r/grc • u/FreeRadical1998 • 9d ago
NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting
I saw this posted in my LinkedIn feed - just wondered if anyone here has tried applying it (or home rolled equivalent) yet?
https://csrc.nist.gov/pubs/sp/1353/ipd
In particular, they've used the COSTAR prompt model - which seems really well suited for compliance type work.
I'd be interested if anyone has tried applying that prompt model to other use cases - or has tried other prompt models
26
Upvotes
6
u/Round_Finance4256 9d ago
I’ve been experimenting with AI for my GRC work, especially around control mapping, gap analysis, evidence summaries, and drafting audit-ready narratives. I haven’t used COSTAR specifically yet, but I like the structure here.
The biggest thing for me is keeping a human in the loop. AI can speed up the analysis significantly, but I wouldn’t want it making the final compliance determination without validation. Definitely interested in testing this model against some real world GRC use cases.