The U.S. National Institute of Standards and Technology (NIST) published a guide that outlines practical and actionable ways AI (artificial intelligence) can support analysis, planning, implementation and monitoring of an organization’s progress toward achieving CSF 2.0 outcomes. The document aims to provide structured AI prompts as tools that practitioners can use to begin creating CSF-related artifacts in support of achieving CSF outcomes, and to identify current state of practice in AI prompt engineering for CSF implementation and analysis.
The NIST SP 1353 (Initial Public Draft), NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting document recognizes that the CSF 2.0 provides guidelines and a common language to help organizations of all sizes and sectors manage cybersecurity risks. In practice, organizations are increasingly leveraging AI systems to better understand, assess, prioritize, and communicate their cybersecurity efforts in alignment with CSF 2.0. For example, AI can help with analyzing, planning, implementing, and monitoring the organization’s progress toward achieving the outcomes of the CSF 2.0.
While the document is not intended to cover AI best practices or provide cybersecurity guidelines, it includes three notional use cases, examples of prompts for structuring natural-language inputs to generate specified CSF 2.0 outputs from generative AI models, simulated organizational files for a fictitious company, tips for getting started, and more.
The first use case illustrates the use of an AI-assisted review to evaluate organizational cybersecurity policy, strategy, and risk governance in alignment with the CSF 2.0 outcomes. The second one demonstrates how to produce a draft Organization Current State Profile mapping artifacts and personnel interview notes to CSF 2.0 outcomes, documenting any assumptions, and recording observed gaps in the interviews and evidence. The third one showcases how to draw upon internal and industry references to create a draft CSF target state profile describing desired outcomes to meet mission objectives, stakeholder expectations, address risk landscape, and fulfill requirements.
In the first instance, the NIST SP 1353 documented that a CSF 2.0 quick-start guide focused on using AI for CSF analysis and reporting. The use case addresses reviewing organizational policies and strategy to align with CSF governance. The CSF 2.0 Governance Alignment View provides a structured way to evaluate whether cybersecurity policy, strategy, and risk governance are aligned with CSF 2.0 GOVERN (GV), with particular emphasis on accountability, oversight, and risk decision-making.
Organizations can input several types of source material for this analysis. These include governance artifacts such as policies, standards, and procedures; cybersecurity risk governance context encompassing risk appetite, tolerance, and decisions; organizational strategy documents; organizational context relating to industry and regulatory environment; and supply chain and third-party risk context.
AI can assist with several outcomes in this use case. These outcomes include conducting a CSF 2.0 GV evaluation across OC, RM, RR, PO, OV, and SC categories; performing cybersecurity risk governance consistency analysis across GV domains; and identifying governance deficiencies and inconsistencies.
It also provides an abbreviated example of an executable co-star prompt that guides an AI evaluation of cybersecurity governance using NIST CSF 2.0 GOVERN, with the AI tasked to produce an executive summary of governance alignment posture and key misalignments, along with governance evaluations and implications across CSF 2.0 Govern categories. Supplemental files also provide a more comprehensive version of this prompt.
The NIST SP 1353 guide detailed Use Case 2 from the CSF 2.0 quick-start guide on using AI for CSF analysis and reporting. The use case focuses on developing a CSF Current State Profile based on organizational artifacts. The use case is to analyze current cybersecurity state and facilitate mapping existing practices to the CSF Core’s Subcategories to improve efficiency and help rapidly develop a draft Current State Profile. Additionally, it automates labor-intensive tasks of reviewing, correlating, and aligning numerous source documents, many of which can be lengthy. This capability creates an effective draft CSF profile with consistent language, reduced variance, and comprehensive outcomes.
Organizations can provide several types of source material as input for this analysis. These materials include governance and policy documents such as security policies, standards, and procedures; existing control frameworks in use such as ISO 27001, SOC 2, PCI DSS, and CIS; assessment artifacts including prior risk assessments, internal and external audit findings, penetration test reports, and vulnerability scan results; other technical and operational process and procedure documentation; organizational strategy documents; and organizational context encompassing business objectives, risk tolerance, and regulatory or contractual requirements, as well as information about practices not otherwise documented.
AI can assist with several outcomes in this use case. AI can compress the initial drafting phase from weeks to hours by rapidly ingesting and correlating large document sets. It can apply uniform language and interpretation that can then be reviewed and refined by human subject matter experts. AI can also surface cross-references that link a policy statement to a scan result to an audit finding, connections that a manual reviewer might overlook.
NIST SP 1353 includes a simplified example of an executable co-star prompt designed to support a NIST CSF 2.0 assessment. The prompt instructs the AI to populate columns of a CSF 2.0 organizational profile template with current policies and practices for every outcome in the framework. The style requirement specifies source-grounded and traceable output with no fabrication, and if an outcome is not addressed in the sources, the AI should plainly state this. The tone is technical but plainly readable, using precise cybersecurity terminology.
The intended audience is the CISO and cybersecurity team members who will use the profile as evidence-based baseline information for gap analysis, prioritization, and target-state planning. The supplemental files provide a more comprehensive version of this prompt.
The guide’s third use case focuses on developing a CSF Target State Profile based on organizational artifacts. It describes a risk-based approach to defining a target state that supports an acceptable level of risk and fulfills applicable requirements. A CSF Organizational Profile draws on complex and interrelated factors to describe desired outcomes that meet mission objectives, stakeholder expectations, address the risk landscape and fulfill requirements.
The example source materials include CSF 2.0 Community Profiles created and published to address shared interests and goals among several organizations, risk governance and management artifacts such as policies, senior leaders’ risk guidance and direction, and risk registers, as well as organizational strategy documents. They also include industry examples and standards of good practices and recommended activities for addressing known risks and requirements.
AI can help map an organization’s context against the NIST CSF 2.0 Functions to produce an initial Target Profile draft, reducing the manual research and writing time typically needed to develop a workable starting point. It can also help ensure that all relevant Categories and Subcategories are considered systematically, flag gaps or inconsistencies between stated risk priorities and selected target tiers, and translate technical outcomes into plain-language descriptions for different audiences, including executives, auditors and technical teams.
The guide also provides a simplified example of an executable CO-STAR prompt for this use case. The prompt instructs the AI to work from the NIST CSF 2.0 Organizational Profile template and use only the attached source materials. Its objective is to define a target state that supports an acceptable level of risk and fulfills applicable requirements, while mapping each CSF outcome to the specific requirements or risk responses that drive it. The prompt emphasizes a source-grounded and traceable approach, with no fabrication, and requires concise and specific responses using consistent structures across the rows.
The prompt is intended for CISOs and cybersecurity team members who will use the Target Profile as a risk-based baseline for risk analysis, prioritization and target-state planning. It directs the AI to complete the relevant columns for all outcomes, cite the drivers inline and identify assumptions and evidence gaps, including outcomes where requirements or risk registers do not define an explicit target, targets that imply new tooling, budget or staffing, and dependencies or sequencing that the team should validate before creating a roadmap.
The guide also provides several tips for getting started. Organizations can use the sample prompts as a starting point for applying AI to CSF 2.0 planning and implementation, choose a prompt format that meets their needs, select AI tools authorized by their security and privacy teams, convene stakeholders to discuss scope, resources, roles and responsibilities, and collect the necessary organizational artifacts approved for ingestion into an authorized AI tool. The guide recommends continuously reviewing and refining inputs and outputs to achieve the desired results.
It also reminds users to review an AI tool’s privacy and security settings, including data retention, training, access privileges and confidentiality terms, as well as company data policies before entering sensitive information. AI-generated content should be reviewed by qualified personnel before being used in organizational decision-making, with users responsible for validating the applicability, scope, inputs, assumptions and outputs of AI systems. The guide also suggests considering multiple AI tools and comparing their results when validating AI output.
The NIST CSF 2.0 guidance emerges amid escalating threats to industrial control systems. On Wednesday, U.S. agencies including the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA) issued a joint Cybersecurity Advisory warning of active exploitation targeting Siemens S7 Series programmable logic controllers (PLCs). The threat spans critical infrastructure sectors including critical manufacturing, energy, water and wastewater systems, chemical, food and agriculture, and commercial facilities. Attackers are leveraging AI-generated scripts to exploit these devices, creating potential for significant operational disruption.
Anna Ribeiro
Industrial Cyber News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in the areas of security, data storage, virtualization and IoT.







