The Cybersecurity Framework, pointed at your models.
CSF is voluntary, outcome-based and deliberately technology-neutral, which is exactly why it extends to an AI estate without modification. What it will not do is tell you which assets you forgot — and in an AI estate, that is most of them.
What is NIST CSF?
A voluntary framework from NIST that organises cybersecurity work into functions and describes outcomes rather than controls. Version 2.0 added a sixth function, Govern, and widened the audience from critical infrastructure to organisations of every kind. Because it is outcome-based it applies to an AI estate unchanged — the outcomes are the same, the assets are not.
- Status Voluntary No certification and no penalties. Widely adopted by reference in contracts.
- Version CSF 2.0 Added Govern, and broadened beyond critical infrastructure.
- Shape Functions and outcomes Functions, categories and subcategories, describing outcomes rather than controls.
- Scoping Tiers and Profiles Tiers describe rigour; Profiles describe where you are and where you intend to be.
Who should adopt NIST CSF?
The most commonly named security framework in US contracts after SOC 2, and the one most often used as the organising spine underneath the others.
- Federal suppliers CSF is the vocabulary US public-sector security policy is written in, and it reaches contractors through the terms.
- Critical infrastructure operators Its original constituency, and still where the community profiles are most developed.
- Anyone running NIST AI RMF The two are built on the same logic. CSF for the estate and AI RMF for the models covers both without duplicating the governance work.
- Boards wanting one picture Its function-level view is the clearest way to report posture without a control-by-control appendix.
- Organisations with several frameworks CSF decides which outcomes matter; ISO 27001 or CIS Controls supply the how. Using it as the spine stops the others competing.
How iDharma supports NIST CSF compliance
Function by function, with the AI estate treated as first-class rather than as an annex.
| Function | What the assessment does |
|---|---|
| Govern | Whether AI risk has an owner, a policy and a route to the board — and whether that route has ever actually been used. |
| Identify | The AI asset inventory: models, training data, artefacts, endpoints and the suppliers behind each. This is where most estates are incomplete. |
| Protect | Access control over data and artefacts, secure development for ML pipelines, and supplier controls that reach model providers. |
| Detect | Whether anything would notice model abuse, data exfiltration through outputs, or a poisoned training run. |
| Respond | An incident path covering AI-specific incidents, with a decision-maker who exists and is reachable out of hours. |
| Recover | Rollback to a known-good model version, and what "known-good" means when the artefact is a set of weights. |
| Profiles | A current profile and a target profile, with the distance between them costed and sequenced. |
| Cross-framework mapping | Findings tagged to AI RMF, ISO 27001 and the CIS Controls so one assessment answers more than one ask. |
CSF and NIST AI RMF compose deliberately: CSF secures the estate the models run in, AI RMF addresses the risks the models themselves create. Same publisher, same logic, and findings map cleanly between them.
What the assessment produces
Six areas, each delivering an artefact rather than an opinion.
Asset inventory and system mapping
Identify comes first for a reason
Models, endpoints, notebooks, pipelines and training data, each with an owner and a dependency line to the business function it serves.
Risk assessment and threat modelling
The threats the estate actually faces
Training data integrity, model theft, prompt injection and leakage through outputs, assessed alongside the conventional threats rather than instead of them.
Control implementation tracking
Outcome to control to evidence
Each CSF outcome mapped to the control that delivers it and the record that proves it operated — which is what turns a framework into a programme.
Monitoring and detection workflows
Would anything notice?
Inference patterns, output as an egress path and pipeline integrity, with alerting that reaches a person who can act on it.
Incident response coordination
Exercised, not scheduled
A response path covering AI-specific incidents, named responders, and a rehearsal so the first attempt is not during a real one.
Recovery planning and improvement
The part that is usually theoretical
Rollback to a known-good model version, artefact integrity, and lessons that actually reach Govern rather than stopping at a retrospective.
Complete NIST CSF categories coverage
All six functions assessed, with the categories beneath each scoped to the profile you are working toward.
- GV Govern Strategy, roles, policy, oversight, supply chain
- Covered by the assessment
- ID Identify Assets, risk assessment, improvement
- Covered by the assessment
- PR Protect Identity, awareness, data security, platform
- Covered by the assessment
- DE Detect Continuous monitoring and adverse event analysis
- Covered by the assessment
- RS Respond Management, analysis, reporting, mitigation
- Covered by the assessment
- RC Recover Plan execution and communication
- Covered by the assessment
Governance integration
Govern assessed as the function it now is rather than as an afterthought bolted onto the original five.
Profile management
A current profile and a target profile, with the gap between them treated as the plan the framework intends it to be.
Implementation tiers
A tier chosen deliberately and recorded, because a supervisor will ask why you drew the line where you did.
Multi-framework mapping
Findings tagged to AI RMF, ISO 27001 and the CIS Controls, so one body of evidence answers several asks.
CSF 2.0 core functions
Six functions organising cybersecurity outcomes. Govern is listed first because 2.0 puts it first — a page that appends it to the old five is describing version 1.1 with an extra card.
Govern
New in 2.0, and the reason to re-read the framework
- Organisational context and mission
- Risk management strategy and appetite
- Roles, responsibilities and authorities
- Policy, oversight and board reporting
- Supply chain risk management
- AI risk owned at a named level
Identify
Assets, risk, improvement
- Asset management including models and artefacts
- Training data classified
- Risk assessment across the estate
- Inference endpoints catalogued
- Improvement fed from real findings
Protect
Safeguards that actually reach
- Identity, authentication and access control
- Awareness and training that reaches ML teams
- Data security in transit and at rest
- Platform security and secure configuration
- Technology resilience built in
Detect
Would anything notice?
- Continuous monitoring of the estate
- Adverse event analysis
- Anomalous inference volume or pattern
- Output monitored as an egress path
- Alerting that reaches a human
Respond
Acting on it
- Incident management and triage
- Analysis that reaches root cause
- Reporting and communication
- Mitigation carried through
- Who can disable a model, and how fast
Recover
Getting back
- Recovery plan execution
- Rollback to a known-good model version
- Artefact integrity verified
- Communication during recovery
- Lessons folded back into Govern
Implementation tiers
Tiers describe how rigorous your risk governance is — not how good your security is, and not a maturity score. They are a characterisation, and moving up one is a decision with a cost attached.
Partial
Ad hoc and reactive
- Risk management is informal and case by case
- Limited awareness of cyber risk
- No organisation-wide approach
- Supply chain risk largely unconsidered
Risk informed
Approved, not yet organisation-wide
- Risk management practices approved but not established as policy
- Awareness exists without a consistent approach
- Some prioritisation informed by risk
- Supply chain risk understood in places
Repeatable
Formal and consistent
- Practices formally approved and expressed as policy
- Organisation-wide approach to managing risk
- Consistent methods updated as risk changes
- Supply chain governance acted on consistently
Adaptive
Continuously improving
- Practices adapted from lessons and predictive indicators
- Risk-informed culture across the organisation
- Real-time information used to improve
- Supply chain risk managed at enterprise level
A tier is not a grade. Tier 4 is not the target for everyone, and choosing Tier 2 deliberately with the reasoning written down is a stronger position than claiming Tier 3 and having nothing behind it.
Framework profiles
Profiles are how CSF is actually used. Two of them, and the distance between them is the programme — the framework is explicit that the gap, not the score, is the output.
Current profile
Assessed, not asserted
- Outcomes the organisation is achieving today
- Evidence behind each rather than an opinion
- Gaps named honestly, including the uncomfortable ones
- Scoped to a system, a unit or the whole estate
- The baseline every later comparison runs against
Target profile
Chosen, and justified
- Outcomes required by risk appetite and obligations
- Informed by sector or community profiles where they exist
- Sequenced by consequence rather than by ease
- Costed, so the plan survives a budget conversation
- Revisited as the estate and the threat change
The gap is the deliverable. A current profile on its own is a report; a target profile on its own is an aspiration. What you can act on — and what a board will fund — is the ranked distance between them.
Implementation roadmap
CSF's own method: establish where you are, decide where you need to be, close the distance, then keep it closed. The phases overlap in practice.
-
Phase 1
Foundation
Govern and Identify first
- Establish AI risk ownership and escalation
- Inventory the AI estate and its dependencies
- Classify training data and artefacts
- Agree the scope of the profile
- Choose and record an Implementation Tier
-
Phase 2
Risk assessment
Build the current profile
- Assess each function against outcomes
- Evidence rather than assertion
- Threat model the AI-specific risks
- Record gaps and rank by consequence
- Set the target profile deliberately
-
Phase 3
Control implementation
Close the distance
- Protect: access, secure development, suppliers
- Detect: monitoring that produces real alerts
- Respond: a path that covers AI incidents
- Recover: rollback tested rather than diagrammed
- Owners and dates on every item
-
Phase 4
Continuous improvement
Keep it closed
- Re-assess against the target profile
- Fold lessons back into Govern
- Update as the estate changes
- Report to whoever is accountable
- Fix the review cadence
NIST CSF vs other frameworks
These are not alternatives and choosing between them is usually the wrong question. CSF decides which outcomes matter; the others supply the how, the certificate or the report.
| NIST CSF | ISO 27001 | SOC 2 | CIS Controls | |
|---|---|---|---|---|
| Type | Voluntary framework | Certifiable standard | Attestation report | Prioritised control set |
| Describes | Outcomes | A management system | Controls against criteria | Specific safeguards |
| Third-party seal | None | Certificate | Auditor opinion | None |
| Best at | Deciding what matters | Proving it is managed | Answering a customer | Deciding what to build first |
| Scoping device | Tiers and Profiles | Statement of Applicability | System boundary | Implementation Groups |
| Reaches AI | The estate around the model | The estate around the model | The system boundary | The infrastructure |
| Pairs with | AI RMF for model risk | ISO 42001 for AI | ISO 27001 evidence | CSF or ISO above it |
Each of these has its own page: ISO 27001, SOC 2 and CIS Controls. For the risks the model itself creates rather than the estate around it, see NIST AI RMF.
Complete cybersecurity policy repository
Ready-to-use templates organised by function, with mapping across to ISO 27001 and the CIS Controls so one set of documents answers more than one question.
Govern & Identify
- Cybersecurity Risk Management Policy
- Roles & Responsibilities Charter
- Asset Management Standard
- Data Classification Policy
- Supply Chain Risk Standard
- Risk Assessment Procedure
+ 4 more policies
Protect
- Access Control Policy
- Identity & Authentication Standard
- Data Security Standard
- Secure Configuration Baseline
- Secure Development Standard
- Awareness & Training Plan
+ 4 more policies
Detect, Respond & Recover
- Continuous Monitoring Standard
- Logging & Alerting Procedure
- Incident Response Plan
- Incident Communications Plan
- Recovery & Rollback Procedure
- Post-Incident Review Standard
+ 3 more policies
Frequently asked questions
What comes up in every CSF scoping call.
Is NIST CSF mandatory?
No. It is voluntary and carries no penalties of its own. It becomes binding where a contract names it — which happens often enough in federal and critical-infrastructure supply chains that many organisations treat it as required.
What changed in CSF 2.0?
The headline change is a sixth function, Govern, which pulls strategy, roles, policy, oversight and supply chain risk into their own function rather than leaving them distributed. The scope also widened from critical infrastructure to organisations of every kind, and implementation examples moved online where they can be updated.
How does CSF relate to ISO 27001?
CSF describes outcomes; ISO 27001 certifies a management system. They are complementary rather than competing — CSF is the better spine for deciding which outcomes matter, ISO the better instrument for proving to a third party that the system around them is managed.
Is there a certification?
No. There is nothing to certify against, which makes CSF excellent as an organising framework and useless as a customer-facing claim on its own. Pair it with something certifiable if you need the latter.
What are the four Implementation Tiers?
Partial, Risk Informed, Repeatable and Adaptive. They characterise how rigorous your risk governance is — not how good your security is. They are deliberately not a maturity model and not a grade.
What is the difference between a current and a target profile?
The current profile records the outcomes you are achieving today, with evidence. The target profile records the outcomes you need, given your risk appetite and obligations. The distance between them, ranked by consequence and costed, is the programme — and it is what a board will actually fund.
How long does implementation take?
The current profile takes weeks; closing the gap takes as long as the gap is wide. The useful discipline is to cost the target profile honestly at the start, because an uncosted target is where CSF programmes quietly stall.
Do we need to reach Tier 4?
Almost certainly not. Tier 4 suits organisations facing sustained targeted attack. For most, choosing Tier 2 or 3 deliberately and recording why is a stronger position than claiming a tier you cannot evidence.
Does CSF cover AI risk?
It covers securing the systems AI runs in, which is a large part of the problem but not all of it. Risks the model itself creates — bias, confabulation, unsafe outputs — sit with NIST AI RMF. Running both is the complete answer, and they were designed to compose.
What does Detect look like for a model?
Monitoring inference patterns for abuse, treating outputs as an egress path that can leak training data, and checking training pipeline integrity. Most estates have none of this, because the model was treated as an application feature rather than as infrastructure.
What does Recover mean when the asset is a set of weights?
Rollback to a known-good version, which requires that versions are retained, integrity-checked and actually restorable. Worth testing, because the first time anyone tries is usually during an incident.
Does Govern change anything for an AI programme?
Materially, yes. Govern is where AI risk ownership, acceptable-use policy, supply chain risk over model providers and board reporting all belong. In 1.1 those were scattered; in 2.0 there is a single place to look and a single place to fail.
Ready to run CSF across your AI estate?
A current profile, a target profile, and the gap ranked by consequence rather than by ease.
This page is guidance on how we scope an assessment, not legal advice.