AIXYRA
All Frameworks
Security & resiliencePublished February 2024. Voluntary framework with six functions, including the new Govern function.

NIST CSF 2.0

NIST Cybersecurity Framework 2.0

The most widely used cybersecurity framework, updated with a Govern function — and increasingly applied to the AI systems inside the enterprise attack surface.

22 individual requirements seeded and assessable in AIXYRA.

NIST CSF 2.0 organizes cybersecurity outcomes into six functions — Govern, Identify, Protect, Detect, Respond, Recover — applicable to organizations of any size. The 2.0 revision elevated governance to a function of its own: risk strategy, roles, policy, and oversight now sit at the framework's center.

AI enters the CSF picture twice: AI systems are assets to identify and protect, and AI-specific risks — model supply chains, agent tool access, data poisoning — stretch the traditional inventory and monitoring practices the framework presumes. Identify still comes first, and it fails if shadow AI never reaches the inventory.

Who it applies to

Organizations using the CSF to structure cybersecurity programs — especially US enterprises, critical infrastructure operators, and government suppliers extending those programs to cover AI.

Key requirement themes

Govern

Cyber risk strategy, roles, and oversight — now explicitly including risks introduced by AI adoption.

Identify

Asset and risk inventory: you cannot protect AI systems your inventory does not know exist.

Protect & Detect

Access control, hardening, and monitoring extended to AI platforms, agents, and their tool integrations.

Respond & Recover

Incident processes that account for AI dependencies — knowing what breaks downstream when a component is compromised.

Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.

How AIXYRA helps

  • Shadow AI discovery across AWS, Azure, and Google Cloud closes the Identify gap for unregistered AI usage
  • The registry, ownership, and approval workflows give the Govern function operational form for AI
  • Architecture dependency graphs support impact analysis — what is affected when an AI component is compromised
  • Monitoring integrations and governance triggers connect Detect signals to documented re-review

NIST CSF 2.0 FAQ

How does AI change NIST CSF adoption?

The functions stay the same, but the asset surface changes: models, agents, MCP servers, and AI data flows must enter the Identify inventory, Govern must assign them owners and policy, and Protect/Detect must reach AI platforms and their tool access. Shadow AI is the biggest structural gap.

What does AIXYRA contribute to a CSF program?

The AI-specific layer: cloud discovery to surface unregistered AI, a governed inventory with owners and approvals, dependency graphs for impact analysis, and assessments against seeded NIST CSF 2.0 articles with evidence and reporting.

Assess your AI systems against NIST CSF 2.0

NIST CSF 2.0 ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.