Skip to content

Govern (Function)

Definition

The sixth and newest CSF core function, introduced in CSF 2.0. It covers the organisational context, risk management strategy, roles and responsibilities, policies, and oversight processes that shape how the other five functions operate. Govern is intended to anchor cybersecurity in business strategy rather than treat it as a purely technical concern.

Framework
NIST Cybersecurity Framework (CSF) 2.0
Introduced
2024, as the sixth core function
Covers
Organisational context, risk strategy, roles, policy, oversight
Relation to other functions
Anchors Identify, Protect, Detect, Respond, Recover

Common questions

Why did NIST add Govern as a new core function in CSF 2.0?+

Earlier CSF versions treated governance as embedded within the Identify function, but NIST elevated it to a standalone function to emphasise that leadership decisions, risk appetite and accountability structures shape and constrain how the other five functions are carried out.

How does Govern interact with the other five CSF functions in practice?+

Govern sets the policies, roles and risk-management strategy that inform decisions made within Identify, Protect, Detect, Respond and Recover, so an organisation's governance choices, such as risk tolerance, directly shape how those other functions are resourced and prioritised.

Does the Govern function apply only to large enterprises?+

No, NIST designed CSF 2.0 to be scalable, so Govern applies to organisations of any size, though the formality of implementation, such as a dedicated risk committee versus an informal owner-led review, will differ by organisational scale.

Related terms

Category
A subdivision of a core function that groups related cybersecurity outcomes. For example, the Identify function contains categories such as Asset Management...
Core Function
The highest level of the CSF hierarchy. CSF 2.0 defines six: Govern, Identify, Protect, Detect, Respond, and Recover. Each function represents a...
CSF Profile
A customised selection of categories and subcategories that reflects an organisation's business environment, risk tolerance, and resources. A Current Profile describes what...
Implementation Tier
A descriptor of how mature an organisation's cybersecurity risk management practices are, on a scale from Tier 1 (Partial, reactive) to Tier...
Subcategory
The most granular level of the CSF core, each describing a specific outcome or practice (for example, 'Physical assets are inventoried'). CSF...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.