r/grc 9d ago

NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting

I saw this posted in my LinkedIn feed - just wondered if anyone here has tried applying it (or home rolled equivalent) yet?

https://csrc.nist.gov/pubs/sp/1353/ipd

In particular, they've used the COSTAR prompt model - which seems really well suited for compliance type work.

I'd be interested if anyone has tried applying that prompt model to other use cases - or has tried other prompt models

26 Upvotes

Duplicates