{
  "document_metadata": {
    "document_id": "GAISSF-CRO-034",
    "title": "GAISSF–CSA Cloud Controls Matrix Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "publication_date": "2026-06-29",
    "verification_date": "2026-10-06",
    "scope": "Domain-level, bidirectional crosswalk between 59 GAISSF™ v1.0 controls and 17 CSA CCM v4.1 security domains.",
    "important_limitation": "This release is domain-level only. It does not establish control-specification-level coverage of the 207 CCM v4.1 controls, CAIQ v4.1 responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, or STAR programme eligibility."
  },
  "source_baseline": {
    "gaissf": "GAISSF™ v1.0; GAISSF-NOR-001 and GAISSF-NOR-004; 59 controls / 9 domains; Applicable-Control Baseline = all 52 controls in D1-D8 plus D9 where Physical AI or cyber-physical actuation is in scope.",
    "ccm": "CSA Cloud Controls Matrix v4.1; released 2026-01-27; 207 controls across 17 domains.",
    "caiq": "CAIQ v4.1 contains 283 questions and is treated separately from CCM control implementation.",
    "star": "CSA STAR is a separate registry/assurance programme. CCM/CAIQ v4.1 are accepted for STAR submissions; CSA states that v4.0 remains accepted during the transition through December 2027."
  },
  "controlled_vocabulary": {
    "relationship": {
      "SP": "Strong partial",
      "P": "Partial",
      "S": "Supporting",
      "C": "Contextual",
      "N": "No material mapping",
      "O": "Outside scope",
      "U": "Unable to determine"
    },
    "confidence": [
      "High",
      "Medium-High",
      "Medium",
      "Low",
      "Not Rated"
    ]
  },
  "gaissf_controls": [
    {
      "id": "D1-CTL-01",
      "title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-02",
      "title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-03",
      "title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-04",
      "title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-05",
      "title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-06",
      "title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-07",
      "title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-08",
      "title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-09",
      "title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-01",
      "title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-02",
      "title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-03",
      "title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-04",
      "title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-05",
      "title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-06",
      "title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-01",
      "title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-02",
      "title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-03",
      "title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-04",
      "title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-05",
      "title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-06",
      "title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-07",
      "title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-01",
      "title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-02",
      "title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-03",
      "title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-04",
      "title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-05",
      "title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-06",
      "title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-07",
      "title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-01",
      "title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-02",
      "title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-03",
      "title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-04",
      "title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-05",
      "title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-06",
      "title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-01",
      "title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-02",
      "title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-03",
      "title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-04",
      "title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-05",
      "title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-06",
      "title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-07",
      "title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H01",
      "title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H02",
      "title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H03",
      "title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H04",
      "title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H05",
      "title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-01",
      "title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-02",
      "title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-03",
      "title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-04",
      "title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-05",
      "title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D9-CTL-01",
      "title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-02",
      "title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-03",
      "title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-04",
      "title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-05",
      "title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-06",
      "title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-07",
      "title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    }
  ],
  "ccm_domains": [
    {
      "code": "A&A",
      "title": "Audit & Assurance",
      "summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance."
    },
    {
      "code": "AIS",
      "title": "Application & Interface Security",
      "summary": "Secure application lifecycle, interfaces, APIs and application-layer protections."
    },
    {
      "code": "BCR",
      "title": "Business Continuity Management & Operational Resilience",
      "summary": "Continuity, recovery, resilience, backup and service restoration."
    },
    {
      "code": "CCC",
      "title": "Change Control & Configuration Management",
      "summary": "Controlled changes, configuration baselines, approvals and integrity."
    },
    {
      "code": "CEK",
      "title": "Cryptography, Encryption & Key Management",
      "summary": "Cryptographic controls, key lifecycle, secrets and protected communications."
    },
    {
      "code": "DCS",
      "title": "Datacenter Security",
      "summary": "Physical facilities, environmental safeguards and infrastructure protection."
    },
    {
      "code": "DSP",
      "title": "Data Security & Privacy",
      "summary": "Data governance, classification, privacy, retention, protection and secure disposal."
    },
    {
      "code": "GRC",
      "title": "Governance, Risk Management & Compliance",
      "summary": "Policies, accountability, risk management, legal obligations and oversight."
    },
    {
      "code": "HRS",
      "title": "Human Resources Security",
      "summary": "Personnel screening, awareness, responsibilities and workforce lifecycle."
    },
    {
      "code": "IAM",
      "title": "Identity & Access Management",
      "summary": "Identity lifecycle, authentication, authorization, privileged access and segregation."
    },
    {
      "code": "IPY",
      "title": "Interoperability & Portability",
      "summary": "Portability, interoperability, exit planning and dependency management."
    },
    {
      "code": "IVS",
      "title": "Infrastructure & Virtualization Security",
      "summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening."
    },
    {
      "code": "LOG",
      "title": "Logging & Monitoring",
      "summary": "Security logging, monitoring, alerting, time synchronization and evidence."
    },
    {
      "code": "SEF",
      "title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "summary": "Incident preparation, response, investigation, evidence and forensics."
    },
    {
      "code": "STA",
      "title": "Supply Chain Management, Transparency & Accountability",
      "summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility."
    },
    {
      "code": "TVM",
      "title": "Threat & Vulnerability Management",
      "summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management."
    },
    {
      "code": "UEM",
      "title": "Universal Endpoint Management",
      "summary": "Endpoint inventory, configuration, protection and lifecycle management."
    }
  ],
  "mappings": [
    {
      "record_id": "GAISSF-CRO-034-MAP-0001",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Dataset Provenance & Poisoning Prevention contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0002",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Dataset Provenance & Poisoning Prevention contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0003",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Dataset Provenance & Poisoning Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0004",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Dataset Provenance & Poisoning Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0005",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Dataset Provenance & Poisoning Prevention contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0006",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Model Extraction Resistance contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0007",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model Extraction Resistance contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0008",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model Extraction Resistance contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0009",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model Extraction Resistance contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0010",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model Extraction Resistance contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0011",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Behavioral Drift Detection contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0012",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Behavioral Drift Detection contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0013",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Behavioral Drift Detection contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0014",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Behavioral Drift Detection contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0015",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Behavioral Drift Detection contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0016",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Federated Learning Poisoning Prevention contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0017",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Federated Learning Poisoning Prevention contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0018",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Federated Learning Poisoning Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0019",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Federated Learning Poisoning Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0020",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Federated Learning Poisoning Prevention contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0021",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Embedding Space Robustness contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0022",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Embedding Space Robustness contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0023",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Embedding Space Robustness contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0024",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Embedding Space Robustness contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0025",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Embedding Space Robustness contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0026",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Post-Quantum Model Signing & Crypto Hardening contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0027",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Post-Quantum Model Signing & Crypto Hardening contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0028",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Post-Quantum Model Signing & Crypto Hardening contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0029",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Post-Quantum Model Signing & Crypto Hardening contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0030",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Post-Quantum Model Signing & Crypto Hardening contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0031",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Lora/Adapter Integrity Verification contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0032",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Lora/Adapter Integrity Verification contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0033",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Lora/Adapter Integrity Verification contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0034",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Lora/Adapter Integrity Verification contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0035",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Lora/Adapter Integrity Verification contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0036",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Model Merge Attack Detection contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0037",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model Merge Attack Detection contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0038",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model Merge Attack Detection contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0039",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model Merge Attack Detection contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0040",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model Merge Attack Detection contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0041",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Quantization Backdoor Screening contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0042",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Quantization Backdoor Screening contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0043",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Quantization Backdoor Screening contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0044",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Quantization Backdoor Screening contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0045",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Quantization Backdoor Screening contributes to the Change Control & Configuration Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0046",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Direct Prompt Injection Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0047",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Direct Prompt Injection Prevention contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0048",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Direct Prompt Injection Prevention contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0049",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Direct Prompt Injection Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0050",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Direct Prompt Injection Prevention contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0051",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Indirect Prompt Injection Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0052",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Indirect Prompt Injection Prevention contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0053",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Indirect Prompt Injection Prevention contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0054",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Indirect Prompt Injection Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0055",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Indirect Prompt Injection Prevention contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0056",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Jailbreak Resistance Testing contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0057",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Jailbreak Resistance Testing contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0058",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Jailbreak Resistance Testing contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0059",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Jailbreak Resistance Testing contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0060",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Jailbreak Resistance Testing contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0061",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Multi-Modal Injection Defense contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0062",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Multi-Modal Injection Defense contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0063",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Multi-Modal Injection Defense contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0064",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Multi-Modal Injection Defense contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0065",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Multi-Modal Injection Defense contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0066",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Function Call/Tool Call Injection Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0067",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Function Call/Tool Call Injection Prevention contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0068",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Function Call/Tool Call Injection Prevention contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0069",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Function Call/Tool Call Injection Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0070",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Function Call/Tool Call Injection Prevention contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0071",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Cross-Context Hijacking Mitigation contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0072",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Cross-Context Hijacking Mitigation contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0073",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Cross-Context Hijacking Mitigation contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0074",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Cross-Context Hijacking Mitigation contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0075",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Cross-Context Hijacking Mitigation contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0076",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Least Agency Enforcement contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0077",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Least Agency Enforcement contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0078",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Least Agency Enforcement contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0079",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Least Agency Enforcement contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0080",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Least Agency Enforcement contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0081",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Inter-Agent Communication Security contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0082",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Inter-Agent Communication Security contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0083",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Inter-Agent Communication Security contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0084",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Inter-Agent Communication Security contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0085",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Inter-Agent Communication Security contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0086",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Agentic Prompt Chaining Detection contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0087",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Agentic Prompt Chaining Detection contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0088",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Agentic Prompt Chaining Detection contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0089",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Agentic Prompt Chaining Detection contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0090",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Agentic Prompt Chaining Detection contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0091",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Embodied Ai Safety Controls contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0092",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Embodied Ai Safety Controls contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0093",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Embodied Ai Safety Controls contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0094",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Embodied Ai Safety Controls contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0095",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Embodied Ai Safety Controls contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0096",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Multi-Agent Trust Chain Attestation contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0097",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Multi-Agent Trust Chain Attestation contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0098",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Multi-Agent Trust Chain Attestation contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0099",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Multi-Agent Trust Chain Attestation contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0100",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Multi-Agent Trust Chain Attestation contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0101",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Persistent Memory Exfiltration Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0102",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Persistent Memory Exfiltration Prevention contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0103",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Persistent Memory Exfiltration Prevention contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0104",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Persistent Memory Exfiltration Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0105",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Persistent Memory Exfiltration Prevention contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0106",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Secure Memory Lifecycle Management contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0107",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Secure Memory Lifecycle Management contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0108",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Secure Memory Lifecycle Management contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0109",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Secure Memory Lifecycle Management contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0110",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Secure Memory Lifecycle Management contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0111",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai Bill Of Materials (Ai Bom) Maintenance contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0112",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Bill Of Materials (Ai Bom) Maintenance contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0113",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Bill Of Materials (Ai Bom) Maintenance contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0114",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Bill Of Materials (Ai Bom) Maintenance contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0115",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "IPY",
      "ccm_domain_title": "Interoperability & Portability",
      "ccm_domain_summary": "Portability, interoperability, exit planning and dependency management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Bill Of Materials (Ai Bom) Maintenance contributes to the Interoperability & Portability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0116",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Model File & Artifact Scanning contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0117",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model File & Artifact Scanning contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0118",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model File & Artifact Scanning contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0119",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model File & Artifact Scanning contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0120",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "IPY",
      "ccm_domain_title": "Interoperability & Portability",
      "ccm_domain_summary": "Portability, interoperability, exit planning and dependency management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model File & Artifact Scanning contributes to the Interoperability & Portability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0121",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Model Hub & Registry Vetting contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0122",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model Hub & Registry Vetting contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0123",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model Hub & Registry Vetting contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0124",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model Hub & Registry Vetting contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0125",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "IPY",
      "ccm_domain_title": "Interoperability & Portability",
      "ccm_domain_summary": "Portability, interoperability, exit planning and dependency management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model Hub & Registry Vetting contributes to the Interoperability & Portability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0126",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Mcp Server Behavioral Monitoring contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0127",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Mcp Server Behavioral Monitoring contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0128",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Mcp Server Behavioral Monitoring contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0129",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Mcp Server Behavioral Monitoring contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0130",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "IPY",
      "ccm_domain_title": "Interoperability & Portability",
      "ccm_domain_summary": "Portability, interoperability, exit planning and dependency management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Mcp Server Behavioral Monitoring contributes to the Interoperability & Portability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0131",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Third-Party Ai Api Security Assessment contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0132",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Third-Party Ai Api Security Assessment contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0133",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Third-Party Ai Api Security Assessment contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0134",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Third-Party Ai Api Security Assessment contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0135",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "IPY",
      "ccm_domain_title": "Interoperability & Portability",
      "ccm_domain_summary": "Portability, interoperability, exit planning and dependency management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Third-Party Ai Api Security Assessment contributes to the Interoperability & Portability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0136",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Shadow Ai Discovery & Governance contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0137",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Shadow Ai Discovery & Governance contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0138",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Shadow Ai Discovery & Governance contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0139",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Shadow Ai Discovery & Governance contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0140",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "IPY",
      "ccm_domain_title": "Interoperability & Portability",
      "ccm_domain_summary": "Portability, interoperability, exit planning and dependency management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Shadow Ai Discovery & Governance contributes to the Interoperability & Portability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0141",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai Software Composition Analysis (Sca) contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0142",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Software Composition Analysis (Sca) contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0143",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Software Composition Analysis (Sca) contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0144",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Software Composition Analysis (Sca) contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0145",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "ccm_domain": "IPY",
      "ccm_domain_title": "Interoperability & Portability",
      "ccm_domain_summary": "Portability, interoperability, exit planning and dependency management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Software Composition Analysis (Sca) contributes to the Interoperability & Portability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0146",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Harmful Content Blocking contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0147",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Harmful Content Blocking contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0148",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Harmful Content Blocking contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0149",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Harmful Content Blocking contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0150",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Pii Leakage Prevention contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0151",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Pii Leakage Prevention contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0152",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Pii Leakage Prevention contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0153",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Pii Leakage Prevention contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0154",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Copyright Detection contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0155",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Copyright Detection contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0156",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Copyright Detection contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0157",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Copyright Detection contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0158",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai Watermarking Robustness contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0159",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Watermarking Robustness contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0160",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Watermarking Robustness contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0161",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Watermarking Robustness contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0162",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Privacy-By-Design Verification contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0163",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Privacy-By-Design Verification contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0164",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Privacy-By-Design Verification contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0165",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Privacy-By-Design Verification contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0166",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Privacy-Preserving Ml Validation contributes to the Data Security & Privacy outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0167",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Privacy-Preserving Ml Validation contributes to the Application & Interface Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0168",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Privacy-Preserving Ml Validation contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0169",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Privacy-Preserving Ml Validation contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0170",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Human-In-The-Loop For High-Risk Actions contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0171",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Human-In-The-Loop For High-Risk Actions contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0172",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Human-In-The-Loop For High-Risk Actions contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0173",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Human-In-The-Loop For High-Risk Actions contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0174",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Human-In-The-Loop For High-Risk Actions contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0175",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Audit Trail Completeness contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0176",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Audit Trail Completeness contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0177",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Audit Trail Completeness contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0178",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Audit Trail Completeness contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0179",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Audit Trail Completeness contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0180",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai Model Card Completeness contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0181",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Model Card Completeness contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0182",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Model Card Completeness contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0183",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Model Card Completeness contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0184",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Model Card Completeness contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0185",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai Incident Response Readiness contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0186",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Incident Response Readiness contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0187",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Incident Response Readiness contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0188",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Incident Response Readiness contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0189",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Incident Response Readiness contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0190",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Model Deprecation & Decommissioning contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0191",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model Deprecation & Decommissioning contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0192",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Model Deprecation & Decommissioning contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0193",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model Deprecation & Decommissioning contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0194",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Model Deprecation & Decommissioning contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0195",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Third-Party Ai Vendor Governance contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0196",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Third-Party Ai Vendor Governance contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0197",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Third-Party Ai Vendor Governance contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0198",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Third-Party Ai Vendor Governance contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0199",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Third-Party Ai Vendor Governance contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0200",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai Resilience & Business Continuity contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0201",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Resilience & Business Continuity contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0202",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Resilience & Business Continuity contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0203",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Resilience & Business Continuity contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0204",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Resilience & Business Continuity contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0205",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "HRS",
      "ccm_domain_title": "Human Resources Security",
      "ccm_domain_summary": "Personnel screening, awareness, responsibilities and workforce lifecycle.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai-Generated Phishing Simulation contributes to the Human Resources Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0206",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai-Generated Phishing Simulation contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0207",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai-Generated Phishing Simulation contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0208",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai-Generated Phishing Simulation contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0209",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai-Generated Phishing Simulation contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0210",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "HRS",
      "ccm_domain_title": "Human Resources Security",
      "ccm_domain_summary": "Personnel screening, awareness, responsibilities and workforce lifecycle.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Deepfake Detection Training contributes to the Human Resources Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0211",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Deepfake Detection Training contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0212",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Deepfake Detection Training contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0213",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Deepfake Detection Training contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0214",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Deepfake Detection Training contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0215",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "HRS",
      "ccm_domain_title": "Human Resources Security",
      "ccm_domain_summary": "Personnel screening, awareness, responsibilities and workforce lifecycle.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Out-Of-Band Authentication contributes to the Human Resources Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0216",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Out-Of-Band Authentication contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0217",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Out-Of-Band Authentication contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0218",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Out-Of-Band Authentication contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0219",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Out-Of-Band Authentication contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0220",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "HRS",
      "ccm_domain_title": "Human Resources Security",
      "ccm_domain_summary": "Personnel screening, awareness, responsibilities and workforce lifecycle.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai Social Engineering Ir contributes to the Human Resources Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0221",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Social Engineering Ir contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0222",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai Social Engineering Ir contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0223",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Social Engineering Ir contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0224",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai Social Engineering Ir contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0225",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "HRS",
      "ccm_domain_title": "Human Resources Security",
      "ccm_domain_summary": "Personnel screening, awareness, responsibilities and workforce lifecycle.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Ai-Enhanced External Attack Defense contributes to the Human Resources Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0226",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai-Enhanced External Attack Defense contributes to the Identity & Access Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0227",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Ai-Enhanced External Attack Defense contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0228",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai-Enhanced External Attack Defense contributes to the Threat & Vulnerability Management outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0229",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Ai-Enhanced External Attack Defense contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0230",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Eu Ai Act Risk Tier Mapping contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0231",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Eu Ai Act Risk Tier Mapping contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0232",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Eu Ai Act Risk Tier Mapping contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0233",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Iso 42001 Gap Analysis contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0234",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Iso 42001 Gap Analysis contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0235",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Iso 42001 Gap Analysis contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0236",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Gpai Technical Documentation Verification contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0237",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Gpai Technical Documentation Verification contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0238",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Gpai Technical Documentation Verification contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0239",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Dora Ict Incident Reporting (Financial Sector) contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0240",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Dora Ict Incident Reporting (Financial Sector) contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0241",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Dora Ict Incident Reporting (Financial Sector) contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0242",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Dora Ict Incident Reporting (Financial Sector) contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0243",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Dora Ict Incident Reporting (Financial Sector) contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0244",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Nist Sp 800-218A Compliance Check contributes to the Governance, Risk Management & Compliance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0245",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Nist Sp 800-218A Compliance Check contributes to the Audit & Assurance outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0246",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Nist Sp 800-218A Compliance Check contributes to the Supply Chain Management, Transparency & Accountability outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0247",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "DCS",
      "ccm_domain_title": "Datacenter Security",
      "ccm_domain_summary": "Physical facilities, environmental safeguards and infrastructure protection.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Physical Harm Boundary Enforcement contributes to the Datacenter Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0248",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Physical Harm Boundary Enforcement contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0249",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Physical Harm Boundary Enforcement contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0250",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Physical Harm Boundary Enforcement contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0251",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Physical Harm Boundary Enforcement contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0252",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "DCS",
      "ccm_domain_title": "Datacenter Security",
      "ccm_domain_summary": "Physical facilities, environmental safeguards and infrastructure protection.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Safe State And Graceful Degradation contributes to the Datacenter Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0253",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Safe State And Graceful Degradation contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0254",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Safe State And Graceful Degradation contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0255",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Safe State And Graceful Degradation contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0256",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Safe State And Graceful Degradation contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0257",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "DCS",
      "ccm_domain_title": "Datacenter Security",
      "ccm_domain_summary": "Physical facilities, environmental safeguards and infrastructure protection.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Human Override And Emergency Stop contributes to the Datacenter Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0258",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Human Override And Emergency Stop contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0259",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Human Override And Emergency Stop contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0260",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Human Override And Emergency Stop contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0261",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Human Override And Emergency Stop contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0262",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "DCS",
      "ccm_domain_title": "Datacenter Security",
      "ccm_domain_summary": "Physical facilities, environmental safeguards and infrastructure protection.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Cyber-Physical Attack Detection contributes to the Datacenter Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0263",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Cyber-Physical Attack Detection contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0264",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Cyber-Physical Attack Detection contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0265",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Cyber-Physical Attack Detection contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0266",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Cyber-Physical Attack Detection contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0267",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "DCS",
      "ccm_domain_title": "Datacenter Security",
      "ccm_domain_summary": "Physical facilities, environmental safeguards and infrastructure protection.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Physical Environment Integrity Monitoring contributes to the Datacenter Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0268",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Physical Environment Integrity Monitoring contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0269",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Physical Environment Integrity Monitoring contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0270",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Physical Environment Integrity Monitoring contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0271",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Physical Environment Integrity Monitoring contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0272",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "DCS",
      "ccm_domain_title": "Datacenter Security",
      "ccm_domain_summary": "Physical facilities, environmental safeguards and infrastructure protection.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Actuator Command Verification contributes to the Datacenter Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0273",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Actuator Command Verification contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0274",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Actuator Command Verification contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0275",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Actuator Command Verification contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0276",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Actuator Command Verification contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0277",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "DCS",
      "ccm_domain_title": "Datacenter Security",
      "ccm_domain_summary": "Physical facilities, environmental safeguards and infrastructure protection.",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "Physical Incident Evidence Preservation contributes to the Datacenter Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0278",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Physical Incident Evidence Preservation contributes to the Infrastructure & Virtualization Security outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0279",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "Physical Incident Evidence Preservation contributes to the Business Continuity Management & Operational Resilience outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0280",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Physical Incident Evidence Preservation contributes to the Security Incident Management, E-Discovery & Cloud Forensics outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    },
    {
      "record_id": "GAISSF-CRO-034-MAP-0281",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "Physical Incident Evidence Preservation contributes to the Logging & Monitoring outcome by providing AI-specific requirements that can operate within the cloud control environment.",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 control specifications, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness, auditing criteria and STAR programme requirements require separate assessment.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "ccm_source": "CSA Cloud Controls Matrix v4.1"
    }
  ],
  "reverse_coverage": [
    {
      "ccm_domain": "A&A",
      "ccm_domain_title": "Audit & Assurance",
      "ccm_domain_summary": "Independent assessment, audit planning, evidence, control effectiveness and assurance.",
      "mapped_controls": [
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D8-CTL-01",
        "D8-CTL-02",
        "D8-CTL-03",
        "D8-CTL-04",
        "D8-CTL-05"
      ],
      "mapped_count": 12,
      "mapping_records": 12,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "AIS",
      "ccm_domain_title": "Application & Interface Security",
      "ccm_domain_summary": "Secure application lifecycle, interfaces, APIs and application-layer protections.",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06"
      ],
      "mapped_count": 28,
      "mapping_records": 28,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "BCR",
      "ccm_domain_title": "Business Continuity Management & Operational Resilience",
      "ccm_domain_summary": "Continuity, recovery, resilience, backup and service restoration.",
      "mapped_controls": [
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 14,
      "mapping_records": 14,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "CCC",
      "ccm_domain_title": "Change Control & Configuration Management",
      "ccm_domain_summary": "Controlled changes, configuration baselines, approvals and integrity.",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09"
      ],
      "mapped_count": 9,
      "mapping_records": 9,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "CEK",
      "ccm_domain_title": "Cryptography, Encryption & Key Management",
      "ccm_domain_summary": "Cryptographic controls, key lifecycle, secrets and protected communications.",
      "mapped_controls": [],
      "mapped_count": 0,
      "mapping_records": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "DCS",
      "ccm_domain_title": "Datacenter Security",
      "ccm_domain_summary": "Physical facilities, environmental safeguards and infrastructure protection.",
      "mapped_controls": [
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 7,
      "mapping_records": 7,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "DSP",
      "ccm_domain_title": "Data Security & Privacy",
      "ccm_domain_summary": "Data governance, classification, privacy, retention, protection and secure disposal.",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06"
      ],
      "mapped_count": 22,
      "mapping_records": 22,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "GRC",
      "ccm_domain_title": "Governance, Risk Management & Compliance",
      "ccm_domain_summary": "Policies, accountability, risk management, legal obligations and oversight.",
      "mapped_controls": [
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D8-CTL-01",
        "D8-CTL-02",
        "D8-CTL-03",
        "D8-CTL-04",
        "D8-CTL-05"
      ],
      "mapped_count": 37,
      "mapping_records": 37,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "HRS",
      "ccm_domain_title": "Human Resources Security",
      "ccm_domain_summary": "Personnel screening, awareness, responsibilities and workforce lifecycle.",
      "mapped_controls": [
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05"
      ],
      "mapped_count": 5,
      "mapping_records": 5,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "IAM",
      "ccm_domain_title": "Identity & Access Management",
      "ccm_domain_summary": "Identity lifecycle, authentication, authorization, privileged access and segregation.",
      "mapped_controls": [
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05"
      ],
      "mapped_count": 18,
      "mapping_records": 18,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "IPY",
      "ccm_domain_title": "Interoperability & Portability",
      "ccm_domain_summary": "Portability, interoperability, exit planning and dependency management.",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07"
      ],
      "mapped_count": 7,
      "mapping_records": 7,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "IVS",
      "ccm_domain_title": "Infrastructure & Virtualization Security",
      "ccm_domain_summary": "Cloud infrastructure, compute, network, containers, virtualization and hardening.",
      "mapped_controls": [
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 13,
      "mapping_records": 13,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "LOG",
      "ccm_domain_title": "Logging & Monitoring",
      "ccm_domain_summary": "Security logging, monitoring, alerting, time synchronization and evidence.",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D8-CTL-04",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 43,
      "mapping_records": 43,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "SEF",
      "ccm_domain_title": "Security Incident Management, E-Discovery & Cloud Forensics",
      "ccm_domain_summary": "Incident preparation, response, investigation, evidence and forensics.",
      "mapped_controls": [
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D8-CTL-04",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 27,
      "mapping_records": 27,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "STA",
      "ccm_domain_title": "Supply Chain Management, Transparency & Accountability",
      "ccm_domain_summary": "Third-party risk, supply chain, contracts, transparency and shared responsibility.",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D8-CTL-01",
        "D8-CTL-02",
        "D8-CTL-03",
        "D8-CTL-04",
        "D8-CTL-05"
      ],
      "mapped_count": 12,
      "mapping_records": 12,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "TVM",
      "ccm_domain_title": "Threat & Vulnerability Management",
      "ccm_domain_summary": "Threat intelligence, vulnerability discovery, remediation, testing and exposure management.",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05"
      ],
      "mapped_count": 27,
      "mapping_records": 27,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    },
    {
      "ccm_domain": "UEM",
      "ccm_domain_title": "Universal Endpoint Management",
      "ccm_domain_summary": "Endpoint inventory, configuration, protection and lifecycle management.",
      "mapped_controls": [],
      "mapped_count": 0,
      "mapping_records": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Domain-level correspondence only. Individual CCM v4.1 controls, CAIQ responses, Shared Security Responsibility Model allocations, evidence sufficiency, operating effectiveness and STAR programme criteria are not established by this crosswalk."
    }
  ],
  "notably_absent": [
    "CSA endorsement or affiliation",
    "STAR listing, certification or attestation",
    "CAIQ submission or validation",
    "Proof of implementation or operating effectiveness",
    "Control-specification-level mapping to all 207 CCM controls",
    "Cloud-provider-specific configuration evidence",
    "Automatic assignment of shared responsibility",
    "No CSA endorsement or affiliation.",
    "No STAR listing, attestation, certification, or registry eligibility determination.",
    "No CAIQ acceptance or pre-completed CAIQ response set.",
    "No control-specification-level mapping to all 207 CCM v4.1 controls.",
    "No evidence-sufficiency or operating-effectiveness finding.",
    "No automatic allocation of cloud shared responsibility.",
    "No automatic GAISSF conformance."
  ],
  "revalidation_triggers": [
    "New CCM, CAIQ, Implementation Guidelines or Auditing Guidelines release",
    "Changes to STAR submission or certification requirements",
    "GAISSF control changes",
    "Material change to cloud service model, provider, region or responsibility allocation",
    "Release of a new CSA CCM/CAIQ version or material STAR programme change.",
    "Material GAISSF control-catalogue or conformance-model change.",
    "Control-specification-level re-performance of this domain mapping."
  ]
}