# CRO-023 - GAISSF-NIST Cybersecurity Framework 2.0 Mapping **Version:** 1.0 **Status:** Publication Candidate **Publisher:** ODA3 Institute **Baseline date:** 29 June 2026 > This crosswalk documents outcome relationships. It does not establish NIST endorsement, certification, equivalence, regulatory compliance, or implementation effectiveness. ## Source baseline - GAISSF-NOR-001 v1.0 and GAISSF-NOR-004 v1.0, 59-control baseline. - NIST CSWP 29, *The NIST Cybersecurity Framework (CSF) 2.0*, published 26 February 2024. - CSF Implementation Examples are supplementary, non-exhaustive examples and are not treated as required actions. ## Executive findings - 59 GAISSF controls assessed. - 106 NIST CSF 2.0 Core subcategories assessed. - 182 forward mapping records generated and bidirectionally checked. - Strongest concentration: GOVERN supply-chain and governance outcomes; IDENTIFY risk assessment; PROTECT platform, data, access and resilience; DETECT monitoring and analysis. - Systematic residual gap: CSF 2.0 is organization-wide and technology-neutral, while GAISSF is scoped to AI systems and their supporting ecosystem. ## Coverage by function | Function | Subcategories | |---|---:| | GOVERN | 31 | | IDENTIFY | 21 | | PROTECT | 22 | | DETECT | 11 | | RESPOND | 13 | | RECOVER | 8 | ## Reverse coverage register | NIST ID | Function | Outcome | GAISSF controls | Coverage | Confidence | |---|---|---|---|---|---| | GV.OC-01 | GOVERN | The organizational mission is understood and informs cybersecurity risk management | D2-CTL-06 | Indirectly Supported | Low | | GV.OC-02 | GOVERN | Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered | D2-CTL-06 | Indirectly Supported | Low | | GV.OC-03 | GOVERN | Legal, regulatory, and contractual requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed | D5-CTL-05, D8-CTL-05 | Indirectly Supported | Low | | GV.OC-04 | GOVERN | Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated | None | Not Addressed | Not Rated | | GV.OC-05 | GOVERN | Outcomes, capabilities, and services that the organization depends on are understood and communicated | None | Not Addressed | Not Rated | | GV.RM-01 | GOVERN | Risk management objectives are established and agreed to by organizational stakeholders | None | Not Addressed | Not Rated | | GV.RM-02 | GOVERN | Risk appetite and risk tolerance statements are established, communicated, and maintained | None | Not Addressed | Not Rated | | GV.RM-03 | GOVERN | Cybersecurity risk management activities and outcomes are included in enterprise risk management processes | None | Not Addressed | Not Rated | | GV.RM-04 | GOVERN | Strategic direction that describes appropriate risk response options is established and communicated | D7-CTL-H05 | Indirectly Supported | Low | | GV.RM-05 | GOVERN | Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties | None | Not Addressed | Not Rated | | GV.RM-06 | GOVERN | A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated | None | Not Addressed | Not Rated | | GV.RM-07 | GOVERN | Strategic opportunities, or positive risks, are characterized and included in organizational cybersecurity risk discussions | None | Not Addressed | Not Rated | | GV.RR-01 | GOVERN | Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving | None | Not Addressed | Not Rated | | GV.RR-02 | GOVERN | Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced | None | Not Addressed | Not Rated | | GV.RR-03 | GOVERN | Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies | None | Not Addressed | Not Rated | | GV.RR-04 | GOVERN | Cybersecurity is included in human resources practices | None | Not Addressed | Not Rated | | GV.PO-01 | GOVERN | Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced | None | Not Addressed | Not Rated | | GV.PO-02 | GOVERN | Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission | D6-CTL-03 | Indirectly Supported | Low | | GV.OV-01 | GOVERN | Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction | None | Not Addressed | Not Rated | | GV.OV-02 | GOVERN | The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks | D8-CTL-01 | Indirectly Supported | Low | | GV.OV-03 | GOVERN | Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed | None | Not Addressed | Not Rated | | GV.SC-01 | GOVERN | A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders | None | Not Addressed | Not Rated | | GV.SC-02 | GOVERN | Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally | D6-CTL-06, D1-CTL-01, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05 | Partially Addressed | Medium | | GV.SC-03 | GOVERN | Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes | D8-CTL-01 | Indirectly Supported | Low | | GV.SC-04 | GOVERN | Suppliers are known and prioritized by criticality | D1-CTL-06, D1-CTL-07 | Indirectly Supported | Low | | GV.SC-05 | GOVERN | Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and agreements with suppliers and other relevant third parties | D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-04, D4-CTL-05, D4-CTL-06 | Partially Addressed | Medium | | GV.SC-06 | GOVERN | Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships | D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D3-CTL-05, D4-CTL-02, D4-CTL-04, D4-CTL-05 | Partially Addressed | Medium | | GV.SC-07 | GOVERN | The risks posed by suppliers, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the relationship | D1-CTL-01, D4-CTL-03, D6-CTL-06, D1-CTL-06, D1-CTL-07, D4-CTL-02, D4-CTL-04, D4-CTL-05 | Partially Addressed | Medium | | GV.SC-08 | GOVERN | Relevant suppliers and other third parties are included in incident planning, response, and recovery activities | D1-CTL-01, D4-CTL-01, D6-CTL-06, D4-CTL-03, D9-CTL-04, D1-CTL-03, D1-CTL-05, D3-CTL-07 | Substantially Addressed | Medium-High | | GV.SC-09 | GOVERN | Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and performance is monitored throughout the technology product and service life cycle | D2-CTL-04, D3-CTL-03 | Indirectly Supported | Low | | GV.SC-10 | GOVERN | Cybersecurity supply chain risk management plans include provisions for activities after the conclusion of a partnership or service agreement | None | Not Addressed | Not Rated | | ID.AM-01 | IDENTIFY | Inventories of hardware managed by the organization are maintained | None | Not Addressed | Not Rated | | ID.AM-02 | IDENTIFY | Inventories of software, services, and systems managed by the organization are maintained | None | Not Addressed | Not Rated | | ID.AM-03 | IDENTIFY | Representations of the organization's authorized network communication and internal and external network data flows are maintained | D2-CTL-02 | Indirectly Supported | Low | | ID.AM-04 | IDENTIFY | Inventories of services provided by suppliers are maintained | None | Not Addressed | Not Rated | | ID.AM-05 | IDENTIFY | Assets are prioritized based on classification, criticality, resources, and impact on the mission | None | Not Addressed | Not Rated | | ID.AM-07 | IDENTIFY | Inventories of data and corresponding metadata for designated data types are maintained | None | Not Addressed | Not Rated | | ID.AM-08 | IDENTIFY | Systems, hardware, software, services, and data are managed throughout their life cycles | None | Not Addressed | Not Rated | | ID.RA-01 | IDENTIFY | Vulnerabilities in assets are identified, validated, and recorded | None | Not Addressed | Not Rated | | ID.RA-02 | IDENTIFY | Cyber threat intelligence is received from information sharing forums and sources | None | Not Addressed | Not Rated | | ID.RA-03 | IDENTIFY | Internal and external threats to the organization are identified and recorded | None | Not Addressed | Not Rated | | ID.RA-04 | IDENTIFY | Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded | None | Not Addressed | Not Rated | | ID.RA-05 | IDENTIFY | Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization | None | Not Addressed | Not Rated | | ID.RA-06 | IDENTIFY | Risk responses are chosen, prioritized, planned, tracked, and communicated | None | Not Addressed | Not Rated | | ID.RA-07 | IDENTIFY | Changes and exceptions are managed, assessed for risk impact, recorded, and tracked | None | Not Addressed | Not Rated | | ID.RA-08 | IDENTIFY | Processes for receiving, analyzing, and responding to vulnerability disclosures are established | None | Not Addressed | Not Rated | | ID.RA-09 | IDENTIFY | The authenticity and integrity of hardware and software are assessed prior to acquisition and use | D1-CTL-04, D1-CTL-08, D1-CTL-09, D2-CTL-02, D3-CTL-04, D3-CTL-06, D5-CTL-01 | Indirectly Supported | Low | | ID.RA-10 | IDENTIFY | Critical suppliers are assessed prior to acquisition | None | Not Addressed | Not Rated | | ID.IM-01 | IDENTIFY | Improvements are identified from evaluations | None | Not Addressed | Not Rated | | ID.IM-02 | IDENTIFY | Improvements are identified from security tests and exercises, including those coordinated with suppliers and relevant third parties | None | Not Addressed | Not Rated | | ID.IM-03 | IDENTIFY | Improvements are identified from execution of operational processes, procedures, and activities | None | Not Addressed | Not Rated | | ID.IM-04 | IDENTIFY | Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved | None | Not Addressed | Not Rated | | PR.AA-01 | PROTECT | Identities and credentials for authorized users, services, and hardware are managed by the organization | D7-CTL-H03 | Indirectly Supported | Low | | PR.AA-02 | PROTECT | Identities are proofed and bound to credentials based on the context of interactions | None | Not Addressed | Not Rated | | PR.AA-03 | PROTECT | Users, services, and hardware are authenticated | None | Not Addressed | Not Rated | | PR.AA-04 | PROTECT | Identity assertions are protected, conveyed, and verified | None | Not Addressed | Not Rated | | PR.AA-05 | PROTECT | Access permissions, entitlements, and authorizations are defined in policy, managed, enforced, and reviewed, incorporating least privilege and separation of duties | D3-CTL-01, D6-CTL-05, D7-CTL-H03 | Indirectly Supported | Low | | PR.AA-06 | PROTECT | Physical access to assets is managed, monitored, and enforced commensurate with risk | D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-07, D1-CTL-04, D1-CTL-08 | Partially Addressed | Medium | | PR.AT-01 | PROTECT | Personnel receive awareness and training to possess the knowledge and skills to perform general tasks with cybersecurity risks in mind | D1-CTL-02, D2-CTL-03, D5-CTL-06, D7-CTL-H01, D8-CTL-03 | Indirectly Supported | Low | | PR.AT-02 | PROTECT | Individuals in specialized roles receive awareness and training to possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind | D1-CTL-02, D2-CTL-03, D5-CTL-06, D7-CTL-H01, D8-CTL-03 | Indirectly Supported | Low | | PR.DS-01 | PROTECT | The confidentiality, integrity, and availability of data at rest are protected | D2-CTL-05, D5-CTL-05, D6-CTL-07 | Indirectly Supported | Low | | PR.DS-02 | PROTECT | The confidentiality, integrity, and availability of data in transit are protected | D2-CTL-05 | Indirectly Supported | Low | | PR.DS-10 | PROTECT | The confidentiality, integrity, and availability of data in use are protected | None | Not Addressed | Not Rated | | PR.DS-11 | PROTECT | Backups of data are created, protected, maintained, and tested | None | Not Addressed | Not Rated | | PR.PS-01 | PROTECT | Configuration management practices are established and applied | None | Not Addressed | Not Rated | | PR.PS-02 | PROTECT | Software is maintained, replaced, and removed commensurate with risk | None | Not Addressed | Not Rated | | PR.PS-03 | PROTECT | Hardware is maintained, replaced, and removed commensurate with risk | None | Not Addressed | Not Rated | | PR.PS-04 | PROTECT | Log records are generated and made available for continuous monitoring | D2-CTL-04 | Indirectly Supported | Low | | PR.PS-05 | PROTECT | Installation and execution of unauthorized software are prevented | None | Not Addressed | Not Rated | | PR.PS-06 | PROTECT | Secure software development practices are integrated, and performance is monitored throughout the software development life cycle | D8-CTL-05 | Indirectly Supported | Low | | PR.IR-01 | PROTECT | Networks and environments are protected from unauthorized logical access and usage | None | Not Addressed | Not Rated | | PR.IR-02 | PROTECT | Technology assets are protected from environmental threats | D3-CTL-02 | Indirectly Supported | Low | | PR.IR-03 | PROTECT | Mechanisms are implemented to achieve resilience requirements in normal and adverse situations | None | Not Addressed | Not Rated | | PR.IR-04 | PROTECT | Adequate resource capacity to ensure availability is maintained | D6-CTL-07 | Indirectly Supported | Low | | DE.CM-01 | DETECT | Networks and network services are monitored to find potentially adverse events | None | Not Addressed | Not Rated | | DE.CM-02 | DETECT | The physical environment is monitored to find potentially adverse events | D9-CTL-05, D9-CTL-07, D5-CTL-02, D5-CTL-03, D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04 | Partially Addressed | Medium | | DE.CM-03 | DETECT | Personnel activity and technology usage are monitored to find potentially adverse events | None | Not Addressed | Not Rated | | DE.CM-06 | DETECT | External service provider activities and services are monitored to find potentially adverse events | None | Not Addressed | Not Rated | | DE.CM-09 | DETECT | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events | None | Not Addressed | Not Rated | | DE.AE-02 | DETECT | Potentially adverse events are analyzed to better understand associated activities | None | Not Addressed | Not Rated | | DE.AE-03 | DETECT | Information is correlated from multiple sources | None | Not Addressed | Not Rated | | DE.AE-04 | DETECT | The estimated impact and scope of adverse events are understood | None | Not Addressed | Not Rated | | DE.AE-06 | DETECT | Information on adverse events is provided to authorized staff and tools | None | Not Addressed | Not Rated | | DE.AE-07 | DETECT | Cyber threat intelligence and other contextual information are integrated into analysis | None | Not Addressed | Not Rated | | DE.AE-08 | DETECT | Incidents are declared when adverse events meet defined incident criteria | None | Not Addressed | Not Rated | | RS.MA-01 | RESPOND | The incident response plan is executed in coordination with relevant third parties once an incident is declared | D7-CTL-H04 | Indirectly Supported | Low | | RS.MA-02 | RESPOND | Incident reports are triaged and validated | None | Not Addressed | Not Rated | | RS.MA-03 | RESPOND | Incidents are categorized and prioritized | None | Not Addressed | Not Rated | | RS.MA-04 | RESPOND | Incidents are escalated or elevated as needed | None | Not Addressed | Not Rated | | RS.MA-05 | RESPOND | Criteria for initiating incident recovery are applied | None | Not Addressed | Not Rated | | RS.AN-03 | RESPOND | Analysis is performed to establish what occurred during an incident and its root cause | D9-CTL-04 | Indirectly Supported | Low | | RS.AN-06 | RESPOND | Actions performed during an investigation are recorded, and record integrity and provenance are preserved | D1-CTL-01, D4-CTL-01, D9-CTL-07, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01 | Partially Addressed | Medium | | RS.AN-07 | RESPOND | Incident data and metadata are collected, and their integrity and provenance are preserved | D1-CTL-01, D4-CTL-01, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01, D6-CTL-04 | Partially Addressed | Medium | | RS.AN-08 | RESPOND | An incident's magnitude is estimated and validated | D2-CTL-01, D5-CTL-04 | Indirectly Supported | Low | | RS.CO-02 | RESPOND | Internal and external stakeholders are notified of incidents | D8-CTL-04 | Indirectly Supported | Low | | RS.CO-03 | RESPOND | Information is shared with designated internal and external stakeholders | D8-CTL-04 | Indirectly Supported | Low | | RS.MI-01 | RESPOND | Incidents are contained | None | Not Addressed | Not Rated | | RS.MI-02 | RESPOND | Incidents are eradicated | None | Not Addressed | Not Rated | | RC.RP-01 | RECOVER | The recovery portion of the incident response plan is executed once initiated from the incident response process | D7-CTL-H04 | Indirectly Supported | Low | | RC.RP-02 | RECOVER | Recovery actions are selected, scoped, prioritized, and performed | None | Not Addressed | Not Rated | | RC.RP-03 | RECOVER | The integrity of backups and other restoration assets is verified before use | D4-CTL-01, D1-CTL-03, D1-CTL-05, D2-CTL-01, D5-CTL-04, D6-CTL-01, D6-CTL-04, D7-CTL-H02 | Partially Addressed | Medium | | RC.RP-04 | RECOVER | Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms | D9-CTL-04, D9-CTL-07, D1-CTL-03, D3-CTL-07, D6-CTL-01, D6-CTL-04, D9-CTL-01 | Partially Addressed | Medium | | RC.RP-05 | RECOVER | The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed | D4-CTL-01, D1-CTL-05, D2-CTL-01, D5-CTL-04, D7-CTL-H02, D9-CTL-01, D9-CTL-05 | Partially Addressed | Medium | | RC.RP-06 | RECOVER | The end of incident recovery is declared based on criteria, and incident-related documentation is completed | None | Not Addressed | Not Rated | | RC.CO-03 | RECOVER | Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders | None | Not Addressed | Not Rated | | RC.CO-04 | RECOVER | Public updates on incident recovery are shared using approved methods and messaging | None | Not Addressed | Not Rated | ## Notably absent - No NIST certification scheme or endorsement of GAISSF was identified. - No basis was identified for claiming that GAISSF conformance automatically achieves an organization-wide CSF 2.0 Target Profile. - No basis was identified for treating Implementation Examples as mandatory controls. - No universal mapping score or regulatory safe harbour is asserted. ## Licence and attribution Copyright © 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. NIST names and publication identifiers are used for identification only.