GV 31 subcategories · 6 categories

NIST CSF 2.0 Govern (GV)

Govern is the function CSF 2.0 added, and adding it was the headline change in the 2.0 revision. It covers organisational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. The outcomes here are decisions rather than deployments, which is why organisations with mature tooling still score low on Govern: there is no product that makes an executive accountable for cyber risk.

GV.OC — Organizational Context

GV.OC-01 Organizational mission
The organizational mission is understood and informs cybersecurity risk management.
GV.OC-02 Internal and external stakeholders
Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered.
GV.OC-03 Legal, regulatory and contractual requirements
Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
GV.OC-04 Critical objectives, capabilities and services
Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated.
GV.OC-05 Dependencies on external resources
Outcomes, capabilities, and services that the organization depends on are understood and communicated.

GV.RM — Risk Management Strategy

GV.RM-01 Risk management objectives
Risk management objectives are established and agreed to by organizational stakeholders.
GV.RM-02 Risk appetite and tolerance
Risk appetite and risk tolerance statements are established, communicated, and maintained.
GV.RM-03 Cyber risk in enterprise risk management
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.
GV.RM-04 Risk response direction
Strategic direction that describes appropriate risk response options is established and communicated.
GV.RM-05 Risk communication lines
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties.
GV.RM-06 Standardized risk measurement
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated.
GV.RM-07 Strategic opportunities
Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions.

GV.RR — Roles, Responsibilities, and Authorities

GV.RR-01 Leadership accountability
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving.
GV.RR-02 Roles, responsibilities and authorities
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced.
GV.RR-03 Adequate resources
Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies.
GV.RR-04 Cybersecurity in HR practices
Cybersecurity is included in human resources practices.

GV.PO — Policy

GV.PO-01 Policy established and communicated
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
GV.PO-02 Policy reviewed and updated
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission.

GV.OV — Oversight

GV.OV-01 Strategy outcomes reviewed
Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction.
GV.OV-02 Strategy reviewed and adjusted for coverage
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks.
GV.OV-03 Risk management performance measured
Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed.

GV.SC — Cybersecurity Supply Chain Risk Management

GV.SC-01 Supply chain risk management program
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders.
GV.SC-02 Supplier roles and responsibilities
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally.
GV.SC-03 Supply chain risk in ERM
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes.
GV.SC-04 Suppliers prioritized by criticality
Suppliers are known and prioritized by criticality.
GV.SC-05 Supply chain requirements in contracts
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties.
GV.SC-06 Due diligence before supplier relationships
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships.
GV.SC-07 Ongoing supplier risk monitoring
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship.
GV.SC-08 Suppliers in incident planning
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities.
GV.SC-09 Supply chain security throughout lifecycle
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle.
GV.SC-10 Post-relationship supply chain plans
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement.

Other CSF 2.0 functions

ID PR DE RS RC
Crosswalk to ISO 27001 & SOC 2 →
Map these outcomes across frameworks in the Control Mapper.
Search all 106 subcategories →
Filter the CSF 2.0 Core by keyword, function or category.

Frequently asked questions

How many subcategories are in the NIST CSF Govern function?

Govern (GV) contains 31 subcategories across 6 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.

Is the Govern function mandatory?

No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

What changed in the Govern function in CSF 2.0?

Govern is entirely new in CSF 2.0 — CSF 1.1 had five functions and no Govern. Supply chain risk management moved here from Identify, and governance content that was previously scattered across other functions was consolidated into it.