{
  "document": {
    "id": "GAISSF-CRO-026",
    "title": "GAISSF™–MITRE ATT&CK Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "classification": "Informative crosswalk / public",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "publication_date": "2026-06-29",
    "verification_date": "2026-10-06"
  },
  "source_baseline": {
    "gaissf": "GAISSF™ v1.0; 59 controls / 9 domains; Applicable-Control Baseline = all 52 controls in D1-D8 plus D9 where Physical AI or cyber-physical actuation is in scope.",
    "mitre_attack": "MITRE ATT&CK Enterprise v19.2; current as of 2026-10-06; v19.0 released 2026-04-28; v19.2 agile update released 2026-08-06.",
    "primary_domain": "Enterprise",
    "excluded_domains": [
      "Mobile",
      "ICS"
    ],
    "source_urls": [
      "https://attack.mitre.org/resources/versions/",
      "https://attack.mitre.org/resources/updates/",
      "https://attack.mitre.org/matrices/enterprise/",
      "https://attack.mitre.org/resources/attack-data-and-tools/"
    ]
  },
  "statistics": {
    "gaissf_controls": 59,
    "enterprise_tactics": 15,
    "priority_techniques": 100,
    "forward_mapping_records": 112,
    "reverse_tactic_records": 15
  },
  "controlled_vocabulary": {
    "relationship": {
      "SP": "Strong partial",
      "P": "Partial",
      "S": "Supporting",
      "C": "Contextual",
      "N": "No material mapping",
      "O": "Outside scope",
      "U": "Unable to determine"
    },
    "confidence": [
      "High",
      "Medium-High",
      "Medium",
      "Low",
      "Not Rated"
    ]
  },
  "limitations": [
    "ATT&CK describes observed adversary behavior and is not a prescriptive control, compliance, certification, or assurance framework.",
    "A mapping does not prove prevention, detection, mitigation effectiveness, test coverage, evidence sufficiency, or operating effectiveness.",
    "The priority technique inventory is a selected Enterprise subset and does not replace the complete official ATT&CK v19.2 dataset.",
    "ATT&CK v19 split the former Enterprise Defense Evasion tactic into Stealth (TA0005) and Defense Impairment (TA0112); the source package used the pre-v19 tactic model and has been reconciled here.",
    "The legacy T1562 Impair Defenses parent entry in the source priority inventory is not a current v19.2 technique entry and is replaced here by T1685 Disable or Modify Tools only for the bounded source context; no automatic inheritance of former T1562 sub-techniques is asserted.",
    "Sub-techniques, procedure examples, current Detection Strategies/Analytics, platforms, groups/software/campaigns, and environment-specific threat relevance require separate analysis.",
    "Mobile and ICS are excluded from this edition and require separate controlled mappings.",
    "D9 is additional/conditional. Where Physical AI is in scope, PAI-SF™ v1.0 may be used alongside GAISSF; CSX-PAISF-004 is mapping only.",
    "ATT&CK major/minor/agile content changes trigger revalidation of affected mapping records.",
    "Independent ATT&CK/crosswalk review and explicit publication approval remain open."
  ],
  "gaissf_controls": [
    {
      "id": "D1-CTL-01",
      "title": "Dataset Provenance & Poisoning Prevention",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-02",
      "title": "Model Extraction Resistance",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-03",
      "title": "Behavioral Drift Detection",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-04",
      "title": "Federated Learning Poisoning Prevention",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-05",
      "title": "Embedding Space Robustness",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-06",
      "title": "Post-Quantum Model Signing & Crypto Hardening",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-07",
      "title": "Lora/Adapter Integrity Verification",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-08",
      "title": "Model Merge Attack Detection",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-09",
      "title": "Quantization Backdoor Screening",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-01",
      "title": "Direct Prompt Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-02",
      "title": "Indirect Prompt Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-03",
      "title": "Jailbreak Resistance Testing",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-04",
      "title": "Multi-Modal Injection Defense",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-05",
      "title": "Function Call/Tool Call Injection Prevention",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-06",
      "title": "Cross-Context Hijacking Mitigation",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-01",
      "title": "Least Agency Enforcement",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-02",
      "title": "Inter-Agent Communication Security",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-03",
      "title": "Agentic Prompt Chaining Detection",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-04",
      "title": "Embodied Ai Safety Controls",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-05",
      "title": "Multi-Agent Trust Chain Attestation",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-06",
      "title": "Persistent Memory Exfiltration Prevention",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-07",
      "title": "Secure Memory Lifecycle Management",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-01",
      "title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-02",
      "title": "Model File & Artifact Scanning",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-03",
      "title": "Model Hub & Registry Vetting",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-04",
      "title": "Mcp Server Behavioral Monitoring",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-05",
      "title": "Third-Party Ai Api Security Assessment",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-06",
      "title": "Shadow Ai Discovery & Governance",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-07",
      "title": "Ai Software Composition Analysis (Sca)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-01",
      "title": "Harmful Content Blocking",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-02",
      "title": "Pii Leakage Prevention",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-03",
      "title": "Copyright Detection",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-04",
      "title": "Ai Watermarking Robustness",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-05",
      "title": "Privacy-By-Design Verification",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-06",
      "title": "Privacy-Preserving Ml Validation",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-01",
      "title": "Human-In-The-Loop For High-Risk Actions",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-02",
      "title": "Audit Trail Completeness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-03",
      "title": "Ai Model Card Completeness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-04",
      "title": "Ai Incident Response Readiness",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-05",
      "title": "Model Deprecation & Decommissioning",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-06",
      "title": "Third-Party Ai Vendor Governance",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-07",
      "title": "Ai Resilience & Business Continuity",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H01",
      "title": "Ai-Generated Phishing Simulation",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H02",
      "title": "Deepfake Detection Training",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H03",
      "title": "Out-Of-Band Authentication",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H04",
      "title": "Ai Social Engineering Ir",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H05",
      "title": "Ai-Enhanced External Attack Defense",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-01",
      "title": "Eu Ai Act Risk Tier Mapping",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-02",
      "title": "Iso 42001 Gap Analysis",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-03",
      "title": "Gpai Technical Documentation Verification",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-04",
      "title": "Dora Ict Incident Reporting (Financial Sector)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-05",
      "title": "Nist Sp 800-218A Compliance Check",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-01",
      "title": "Physical Harm Boundary Enforcement",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-02",
      "title": "Safe State And Graceful Degradation",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-03",
      "title": "Human Override And Emergency Stop",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-04",
      "title": "Cyber-Physical Attack Detection",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-05",
      "title": "Physical Environment Integrity Monitoring",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-06",
      "title": "Actuator Command Verification",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-07",
      "title": "Physical Incident Evidence Preservation",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled threat-informed validation appropriate to the control, system boundary, relevant ATT&CK behaviors and assurance objective. Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked threat model, telemetry, detection, test, incident, red/purple-team and assurance records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    }
  ],
  "attack_tactics": [
    {
      "id": "TA0043",
      "name": "Reconnaissance"
    },
    {
      "id": "TA0042",
      "name": "Resource Development"
    },
    {
      "id": "TA0001",
      "name": "Initial Access"
    },
    {
      "id": "TA0002",
      "name": "Execution"
    },
    {
      "id": "TA0003",
      "name": "Persistence"
    },
    {
      "id": "TA0004",
      "name": "Privilege Escalation"
    },
    {
      "id": "TA0005",
      "name": "Stealth"
    },
    {
      "id": "TA0112",
      "name": "Defense Impairment"
    },
    {
      "id": "TA0006",
      "name": "Credential Access"
    },
    {
      "id": "TA0007",
      "name": "Discovery"
    },
    {
      "id": "TA0008",
      "name": "Lateral Movement"
    },
    {
      "id": "TA0009",
      "name": "Collection"
    },
    {
      "id": "TA0011",
      "name": "Command and Control"
    },
    {
      "id": "TA0010",
      "name": "Exfiltration"
    },
    {
      "id": "TA0040",
      "name": "Impact"
    }
  ],
  "priority_attack_techniques": [
    {
      "id": "T1595",
      "name": "Active Scanning",
      "tactic": "Reconnaissance"
    },
    {
      "id": "T1592",
      "name": "Gather Victim Host Information",
      "tactic": "Reconnaissance"
    },
    {
      "id": "T1589",
      "name": "Gather Victim Identity Information",
      "tactic": "Reconnaissance"
    },
    {
      "id": "T1590",
      "name": "Gather Victim Network Information",
      "tactic": "Reconnaissance"
    },
    {
      "id": "T1591",
      "name": "Gather Victim Org Information",
      "tactic": "Reconnaissance"
    },
    {
      "id": "T1593",
      "name": "Search Open Websites/Domains",
      "tactic": "Reconnaissance"
    },
    {
      "id": "T1594",
      "name": "Search Victim-Owned Websites",
      "tactic": "Reconnaissance"
    },
    {
      "id": "T1596",
      "name": "Search Open Technical Databases",
      "tactic": "Reconnaissance"
    },
    {
      "id": "T1583",
      "name": "Acquire Infrastructure",
      "tactic": "Resource Development"
    },
    {
      "id": "T1584",
      "name": "Compromise Infrastructure",
      "tactic": "Resource Development"
    },
    {
      "id": "T1585",
      "name": "Establish Accounts",
      "tactic": "Resource Development"
    },
    {
      "id": "T1586",
      "name": "Compromise Accounts",
      "tactic": "Resource Development"
    },
    {
      "id": "T1587",
      "name": "Develop Capabilities",
      "tactic": "Resource Development"
    },
    {
      "id": "T1588",
      "name": "Obtain Capabilities",
      "tactic": "Resource Development"
    },
    {
      "id": "T1608",
      "name": "Stage Capabilities",
      "tactic": "Resource Development"
    },
    {
      "id": "T1189",
      "name": "Drive-by Compromise",
      "tactic": "Initial Access"
    },
    {
      "id": "T1190",
      "name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "id": "T1133",
      "name": "External Remote Services",
      "tactic": "Initial Access"
    },
    {
      "id": "T1566",
      "name": "Phishing",
      "tactic": "Initial Access"
    },
    {
      "id": "T1195",
      "name": "Supply Chain Compromise",
      "tactic": "Initial Access"
    },
    {
      "id": "T1078",
      "name": "Valid Accounts",
      "tactic": "Initial Access"
    },
    {
      "id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactic": "Execution"
    },
    {
      "id": "T1203",
      "name": "Exploitation for Client Execution",
      "tactic": "Execution"
    },
    {
      "id": "T1204",
      "name": "User Execution",
      "tactic": "Execution"
    },
    {
      "id": "T1047",
      "name": "Windows Management Instrumentation",
      "tactic": "Execution"
    },
    {
      "id": "T1129",
      "name": "Shared Modules",
      "tactic": "Execution"
    },
    {
      "id": "T1106",
      "name": "Native API",
      "tactic": "Execution"
    },
    {
      "id": "T1053",
      "name": "Scheduled Task/Job",
      "tactic": "Execution"
    },
    {
      "id": "T1127",
      "name": "Trusted Developer Utilities Proxy Execution",
      "tactic": "Execution"
    },
    {
      "id": "T1098",
      "name": "Account Manipulation",
      "tactic": "Persistence"
    },
    {
      "id": "T1547",
      "name": "Boot or Logon Autostart Execution",
      "tactic": "Persistence"
    },
    {
      "id": "T1136",
      "name": "Create Account",
      "tactic": "Persistence"
    },
    {
      "id": "T1505",
      "name": "Server Software Component",
      "tactic": "Persistence"
    },
    {
      "id": "T1525",
      "name": "Implant Internal Image",
      "tactic": "Persistence"
    },
    {
      "id": "T1554",
      "name": "Compromise Host Software Binary",
      "tactic": "Persistence"
    },
    {
      "id": "T1053.003",
      "name": "Scheduled Task/Job: Cron",
      "tactic": "Persistence"
    },
    {
      "id": "T1068",
      "name": "Exploitation for Privilege Escalation",
      "tactic": "Privilege Escalation"
    },
    {
      "id": "T1548",
      "name": "Abuse Elevation Control Mechanism",
      "tactic": "Privilege Escalation"
    },
    {
      "id": "T1134",
      "name": "Access Token Manipulation",
      "tactic": "Privilege Escalation"
    },
    {
      "id": "T1484",
      "name": "Domain or Tenant Policy Modification",
      "tactic": "Privilege Escalation"
    },
    {
      "id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactic": "Stealth"
    },
    {
      "id": "T1070",
      "name": "Indicator Removal",
      "tactic": "Stealth"
    },
    {
      "id": "T1036",
      "name": "Masquerading",
      "tactic": "Stealth"
    },
    {
      "id": "T1685",
      "name": "Disable or Modify Tools",
      "tactic": "Defense Impairment",
      "source_note": "Replaces the legacy pre-v19 T1562 Impair Defenses parent entry used in the source package; current v19.2 technique scope must not be inferred to include every former T1562 sub-technique."
    },
    {
      "id": "T1553",
      "name": "Subvert Trust Controls",
      "tactic": "Defense Impairment"
    },
    {
      "id": "T1218",
      "name": "System Binary Proxy Execution",
      "tactic": "Stealth"
    },
    {
      "id": "T1222",
      "name": "File and Directory Permissions Modification",
      "tactic": "Defense Impairment"
    },
    {
      "id": "T1497",
      "name": "Virtualization/Sandbox Evasion",
      "tactic": "Stealth"
    },
    {
      "id": "T1574",
      "name": "Hijack Execution Flow",
      "tactic": "Stealth"
    },
    {
      "id": "T1110",
      "name": "Brute Force",
      "tactic": "Credential Access"
    },
    {
      "id": "T1555",
      "name": "Credentials from Password Stores",
      "tactic": "Credential Access"
    },
    {
      "id": "T1552",
      "name": "Unsecured Credentials",
      "tactic": "Credential Access"
    },
    {
      "id": "T1003",
      "name": "OS Credential Dumping",
      "tactic": "Credential Access"
    },
    {
      "id": "T1528",
      "name": "Steal Application Access Token",
      "tactic": "Credential Access"
    },
    {
      "id": "T1539",
      "name": "Steal Web Session Cookie",
      "tactic": "Credential Access"
    },
    {
      "id": "T1649",
      "name": "Steal or Forge Authentication Certificates",
      "tactic": "Credential Access"
    },
    {
      "id": "T1621",
      "name": "Multi-Factor Authentication Request Generation",
      "tactic": "Credential Access"
    },
    {
      "id": "T1087",
      "name": "Account Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1580",
      "name": "Cloud Infrastructure Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1613",
      "name": "Container and Resource Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1526",
      "name": "Cloud Service Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1083",
      "name": "File and Directory Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1049",
      "name": "System Network Connections Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1018",
      "name": "Remote System Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1518",
      "name": "Software Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1482",
      "name": "Domain Trust Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1614",
      "name": "System Location Discovery",
      "tactic": "Discovery"
    },
    {
      "id": "T1021",
      "name": "Remote Services",
      "tactic": "Lateral Movement"
    },
    {
      "id": "T1570",
      "name": "Lateral Tool Transfer",
      "tactic": "Lateral Movement"
    },
    {
      "id": "T1210",
      "name": "Exploitation of Remote Services",
      "tactic": "Lateral Movement"
    },
    {
      "id": "T1550",
      "name": "Use Alternate Authentication Material",
      "tactic": "Lateral Movement"
    },
    {
      "id": "T1119",
      "name": "Automated Collection",
      "tactic": "Collection"
    },
    {
      "id": "T1213",
      "name": "Data from Information Repositories",
      "tactic": "Collection"
    },
    {
      "id": "T1530",
      "name": "Data from Cloud Storage",
      "tactic": "Collection"
    },
    {
      "id": "T1114",
      "name": "Email Collection",
      "tactic": "Collection"
    },
    {
      "id": "T1005",
      "name": "Data from Local System",
      "tactic": "Collection"
    },
    {
      "id": "T1074",
      "name": "Data Staged",
      "tactic": "Collection"
    },
    {
      "id": "T1560",
      "name": "Archive Collected Data",
      "tactic": "Collection"
    },
    {
      "id": "T1056",
      "name": "Input Capture",
      "tactic": "Collection"
    },
    {
      "id": "T1071",
      "name": "Application Layer Protocol",
      "tactic": "Command and Control"
    },
    {
      "id": "T1105",
      "name": "Ingress Tool Transfer",
      "tactic": "Command and Control"
    },
    {
      "id": "T1090",
      "name": "Proxy",
      "tactic": "Command and Control"
    },
    {
      "id": "T1219",
      "name": "Remote Access Software",
      "tactic": "Command and Control"
    },
    {
      "id": "T1572",
      "name": "Protocol Tunneling",
      "tactic": "Command and Control"
    },
    {
      "id": "T1102",
      "name": "Web Service",
      "tactic": "Command and Control"
    },
    {
      "id": "T1048",
      "name": "Exfiltration Over Alternative Protocol",
      "tactic": "Exfiltration"
    },
    {
      "id": "T1567",
      "name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    },
    {
      "id": "T1537",
      "name": "Transfer Data to Cloud Account",
      "tactic": "Exfiltration"
    },
    {
      "id": "T1020",
      "name": "Automated Exfiltration",
      "tactic": "Exfiltration"
    },
    {
      "id": "T1041",
      "name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    },
    {
      "id": "T1052",
      "name": "Exfiltration Over Physical Medium",
      "tactic": "Exfiltration"
    },
    {
      "id": "T1486",
      "name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "id": "T1485",
      "name": "Data Destruction",
      "tactic": "Impact"
    },
    {
      "id": "T1490",
      "name": "Inhibit System Recovery",
      "tactic": "Impact"
    },
    {
      "id": "T1498",
      "name": "Network Denial of Service",
      "tactic": "Impact"
    },
    {
      "id": "T1499",
      "name": "Endpoint Denial of Service",
      "tactic": "Impact"
    },
    {
      "id": "T1565",
      "name": "Data Manipulation",
      "tactic": "Impact"
    },
    {
      "id": "T1531",
      "name": "Account Access Removal",
      "tactic": "Impact"
    },
    {
      "id": "T1529",
      "name": "System Shutdown/Reboot",
      "tactic": "Impact"
    },
    {
      "id": "T1657",
      "name": "Financial Theft",
      "tactic": "Impact"
    }
  ],
  "forward_mappings": [
    {
      "record_id": "GAISSF-CRO-026-MAP-0001",
      "gaissf_control_id": "D1-CTL-01",
      "gaissf_control_title": "Dataset Provenance & Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0002",
      "gaissf_control_id": "D1-CTL-01",
      "gaissf_control_title": "Dataset Provenance & Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1554",
      "attack_technique_name": "Compromise Host Software Binary",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1554 Compromise Host Software Binary. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0003",
      "gaissf_control_id": "D1-CTL-02",
      "gaissf_control_title": "Model Extraction Resistance",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0004",
      "gaissf_control_id": "D1-CTL-02",
      "gaissf_control_title": "Model Extraction Resistance",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1554",
      "attack_technique_name": "Compromise Host Software Binary",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1554 Compromise Host Software Binary. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0005",
      "gaissf_control_id": "D1-CTL-03",
      "gaissf_control_title": "Behavioral Drift Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0006",
      "gaissf_control_id": "D1-CTL-03",
      "gaissf_control_title": "Behavioral Drift Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1554",
      "attack_technique_name": "Compromise Host Software Binary",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1554 Compromise Host Software Binary. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0007",
      "gaissf_control_id": "D1-CTL-04",
      "gaissf_control_title": "Federated Learning Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0008",
      "gaissf_control_id": "D1-CTL-04",
      "gaissf_control_title": "Federated Learning Poisoning Prevention",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1554",
      "attack_technique_name": "Compromise Host Software Binary",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1554 Compromise Host Software Binary. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0009",
      "gaissf_control_id": "D1-CTL-05",
      "gaissf_control_title": "Embedding Space Robustness",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0010",
      "gaissf_control_id": "D1-CTL-05",
      "gaissf_control_title": "Embedding Space Robustness",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1554",
      "attack_technique_name": "Compromise Host Software Binary",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1554 Compromise Host Software Binary. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0011",
      "gaissf_control_id": "D1-CTL-06",
      "gaissf_control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0012",
      "gaissf_control_id": "D1-CTL-07",
      "gaissf_control_title": "Lora/Adapter Integrity Verification",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0013",
      "gaissf_control_id": "D1-CTL-07",
      "gaissf_control_title": "Lora/Adapter Integrity Verification",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1554",
      "attack_technique_name": "Compromise Host Software Binary",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1554 Compromise Host Software Binary. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0014",
      "gaissf_control_id": "D1-CTL-08",
      "gaissf_control_title": "Model Merge Attack Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-08 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0015",
      "gaissf_control_id": "D1-CTL-08",
      "gaissf_control_title": "Model Merge Attack Detection",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1554",
      "attack_technique_name": "Compromise Host Software Binary",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-08 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1554 Compromise Host Software Binary. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0016",
      "gaissf_control_id": "D1-CTL-09",
      "gaissf_control_title": "Quantization Backdoor Screening",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-09 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0017",
      "gaissf_control_id": "D1-CTL-09",
      "gaissf_control_title": "Quantization Backdoor Screening",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1554",
      "attack_technique_name": "Compromise Host Software Binary",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D1-CTL-09 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1554 Compromise Host Software Binary. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0018",
      "gaissf_control_id": "D2-CTL-01",
      "gaissf_control_title": "Direct Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1078",
      "attack_technique_name": "Valid Accounts",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1078 Valid Accounts. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0019",
      "gaissf_control_id": "D2-CTL-01",
      "gaissf_control_title": "Direct Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Stealth",
      "attack_technique_id": "T1218",
      "attack_technique_name": "System Binary Proxy Execution",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1218 System Binary Proxy Execution. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0020",
      "gaissf_control_id": "D2-CTL-02",
      "gaissf_control_title": "Indirect Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1485",
      "attack_technique_name": "Data Destruction",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1485 Data Destruction. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0021",
      "gaissf_control_id": "D2-CTL-02",
      "gaissf_control_title": "Indirect Prompt Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0022",
      "gaissf_control_id": "D2-CTL-03",
      "gaissf_control_title": "Jailbreak Resistance Testing",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1078",
      "attack_technique_name": "Valid Accounts",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1078 Valid Accounts. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0023",
      "gaissf_control_id": "D2-CTL-03",
      "gaissf_control_title": "Jailbreak Resistance Testing",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Collection",
      "attack_technique_id": "T1119",
      "attack_technique_name": "Automated Collection",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1119 Automated Collection. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0024",
      "gaissf_control_id": "D2-CTL-04",
      "gaissf_control_title": "Multi-Modal Injection Defense",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0025",
      "gaissf_control_id": "D2-CTL-04",
      "gaissf_control_title": "Multi-Modal Injection Defense",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Execution",
      "attack_technique_id": "T1059",
      "attack_technique_name": "Command and Scripting Interpreter",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1059 Command and Scripting Interpreter. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0026",
      "gaissf_control_id": "D2-CTL-05",
      "gaissf_control_title": "Function Call/Tool Call Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1078",
      "attack_technique_name": "Valid Accounts",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1078 Valid Accounts. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0027",
      "gaissf_control_id": "D2-CTL-05",
      "gaissf_control_title": "Function Call/Tool Call Injection Prevention",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Execution",
      "attack_technique_id": "T1203",
      "attack_technique_name": "Exploitation for Client Execution",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1203 Exploitation for Client Execution. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0028",
      "gaissf_control_id": "D2-CTL-06",
      "gaissf_control_title": "Cross-Context Hijacking Mitigation",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Execution",
      "attack_technique_id": "T1047",
      "attack_technique_name": "Windows Management Instrumentation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1047 Windows Management Instrumentation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0029",
      "gaissf_control_id": "D2-CTL-06",
      "gaissf_control_title": "Cross-Context Hijacking Mitigation",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "attack_tactic": "Stealth",
      "attack_technique_id": "T1218",
      "attack_technique_name": "System Binary Proxy Execution",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D2-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1218 System Binary Proxy Execution. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0030",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1133",
      "attack_technique_name": "External Remote Services",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1133 External Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0031",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Lateral Movement",
      "attack_technique_id": "T1021",
      "attack_technique_name": "Remote Services",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1021 Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0032",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Lateral Movement",
      "attack_technique_id": "T1210",
      "attack_technique_name": "Exploitation of Remote Services",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1210 Exploitation of Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0033",
      "gaissf_control_id": "D3-CTL-02",
      "gaissf_control_title": "Inter-Agent Communication Security",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Stealth",
      "attack_technique_id": "T1218",
      "attack_technique_name": "System Binary Proxy Execution",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1218 System Binary Proxy Execution. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0034",
      "gaissf_control_id": "D3-CTL-02",
      "gaissf_control_title": "Inter-Agent Communication Security",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1133",
      "attack_technique_name": "External Remote Services",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1133 External Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0035",
      "gaissf_control_id": "D3-CTL-03",
      "gaissf_control_title": "Agentic Prompt Chaining Detection",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Stealth",
      "attack_technique_id": "T1218",
      "attack_technique_name": "System Binary Proxy Execution",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1218 System Binary Proxy Execution. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0036",
      "gaissf_control_id": "D3-CTL-03",
      "gaissf_control_title": "Agentic Prompt Chaining Detection",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1133",
      "attack_technique_name": "External Remote Services",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1133 External Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0037",
      "gaissf_control_id": "D3-CTL-04",
      "gaissf_control_title": "Embodied Ai Safety Controls",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Execution",
      "attack_technique_id": "T1059",
      "attack_technique_name": "Command and Scripting Interpreter",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1059 Command and Scripting Interpreter. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0038",
      "gaissf_control_id": "D3-CTL-04",
      "gaissf_control_title": "Embodied Ai Safety Controls",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Defense Impairment",
      "attack_technique_id": "T1553",
      "attack_technique_name": "Subvert Trust Controls",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1553 Subvert Trust Controls. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0039",
      "gaissf_control_id": "D3-CTL-05",
      "gaissf_control_title": "Multi-Agent Trust Chain Attestation",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1589",
      "attack_technique_name": "Gather Victim Identity Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1589 Gather Victim Identity Information. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0040",
      "gaissf_control_id": "D3-CTL-05",
      "gaissf_control_title": "Multi-Agent Trust Chain Attestation",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Stealth",
      "attack_technique_id": "T1218",
      "attack_technique_name": "System Binary Proxy Execution",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1218 System Binary Proxy Execution. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0041",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1133",
      "attack_technique_name": "External Remote Services",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1133 External Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0042",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Lateral Movement",
      "attack_technique_id": "T1021",
      "attack_technique_name": "Remote Services",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1021 Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0043",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Lateral Movement",
      "attack_technique_id": "T1210",
      "attack_technique_name": "Exploitation of Remote Services",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1210 Exploitation of Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0044",
      "gaissf_control_id": "D3-CTL-07",
      "gaissf_control_title": "Secure Memory Lifecycle Management",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Stealth",
      "attack_technique_id": "T1218",
      "attack_technique_name": "System Binary Proxy Execution",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1218 System Binary Proxy Execution. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0045",
      "gaissf_control_id": "D3-CTL-07",
      "gaissf_control_title": "Secure Memory Lifecycle Management",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1133",
      "attack_technique_name": "External Remote Services",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D3-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1133 External Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0046",
      "gaissf_control_id": "D4-CTL-01",
      "gaissf_control_title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0047",
      "gaissf_control_id": "D4-CTL-01",
      "gaissf_control_title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Resource Development",
      "attack_technique_id": "T1584",
      "attack_technique_name": "Compromise Infrastructure",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1584 Compromise Infrastructure. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0048",
      "gaissf_control_id": "D4-CTL-02",
      "gaissf_control_title": "Model File & Artifact Scanning",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0049",
      "gaissf_control_id": "D4-CTL-02",
      "gaissf_control_title": "Model File & Artifact Scanning",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Resource Development",
      "attack_technique_id": "T1584",
      "attack_technique_name": "Compromise Infrastructure",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1584 Compromise Infrastructure. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0050",
      "gaissf_control_id": "D4-CTL-03",
      "gaissf_control_title": "Model Hub & Registry Vetting",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0051",
      "gaissf_control_id": "D4-CTL-03",
      "gaissf_control_title": "Model Hub & Registry Vetting",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Resource Development",
      "attack_technique_id": "T1584",
      "attack_technique_name": "Compromise Infrastructure",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1584 Compromise Infrastructure. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0052",
      "gaissf_control_id": "D4-CTL-04",
      "gaissf_control_title": "Mcp Server Behavioral Monitoring",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0053",
      "gaissf_control_id": "D4-CTL-04",
      "gaissf_control_title": "Mcp Server Behavioral Monitoring",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Resource Development",
      "attack_technique_id": "T1584",
      "attack_technique_name": "Compromise Infrastructure",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1584 Compromise Infrastructure. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0054",
      "gaissf_control_id": "D4-CTL-05",
      "gaissf_control_title": "Third-Party Ai Api Security Assessment",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0055",
      "gaissf_control_id": "D4-CTL-05",
      "gaissf_control_title": "Third-Party Ai Api Security Assessment",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Resource Development",
      "attack_technique_id": "T1584",
      "attack_technique_name": "Compromise Infrastructure",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1584 Compromise Infrastructure. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0056",
      "gaissf_control_id": "D4-CTL-06",
      "gaissf_control_title": "Shadow Ai Discovery & Governance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0057",
      "gaissf_control_id": "D4-CTL-06",
      "gaissf_control_title": "Shadow Ai Discovery & Governance",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Discovery",
      "attack_technique_id": "T1049",
      "attack_technique_name": "System Network Connections Discovery",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1049 System Network Connections Discovery. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0058",
      "gaissf_control_id": "D4-CTL-07",
      "gaissf_control_title": "Ai Software Composition Analysis (Sca)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0059",
      "gaissf_control_id": "D4-CTL-07",
      "gaissf_control_title": "Ai Software Composition Analysis (Sca)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "attack_tactic": "Resource Development",
      "attack_technique_id": "T1584",
      "attack_technique_name": "Compromise Infrastructure",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D4-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1584 Compromise Infrastructure. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0060",
      "gaissf_control_id": "D5-CTL-01",
      "gaissf_control_title": "Harmful Content Blocking",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0061",
      "gaissf_control_id": "D5-CTL-02",
      "gaissf_control_title": "Pii Leakage Prevention",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0062",
      "gaissf_control_id": "D5-CTL-03",
      "gaissf_control_title": "Copyright Detection",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0063",
      "gaissf_control_id": "D5-CTL-04",
      "gaissf_control_title": "Ai Watermarking Robustness",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0064",
      "gaissf_control_id": "D5-CTL-05",
      "gaissf_control_title": "Privacy-By-Design Verification",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0065",
      "gaissf_control_id": "D5-CTL-06",
      "gaissf_control_title": "Privacy-Preserving Ml Validation",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0066",
      "gaissf_control_id": "D6-CTL-01",
      "gaissf_control_title": "Human-In-The-Loop For High-Risk Actions",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1098",
      "attack_technique_name": "Account Manipulation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1098 Account Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0067",
      "gaissf_control_id": "D6-CTL-01",
      "gaissf_control_title": "Human-In-The-Loop For High-Risk Actions",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1136",
      "attack_technique_name": "Create Account",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1136 Create Account. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0068",
      "gaissf_control_id": "D6-CTL-02",
      "gaissf_control_title": "Audit Trail Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Discovery",
      "attack_technique_id": "T1087",
      "attack_technique_name": "Account Discovery",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1087 Account Discovery. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0069",
      "gaissf_control_id": "D6-CTL-02",
      "gaissf_control_title": "Audit Trail Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Stealth",
      "attack_technique_id": "T1070",
      "attack_technique_name": "Indicator Removal",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1070 Indicator Removal. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0070",
      "gaissf_control_id": "D6-CTL-03",
      "gaissf_control_title": "Ai Model Card Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1190",
      "attack_technique_name": "Exploit Public-Facing Application",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1190 Exploit Public-Facing Application. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0071",
      "gaissf_control_id": "D6-CTL-03",
      "gaissf_control_title": "Ai Model Card Completeness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1133",
      "attack_technique_name": "External Remote Services",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1133 External Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0072",
      "gaissf_control_id": "D6-CTL-04",
      "gaissf_control_title": "Ai Incident Response Readiness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1098",
      "attack_technique_name": "Account Manipulation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1098 Account Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0073",
      "gaissf_control_id": "D6-CTL-04",
      "gaissf_control_title": "Ai Incident Response Readiness",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Persistence",
      "attack_technique_id": "T1136",
      "attack_technique_name": "Create Account",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1136 Create Account. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0074",
      "gaissf_control_id": "D6-CTL-05",
      "gaissf_control_title": "Model Deprecation & Decommissioning",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1190",
      "attack_technique_name": "Exploit Public-Facing Application",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1190 Exploit Public-Facing Application. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0075",
      "gaissf_control_id": "D6-CTL-05",
      "gaissf_control_title": "Model Deprecation & Decommissioning",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1133",
      "attack_technique_name": "External Remote Services",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1133 External Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0076",
      "gaissf_control_id": "D6-CTL-06",
      "gaissf_control_title": "Third-Party Ai Vendor Governance",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0077",
      "gaissf_control_id": "D6-CTL-06",
      "gaissf_control_title": "Third-Party Ai Vendor Governance",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Resource Development",
      "attack_technique_id": "T1584",
      "attack_technique_name": "Compromise Infrastructure",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1584 Compromise Infrastructure. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0078",
      "gaissf_control_id": "D6-CTL-07",
      "gaissf_control_title": "Ai Resilience & Business Continuity",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1490",
      "attack_technique_name": "Inhibit System Recovery",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1490 Inhibit System Recovery. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0079",
      "gaissf_control_id": "D6-CTL-07",
      "gaissf_control_title": "Ai Resilience & Business Continuity",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1529",
      "attack_technique_name": "System Shutdown/Reboot",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D6-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1529 System Shutdown/Reboot. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0080",
      "gaissf_control_id": "D7-CTL-H01",
      "gaissf_control_title": "Ai-Generated Phishing Simulation",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1566",
      "attack_technique_name": "Phishing",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1566 Phishing. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0081",
      "gaissf_control_id": "D7-CTL-H01",
      "gaissf_control_title": "Ai-Generated Phishing Simulation",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0082",
      "gaissf_control_id": "D7-CTL-H02",
      "gaissf_control_title": "Deepfake Detection Training",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Execution",
      "attack_technique_id": "T1129",
      "attack_technique_name": "Shared Modules",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1129 Shared Modules. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0083",
      "gaissf_control_id": "D7-CTL-H02",
      "gaissf_control_title": "Deepfake Detection Training",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0084",
      "gaissf_control_id": "D7-CTL-H03",
      "gaissf_control_title": "Out-Of-Band Authentication",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Privilege Escalation",
      "attack_technique_id": "T1484",
      "attack_technique_name": "Domain or Tenant Policy Modification",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1484 Domain or Tenant Policy Modification. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0085",
      "gaissf_control_id": "D7-CTL-H03",
      "gaissf_control_title": "Out-Of-Band Authentication",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Credential Access",
      "attack_technique_id": "T1110",
      "attack_technique_name": "Brute Force",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1110 Brute Force. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0086",
      "gaissf_control_id": "D7-CTL-H04",
      "gaissf_control_title": "Ai Social Engineering Ir",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0087",
      "gaissf_control_id": "D7-CTL-H04",
      "gaissf_control_title": "Ai Social Engineering Ir",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1592",
      "attack_technique_name": "Gather Victim Host Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1592 Gather Victim Host Information. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0088",
      "gaissf_control_id": "D7-CTL-H05",
      "gaissf_control_title": "Ai-Enhanced External Attack Defense",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1133",
      "attack_technique_name": "External Remote Services",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1133 External Remote Services. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0089",
      "gaissf_control_id": "D7-CTL-H05",
      "gaissf_control_title": "Ai-Enhanced External Attack Defense",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1566",
      "attack_technique_name": "Phishing",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D7-CTL-H05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1566 Phishing. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0090",
      "gaissf_control_id": "D8-CTL-01",
      "gaissf_control_title": "Eu Ai Act Risk Tier Mapping",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0091",
      "gaissf_control_id": "D8-CTL-01",
      "gaissf_control_title": "Eu Ai Act Risk Tier Mapping",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1592",
      "attack_technique_name": "Gather Victim Host Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1592 Gather Victim Host Information. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0092",
      "gaissf_control_id": "D8-CTL-02",
      "gaissf_control_title": "Iso 42001 Gap Analysis",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0093",
      "gaissf_control_id": "D8-CTL-02",
      "gaissf_control_title": "Iso 42001 Gap Analysis",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1592",
      "attack_technique_name": "Gather Victim Host Information",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1592 Gather Victim Host Information. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0094",
      "gaissf_control_id": "D8-CTL-03",
      "gaissf_control_title": "Gpai Technical Documentation Verification",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1596",
      "attack_technique_name": "Search Open Technical Databases",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1596 Search Open Technical Databases. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0095",
      "gaissf_control_id": "D8-CTL-03",
      "gaissf_control_title": "Gpai Technical Documentation Verification",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0096",
      "gaissf_control_id": "D8-CTL-04",
      "gaissf_control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1657",
      "attack_technique_name": "Financial Theft",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1657 Financial Theft. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0097",
      "gaissf_control_id": "D8-CTL-04",
      "gaissf_control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0098",
      "gaissf_control_id": "D8-CTL-05",
      "gaissf_control_title": "Nist Sp 800-218A Compliance Check",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Resource Development",
      "attack_technique_id": "T1587",
      "attack_technique_name": "Develop Capabilities",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1587 Develop Capabilities. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0099",
      "gaissf_control_id": "D8-CTL-05",
      "gaissf_control_title": "Nist Sp 800-218A Compliance Check",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "attack_tactic": "Reconnaissance",
      "attack_technique_id": "T1595",
      "attack_technique_name": "Active Scanning",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D8-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1595 Active Scanning. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0100",
      "gaissf_control_id": "D9-CTL-01",
      "gaissf_control_title": "Physical Harm Boundary Enforcement",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Exfiltration",
      "attack_technique_id": "T1052",
      "attack_technique_name": "Exfiltration Over Physical Medium",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1052 Exfiltration Over Physical Medium. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0101",
      "gaissf_control_id": "D9-CTL-01",
      "gaissf_control_title": "Physical Harm Boundary Enforcement",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-01 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0102",
      "gaissf_control_id": "D9-CTL-02",
      "gaissf_control_title": "Safe State And Graceful Degradation",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Exfiltration",
      "attack_technique_id": "T1052",
      "attack_technique_name": "Exfiltration Over Physical Medium",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1052 Exfiltration Over Physical Medium. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0103",
      "gaissf_control_id": "D9-CTL-02",
      "gaissf_control_title": "Safe State And Graceful Degradation",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1490",
      "attack_technique_name": "Inhibit System Recovery",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-02 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1490 Inhibit System Recovery. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0104",
      "gaissf_control_id": "D9-CTL-03",
      "gaissf_control_title": "Human Override And Emergency Stop",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Exfiltration",
      "attack_technique_id": "T1052",
      "attack_technique_name": "Exfiltration Over Physical Medium",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1052 Exfiltration Over Physical Medium. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0105",
      "gaissf_control_id": "D9-CTL-03",
      "gaissf_control_title": "Human Override And Emergency Stop",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1190",
      "attack_technique_name": "Exploit Public-Facing Application",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-03 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1190 Exploit Public-Facing Application. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0106",
      "gaissf_control_id": "D9-CTL-04",
      "gaissf_control_title": "Cyber-Physical Attack Detection",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Exfiltration",
      "attack_technique_id": "T1052",
      "attack_technique_name": "Exfiltration Over Physical Medium",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1052 Exfiltration Over Physical Medium. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0107",
      "gaissf_control_id": "D9-CTL-04",
      "gaissf_control_title": "Cyber-Physical Attack Detection",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1078",
      "attack_technique_name": "Valid Accounts",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-04 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1078 Valid Accounts. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0108",
      "gaissf_control_id": "D9-CTL-05",
      "gaissf_control_title": "Physical Environment Integrity Monitoring",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Exfiltration",
      "attack_technique_id": "T1052",
      "attack_technique_name": "Exfiltration Over Physical Medium",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1052 Exfiltration Over Physical Medium. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0109",
      "gaissf_control_id": "D9-CTL-05",
      "gaissf_control_title": "Physical Environment Integrity Monitoring",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Initial Access",
      "attack_technique_id": "T1195",
      "attack_technique_name": "Supply Chain Compromise",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-05 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1195 Supply Chain Compromise. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0110",
      "gaissf_control_id": "D9-CTL-06",
      "gaissf_control_title": "Actuator Command Verification",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Exfiltration",
      "attack_technique_id": "T1052",
      "attack_technique_name": "Exfiltration Over Physical Medium",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1052 Exfiltration Over Physical Medium. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0111",
      "gaissf_control_id": "D9-CTL-06",
      "gaissf_control_title": "Actuator Command Verification",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Stealth",
      "attack_technique_id": "T1218",
      "attack_technique_name": "System Binary Proxy Execution",
      "relationship": "S",
      "confidence": "Low",
      "rationale": "GAISSF D9-CTL-06 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1218 System Binary Proxy Execution. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    },
    {
      "record_id": "GAISSF-CRO-026-MAP-0112",
      "gaissf_control_id": "D9-CTL-07",
      "gaissf_control_title": "Physical Incident Evidence Preservation",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "attack_tactic": "Impact",
      "attack_technique_id": "T1565",
      "attack_technique_name": "Data Manipulation",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides preventive, detective, governance, resilience, or assurance measures materially relevant to adversary behavior described by ATT&CK technique T1565 Data Manipulation. The relationship is defensive and contextual; it does not assert that the technique is eliminated, detected, or tested in a particular environment.",
      "residual_gap": "Environment-specific threat intelligence, sub-technique/procedure analysis, platform scope, telemetry engineering, detection-strategy/analytic selection, adversary emulation, evidence sufficiency and operating-effectiveness testing remain necessary.",
      "expected_evidence": "",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "attack_source": "MITRE ATT&CK Enterprise v19.2"
    }
  ],
  "reverse_tactic_coverage": [
    {
      "attack_tactic_id": "TA0043",
      "attack_tactic": "Reconnaissance",
      "mapped_gaissf_controls": "D2-CTL-04, D3-CTL-05, D7-CTL-H01, D7-CTL-H02, D7-CTL-H04, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-04, D8-CTL-05",
      "mapped_priority_techniques": "T1589 Gather Victim Identity Information; T1592 Gather Victim Host Information; T1595 Active Scanning; T1596 Search Open Technical Databases",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium-High",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0042",
      "attack_tactic": "Resource Development",
      "mapped_gaissf_controls": "D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-07, D6-CTL-06, D8-CTL-05",
      "mapped_priority_techniques": "T1584 Compromise Infrastructure; T1587 Develop Capabilities",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium-High",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0001",
      "attack_tactic": "Initial Access",
      "mapped_gaissf_controls": "D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D1-CTL-09, D2-CTL-01, D2-CTL-03, D2-CTL-05, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-06, D3-CTL-07, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-03, D6-CTL-05, D6-CTL-06, D7-CTL-H01, D7-CTL-H05, D9-CTL-03, D9-CTL-04, D9-CTL-05",
      "mapped_priority_techniques": "T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium-High",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0002",
      "attack_tactic": "Execution",
      "mapped_gaissf_controls": "D2-CTL-04, D2-CTL-05, D2-CTL-06, D3-CTL-04, D7-CTL-H02",
      "mapped_priority_techniques": "T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1129 Shared Modules; T1203 Exploitation for Client Execution",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0003",
      "attack_tactic": "Persistence",
      "mapped_gaissf_controls": "D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-07, D1-CTL-08, D1-CTL-09, D6-CTL-01, D6-CTL-04",
      "mapped_priority_techniques": "T1098 Account Manipulation; T1136 Create Account; T1554 Compromise Host Software Binary",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium-High",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0004",
      "attack_tactic": "Privilege Escalation",
      "mapped_gaissf_controls": "D7-CTL-H03",
      "mapped_priority_techniques": "T1484 Domain or Tenant Policy Modification",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0005",
      "attack_tactic": "Stealth",
      "mapped_gaissf_controls": "D2-CTL-01, D2-CTL-06, D3-CTL-02, D3-CTL-03, D3-CTL-05, D3-CTL-07, D6-CTL-02, D9-CTL-06",
      "mapped_priority_techniques": "T1070 Indicator Removal; T1218 System Binary Proxy Execution",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium-High",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0112",
      "attack_tactic": "Defense Impairment",
      "mapped_gaissf_controls": "D3-CTL-04",
      "mapped_priority_techniques": "T1553 Subvert Trust Controls",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0006",
      "attack_tactic": "Credential Access",
      "mapped_gaissf_controls": "D7-CTL-H03",
      "mapped_priority_techniques": "T1110 Brute Force",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0007",
      "attack_tactic": "Discovery",
      "mapped_gaissf_controls": "D4-CTL-06, D6-CTL-02",
      "mapped_priority_techniques": "T1049 System Network Connections Discovery; T1087 Account Discovery",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0008",
      "attack_tactic": "Lateral Movement",
      "mapped_gaissf_controls": "D3-CTL-01, D3-CTL-06",
      "mapped_priority_techniques": "T1021 Remote Services; T1210 Exploitation of Remote Services",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0009",
      "attack_tactic": "Collection",
      "mapped_gaissf_controls": "D2-CTL-03",
      "mapped_priority_techniques": "T1119 Automated Collection",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0011",
      "attack_tactic": "Command and Control",
      "mapped_gaissf_controls": "",
      "mapped_priority_techniques": "",
      "coverage_status": "Not Addressed",
      "confidence": "Not Rated",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0010",
      "attack_tactic": "Exfiltration",
      "mapped_gaissf_controls": "D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-06",
      "mapped_priority_techniques": "T1052 Exfiltration Over Physical Medium",
      "coverage_status": "Partially Addressed",
      "confidence": "Medium",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    },
    {
      "attack_tactic_id": "TA0040",
      "attack_tactic": "Impact",
      "mapped_gaissf_controls": "D2-CTL-02, D5-CTL-01, D5-CTL-02, D5-CTL-03, D5-CTL-04, D5-CTL-05, D5-CTL-06, D6-CTL-07, D8-CTL-04, D9-CTL-01, D9-CTL-02, D9-CTL-07",
      "mapped_priority_techniques": "T1485 Data Destruction; T1490 Inhibit System Recovery; T1529 System Shutdown/Reboot; T1565 Data Manipulation; T1657 Financial Theft",
      "coverage_status": "Substantially Addressed",
      "confidence": "Medium-High",
      "residual_gap": "Priority-set tactic coverage does not establish complete ATT&CK Enterprise technique/sub-technique coverage, procedure coverage, platform-specific detection coverage, validated telemetry, evidence sufficiency or operating effectiveness."
    }
  ]
}