NIST Draft Shows How AI Can Support Cybersecurity Assessments

The proposed guide offers structured prompts for reviewing cybersecurity governance, documenting current controls, and identifying target outcomes

Written byMichelle Gaulin
| 3 min read
Concept of laboratory cybersecurity with AI integration
Register for free to listen to this article
Listen with Speechify
0:00
3:00

The National Institute of Standards and Technology has released draft guidance showing how organizations can use generative artificial intelligence to support cybersecurity analysis and reporting.

The initial public draft of NIST Special Publication 1353, Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting, provides structured prompts and example materials for applying AI to Cybersecurity Framework 2.0 activities.

The guide focuses on using generative AI to analyze, plan, implement, and monitor progress toward cybersecurity outcomes. NIST is accepting public comments through October 15.

Three AI-assisted cybersecurity use cases

NIST organizes the guide around three illustrative use cases. The first uses AI to review an organization’s cybersecurity policy, strategy, and risk governance against Cybersecurity Framework outcomes.

The second demonstrates how AI can help create a draft current-state profile. In the example, the system maps organizational documents and employee interview notes to framework outcomes, documents assumptions, and identifies gaps in the available evidence.

The third use case draws on internal documents and industry references to produce a draft target-state profile. That profile describes the cybersecurity outcomes an organization wants to achieve based on its objectives, stakeholder expectations, requirements, and risk environment.

NIST emphasizes that the examples demonstrate one possible approach. They do not constitute prescriptive assessment or assurance methods. The publication also does not provide comprehensive AI or cybersecurity best practices.

Applying the guidance to laboratory systems

For laboratory leaders, the draft offers a potential starting point for reviewing cybersecurity governance across laboratory information management systems, electronic laboratory notebooks, instrument workstations, cloud services, and connected automation.

A laboratory could use an approved AI tool to organize existing policies, system inventories, vendor documentation, and staff interview notes before comparing them with Cybersecurity Framework outcomes. The resulting draft could help lab managers and information technology teams identify missing documentation, unclear responsibilities, or systems that require further investigation.

For example, a current-state review could examine how a laboratory controls access to instrument computers, manages vendor support accounts, documents software updates, or backs up data generated by stand-alone systems. A target-state profile could then describe the desired cybersecurity outcomes and help teams prioritize improvements.

Lab manager academy logo

Lab Management Certificate

The Lab Management certificate is more than training—it’s a professional advantage.

Gain critical skills and IACET-approved CEUs that make a measurable difference.

That work should remain distinct from a formal audit or assurance process. AI-generated conclusions require supporting evidence and qualified human review before they are entered into quality, compliance, or audit records. This distinction is particularly important in regulated laboratories, where documentation must remain accurate, traceable, and retrievable. An audit-readiness approach to data integrity and security can help managers connect cybersecurity controls with documentation requirements.

Human review remains essential

Before using AI for cybersecurity assessments, laboratory leaders should define which tools employees may use and which records they may submit. Sensitive research, patient information, intellectual property, security configurations, and account credentials require appropriate controls for handling.

Laboratories should also retain the source material supporting each generated conclusion, document assumptions, identify unsupported statements, and assign responsibility for reviewing outputs. These practices reflect the close relationship between laboratory data integrity and data security.

Lab managers do not need to conduct cybersecurity assessments alone. Their role includes identifying critical laboratory systems, explaining operational dependencies, and working with information technology, quality, compliance, and instrument vendors to evaluate risks. This cross-functional approach can prevent technical reviews from overlooking equipment that operates outside centrally managed networks.

The NIST draft does not address laboratories specifically. However, its structured approach gives lab managers a practical framework for examining cybersecurity governance without treating AI as an assessor or source of assurance. As laboratories become more dependent on interconnected instruments and digital records, maintaining that boundary will be central to responsible use.

This article was created with the assistance of Generative AI and has undergone editorial review before publishing.

Add Lab Manager as a preferred source on Google

Add Lab Manager as a preferred Google source to see more of our trusted coverage.

Frequently Asked Questions (FAQs)

  • What is the purpose of the NIST Special Publication 1353?

    The NIST Special Publication 1353 provides structured guidance on how organizations can use generative artificial intelligence to support cybersecurity analysis and reporting, focusing on the Cybersecurity Framework 2.0.

  • How can generative AI assist in laboratory cybersecurity?

    Generative AI can help laboratory leaders review cybersecurity governance by organizing existing policies, system inventories, and vendor documentation, aligning them with the outcomes outlined in the NIST Cybersecurity Framework.

  • What are the three use cases illustrated in the NIST guidance?

    The three use cases include using AI to review an organization’s cybersecurity policy, creating a draft current-state profile, and producing a draft target-state profile for desired cybersecurity outcomes.

  • Why is human review essential when using AI for cybersecurity assessments?

    Human review is crucial because AI-generated conclusions require supporting evidence, and sensitive information must be handled appropriately. This ensures accuracy and accountability, especially in regulated laboratory environments.

  • Does the NIST draft provide exhaustive best practices for AI in cybersecurity?

    No, the NIST draft does not provide comprehensive AI or cybersecurity best practices. It offers a structured approach to AI-assisted assessments but emphasizes that the examples are not prescriptive methods.

About the Author

  • Headshot photo of Michelle Gaulin

    Michelle Gaulin is an associate editor for Lab Manager. She holds a bachelor of journalism degree from Toronto Metropolitan University in Toronto, Ontario, Canada, and has two decades of experience in editorial writing, content creation, and brand storytelling. In her role, she contributes to the production of the magazine’s print and online content, collaborates with industry experts, and works closely with freelance writers to deliver high-quality, engaging material.

    Her professional background spans multiple industries, including automotive, travel, finance, publishing, and technology. She specializes in simplifying complex topics and crafting compelling narratives that connect with both B2B and B2C audiences.

    In her spare time, Michelle enjoys outdoor activities and cherishes time with her daughter. She can be reached at mgaulin@labmanager.com.

    View Full Profile

Related Topics

Loading Next Article...
Loading Next Article...
Current Magazine Issue Background Image

CURRENT ISSUE - September/2026

Are You Asking the Right Questions?

How Question Framing Shapes Better Lab Decisions

Lab Manager September 2026 Cover Image