configuration",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0106 Discover AI Agent Configuration. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0098",
      "gaissf_control_id": "D8-CTL-04",
      "gaissf_control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0007",
      "atlas_technique_name": "Discover AI Artifacts",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0007 Discover AI Artifacts. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0099",
      "gaissf_control_id": "D8-CTL-05",
      "gaissf_control_title": "Nist Sp 800-218A Compliance Check",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Resource Development",
      "atlas_technique_id": "AML.T0017",
      "atlas_technique_name": "Develop Capabilities",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0017 Develop Capabilities. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0100",
      "gaissf_control_id": "D8-CTL-05",
      "gaissf_control_title": "Nist Sp 800-218A Compliance Check",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "atlas_tactic": "Reconnaissance",
      "atlas_technique_id": "AML.T0064",
      "atlas_technique_name": "Gather RAG-Indexed Targets",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0064 Gather RAG-Indexed Targets. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0101",
      "gaissf_control_id": "D9-CTL-01",
      "gaissf_control_title": "Physical Harm Boundary Enforcement",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0062",
      "atlas_technique_name": "Discover LLM Hallucinations",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0062 Discover LLM Hallucinations. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0102",
      "gaissf_control_id": "D9-CTL-01",
      "gaissf_control_title": "Physical Harm Boundary Enforcement",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0042",
      "atlas_technique_name": "Verify Attack",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-01 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0103",
      "gaissf_control_id": "D9-CTL-02",
      "gaissf_control_title": "Safe State And Graceful Degradation",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0041",
      "atlas_technique_name": "Physical Environment Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0041 Physical Environment Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0104",
      "gaissf_control_id": "D9-CTL-02",
      "gaissf_control_title": "Safe State And Graceful Degradation",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "Persistence",
      "atlas_technique_id": "AML.T0110",
      "atlas_technique_name": "AI Agent Context Poisoning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-02 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0110 AI Agent Context Poisoning. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0105",
      "gaissf_control_id": "D9-CTL-03",
      "gaissf_control_title": "Human Override And Emergency Stop",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0040",
      "atlas_technique_name": "AI Model Inference API Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0040 AI Model Inference API Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0106",
      "gaissf_control_id": "D9-CTL-03",
      "gaissf_control_title": "Human Override And Emergency Stop",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0044",
      "atlas_technique_name": "Full AI Model Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-03 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0044 Full AI Model Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0107",
      "gaissf_control_id": "D9-CTL-04",
      "gaissf_control_title": "Cyber-Physical Attack Detection",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "AI Attack Adaptation",
      "atlas_technique_id": "AML.T0042",
      "atlas_technique_name": "Verify Attack",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0042 Verify Attack. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0108",
      "gaissf_control_id": "D9-CTL-05",
      "gaissf_control_title": "Physical Environment Integrity Monitoring",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0041",
      "atlas_technique_name": "Physical Environment Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0041 Physical Environment Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0109",
      "gaissf_control_id": "D9-CTL-05",
      "gaissf_control_title": "Physical Environment Integrity Monitoring",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0069",
      "atlas_technique_name": "Discover LLM System Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-05 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0069 Discover LLM System Information. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0110",
      "gaissf_control_id": "D9-CTL-06",
      "gaissf_control_title": "Actuator Command Verification",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "Initial Access",
      "atlas_technique_id": "AML.T0015",
      "atlas_technique_name": "Evade AI Model",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0015 Evade AI Model. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0111",
      "gaissf_control_id": "D9-CTL-06",
      "gaissf_control_title": "Actuator Command Verification",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "AI Model Access",
      "atlas_technique_id": "AML.T0041",
      "atlas_technique_name": "Physical Environment Access",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-06 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0041 Physical Environment Access. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    },
    {
      "record_id": "GAISSF-CRO-025-MAP-0112",
      "gaissf_control_id": "D9-CTL-07",
      "gaissf_control_title": "Physical Incident Evidence Preservation",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "atlas_tactic": "Discovery",
      "atlas_technique_id": "AML.T0062",
      "atlas_technique_name": "Discover LLM Hallucinations",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides preventive, detective, governance, or assurance measures relevant to adversary use of AML.T0062 Discover LLM Hallucinations. The mapping records defensive relevance, not technique elimination or verified operating effectiveness.",
      "residual_gap": "Threat modelling, architecture-specific telemetry, adversary emulation, detection engineering, technique currency, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "atlas_source": "MITRE ATLAS v2026.09"
    }
  ],
  "atlas_tactic_to_gaissf_reverse_coverage": [
    {
      "atlas_tactic_id": "AML.TA0002",
      "atlas_tactic": "Reconnaissance",
      "mapped_gaissf_controls": "D5-CTL-05, D5-CTL-06, D6-CTL-01, D6-CTL-02, D6-CTL-04, D7-CTL-H01, D7-CTL-H03, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-05",
      "mapped_priority_techniques": "AML.T0087 Gather Victim Identity Information; AML.T0064 Gather RAG-Indexed Targets; AML.T0001 Search Open AI Vulnerability Analysis; AML.T0000 Search Open Technical Databases",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0003",
      "atlas_tactic": "Resource Development",
      "mapped_gaissf_controls": "D1-CTL-01, D1-CTL-04, D2-CTL-02, D2-CTL-06, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D7-CTL-H01, D7-CTL-H02, D8-CTL-03, D8-CTL-05",
      "mapped_priority_techniques": "AML.T0020 Training Data Poisoning; AML.T0058 Publish Poisoned AI Artifacts: Models; AML.T0065 LLM Prompt Crafting; AML.T0104 Publish Poisoned AI Artifacts: AI Agent Tools; AML.T0017 Develop Capabilities",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0004",
      "atlas_tactic": "Initial Access",
      "mapped_gaissf_controls": "D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D2-CTL-04, D2-CTL-05, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06, D7-CTL-H05",
      "mapped_priority_techniques": "AML.T0015 Evade AI Model; AML.T0010 AI Supply Chain Compromise; AML.T0052 Phishing",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0000",
      "atlas_tactic": "AI Model Access",
      "mapped_gaissf_controls": "D3-CTL-01, D3-CTL-04, D4-CTL-04, D5-CTL-02, D6-CTL-03, D6-CTL-05, D9-CTL-02, D9-CTL-03, D9-CTL-05, D9-CTL-06",
      "mapped_priority_techniques": "AML.T0040 AI Model Inference API Access; AML.T0041 Physical Environment Access; AML.T0044 Full AI Model Access",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0005",
      "atlas_tactic": "Execution",
      "mapped_gaissf_controls": "D2-CTL-01, D2-CTL-02, D3-CTL-02, D3-CTL-05, D3-CTL-07",
      "mapped_priority_techniques": "AML.T0051 LLM Prompt Injection; AML.T0100 AI Agent Clickbait",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0006",
      "atlas_tactic": "Persistence",
      "mapped_gaissf_controls": "D9-CTL-02",
      "mapped_priority_techniques": "AML.T0110 AI Agent Context Poisoning",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0012",
      "atlas_tactic": "Privilege Escalation",
      "mapped_gaissf_controls": "",
      "mapped_priority_techniques": "",
      "coverage_status": "Not Addressed",
      "confidence": "Not Rated",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0007",
      "atlas_tactic": "Defense Evasion",
      "mapped_gaissf_controls": "D1-CTL-06, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06",
      "mapped_priority_techniques": "AML.T0109 AI Supply Chain Reputation Inflation",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0013",
      "atlas_tactic": "Credential Access",
      "mapped_gaissf_controls": "",
      "mapped_priority_techniques": "",
      "coverage_status": "Not Addressed",
      "confidence": "Not Rated",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0008",
      "atlas_tactic": "Discovery",
      "mapped_gaissf_controls": "D5-CTL-01, D5-CTL-03, D5-CTL-04, D5-CTL-05, D8-CTL-04, D9-CTL-01, D9-CTL-05, D9-CTL-07",
      "mapped_priority_techniques": "AML.T0062 Discover LLM Hallucinations; AML.T0106 Discover AI Agent Configuration; AML.T0007 Discover AI Artifacts; AML.T0069 Discover LLM System Information",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0015",
      "atlas_tactic": "Lateral Movement",
      "mapped_gaissf_controls": "",
      "mapped_priority_techniques": "",
      "coverage_status": "Not Addressed",
      "confidence": "Not Rated",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0009",
      "atlas_tactic": "Collection",
      "mapped_gaissf_controls": "",
      "mapped_priority_techniques": "",
      "coverage_status": "Not Addressed",
      "confidence": "Not Rated",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0001",
      "atlas_tactic": "AI Attack Adaptation",
      "mapped_gaissf_controls": "D1-CTL-02, D1-CTL-03, D1-CTL-05, D1-CTL-07, D1-CTL-08, D1-CTL-09, D2-CTL-03, D2-CTL-04, D2-CTL-05, D5-CTL-01, D5-CTL-03, D5-CTL-04, D7-CTL-H02, D7-CTL-H04, D9-CTL-01",
      "mapped_priority_techniques": "AML.T0042 Verify Attack; AML.T0005 Create Proxy AI Model; AML.T0043 Craft Adversarial Data; AML.T0099 Generate Deepfakes",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0014",
      "atlas_tactic": "Command and Control",
      "mapped_gaissf_controls": "",
      "mapped_priority_techniques": "",
      "coverage_status": "Not Addressed",
      "confidence": "Not Rated",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0010",
      "atlas_tactic": "Exfiltration",
      "mapped_gaissf_controls": "D2-CTL-01, D2-CTL-06, D3-CTL-03, D3-CTL-06, D5-CTL-06, D6-CTL-04, D7-CTL-H04",
      "mapped_priority_techniques": "AML.T0056 Extract LLM System Prompt; AML.T0101 Exfiltration via AI Agent Tool Invocation; AML.T0024 Exfiltration via AI Inference API; AML.T0090 LLM Response Rendering",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    },
    {
      "atlas_tactic_id": "AML.TA0011",
      "atlas_tactic": "Impact",
      "mapped_gaissf_controls": "D1-CTL-01, D6-CTL-07, D7-CTL-H03, D7-CTL-H05",
      "mapped_priority_techniques": "AML.T0059 Erode Dataset Integrity; AML.T0046 Spamming AI System with Chaff Data; AML.T0029 Denial of AI Service; AML.T0048 External Harms",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Tactic-level correspondence does not establish prevention, detection, mitigation, evidence sufficiency, operating effectiveness, or exhaustive technique/sub-technique coverage."
    }
  ]
}