Short answer
NIST released Cybersecurity Framework 2.0 on 26 February 2024 and added Govern as a sixth function alongside Identify, Protect, Detect, Respond and Recover. Govern has six categories: organisational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. Its evidence is mostly decisions, approvals and reviews, not technical settings.
Key takeaways
- Govern (GV) sits at the centre of the CSF 2.0 functions and informs the other five.
- Six categories: GV.OC, GV.RM, GV.RR, GV.PO, GV.OV and GV.SC.
- Supply chain risk management moved into Govern in 2.0.
- If you run ISO 27001, most Govern evidence already exists in your ISMS.
The six Govern categories
| Category | Covers | Evidence auditors ask for |
|---|---|---|
| GV.OC Organizational Context | Mission, stakeholders, legal and contractual requirements | Context analysis, register of obligations |
| GV.RM Risk Management Strategy | Risk appetite, tolerance and priorities | Approved risk appetite statement, risk methodology |
| GV.RR Roles, Responsibilities, and Authorities | Accountability, resourcing, leadership | RACI, job descriptions, board minutes assigning ownership |
| GV.PO Policy | Policy set, communication and review | Approved policies with review dates |
| GV.OV Oversight | Reviewing strategy and performance | Management review minutes, KPI reports |
| GV.SC Cybersecurity Supply Chain Risk Management | Supplier risk across the lifecycle | Supplier inventory, due diligence, contract clauses |
Reusing ISO 27001 evidence
Organisations with an ISO 27001 ISMS can map much of Govern to clauses and controls they already evidence. The mapping below is a starting point; test it against your own control descriptions.
GV.OCOrganizational context4.1–4.2Context and interested partiesGV.RMRisk management strategy6.1Actions to address risksGV.RRRoles and responsibilities5.3Roles, responsibilities and authoritiesGV.POPolicy5.2, A.5.1Information security policyGV.OVOversight9.3Management reviewGV.SCSupply chain riskA.5.19–5.22Supplier relationships
Where teams fall short
- No written risk appetite: risk decisions are made, but nobody can show the threshold they were measured against.
- Oversight without follow-up: reviews happen, but actions from them are not tracked to closure.
- Supplier risk limited to onboarding: due diligence at contract signature, then nothing for years.
Checklist
Govern evidence to have ready
0 of 6 done
Frequently asked questions
What is the Govern function in NIST CSF 2.0?
Govern is the function added in CSF 2.0 covering how an organisation's cybersecurity risk strategy, expectations and policy are established, communicated and monitored. It has six categories, including cybersecurity supply chain risk management.