We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

NIST CSF 2.0 · Function 1 of 6

Govern (GV): what it demands and how it is evidenced

The function CSF 2.0 added — and put first. Governance moved from a category buried in Identify to the function that wraps all others: context, risk strategy, roles, policy, oversight and supply chain. If your CSF 1.1 profile predates 2024, this is where the rewrite starts.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the CSF 2.0 series · CSF is voluntary guidance — we build profiles, not certificates

The categories inside Govern

GV.OC
Organizational context

Mission, stakeholder expectations, legal and regulatory requirements understood — the inputs that make the rest of the profile YOURS rather than generic.

GV.RM
Risk management strategy

Risk appetite and tolerance established, communicated and used in decisions — the artefact examiners and boards actually ask for.

GV.RR
Roles, responsibilities and authorities

Cybersecurity roles defined, resourced and communicated — including leadership accountability.

GV.PO
Policy

Cybersecurity policy established, communicated and enforced, refreshed as risks and requirements change.

GV.OV
Oversight

Risk-management performance reviewed and used to adjust strategy — metrics with a feedback loop, not a dashboard nobody reads.

GV.SC
Cybersecurity supply chain risk management

Supplier cyber risk integrated into wider risk management: criteria, contracts, monitoring, incident coordination — heavily expanded in 2.0.

Category identifiers reference NIST CSF 2.0 (26 February 2024) — nist.gov/cyberframework.

Where profiles fall short

CSF 1.1 profiles lightly relabelled

Govern is not a rename — GV.SC and GV.OV contain expectations 1.1 never had. Mapping old ID.GV rows across and calling it 2.0 collapses under review.

Risk appetite that exists only in the audit binder

GV.RM is tested by decisions: can anyone show a choice that changed because of the stated tolerance?

Supply chain treated as procurement paperwork

GV.SC expects cyber criteria in selection, contractual obligations, and coordination when a supplier has an incident.

Evidence that holds up

  • Documented context: obligations register, stakeholder requirements (GV.OC)
  • Risk appetite/tolerance statement with decision examples (GV.RM)
  • RACI or equivalent for cyber roles incl. board oversight (GV.RR)
  • Policy set with review and communication records (GV.PO)
  • Metrics pack + minutes showing oversight adjustments (GV.OV)
  • Supplier cyber-risk criteria, contract clauses, monitoring records (GV.SC)

Govern FAQ

What changed between NIST CSF 1.1 and 2.0?

CSF 2.0 (26 February 2024) added Govern as a sixth function, expanded supply-chain risk management, broadened the audience beyond critical infrastructure, and introduced implementation examples and community profiles.

Is NIST CSF certifiable?

No — CSF is voluntary guidance. Organisations build profiles and measure tiers; attestation happens through other frameworks (ISO 27001, SOC 2) that CSF maps to.

Why does CSF matter for Indian regulated entities?

SEBI's CSCRF is explicitly structured on CSF functions, and RBI/IRDAI expectations map cleanly onto them — a CSF profile becomes the common backbone for multiple Indian regulatory conversations.

Identify (ID)

Your CSF 2.0 profile, built properly

Current and target profiles, gap analysis, and a prioritised roadmap that maps onto the ISO 27001, SOC 2 or SEBI CSCRF work you may already owe — kept current on SigmaTrust.