Core Function
Definition
The highest level of the CSF hierarchy. CSF 2.0 defines six: Govern, Identify, Protect, Detect, Respond, and Recover. Each function represents a broad cybersecurity outcome and subdivides into categories and subcategories.
- Framework
- NIST Cybersecurity Framework 2.0
- Count
- Six functions
- Functions
- Govern, Identify, Protect, Detect, Respond, Recover
- Sits above
- Categories and subcategories
Common questions
What changed between CSF 1.1 and CSF 2.0 at the function level?+
CSF 2.0 added Govern as a sixth core function, making organisational oversight, roles, policy, and risk-management strategy an explicit top-level outcome rather than something implied across the other five functions.
How does a core function relate to an incident investigation?+
Detect and Respond map most directly to forensic activity, but a weakness anywhere in Govern, Identify, or Protect is often what an incident investigation traces the root cause back to, since those functions shape what logging and access controls existed before the incident.
Related terms
- Category
- A subdivision of a core function that groups related cybersecurity outcomes. For example, the Identify function contains categories such as Asset Management...
- CSF Profile
- A customised selection of categories and subcategories that reflects an organisation's business environment, risk tolerance, and resources. A Current Profile describes what...
- Govern (Function)
- The sixth and newest CSF core function, introduced in CSF 2.0. It covers the organisational context, risk management strategy, roles and responsibilities,...
- Implementation Tier
- A descriptor of how mature an organisation's cybersecurity risk management practices are, on a scale from Tier 1 (Partial, reactive) to Tier...
- Subcategory
- The most granular level of the CSF core, each describing a specific outcome or practice (for example, 'Physical assets are inventoried'). CSF...