The draft offers prompts for reviewing cyber governance and developing organizational profiles, while emphasizing human oversight and data safeguards. Public comments are due by Oct. 15.

The National Institute of Standards and Technology (NIST) released a draft guide on Aug. 19 outlining how organizations can use artificial intelligence (AI) to analyze and monitor their progress toward achieving the agency’s Cybersecurity Framework (CSF) 2.0 outcomes.

The draft document, titled “Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting,” provides sample prompts and three notional use cases for applying generative AI to CSF analysis. NIST is accepting public comments on the draft guide through Oct. 15.

“The CSF 2.0 provides guidelines and a common language to help organizations of all sizes and sectors manage cybersecurity risks,” the guide says. “In practice, organizations are increasingly leveraging Artificial Intelligence (AI) systems to better understand, assess, prioritize, and communicate their cybersecurity efforts in alignment with CSF 2.0.”

“For example, AI can help with analyzing, planning, implementing, and monitoring the organization’s progress toward achieving the outcomes of the CSF 2.0,” it adds.

The first use case applies AI to evaluate an organization’s cybersecurity policy, strategy, and risk governance in alignment with the CSF 2.0 outcomes. A sample prompt directs the AI system to identify areas that are aligned, partially aligned, misaligned, or not addressed.

The second use case shows how AI could be used “to produce a draft CSF Organization Current State Profile – mapping artifacts and personnel interview notes to CSF 2.0 outcomes, documenting any assumptions, and recording observed gaps in the interviews and evidence.”

The third use case focuses on developing a target-state profile based on organizational artifacts. NIST said the model would reduce manual research, as well as flag “gaps or inconsistencies between stated risk priorities and the selected target tiers.”

NIST uses the Context, Objective, Style, Tone, Audience, and Response – or CO-STAR – prompt framework in its examples. However, the agency said organizations should choose whichever prompt structure best fits their requirements.

The draft stresses that its examples are not assessment or assurance methodologies. Organizations should review AI tools’ data-retention, training, access-control, and confidentiality settings before submitting sensitive information.

“AI-generated content should always be reviewed by qualified personnel before being used in organizational decision-making,” the guide says. “Users are responsible for validating applicability, scope, inputs, assumptions, and outputs of AI systems.”

Comments and proposed additional use cases may be submitted to NIST at csf@nist.gov.

Read More About