---
title: "NIST CSF 2.0 — RESPOND & RECOVER — KYE Protocol™ coverage"
description: "NIST CSF 2.0 — RESPOND & RECOVER coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it."
url: https://kyeprotocol.com/compliance/nist-csf-2-respond-recover/
lang: en
source: "KYE Protocol"
---

> NIST CSF 2.0 — RESPOND & RECOVER coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.

NIST CSF 2.0 — RESPOND & RECOVER

# NIST CSF 2.0 — RESPOND & RECOVER — 100% of in-scope requirements covered.

4 requirements · 3 in scope (3 enforced) · 1 out-of-scope (outside KYE™’s authority layer). The 100% is weighted over the in-scope base.

**Source:** The NIST Cybersecurity Framework 2.0 (2024) organises cybersecurity outcomes into six Functions; the RESPOND (RS) Function covers incident management, analysis, mitigation, and reporting, and the RECOVER (RC) Function covers recovery execution and communication. KYE Protocol™ governs whether an AI-assisted response / mitigation action under CSF RESPOND/RECOVER may PROCEED to a consequential incident action — under a named accountable officer's authority, with the incident analysis pinned to verifiable signal sources, chain-of-custody recorded, and a contestability record. KYE™ does not detect the incident, run the response tooling, or execute the recovery. · **License:** The NIST Cybersecurity Framework is a US NIST publication in the public domain; KYE™ registry paraphrases each subcategory's intent and cites the official Function/Category identifier for mapping purposes only.

## By category

| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
| --- | --- | --- | --- | --- | --- | --- |
| Named-authority on the RESPOND/RECOVER action (RS.MA / RC.RP) | 1 | 1 | 0 | 0 | 0 | **100%** |
| Incident-analysis source pin (RS.AN) | 1 | 1 | 0 | 0 | 0 | **100%** |
| Contestability & post-incident reconstruction (RS.MA / improvement) | 1 | 1 | 0 | 0 | 0 | **100%** |
| Threat detection (DETECT) & recovery execution tooling | 1 | 0 | 0 | 0 | 0 | **0%** |

## Every requirement → the KYE™ artefact that enforces it

| ID | Title | Status | KYE™ enforcement |
| --- | --- | --- | --- |
| `nist-csf-2-respond-recover.rs-action-authority` | An AI-assisted RESPOND / RECOVER action proceeds only under a recorded named-authority decision | enforced | **audit\_events**: `kye.purpose.request.v1`, `kye.purpose.admissibility.v1`, `kye.evidence.decision_map.v1` **engines**: `internal`, `internal` **rule\_packs**: `kye:rule-pack:cyber-resilience-incident` **dictionaries**: `internal` **constitution\_refs**: `constitution/12-PURPOSE-PERMISSION.md` |
| `nist-csf-2-respond-recover.rs-incident-evidence` | Incident analysis (RS.AN) is pinned to verifiable signal sources before it is relied on | enforced | **audit\_events**: `kye.evidence.tool_call.v1`, `kye.replay.context_seal.v1`, `kye.evidence.pack.v1` **engines**: `internal`, `internal` **rule\_packs**: `kye:rule-pack:cyber-resilience-incident` **constitution\_refs**: `constitution/13-RESILIENCE-LOOP.md` |
| `nist-csf-2-respond-recover.rs-contestability` | Contestability & post-incident reconstruction of the response decision | enforced | **audit\_events**: `kye.evidence.pack.v1`, `kye.replay.context_seal.v1`, `kye.replay.proof.v1` **engines**: `internal`, `internal` **rule\_packs**: `kye:rule-pack:cyber-resilience-incident` **constitution\_refs**: `constitution/13-RESILIENCE-LOOP.md`, `constitution/21-DELEGATED-AUDITABILITY.md` |
| `nist-csf-2-respond-recover.detection-recovery-tooling` | Threat detection (DETECT) and recovery execution tooling | out-of-scope | _(no enforcement cited)_ |

Canonical KYE™ surfaces referenced on this page: [KYE Protocol™](https://kyeprotocol.com/).
