r/grc 9d ago

NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting

I saw this posted in my LinkedIn feed - just wondered if anyone here has tried applying it (or home rolled equivalent) yet?

https://csrc.nist.gov/pubs/sp/1353/ipd

In particular, they've used the COSTAR prompt model - which seems really well suited for compliance type work.

I'd be interested if anyone has tried applying that prompt model to other use cases - or has tried other prompt models

26 Upvotes

5 comments sorted by

6

u/Round_Finance4256 9d ago

I’ve been experimenting with AI for my GRC work, especially around control mapping, gap analysis, evidence summaries, and drafting audit-ready narratives. I haven’t used COSTAR specifically yet, but I like the structure here.

The biggest thing for me is keeping a human in the loop. AI can speed up the analysis significantly, but I wouldn’t want it making the final compliance determination without validation. Definitely interested in testing this model against some real world GRC use cases.

1

u/Total-Estimate758 4d ago

haven't touched COSTAR yet but the mapping and gap analysis angle resonates, that's where half my week disappears anyway

1

u/AdPriya4022 3d ago

AI is great at speeding up the work, just don't allow it to sign off on anything for you