Last verified 6 min read Security standards and AI usage

NIST SP 1353 ipd: CO-STAR Prompts for CSF 2.0 Analysis

What NIST's draft SP 1353 contains: three notional use cases, NIST's guidance for each CO-STAR field, the Style-line differences, and the comment deadline.

This article was researched, verified against primary sources, and written by AI agents. It is not a hands-on review.

Conclusion: a draft open for comment, with CO-STAR prompts for three notional use cases

According to the NIST CSRC publication page, the initial public draft of SP 1353 was published on 19 August 2026. What it contains:

  • Three notional use cases: a governance policy review, a Current State Profile draft, and a Target State Profile draft
  • One CO-STAR sample prompt per use case, abbreviated in the body of the guide
  • A comment deadline of 15 October 2026 at 11:59 PM, addressed to csf@nist.gov
  • An explicit disclaimer that the use case examples “illustrate a possible approach and are not prescriptive assessment or assurance methodologies”

Everything below comes from NIST’s own published documents. As of 20 August 2026, no independent third-party reporting on this draft was found.

Reference details

ItemValue
DocumentNIST SP 1353 ipd (Initial Public Draft)
TitleQuick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting
Published19 August 2026
Body PDF9 pages
DOI10.6028/NIST.SP.1353.ipd
Comments due15 October 2026, 11:59 PM
Comment addresscsf@nist.gov

What each use case produces

Use caseInputs comparedOutput
Use Case 1Organizational cybersecurity policy, strategy and risk governance against the CSF 2.0 GOVERN (GV) outcomesAn AI-assisted review
Use Case 2Organizational artifacts plus personnel interview notesA draft CSF Organization Current State Profile
Use Case 3Internal and industry referencesA draft CSF Target State Profile

Use Case 2 also covers documenting assumptions and recording observed gaps in the interviews and evidence. Use Case 3 describes desired outcomes meeting mission objectives, stakeholder expectations, the risk landscape, and requirements.

“Outcome” is a defined CSF term

The glossary reads: “Outcome — A desired cybersecurity result described by a CSF Subcategory.” It also notes that its definitions are “intended as plain language” and points to the NIST Glossary for official ones. Use Cases 2 and 3 produce a draft profile, not a finished one; Use Case 1 produces an AI-assisted review.

What NIST says about each CO-STAR field

FieldNIST’s description (page 3)
ContextBackground, constraints and the specific scenario affecting the desired CSF outcomes
ObjectiveThe purpose of the CSF activity, so the model focuses on that goal
StyleThe response style (e.g. technical, managerial, audit-based)
ToneThe tone (i.e. objective, authoritative), to align with the target audience
AudienceThe intended audience, setting abstraction, precision of terms and structure
ResponseFormat and structure of the CSF-related output

NIST does not recommend CO-STAR

The guide lists other frameworks — CRAFT, RISEN, RTF, APE, CREATE — with “e.g.” and “etc.”, and states that “Users should choose a prompt framework that best serves their particular use case.” Page 7 adds that CO-STAR is what this guide uses, but organizations “may want or need to use an alternative prompt format.” What those five frameworks contain is never explained.

The Style lines are not identical across the three prompts

Use caseStyle field (opening)
Use Case 1Executive, evidence-based; no inference beyond provided artifacts; no maturity scoring; no benchmarking unless explicitly provided
Use Case 2Source-grounded and traceable. No fabrication. If an outcome is not addressed in the sources, say so plainly.
Use Case 3Identical wording to Use Case 2

Use Cases 2 and 3 continue by asking for concise, specific writing with consistent structure across all rows. Their Tone fields are also identical: “Technical but plainly readable. Use precise cybersecurity terminology.”

So the sentence “No fabrication.” appears in two of the three Style fields. Use Case 1 uses different wording pointing the same way: stay inside the supplied artifacts.

Two qualifiers that are easy to drop

no benchmarking unless explicitly provided is conditional, not a blanket ban on benchmarking. And If an outcome is not addressed in the sources, say so plainly asks the model to state the absence, not to fill the gap by inference.

The prompts on pages 4 to 6 carry a footnote saying they are abbreviated for illustrative purposes, and that the supplemental files provide a more comprehensive prompt for each use case.

Supplemental files and the page 9 workflow

The CSRC publication page distributes four ZIP files: an “Organizational Documents” folder for a fictitious company called Halverston Community Bank, and one folder per use case holding the abbreviated prompt plus an expanded version. The simulated documents are bank security requirements, staff interview notes, a security policy handbook, a risk register, and an Organizational Profile template.

Page 9 gives four steps:

  1. Open an AI tool authorized for use by the organization’s security and privacy team
  2. Upload the files from the “Organizational Documents” folder into the AI tool
  3. Copy the entire CO-STAR formatted prompt from one of the use cases and paste it in
  4. Generate output in the preferred format for review

Caveats before you reuse any of this

Review by qualified personnel is a “should”, not a “must”

Pages 3, 7 and 9 repeat: “AI-generated content should always be reviewed by qualified personnel before being used in organizational decision-making.” Users are responsible for validating applicability, scope, inputs, assumptions and outputs, and the guide says to “Consider using multiple AI tools and comparing results when validating AI output” — consider, not recommend.

There are no effectiveness numbers in the draft

Use Case 2 lists “Compressing the initial drafting from weeks to hours” under “Example ways AI can help.” That is an example item, not a measured result. The 9-page body has no accuracy figures, hallucination rates or reduction percentages.

Hallucinations are reduced, not removed

The glossary defines hallucination as “Plausible but inaccurate AI output; requires expert review before use.” Page 9 advises: “When presented with options, use a more advanced processing option to reduce likelihood of hallucinations (though they can still occur).” The parenthesis is the point, and no specific model or paid tier is named. Page 9 also notes the content reflects a point-in-time output and results can change or vary.

No product names appear in the body

No AI model, product or vendor name appears in the 9-page body (the supplemental ZIP files were outside the scope of this check). The guide states that its usage “does not imply that the models, software, profiles or services are the best available for this purpose, nor does it imply recommendation or endorsement by NIST.”

The fictitious documents are not templates

The guide states: “Although AI tools were not used to author this QSG, AI tools, prompts, profiles and fictitious data were used in the prompt research to produce this guide and the sample organizational documents.” The Halverston Community Bank records were created with generative AI and “should not be used as templates for actual use.” The publication page adds that NIST seeks comment on the guide and prompts, not on the fictional documents.

Translations, as of 20 August 2026

On the NIST CSF 2.0 Quick Start Guides page, this AI guide offers an English download only; the “Download Translations” links that accompany other guides are absent for this entry. CSF 2.0 itself and several other quick-start guides do have translations, including Japanese. NIST says nothing about translation plans, so treat this as a point-in-time observation.

Sources

  1. NIST SP 1353 (Initial Public Draft) publication page (CSRC) 米国政府機関 published 2026-08-19 accessed 2026-08-20
  2. Seeking Public Comment! Using Artificial Intelligence for Cybersecurity Framework 2.0 Analysis and Reporting (NIST news) 米国政府機関 published 2026-08-19 accessed 2026-08-20
  3. NIST SP 1353 ipd full text PDF (9 pages) 米国政府機関 published 2026-08-19 accessed 2026-08-20
  4. CSF 2.0 Quick Start Guides (NIST) 米国政府機関 published 2026-08-19 accessed 2026-08-20