NIST CSF 2.0 Govern Function Explained: What Changed and How to Implement It
The Govern function is the headline change in NIST Cybersecurity Framework 2.0, released in February 2024 โ the first structural change to the framework since the 2014 original. It adds a sixth Function (abbreviated GV) that sits above and around the existing five, establishing the organizational context, risk-management strategy, roles, policies, and oversight that the other Functions depend on. In practical terms, Govern is where cybersecurity stops being an IT project and becomes a governed enterprise risk โ with named accountability, a defined risk appetite, and board-level oversight. If you're looking for a "Govern function explained PDF," the authoritative source is NIST's own free CSF 2.0 publication and reference tool at nist.gov/cyberframework; below is the working explanation you actually need to act on.
The six Functions of CSF 2.0 (and why the count changed)
People still ask about "the five NIST CSF functions" or "the six core functions" โ both are correct depending on which version you mean. CSF 1.1 had five; CSF 2.0 has six. The full set is:
- Govern (GV) โ new in 2.0. Establishes and monitors the cybersecurity risk management strategy, expectations, and policy.
- Identify (ID) โ understand assets, suppliers, and risks.
- Protect (PR) โ safeguards to limit or contain the impact of events.
- Detect (DE) โ find and analyze possible attacks and compromises.
- Respond (RS) โ take action on a detected incident.
- Recover (RC) โ restore assets and operations affected by an incident.
The important shift is conceptual: NIST visualizes Govern as a ring surrounding the other five, not as a step in a sequence. Governance informs how you Identify, Protect, Detect, Respond, and Recover โ it isn't a phase you finish and move past. Much of what previously lived in the Identify function under "Governance" and "Risk Management Strategy" categories in CSF 1.1 was pulled out and elevated into this new top-level Function, which is why the change is structural rather than cosmetic.
What's inside Govern: the six categories
Govern is broken into six categories. Knowing these by name lets you map your existing program artifacts directly against them:
- Organizational Context (GV.OC) โ the mission, stakeholder expectations, legal/regulatory requirements, and dependencies that shape risk decisions.
- Risk Management Strategy (GV.RM) โ risk appetite and tolerance statements, and how risk decisions are made and communicated.
- Roles, Responsibilities, and Authorities (GV.RR) โ who owns what, including leadership accountability and resource allocation.
- Policy (GV.PO) โ the establishment, communication, and enforcement of cybersecurity policy.
- Oversight (GV.OV) โ how leadership reviews strategy performance and adjusts based on results.
- Cybersecurity Supply Chain Risk Management (GV.SC) โ C-SCRM as a governed program, not an ad hoc procurement checkbox.
Two of these deserve emphasis because they're where most programs are weakest. GV.OV (Oversight) is the feedback loop โ it forces you to measure whether your strategy is working and report that upward, which is exactly what boards now expect after SEC disclosure rules put cyber risk in the same category as material financial risk. GV.SC gives supply chain risk its own home; in CSF 1.1 it was buried, and elevating it reflects the reality that most large breaches now enter through a third party.
How Govern relates to the RMF's 7 steps
Readers frequently confuse CSF with the NIST Risk Management Framework (RMF). They're complementary, not the same. The 7 steps of the RMF (from NIST SP 800-37) are: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. RMF is a detailed, control-level process โ primarily for federal systems seeking Authorization to Operate โ built around NIST SP 800-53 controls. CSF is higher-level and outcome-based, intended for any organization to communicate and prioritize risk.
The connection: RMF's "Prepare" step and CSF's Govern function cover a lot of the same ground โ establishing context, roles, and risk strategy before you touch a single technical control. If you run RMF, treat Govern as the language you use to report RMF outcomes to executives who don't want to hear about control baselines. Govern is the boardroom; RMF is the engineering floor.
There is no official "CSF 2.0 controls list" โ here's what to use instead
A common search is for a "NIST CSF 2.0 controls list Excel." Be precise here: CSF does not publish controls. It publishes Functions โ Categories โ Subcategories (outcome statements), plus Informative References that map each Subcategory to actual control sets like NIST SP 800-53, CIS Controls, and ISO/IEC 27001. So when someone hands you a "CSF controls list," what they usually mean is one of two things:
- The CSF Core itself โ all six Functions and their Subcategories, available as a downloadable spreadsheet from NIST's website. This is your assessment scaffold.
- A crosswalk that maps CSF Subcategories to the control framework you actually implement against (800-53, CIS, ISO 27001).
Use NIST's free CSF 2.0 Reference Tool to export the Core and its mappings as JSON or Excel rather than trusting a third-party PDF of unknown vintage. That way your "controls list" is traceable back to source and stays aligned when NIST updates the Informative References.
A practical first pass at implementing Govern
Don't try to implement all six Govern categories at once. Prioritize by what your organization is most likely to be asked to prove:
- Start with GV.RR (roles). Write down, in one page, who is accountable for cybersecurity risk at the executive level and who owns each risk domain. If you can't name a single accountable executive, that's your first gap.
- Then GV.RM (risk strategy). Draft a one-paragraph risk appetite statement your leadership will actually sign. "We accept X, we do not accept Y" โ concrete, not aspirational.
- Then GV.OC (context). List your legal/regulatory obligations and top three mission dependencies. This scopes everything else.
- Then GV.PO and GV.OV. Confirm your policies map to the above and that leadership reviews performance on a set cadence โ quarterly is a reasonable default.
- Then GV.SC. Inventory your critical suppliers and their access, and require security terms in contracts.
For each, rate yourself against the four CSF Tiers (Partial, Risk Informed, Repeatable, Adaptive) and record evidence. That gives you a defensible current-state profile and a target profile โ the exact artifact auditors and boards ask for.
If you want to move from reading about Govern to scoring your own program against all six Functions, PlayCISO's free NIST CSF 2.0 Assessment walks you through each Function and Category โ including the new Govern outcomes โ and produces a current-versus-target profile you can take straight into a leadership review.
Ready to practise the decisions these articles describe?
Run a free War Room โ