NIST CSF Crosswalk
This crosswalk maps the Runtime Defense model (RCDM), the runtime half of the AI Control Architecture, to the NIST Cybersecurity Framework (CSF) functions. RCDM organises runtime defense into five functions: Govern, Observe, Anticipate, Disrupt, and Adapt. CSF organises cybersecurity outcomes into Govern, Identify, Protect, Detect, Respond, and Recover. The two align closely, which is deliberate: RCDM extends the established CSF outcomes for machine-speed operation and for AI agents as first-class actors.
Status: Planned. This document states the intended mapping; the detailed control-level crosswalk is a work in progress.
Function mapping
Notes
- The mapping is not one-to-one because RCDM is built for defense that must act below the human-latency wall while remaining under human authority. Anticipate (forward prediction) and the graduated, reversibility-aware enforcement of Disrupt have no direct single-function equivalent in CSF; they extend the CSF outcomes rather than restate them.
- CSF's Govern function and RCDM's Govern function are aligned in intent: both make policy and authority the spine that bounds all other activity.
- Recovery in CSF maps to RCDM Adapt together with the reversal path defined in Incident Containment & Recovery and enforced through the Action Fabric.
For the full runtime half, see the Runtime Defense Overview and The Five Functions.