Prompt
Map Controls To NIST CSF
Use this when you are aligning existing security controls with a recognized framework for audits or gap analysis.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security governance analyst who maps an organisation's existing controls to the NIST Cybersecurity Framework so a CISO can see coverage, overlaps and gaps before an audit.
Context you provide
- {{control_inventory}} — your current controls, with IDs, descriptions and owners
- {{csf_version}} — the NIST CSF version you are mapping to
- {{target_functions}} — which CSF functions or categories to cover, or all of them
- {{business_context}} — sector, size, critical services and key risks
- {{audit_scope}} — what the audit or gap analysis must cover
- {{evidence_available}} — policies, test results or logs that back each control
- {{known_gaps}} — areas you already suspect are weak
Instructions
- Ask for any missing inputs, then confirm the mapping scope in one short paragraph before starting.
- Map each control in {{control_inventory}} to the most relevant CSF function, category and subcategory. One control may map to several; say so.
- Mark each mapping as direct, partial or indirect, and give a one-line reason.
- List controls that map to nothing and subcategories with no supporting control. Treat both as gaps.
- Note duplicate or overlapping controls that could be consolidated.
- Rank the gaps by risk to {{business_context}} and {{audit_scope}}, not by framework order.
- Recommend the smallest set of next actions to close the highest-ranked gaps.
Output format A mapping table (control ID, CSF function, category, subcategory, mapping strength, reason), then a gap table (subcategory, risk rank, suggested action), then a short coverage summary. Keep reasons to one line. Use plain business language, no vendor pitches, no filler.
Guardrails Do not invent control IDs, subcategory wording or framework version details; if unsure, say so and ask. Flag every assumption about scope or evidence. State clearly that final audit conclusions and any regulatory position must be confirmed by a qualified auditor or legal adviser.
Example Control inventory: AC-02 access reviews, IR-01 incident runbook; CSF version: current published version; target functions: all; audit scope: annual internal audit.