{
  "meta": {
    "document_id": "GAISSF-CRO-032",
    "title": "GAISSF-PCI DSS Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "publication_date": "29 June 2026",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "gaissf_baseline": "GAISSF v1.0, 59 controls",
    "external_baseline": "PCI DSS v4.0.1",
    "verification_date": "29 June 2026",
    "scope": "All 12 principal PCI DSS requirements at requirement-family level. Subrequirements and testing procedures remain authoritative in the official standard."
  },
  "controls": [
    {
      "id": "D1-CTL-01",
      "title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-02",
      "title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-03",
      "title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-04",
      "title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-05",
      "title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-06",
      "title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-07",
      "title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-08",
      "title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-09",
      "title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-01",
      "title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-02",
      "title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-03",
      "title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-04",
      "title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-05",
      "title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-06",
      "title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-01",
      "title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-02",
      "title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-03",
      "title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-04",
      "title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-05",
      "title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-06",
      "title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-07",
      "title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-01",
      "title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-02",
      "title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-03",
      "title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-04",
      "title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-05",
      "title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-06",
      "title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-07",
      "title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-01",
      "title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-02",
      "title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-03",
      "title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-04",
      "title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-05",
      "title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-06",
      "title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-01",
      "title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-02",
      "title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-03",
      "title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-04",
      "title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-05",
      "title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-06",
      "title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-07",
      "title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H01",
      "title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H02",
      "title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H03",
      "title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H04",
      "title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H05",
      "title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-01",
      "title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-02",
      "title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-03",
      "title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-04",
      "title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-05",
      "title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D9-CTL-01",
      "title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-02",
      "title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-03",
      "title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-04",
      "title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-05",
      "title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-06",
      "title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-07",
      "title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    }
  ],
  "requirements": [
    {
      "id": "1",
      "title": "Install and maintain network security controls",
      "goal": "Build and Maintain a Secure Network and Systems",
      "terms": [
        "network",
        "boundary",
        "firewall",
        "segmentation",
        "architecture",
        "traffic",
        "access"
      ]
    },
    {
      "id": "2",
      "title": "Apply secure configurations to all system components",
      "goal": "Build and Maintain a Secure Network and Systems",
      "terms": [
        "configuration",
        "hardening",
        "baseline",
        "default",
        "inventory",
        "system component"
      ]
    },
    {
      "id": "3",
      "title": "Protect stored account data",
      "goal": "Protect Account Data",
      "terms": [
        "data",
        "storage",
        "encryption",
        "retention",
        "disposal",
        "confidential",
        "privacy"
      ]
    },
    {
      "id": "4",
      "title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "goal": "Protect Account Data",
      "terms": [
        "transmission",
        "encryption",
        "cryptography",
        "network",
        "transport",
        "data"
      ]
    },
    {
      "id": "5",
      "title": "Protect all systems and networks from malicious software",
      "goal": "Maintain a Vulnerability Management Program",
      "terms": [
        "malware",
        "malicious",
        "runtime",
        "detection",
        "prevention",
        "adversarial"
      ]
    },
    {
      "id": "6",
      "title": "Develop and maintain secure systems and software",
      "goal": "Maintain a Vulnerability Management Program",
      "terms": [
        "development",
        "software",
        "vulnerability",
        "patch",
        "change",
        "secure",
        "testing",
        "supply chain"
      ]
    },
    {
      "id": "7",
      "title": "Restrict access to system components and cardholder data by business need to know",
      "goal": "Implement Strong Access Control Measures",
      "terms": [
        "access",
        "authorization",
        "least privilege",
        "role",
        "need",
        "identity"
      ]
    },
    {
      "id": "8",
      "title": "Identify users and authenticate access to system components",
      "goal": "Implement Strong Access Control Measures",
      "terms": [
        "identity",
        "authentication",
        "credential",
        "user",
        "access",
        "mfa"
      ]
    },
    {
      "id": "9",
      "title": "Restrict physical access to cardholder data",
      "goal": "Implement Strong Access Control Measures",
      "terms": [
        "physical",
        "facility",
        "device",
        "media",
        "access",
        "tamper"
      ]
    },
    {
      "id": "10",
      "title": "Log and monitor all access to system components and cardholder data",
      "goal": "Regularly Monitor and Test Networks",
      "terms": [
        "log",
        "monitor",
        "telemetry",
        "event",
        "audit",
        "access",
        "detection"
      ]
    },
    {
      "id": "11",
      "title": "Test security of systems and networks regularly",
      "goal": "Regularly Monitor and Test Networks",
      "terms": [
        "test",
        "assessment",
        "penetration",
        "vulnerability",
        "validation",
        "monitor",
        "security"
      ]
    },
    {
      "id": "12",
      "title": "Support information security with organizational policies and programs",
      "goal": "Maintain an Information Security Policy",
      "terms": [
        "governance",
        "policy",
        "risk",
        "training",
        "incident",
        "supplier",
        "roles",
        "awareness",
        "scope"
      ]
    }
  ],
  "mappings": [
    {
      "record_id": "CRO032-MAP-0001",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0002",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0003",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0004",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0005",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0006",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0007",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0008",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "2",
      "pci_title": "Apply secure configurations to all system components",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 2 (Apply secure configurations to all system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0009",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0010",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0011",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "2",
      "pci_title": "Apply secure configurations to all system components",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 2 (Apply secure configurations to all system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0012",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0013",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0014",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0015",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0016",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "2",
      "pci_title": "Apply secure configurations to all system components",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 2 (Apply secure configurations to all system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0017",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0018",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0019",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "2",
      "pci_title": "Apply secure configurations to all system components",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 2 (Apply secure configurations to all system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0020",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0021",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0022",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "2",
      "pci_title": "Apply secure configurations to all system components",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 2 (Apply secure configurations to all system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0023",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0024",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0025",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0026",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0027",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "2",
      "pci_title": "Apply secure configurations to all system components",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 2 (Apply secure configurations to all system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0028",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0029",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-08 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0030",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0031",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0032",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0033",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0034",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0035",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0036",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "pci_requirement": "2",
      "pci_title": "Apply secure configurations to all system components",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 2 (Apply secure configurations to all system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0037",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0038",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0039",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0040",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0041",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D2-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0042",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0043",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0044",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 4 (Protect cardholder data with strong cryptography during transmission over open, public networks). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0045",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0046",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0047",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0048",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0049",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0050",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0051",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 4 (Protect cardholder data with strong cryptography during transmission over open, public networks). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0052",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0053",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0054",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0055",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0056",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0057",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0058",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0059",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0060",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "pci_requirement": "1",
      "pci_title": "Install and maintain network security controls",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 1 (Install and maintain network security controls). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0061",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0062",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0063",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0064",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0065",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0066",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0067",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0068",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0069",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0070",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0071",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0072",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0073",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0074",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0075",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0076",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0077",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0078",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0079",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0080",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0081",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0082",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0083",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0084",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0085",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0086",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0087",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0088",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0089",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0090",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0091",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 4 (Protect cardholder data with strong cryptography during transmission over open, public networks). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0092",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0093",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0094",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0095",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 4 (Protect cardholder data with strong cryptography during transmission over open, public networks). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0096",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0097",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0098",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0099",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 4 (Protect cardholder data with strong cryptography during transmission over open, public networks). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0100",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0101",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0102",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0103",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0104",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0105",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0106",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0107",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0108",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 4 (Protect cardholder data with strong cryptography during transmission over open, public networks). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0109",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0110",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "1",
      "pci_title": "Install and maintain network security controls",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 1 (Install and maintain network security controls). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0111",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0112",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 4 (Protect cardholder data with strong cryptography during transmission over open, public networks). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0113",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0114",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0115",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 4 (Protect cardholder data with strong cryptography during transmission over open, public networks). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0116",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0117",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0118",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0119",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0120",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0121",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0122",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0123",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0124",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0125",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0126",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0127",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0128",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0129",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0130",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0131",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0132",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0133",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0134",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0135",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0136",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0137",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0138",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0139",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0140",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0141",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0142",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0143",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0144",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0145",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0146",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0147",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0148",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0149",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0150",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 7 (Restrict access to system components and cardholder data by business need to know). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0151",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0152",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0153",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0154",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0155",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0156",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0157",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0158",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0159",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0160",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0161",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0162",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0163",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0164",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0165",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 8 (Identify users and authenticate access to system components). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0166",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0167",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0168",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0169",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 9 (Restrict physical access to cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0170",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 3 (Protect stored account data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0171",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0172",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 6 (Develop and maintain secure systems and software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0173",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 9 (Restrict physical access to cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0174",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "1",
      "pci_title": "Install and maintain network security controls",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-01 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 1 (Install and maintain network security controls). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0175",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-02 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 9 (Restrict physical access to cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0176",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-03 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 9 (Restrict physical access to cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0177",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 9 (Restrict physical access to cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0178",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 5 (Protect all systems and networks from malicious software). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0179",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0180",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0181",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 9 (Restrict physical access to cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0182",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 11 (Test security of systems and networks regularly). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0183",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0184",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-06 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 9 (Restrict physical access to cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0185",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 9 (Restrict physical access to cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0186",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 12 (Support information security with organizational policies and programs). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    },
    {
      "record_id": "CRO032-MAP-0187",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides governance, technical, or evidentiary capability relevant to PCI DSS Requirement 10 (Log and monitor all access to system components and cardholder data). The relationship is outcome-based and does not establish applicability, assessment status, or compliance for a cardholder data environment.",
      "residual_gap": "The entity must establish PCI DSS scope, connected-to and security-impacting systems, account-data flows, validation method, requirement-level testing procedures, evidence, targeted risk analyses where required, compensating-control documentation where used, and acceptance by the applicable acquirer, payment brand, or assessor.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "pci_source": "PCI DSS v4.0.1"
    }
  ],
  "reverse": [
    {
      "pci_requirement": "1",
      "pci_title": "Install and maintain network security controls",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "mapped_controls": [
        "D2-CTL-06",
        "D4-CTL-06",
        "D9-CTL-01"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "2",
      "pci_title": "Apply secure configurations to all system components",
      "pci_goal": "Build and Maintain a Secure Network and Systems",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-09"
      ],
      "mapped_count": 7,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "3",
      "pci_title": "Protect stored account data",
      "pci_goal": "Protect Account Data",
      "mapped_controls": [
        "D1-CTL-01",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-07",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D8-CTL-03"
      ],
      "mapped_count": 21,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "4",
      "pci_title": "Protect cardholder data with strong cryptography during transmission over open, public networks",
      "pci_goal": "Protect Account Data",
      "mapped_controls": [
        "D2-CTL-02",
        "D2-CTL-04",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "5",
      "pci_title": "Protect all systems and networks from malicious software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-06",
        "D3-CTL-07",
        "D5-CTL-02",
        "D5-CTL-03",
        "D7-CTL-H02",
        "D9-CTL-04"
      ],
      "mapped_count": 23,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "6",
      "pci_title": "Develop and maintain secure systems and software",
      "pci_goal": "Maintain a Vulnerability Management Program",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-07",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D8-CTL-05"
      ],
      "mapped_count": 21,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "7",
      "pci_title": "Restrict access to system components and cardholder data by business need to know",
      "pci_goal": "Implement Strong Access Control Measures",
      "mapped_controls": [
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05"
      ],
      "mapped_count": 10,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "8",
      "pci_title": "Identify users and authenticate access to system components",
      "pci_goal": "Implement Strong Access Control Measures",
      "mapped_controls": [
        "D2-CTL-01",
        "D2-CTL-03",
        "D2-CTL-05",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-07",
        "D7-CTL-H03"
      ],
      "mapped_count": 17,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "9",
      "pci_title": "Restrict physical access to cardholder data",
      "pci_goal": "Implement Strong Access Control Measures",
      "mapped_controls": [
        "D8-CTL-02",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "10",
      "pci_title": "Log and monitor all access to system components and cardholder data",
      "pci_goal": "Regularly Monitor and Test Networks",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-08",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-03",
        "D3-CTL-06",
        "D4-CTL-04",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-05",
        "D6-CTL-06",
        "D7-CTL-H02",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-07"
      ],
      "mapped_count": 28,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "11",
      "pci_title": "Test security of systems and networks regularly",
      "pci_goal": "Regularly Monitor and Test Networks",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-02",
        "D3-CTL-05",
        "D4-CTL-04",
        "D4-CTL-05",
        "D5-CTL-06",
        "D6-CTL-06",
        "D6-CTL-07",
        "D9-CTL-04",
        "D9-CTL-05"
      ],
      "mapped_count": 22,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    },
    {
      "pci_requirement": "12",
      "pci_title": "Support information security with organizational policies and programs",
      "pci_goal": "Maintain an Information Security Policy",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-06",
        "D4-CTL-07",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-06",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D8-CTL-01",
        "D8-CTL-04",
        "D9-CTL-07"
      ],
      "mapped_count": 19,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Requirement-level coverage does not establish PCI DSS applicability, CDE scope, implementation of every subrequirement and testing procedure, customized-approach documentation, compensating controls, evidence sufficiency, or validation through a ROC, SAQ, AOC, or other payment-brand process."
    }
  ],
  "limitations": [
    "Mapping is not PCI DSS compliance, validation, certification, a ROC, SAQ, AOC, QSA opinion, or payment-brand acceptance.",
    "PCI DSS applicability and scope depend on storage, processing or transmission of account data and on systems connected to or affecting the security of the cardholder data environment.",
    "The official PCI DSS v4.0.1 requirements, testing procedures, applicability notes, defined approach, customized approach, targeted risk analyses and appendices remain controlling.",
    "Future-dated requirements are treated as active because their effective date of 31 March 2025 has passed.",
    "Compensating controls and customized approaches require PCI-specific documentation and assessment; GAISSF mapping does not approve them.",
    "PCI SSC materials are proprietary; this publication uses requirement numbers and concise functional summaries, not a reproduction of the standard."
  ]
}
