# CRO-033 — GAISSF–CIS Controls Mapping v1.0 > Status: Publication Candidate This crosswalk maps 59 GAISSF controls to the 18 CIS Controls v8.1 families through 194 outcome-based records. It does not establish implementation of the 153 underlying Safeguards. ## Source baseline - GAISSF-NOR-001 and GAISSF-NOR-004 v1.0 - CIS Controls v8.1 - Verification date: 29 June 2026 ## Control coverage | Control | Title | Mapped GAISSF controls | Coverage | |---|---|---:|---| | 1 | Inventory and Control of Enterprise Assets | 10 | Substantially Addressed | | 2 | Inventory and Control of Software Assets | 6 | Partially Addressed | | 3 | Data Protection | 21 | Substantially Addressed | | 4 | Secure Configuration of Enterprise Assets and Software | 7 | Partially Addressed | | 5 | Account Management | 14 | Substantially Addressed | | 6 | Access Control Management | 9 | Substantially Addressed | | 7 | Continuous Vulnerability Management | 12 | Substantially Addressed | | 8 | Audit Log Management | 21 | Substantially Addressed | | 9 | Email and Web Browser Protections | 9 | Substantially Addressed | | 10 | Malware Defenses | 14 | Substantially Addressed | | 11 | Data Recovery | 1 | Indirectly Supported | | 12 | Network Infrastructure Management | 3 | Partially Addressed | | 13 | Network Monitoring and Defense | 13 | Substantially Addressed | | 14 | Security Awareness and Skills Training | 10 | Substantially Addressed | | 15 | Service Provider Management | 8 | Substantially Addressed | | 16 | Application Software Security | 11 | Substantially Addressed | | 17 | Incident Response Management | 5 | Partially Addressed | | 18 | Penetration Testing | 20 | Substantially Addressed | ## Limitations - Mapping is not CIS certification, accreditation, assessment, SecureSuite conformance, or proof of implementation effectiveness. - CIS Controls v8.1 contains 153 Safeguards assigned across Implementation Groups; this publication maps at the 18-Control family level and does not reproduce the full licensed Safeguard text. - Implementation Group selection is risk- and resource-dependent and must be determined by the implementing enterprise. - CIS Benchmarks, CIS RAM, CIS CSAT and CIS SecureSuite are separate resources and are not substituted by this crosswalk. - Similar terminology does not establish equivalence; enterprise IT outcomes and AI-specific security outcomes may differ materially. - Future CIS revisions require revalidation. ## Notably Absent No CIS certification, accreditation, Safeguard-completeness claim, IG determination or CIS endorsement is asserted.