Govern (GV): what it demands and how it is evidenced
The function CSF 2.0 added — and put first. Governance moved from a category buried in Identify to the function that wraps all others: context, risk strategy, roles, policy, oversight and supply chain. If your CSF 1.1 profile predates 2024, this is where the rewrite starts.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the CSF 2.0 series · CSF is voluntary guidance — we build profiles, not certificates
The categories inside Govern
Category identifiers reference NIST CSF 2.0 (26 February 2024) — nist.gov/cyberframework.
Where profiles fall short
Govern is not a rename — GV.SC and GV.OV contain expectations 1.1 never had. Mapping old ID.GV rows across and calling it 2.0 collapses under review.
GV.RM is tested by decisions: can anyone show a choice that changed because of the stated tolerance?
GV.SC expects cyber criteria in selection, contractual obligations, and coordination when a supplier has an incident.
Evidence that holds up
- Documented context: obligations register, stakeholder requirements (GV.OC)
- Risk appetite/tolerance statement with decision examples (GV.RM)
- RACI or equivalent for cyber roles incl. board oversight (GV.RR)
- Policy set with review and communication records (GV.PO)
- Metrics pack + minutes showing oversight adjustments (GV.OV)
- Supplier cyber-risk criteria, contract clauses, monitoring records (GV.SC)
Govern FAQ
What changed between NIST CSF 1.1 and 2.0?
CSF 2.0 (26 February 2024) added Govern as a sixth function, expanded supply-chain risk management, broadened the audience beyond critical infrastructure, and introduced implementation examples and community profiles.
Is NIST CSF certifiable?
No — CSF is voluntary guidance. Organisations build profiles and measure tiers; attestation happens through other frameworks (ISO 27001, SOC 2) that CSF maps to.
Why does CSF matter for Indian regulated entities?
SEBI's CSCRF is explicitly structured on CSF functions, and RBI/IRDAI expectations map cleanly onto them — a CSF profile becomes the common backbone for multiple Indian regulatory conversations.
Your CSF 2.0 profile, built properly
Current and target profiles, gap analysis, and a prioritised roadmap that maps onto the ISO 27001, SOC 2 or SEBI CSCRF work you may already owe — kept current on SigmaTrust.
