NIST & CIS

NIST CSF 2.0 Govern function: what's new and how to evidence it

CSF 2.0 added Govern as a sixth function. It covers strategy, roles, policy, oversight and supply chain risk, and it is where most organisations have the least evidence.

Short answer

NIST released Cybersecurity Framework 2.0 on 26 February 2024 and added Govern as a sixth function alongside Identify, Protect, Detect, Respond and Recover. Govern has six categories: organisational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. Its evidence is mostly decisions, approvals and reviews, not technical settings.

Key takeaways

  • Govern (GV) sits at the centre of the CSF 2.0 functions and informs the other five.
  • Six categories: GV.OC, GV.RM, GV.RR, GV.PO, GV.OV and GV.SC.
  • Supply chain risk management moved into Govern in 2.0.
  • If you run ISO 27001, most Govern evidence already exists in your ISMS.

The six Govern categories

CategoryCoversEvidence auditors ask for
GV.OC Organizational ContextMission, stakeholders, legal and contractual requirementsContext analysis, register of obligations
GV.RM Risk Management StrategyRisk appetite, tolerance and prioritiesApproved risk appetite statement, risk methodology
GV.RR Roles, Responsibilities, and AuthoritiesAccountability, resourcing, leadershipRACI, job descriptions, board minutes assigning ownership
GV.PO PolicyPolicy set, communication and reviewApproved policies with review dates
GV.OV OversightReviewing strategy and performanceManagement review minutes, KPI reports
GV.SC Cybersecurity Supply Chain Risk ManagementSupplier risk across the lifecycleSupplier inventory, due diligence, contract clauses

Reusing ISO 27001 evidence

Organisations with an ISO 27001 ISMS can map much of Govern to clauses and controls they already evidence. The mapping below is a starting point; test it against your own control descriptions.

NIST CSF 2.0 GovernISO/IEC 27001:2022
  1. GV.OCOrganizational context4.1–4.2Context and interested parties
  2. GV.RMRisk management strategy6.1Actions to address risks
  3. GV.RRRoles and responsibilities5.3Roles, responsibilities and authorities
  4. GV.POPolicy5.2, A.5.1Information security policy
  5. GV.OVOversight9.3Management review
  6. GV.SCSupply chain riskA.5.19–5.22Supplier relationships
Full mappingPartial mappingIllustrative mapping; GV.RM and GV.OV ask for more explicit risk appetite and oversight than ISO 27001 does.

Where teams fall short

  • No written risk appetite: risk decisions are made, but nobody can show the threshold they were measured against.
  • Oversight without follow-up: reviews happen, but actions from them are not tracked to closure.
  • Supplier risk limited to onboarding: due diligence at contract signature, then nothing for years.

Checklist

Govern evidence to have ready

0 of 6 done

Frequently asked questions

What is the Govern function in NIST CSF 2.0?

Govern is the function added in CSF 2.0 covering how an organisation's cybersecurity risk strategy, expectations and policy are established, communicated and monitored. It has six categories, including cybersecurity supply chain risk management.

Sources

  1. The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29), NIST