Skip to the content.

Mappings to the six CSF 2.0 functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER.

This file is one self-contained piece of the AI IR Overlay™ framework. Cross-references to other pieces point to other packages in the same set, which you can obtain at jacobideji.com.


Crosswalk: AI IR Overlay ↔ NIST Cybersecurity Framework 2.0 (CSF 2.0)

This crosswalk maps AI IR Overlay controls to NIST CSF 2.0 functions and categories. CSF 2.0 (February 2024) introduced GOVERN as a sixth function and is the foundation for NIST SP 800-61 r3’s incident-response Community Profile (April 2025).

The crosswalk gives auditors, regulators, and boards a direct path from AI IR Overlay conformance to CSF 2.0 outcomes, and by extension, to SP 800-61 r3 alignment.

At a Glance

AI IR Overlay Control Primary CSF 2.0 Function(s) Categories
MVO-1 Inventory IDENTIFY (+ GOVERN) ID.AM, GV.OC, GV.RR
MVO-2 Safe Modes (Kill-Switches) RESPOND RS.MA, RS.MI
MVO-3 Minimum Evidence Set RESPOND (+ DETECT) RS.AN, DE.AE
MVO-4 Controlled Re-Enable RECOVER RC.RP, RC.CO
Six Triage Questions RESPOND RS.MA, RS.AN
Mental Model GOVERN (+ PROTECT) GV.PO, GV.RM, PR.AA
Maturity Roadmap IDENTIFY + GOVERN ID.IM, GV.OV

Detailed Mappings

MVO-1 Inventory ↔ IDENTIFY + GOVERN

The AI-BOM template (see README) operationalizes:

Gap note: CSF 2.0 doesn’t specify an inventory schema for AI agents. AI-BOM fills the gap with a concrete YAML template.

MVO-2 Safe Modes ↔ RESPOND

The Kill-Switch Modes (M0–M5) operationalize:

Gap note: CSF 2.0 specifies that incidents must be contained but not how to graduate containment to preserve business value while preventing harm. The six-mode ladder fills this operational gap.

MVO-3 Minimum Evidence Set ↔ RESPOND (with DETECT inputs)

The Six Evidence Types (A–F) operationalize:

Gap note: CSF 2.0 mandates evidence collection and preservation but doesn’t enumerate AI-specific evidence types. The A–F set provides the operational specification.

MVO-4 Controlled Re-Enable ↔ RECOVER

Staged recovery operationalizes:

Six Triage Questions ↔ RESPOND

The first-hour discipline operationalizes:

Mental Model ↔ GOVERN + PROTECT

The four-clause model operationalizes:

Maturity Roadmap ↔ IDENTIFY + GOVERN

The four-level model operationalizes:

How to Use This Crosswalk

When responding to an auditor, regulator, board member, or downstream contributor framing a question in CSF 2.0 terms, this crosswalk provides direct evidence of AI IR Overlay conformance.

Example: “How does your organization satisfy RS.MI-01 (incidents are contained) for your AI agents?”

Answer: “We implement the AI IR Overlay Kill-Switch Modes M1–M4 (Read-Only, Approvals Required, Tool Tiering, Full Disable), tabletop-tested quarterly per the Kill-Switch Modes specification. Our AI-BOM documents which modes each agent supports, with last-tested dates and measured Time-to-Activate (TTA) values.”

Relationship to SP 800-61 r3

NIST SP 800-61 r3 (April 2025) is itself a CSF 2.0 Community Profile for incident response. The AI IR Overlay can be read as an AI-specific extension of SP 800-61 r3:

A future v0.2+ playbook will formalize this layered relationship in a companion SP 800-61 r3 ↔ AI IR Overlay crosswalk.

Status

Source


Last revised: 2026-06-20 · Maintainer interpretation, not a NIST publication.

Source: AI IR Overlay newsletter and framework synthesis, by Jacob Ideji. https://www.linkedin.com/in/jacobideji/