# CRO-024 - GAISSF-OWASP Top 10 for LLM Applications 2025 Mapping **Version:** 1.0 **Status:** Publication Candidate **Publisher:** ODA3 Institute **Publication date:** 29 June 2026 > This crosswalk documents risk-to-control relationships. It does not establish OWASP endorsement, certification, equivalence, vulnerability absence, or implementation effectiveness. ## Source baseline - GAISSF-NOR-001 v1.0 and GAISSF-NOR-004 v1.0, 59-control baseline. - OWASP Top 10 for LLM Applications 2025, published 17 November 2024. - The 2025 identifiers LLM01:2025 through LLM10:2025 are used throughout. ## Executive findings - 59 GAISSF controls assessed. - 10 OWASP risk categories assessed. - 59 forward mapping records created and reverse checked. - Strongest alignment areas include adversarial robustness, runtime defenses, agentic controls, supply-chain assurance, output integrity, sensitive-information protection, and resource governance. - Residual implementation risk remains material because OWASP categories describe vulnerability classes, while GAISSF defines controls and evidence expectations. ## OWASP-to-GAISSF reverse coverage | OWASP ID | Risk | GAISSF controls | Coverage | Confidence | |---|---|---|---|---| | LLM01:2025 | Prompt Injection | D1-CTL-03, D1-CTL-05, D1-CTL-06, D1-CTL-08, D2-CTL-01, D2-CTL-02, D2-CTL-03, D2-CTL-04, D2-CTL-05, D2-CTL-06, D6-CTL-02, D6-CTL-03 | Indirectly Supported | Low | | LLM02:2025 | Sensitive Information Disclosure | D5-CTL-05 | Indirectly Supported | Low | | LLM03:2025 | Supply Chain | D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-06, D8-CTL-02 | Indirectly Supported | Low | | LLM04:2025 | Data and Model Poisoning | D1-CTL-01, D1-CTL-04, D1-CTL-07, D1-CTL-09, D5-CTL-01, D5-CTL-02, D5-CTL-03, D5-CTL-04, D5-CTL-06, D8-CTL-03, D9-CTL-07 | Indirectly Supported | Low | | LLM05:2025 | Improper Output Handling | | Indirectly Supported | Low | | LLM06:2025 | Excessive Agency | D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-06, D3-CTL-07, D6-CTL-01, D9-CTL-02 | Indirectly Supported | Low | | LLM07:2025 | System Prompt Leakage | | Indirectly Supported | Low | | LLM08:2025 | Vector and Embedding Weaknesses | D7-CTL-H01 | Indirectly Supported | Low | | LLM09:2025 | Misinformation | D7-CTL-H03, D7-CTL-H04 | Indirectly Supported | Low | | LLM10:2025 | Unbounded Consumption | D1-CTL-02, D6-CTL-04, D6-CTL-07, D7-CTL-H02 | Indirectly Supported | Low | ## Notably absent - No OWASP certification, approval, or endorsement of GAISSF is asserted. - No claim is made that mapping coverage proves a vulnerability has been eliminated. - No claim is made that the OWASP Top 10 is exhaustive or substitutes for threat modelling and testing. - No aggregate compliance percentage or safe-harbour claim is provided. ## Licence and attribution Copyright © 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. OWASP and its project names remain the property of the OWASP Foundation, Inc. References are for identification and interoperability analysis only.