QIS-S-118 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-02 · BUILD 13.3
Standards register · US National Institute of Standards and Technology

NIST Cybersecurity Framework 2.0

A voluntary framework organized around six functions — Govern, Identify, Protect, Detect, Respond, Recover — published in February 2024. Version 2.0 added the Govern function and broadened scope beyond critical infrastructure to organizations of all sizes and sectors.

QIS-S-118·Addresses 3 of 8 MARQUE questions

Why it matters for autonomous finance

The security counterpart to the AI-specific frameworks, and it shares the NIST AI RMF's structural insight: Govern comes first, because organizational accountability precedes technical control. For agentic systems the relevant surfaces are supply chain and detection — a model, its weights, its training data and its retrieval corpus are all supply chain, and poisoning any of them is a security event that presents as a model quality problem.

What it does not cover

General cybersecurity, not AI governance. It will harden the infrastructure an agent runs on and has nothing to say about whether the agent should have acted. Mapping it to AI risk requires the AI RMF alongside it; neither is sufficient alone, and claiming CSF alignment as an AI governance answer is a common overclaim.

No model behavior, no authority, no agent identity. Every entry in this register carries this section. A standard read past its scope is worse than no standard, because it produces confidence without coverage.

Read it