{
  "meta": {
    "document_id": "GAISSF-CRO-033",
    "title": "GAISSF-CIS Controls Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "publication_date": "29 June 2026",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "gaissf_baseline": "GAISSF™ v1.0; GAISSF-NOR-001 and GAISSF-NOR-004; 59 controls / 9 domains; Applicable-Control Baseline = all 52 controls in D1-D8 plus D9 where Physical AI or cyber-physical actuation is in scope.",
    "external_baseline": "CIS Controls v8.1; published 2024-06-24; 18 Controls / 153 Safeguards.",
    "verification_date": "2026-10-06",
    "scope": "Control-family-level bidirectional crosswalk between 59 GAISSF™ v1.0 controls and the 18 CIS Controls v8.1 Control families. Safeguard-level implementation, Implementation Group selection, measurement criteria and operating evidence remain outside this mapping."
  },
  "controls": [
    {
      "id": "D1-CTL-01",
      "title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-02",
      "title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-03",
      "title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-04",
      "title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-05",
      "title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-06",
      "title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-07",
      "title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-08",
      "title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D1-CTL-09",
      "title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-01",
      "title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-02",
      "title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-03",
      "title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-04",
      "title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-05",
      "title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D2-CTL-06",
      "title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-01",
      "title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-02",
      "title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-03",
      "title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-04",
      "title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-05",
      "title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-06",
      "title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D3-CTL-07",
      "title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-01",
      "title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-02",
      "title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-03",
      "title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-04",
      "title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-05",
      "title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-06",
      "title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D4-CTL-07",
      "title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-01",
      "title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-02",
      "title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-03",
      "title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-04",
      "title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-05",
      "title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D5-CTL-06",
      "title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-01",
      "title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-02",
      "title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-03",
      "title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-04",
      "title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-05",
      "title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-06",
      "title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D6-CTL-07",
      "title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H01",
      "title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H02",
      "title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H03",
      "title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H04",
      "title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D7-CTL-H05",
      "title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-01",
      "title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-02",
      "title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-03",
      "title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-04",
      "title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D8-CTL-05",
      "title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-01",
      "title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-02",
      "title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-03",
      "title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-04",
      "title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-05",
      "title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-06",
      "title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "id": "D9-CTL-07",
      "title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    }
  ],
  "cis_controls": [
    {
      "id": "1",
      "title": "Inventory and Control of Enterprise Assets",
      "summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments."
    },
    {
      "id": "2",
      "title": "Inventory and Control of Software Assets",
      "summary": "Actively manage software so only authorized software is installed and executes."
    },
    {
      "id": "3",
      "title": "Data Protection",
      "summary": "Identify, classify, securely handle, retain and dispose of data."
    },
    {
      "id": "4",
      "title": "Secure Configuration of Enterprise Assets and Software",
      "summary": "Establish and maintain secure configurations for enterprise assets and software."
    },
    {
      "id": "5",
      "title": "Account Management",
      "summary": "Assign and manage user, administrator and service accounts."
    },
    {
      "id": "6",
      "title": "Access Control Management",
      "summary": "Create, assign, manage and revoke access credentials and privileges."
    },
    {
      "id": "7",
      "title": "Continuous Vulnerability Management",
      "summary": "Continuously assess, track and remediate vulnerabilities."
    },
    {
      "id": "8",
      "title": "Audit Log Management",
      "summary": "Collect, alert, review and retain audit logs."
    },
    {
      "id": "9",
      "title": "Email and Web Browser Protections",
      "summary": "Improve protection and detection for email and web vectors."
    },
    {
      "id": "10",
      "title": "Malware Defenses",
      "summary": "Prevent or control malicious applications, code and scripts."
    },
    {
      "id": "11",
      "title": "Data Recovery",
      "summary": "Maintain recovery practices sufficient to restore systems to a trusted state."
    },
    {
      "id": "12",
      "title": "Network Infrastructure Management",
      "summary": "Actively manage network devices and services."
    },
    {
      "id": "13",
      "title": "Network Monitoring and Defense",
      "summary": "Operate comprehensive network monitoring and defense."
    },
    {
      "id": "14",
      "title": "Security Awareness and Skills Training",
      "summary": "Maintain security awareness and role-relevant skills."
    },
    {
      "id": "15",
      "title": "Service Provider Management",
      "summary": "Evaluate and manage service providers protecting critical platforms or sensitive data."
    },
    {
      "id": "16",
      "title": "Application Software Security",
      "summary": "Manage the security lifecycle of developed, hosted or acquired software."
    },
    {
      "id": "17",
      "title": "Incident Response Management",
      "summary": "Maintain an incident response capability with plans, roles, training and communications."
    },
    {
      "id": "18",
      "title": "Penetration Testing",
      "summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses."
    }
  ],
  "mappings": [
    {
      "record_id": "GAISSF-CRO-033-MAP-0001",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0002",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0003",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0004",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0005",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0006",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0007",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0008",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0009",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0010",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0011",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "4",
      "cis_title": "Secure Configuration of Enterprise Assets and Software",
      "cis_summary": "Establish and maintain secure configurations for enterprise assets and software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 4 (Secure Configuration of Enterprise Assets and Software). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0012",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0013",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0014",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0015",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0016",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "4",
      "cis_title": "Secure Configuration of Enterprise Assets and Software",
      "cis_summary": "Establish and maintain secure configurations for enterprise assets and software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 4 (Secure Configuration of Enterprise Assets and Software). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0017",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0018",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0019",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0020",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "4",
      "cis_title": "Secure Configuration of Enterprise Assets and Software",
      "cis_summary": "Establish and maintain secure configurations for enterprise assets and software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 4 (Secure Configuration of Enterprise Assets and Software). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0021",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "4",
      "cis_title": "Secure Configuration of Enterprise Assets and Software",
      "cis_summary": "Establish and maintain secure configurations for enterprise assets and software.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 4 (Secure Configuration of Enterprise Assets and Software). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0022",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0023",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0024",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0025",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0026",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0027",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0028",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0029",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0030",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0031",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0032",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0033",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0034",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0035",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0036",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0037",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0038",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0039",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0040",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0041",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0042",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0043",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0044",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "4",
      "cis_title": "Secure Configuration of Enterprise Assets and Software",
      "cis_summary": "Establish and maintain secure configurations for enterprise assets and software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 4 (Secure Configuration of Enterprise Assets and Software). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0045",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0046",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0047",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0048",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0049",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0050",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0051",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0052",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0053",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0054",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "4",
      "cis_title": "Secure Configuration of Enterprise Assets and Software",
      "cis_summary": "Establish and maintain secure configurations for enterprise assets and software.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 4 (Secure Configuration of Enterprise Assets and Software). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0055",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0056",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0057",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0058",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0059",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "12",
      "cis_title": "Network Infrastructure Management",
      "cis_summary": "Actively manage network devices and services.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 12 (Network Infrastructure Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0060",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0061",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0062",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0063",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 10 (Malware Defenses). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0064",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0065",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0066",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0067",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0068",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0069",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0070",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0071",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0072",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0073",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0074",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0075",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0076",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0077",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0078",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0079",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0080",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0081",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0082",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0083",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0084",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0085",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0086",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0087",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0088",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "cis_control": "4",
      "cis_title": "Secure Configuration of Enterprise Assets and Software",
      "cis_summary": "Establish and maintain secure configurations for enterprise assets and software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 4 (Secure Configuration of Enterprise Assets and Software). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0089",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "2",
      "cis_title": "Inventory and Control of Software Assets",
      "cis_summary": "Actively manage software so only authorized software is installed and executes.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 2 (Inventory and Control of Software Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0090",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 15 (Service Provider Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0091",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0092",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0093",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 15 (Service Provider Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0094",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0095",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "2",
      "cis_title": "Inventory and Control of Software Assets",
      "cis_summary": "Actively manage software so only authorized software is installed and executes.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 2 (Inventory and Control of Software Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0096",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0097",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 15 (Service Provider Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0098",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0099",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "2",
      "cis_title": "Inventory and Control of Software Assets",
      "cis_summary": "Actively manage software so only authorized software is installed and executes.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 2 (Inventory and Control of Software Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0100",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0101",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0102",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 15 (Service Provider Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0103",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0104",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "2",
      "cis_title": "Inventory and Control of Software Assets",
      "cis_summary": "Actively manage software so only authorized software is installed and executes.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 2 (Inventory and Control of Software Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0105",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 15 (Service Provider Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0106",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0107",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0108",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0109",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0110",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 15 (Service Provider Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0111",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "12",
      "cis_title": "Network Infrastructure Management",
      "cis_summary": "Actively manage network devices and services.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 12 (Network Infrastructure Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0112",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "2",
      "cis_title": "Inventory and Control of Software Assets",
      "cis_summary": "Actively manage software so only authorized software is installed and executes.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 2 (Inventory and Control of Software Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0113",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "2",
      "cis_title": "Inventory and Control of Software Assets",
      "cis_summary": "Actively manage software so only authorized software is installed and executes.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 2 (Inventory and Control of Software Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0114",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 16 (Application Software Security). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0115",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0116",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 15 (Service Provider Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0117",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0118",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0119",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0120",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0121",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0122",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0123",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0124",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0125",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0126",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0127",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0128",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0129",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0130",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0131",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0132",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0133",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0134",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0135",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0136",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0137",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0138",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0139",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "17",
      "cis_title": "Incident Response Management",
      "cis_summary": "Maintain an incident response capability with plans, roles, training and communications.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 17 (Incident Response Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0140",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0141",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0142",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0143",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0144",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "17",
      "cis_title": "Incident Response Management",
      "cis_summary": "Maintain an incident response capability with plans, roles, training and communications.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 17 (Incident Response Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0145",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0146",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0147",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0148",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0149",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0150",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 6 (Access Control Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0151",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0152",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 15 (Service Provider Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0153",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0154",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0155",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0156",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "11",
      "cis_title": "Data Recovery",
      "cis_summary": "Maintain recovery practices sufficient to restore systems to a trusted state.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 11 (Data Recovery). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0157",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 5 (Account Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0158",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0159",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0160",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0161",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0162",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 9 (Email and Web Browser Protections). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0163",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0164",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0165",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0166",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0167",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0168",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0169",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0170",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "17",
      "cis_title": "Incident Response Management",
      "cis_summary": "Maintain an incident response capability with plans, roles, training and communications.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 17 (Incident Response Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0171",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0172",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0173",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0174",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0175",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0176",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 3 (Data Protection). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0177",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "cis_control": "17",
      "cis_title": "Incident Response Management",
      "cis_summary": "Maintain an incident response capability with plans, roles, training and communications.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 17 (Incident Response Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0178",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0179",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0180",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "12",
      "cis_title": "Network Infrastructure Management",
      "cis_summary": "Actively manage network devices and services.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-01 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 12 (Network Infrastructure Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0181",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-02 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0182",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0183",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-03 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 14 (Security Awareness and Skills Training). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0184",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0185",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 18 (Penetration Testing). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0186",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0187",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0188",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0189",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 7 (Continuous Vulnerability Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0190",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 13 (Network Monitoring and Defense). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0191",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-06 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0192",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 8 (Audit Log Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0193",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 1 (Inventory and Control of Enterprise Assets). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    },
    {
      "record_id": "GAISSF-CRO-033-MAP-0194",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "cis_control": "17",
      "cis_title": "Incident Response Management",
      "cis_summary": "Maintain an incident response capability with plans, roles, training and communications.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides an AI-security governance, technical or evidentiary capability relevant to CIS Control 17 (Incident Response Management). The relationship is outcome-based and does not establish implementation of the underlying CIS Safeguards.",
      "residual_gap": "Control-family correspondence only. Applicable CIS v8.1 Safeguards, Implementation Group, asset classes, implementation frequencies, measurement criteria, enterprise scope, evidence sufficiency and operating effectiveness require separate Safeguard-level assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "cis_source": "CIS Controls v8.1"
    }
  ],
  "reverse": [
    {
      "cis_control": "1",
      "cis_title": "Inventory and Control of Enterprise Assets",
      "cis_summary": "Actively manage enterprise assets across physical, virtual, remote and cloud environments.",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-06",
        "D6-CTL-05",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 10,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "2",
      "cis_title": "Inventory and Control of Software Assets",
      "cis_summary": "Actively manage software so only authorized software is installed and executes.",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-06",
        "D4-CTL-07"
      ],
      "mapped_count": 6,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "3",
      "cis_title": "Data Protection",
      "cis_summary": "Identify, classify, securely handle, retain and dispose of data.",
      "mapped_controls": [
        "D1-CTL-01",
        "D3-CTL-06",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-06",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D8-CTL-01",
        "D8-CTL-03"
      ],
      "mapped_count": 21,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "4",
      "cis_title": "Secure Configuration of Enterprise Assets and Software",
      "cis_summary": "Establish and maintain secure configurations for enterprise assets and software.",
      "mapped_controls": [
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D2-CTL-02",
        "D2-CTL-05",
        "D3-CTL-07"
      ],
      "mapped_count": 7,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "5",
      "cis_title": "Account Management",
      "cis_summary": "Assign and manage user, administrator and service accounts.",
      "mapped_controls": [
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07"
      ],
      "mapped_count": 14,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "6",
      "cis_title": "Access Control Management",
      "cis_summary": "Create, assign, manage and revoke access credentials and privileges.",
      "mapped_controls": [
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D6-CTL-03",
        "D6-CTL-05"
      ],
      "mapped_count": 9,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "7",
      "cis_title": "Continuous Vulnerability Management",
      "cis_summary": "Continuously assess, track and remediate vulnerabilities.",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-05",
        "D1-CTL-07",
        "D1-CTL-09",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-07",
        "D9-CTL-05"
      ],
      "mapped_count": 12,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "8",
      "cis_title": "Audit Log Management",
      "cis_summary": "Collect, alert, review and retain audit logs.",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-04",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-06",
        "D4-CTL-04",
        "D5-CTL-02",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-05",
        "D6-CTL-06",
        "D8-CTL-02",
        "D8-CTL-05",
        "D9-CTL-05",
        "D9-CTL-07"
      ],
      "mapped_count": 21,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "9",
      "cis_title": "Email and Web Browser Protections",
      "cis_summary": "Improve protection and detection for email and web vectors.",
      "mapped_controls": [
        "D2-CTL-01",
        "D2-CTL-04",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D7-CTL-H01"
      ],
      "mapped_count": 9,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "10",
      "cis_title": "Malware Defenses",
      "cis_summary": "Prevent or control malicious applications, code and scripts.",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01"
      ],
      "mapped_count": 14,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "11",
      "cis_title": "Data Recovery",
      "cis_summary": "Maintain recovery practices sufficient to restore systems to a trusted state.",
      "mapped_controls": [
        "D6-CTL-07"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "12",
      "cis_title": "Network Infrastructure Management",
      "cis_summary": "Actively manage network devices and services.",
      "mapped_controls": [
        "D2-CTL-06",
        "D4-CTL-06",
        "D9-CTL-01"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "13",
      "cis_title": "Network Monitoring and Defense",
      "cis_summary": "Operate comprehensive network monitoring and defense.",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-03",
        "D2-CTL-04",
        "D5-CTL-03",
        "D7-CTL-H02",
        "D7-CTL-H05",
        "D9-CTL-04",
        "D9-CTL-05"
      ],
      "mapped_count": 13,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "14",
      "cis_title": "Security Awareness and Skills Training",
      "cis_summary": "Maintain security awareness and role-relevant skills.",
      "mapped_controls": [
        "D6-CTL-01",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D9-CTL-03"
      ],
      "mapped_count": 10,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "15",
      "cis_title": "Service Provider Management",
      "cis_summary": "Evaluate and manage service providers protecting critical platforms or sensitive data.",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D6-CTL-06"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "16",
      "cis_title": "Application Software Security",
      "cis_summary": "Manage the security lifecycle of developed, hosted or acquired software.",
      "mapped_controls": [
        "D1-CTL-04",
        "D1-CTL-06",
        "D1-CTL-08",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-07",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-05",
        "D4-CTL-07"
      ],
      "mapped_count": 11,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "17",
      "cis_title": "Incident Response Management",
      "cis_summary": "Maintain an incident response capability with plans, roles, training and communications.",
      "mapped_controls": [
        "D6-CTL-02",
        "D6-CTL-04",
        "D7-CTL-H04",
        "D8-CTL-04",
        "D9-CTL-07"
      ],
      "mapped_count": 5,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    },
    {
      "cis_control": "18",
      "cis_title": "Penetration Testing",
      "cis_summary": "Test control effectiveness and resilience by identifying and exploiting weaknesses.",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D4-CTL-05",
        "D5-CTL-06",
        "D9-CTL-04"
      ],
      "mapped_count": 20,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Control-family mapping does not establish implementation of associated CIS v8.1 Safeguards, correct Implementation Group selection, measurement results, CIS Controls Accreditation, CIS SecureSuite status, evidence sufficiency, or operating effectiveness."
    }
  ],
  "limitations": [
    "This is a Control-family-level mapping; it does not establish implementation of the 153 CIS Controls v8.1 Safeguards.",
    "Implementation Group selection (IG1, IG2 or IG3) must be determined separately using enterprise risk profile, resources, asset/data sensitivity and threat exposure.",
    "No mapping establishes equivalence, evidence sufficiency, operating effectiveness, CIS endorsement, CIS Controls Accreditation, CIS SecureSuite status, or a successful CIS Controls assessment.",
    "CIS Benchmarks, CIS RAM, CIS CSAT and the CIS Controls Assessment Specification are separate resources and are not substituted by this crosswalk.",
    "Held/internal GAISSF VTS, unpublished benchmark suites and test harnesses are not publication dependencies of this public crosswalk.",
    "D9 is additional/conditional. Where Physical AI is in scope, PAI-SF™ v1.0 may be used alongside GAISSF; CSX-PAISF-004 is mapping only.",
    "A new CIS Controls edition or material GAISSF baseline change triggers revalidation.",
    "Independent CIS/crosswalk review and explicit publication approval remain open."
  ]
}