Skip to content
Menu
Menu

NIST Publishes AI Prompts That Draft A Company’s Cybersecurity Assessment, Opens Them To Comment

Companies paste the prompts into a chatbot, which drafts the cybersecurity assessment that customers, regulators, and insurers ask to see; comments are open until October 15.

 

The National Institute of Standards and Technology (NIST) published three free AI prompts that speed up the creation of a company’s cybersecurity assessment. NIST released them on August 19 as a draft and is taking public comments until October 15.

A cybersecurity assessment is a line-by-line record of the policies and practices a company has in place for each of NIST’s security recommendations. Customers, regulators, and insurers ask to see these assessments when they want to judge how a company manages security risk. Producing one means reading every security policy, audit result, penetration test report, and procedure the company holds, then writing up each item by hand.

Companies are already using AI for this, NIST says. Each prompt is a block of text a company pastes into an AI tool along with those documents, and all three prompts follow a format called CO-STAR: context, objective, style, tone, audience, and the desired response. NIST published them to give security teams a usable starting point and to record how practitioners construct prompts for this task.

 

Each prompt produces a different part of the cybersecurity assessment

The first prompt covers security governance: who makes security decisions and who oversees them. It reads the company’s policies and strategy and rates each item as aligned, partly aligned, misaligned, or not addressed, naming the document behind every mark.

The second drafts the full cybersecurity assessment for where the company currently stands. NIST says this prompt can compress the initial drafting from weeks to hours.

The third recommends the cybersecurity posture the company should have instead, based on risks it already identified and published industry practice. The difference between what the company does today and what it should be doing shows which of NIST’s recommendations it is not yet meeting.

 

NIST limits the scope of the prompt

The NIST prompts tell the chatbot to use only the documents they receive and infer nothing beyond them, to cite the policy or requirement behind every entry, and to state plainly where those documents say nothing rather than filling the gap. They bar the chatbots from rating how advanced the company’s security is, or comparing it to other companies, unless someone supplies the comparison data.

Each draft must close with a note on where the evidence is thin, including any entry resting on a documented procedure rather than proof that anyone follows it.

 

NIST tells companies to check

The chatbot analyzes documents a company already holds: security policies, past risk assessments, audit results, penetration test reports, vulnerability scan results, and notes from staff interviews. Before uploading, NIST says to check how the AI tool handles the above data, including how long it keeps what it receives and whether it trains on it, and to follow the company’s own data policy. Once the chatbot produces a draft, NIST recommends that someone qualified review it before anyone acts on it.

 

How to comment

Comments go to [email protected] until October 15. NIST can revise the prompts, the conditions attached to them, or the three uses before it publishes a final version.

 

NIST published a separate draft in December on how to protect AI systems from attack and how to defend against attackers who use AI. Comments on that one closed on January 30.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!