Spelling: American spellings in the NIST Cybersecurity Framework (CSF) 2.0 and AI RMF 1.0 text have been changed to British English, for example organisation, authorise and behaviour. The National Institute of Standards and Technology name, function names, tier names and identifiers are unchanged.
NIST AI Risk Management Framework (AI RMF 1.0)
Open a function, then select a category to see its subcategories and the AI RMF Playbook's suggested actions.
Sources and counts
The text of every element shown is NIST's own, taken from the exports listed below. Only American spellings have been changed to British English, by a fixed word table, and the CSF 1.1 legacy elements in the CSF 2.0 export are left out. Times are Europe/London.
Sources
- NIST CSF 2.0 Core with Implementation ExamplesCybersecurity and Privacy Reference Tool (CPRT) JSON export, framework version CSF_2_0_0https://csrc.nist.gov/extensions/nudp/services/json/nudp/framework/version/csf_2_0_0/export/json?element=all
- NIST AI RMF 1.0 CoreCPRT JSON export, framework version AI_100_1_0_0 (NIST AI 100-1; CPRT data version 1.1.0)https://csrc.nist.gov/extensions/nudp/services/json/nudp/framework/version/ai_100_1_0_0/export/json?element=all
- NIST AI RMF PlaybookNIST AI Resource Center JSON download (suggested actions per subcategory)https://airc.nist.gov/docs/playbook.json
Counts
| Framework | Functions | Categories | Subcategories | Examples | Notes |
|---|---|---|---|---|---|
| CSF 2.0 | 6 | 22 | 106 | 363 implementation examples | 91 CSF 1.1 legacy elements removed from the NIST export (12 categories, 79 subcategories marked withdrawn, moved or incorporated into CSF 2.0 elements). |
| AI RMF 1.0 | 4 | 19 | 72 | 462 Playbook suggested actions | First level actions only; nested points are listed under the action they belong to. |