Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST CSF GOVERN function — The NIST CSF GOVERN Function: All 31 Outcomes Explained

The NIST CSF GOVERN Function: All 31 Outcomes Explained

What this guide covers

NIST CSF GOVERN function explained
GOVERN carries 31 of the 106 CSF 2.0 outcomes — more than PROTECT

What the NIST CSF GOVERN function is for

The NIST CSF GOVERN function is the largest and newest part of the Cybersecurity Framework, and it is the part an organisation moving from CSF 1.1 will have almost nothing to show for. Thirty-one of the Framework’s 106 Subcategories sit under GOVERN — more than under PROTECT — across six Categories. In CSF 1.1, governance was four Subcategories buried inside IDENTIFY.

That is not a reorganisation. It is NIST stating that cybersecurity risk is an enterprise risk, that it needs an enterprise mandate, and that the absence of one is a finding in its own right.

The six Categories inside the NIST CSF GOVERN function

Category Name Subcategories What it asks for
GV.OC Organizational Context 5 Mission, stakeholder expectations, legal and contractual requirements, what you provide, what you depend on
GV.RM Risk Management Strategy 7 Objectives agreed with stakeholders, appetite and tolerance, enterprise integration, response options, communication, prioritisation, and opportunities
GV.RR Roles, Responsibilities and Authorities 4 Leadership accountability and culture, roles enforced, resources commensurate with the strategy, cybersecurity in HR practices
GV.PO Policy 2 Policy established, communicated and enforced; and reviewed and updated as things change
GV.OV Oversight 3 Reviewing strategy direction, coverage and performance, and adjusting on the result
GV.SC Cybersecurity Supply Chain Risk Management 10 The whole supplier lifecycle, from programme and roles through due diligence and monitoring to exit

Two things stand out about the NIST CSF GOVERN function. GV.SC alone is ten Subcategories — a tenth of the entire Framework devoted to supply chain. And GV.OV, all three of its outcomes, has no CSF 1.1 ancestor at all.

The NIST CSF GOVERN function outcomes with no predecessor

Sixteen of the 106 Subcategories in CSF 2.0 are genuinely new, with no CSF 1.1 informative reference behind them. Six of those sixteen are inside GOVERN:

  • GV.RM-07 — positive risks, meaning opportunities, are characterised and included in cybersecurity risk discussions.
  • GV.RR-01 — leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical and continually improving.
  • GV.OV-01, GV.OV-02, GV.OV-03 — the three oversight outcomes: reviewing strategy to adjust direction, reviewing it for coverage of requirements and risks, and evaluating risk management performance.

GV.RM-07 is the one almost nobody does. Every risk register in the world lists threats; very few record the opportunities a security decision creates — a control consolidation that reduces cost, a platform migration that improves resilience and security together, a supplier change that removes a single point of failure. The Framework asks for them, and an assessment that ignores the outcome is scoring itself as achieved on something it has never attempted.

Why oversight catches so many programmes out

Inside the NIST CSF GOVERN function, the three oversight outcomes look like one requirement written three times. They are not, and reading them as one is why they are commonly answered with a single sentence about an annual review.

  • GV.OV-01 asks whether the strategy’s outcomes are reviewed to inform and adjust strategy and direction.
  • GV.OV-02 asks whether the strategy covers organisational requirements and risks — a coverage question.
  • GV.OV-03 asks whether risk management performance is evaluated and reviewed for adjustments needed.

Direction, coverage, performance. A management review that considers the risk register and approves next year’s plan has answered one of the three at best. The coverage question in particular is the one that surfaces shadow scope — the business unit nobody assessed, the SaaS product bought on a card, the regulatory obligation with no owner.

A cheap and effective way to answer GV.OV-02 honestly: reconcile your systems inventory against accounts payable rather than against the IT asset register. Systems that IT does not know about are still paid for, and the invoice is the one artefact that exists for all of them.

The supply chain half of the NIST CSF GOVERN function

GV.SC runs from GV.SC-01 to GV.SC-10 and covers a full lifecycle: establish a programme, set roles internally and with third parties, integrate supplier risk into enterprise risk, know and prioritise your suppliers, get requirements into contracts, do due diligence before you commit, monitor through the relationship, include suppliers in incident planning, apply practices across the technology lifecycle, and manage what happens after the relationship ends.

Three of those are routinely missing even in mature programmes:

  1. GV.SC-04 — knowing who your suppliers are. The hard half is finding them. Suppliers engaged outside the procurement process are exactly the ones never assessed, and they are invisible in every list except the one that pays them.
  2. GV.SC-08 — including suppliers in incident planning and response. Not just requiring notification in a contract, but rehearsing it. A joint tabletop with one critical supplier a year reliably discovers that the contracted 24/7 security contact has left the company.
  3. GV.SC-10 — practices that apply after the relationship ends. Data extraction, access revocation, federation trusts removed, and a destruction certificate that covers backups as well as production. Backups are where residual data survives an exit.

What implementing the NIST CSF GOVERN function actually costs

Most of GOVERN is not technology. It is decisions written down, with an owner and a date, and evidence that somebody reviewed them. That makes it cheaper than the other five Functions in cash terms and considerably more expensive in executive attention — which is the resource most programmes are shortest of.

Category Typical first artefact Who has to be involved
GV.OC Organisational context and stakeholder expectation analysis Business owners, legal
GV.RM Risk management strategy, appetite and tolerance statements Board
GV.RR Roles, responsibilities and authorities; a resourcing decision Accountable executive, HR
GV.PO Cybersecurity policy, and a review cadence that runs Accountable executive
GV.OV An oversight review with a standing agenda covering all three outcomes Board, internal audit
GV.SC Supplier register reconciled against accounts payable, then criticality tiers Procurement, relationship owners

The single highest-value artefact on that list is the appetite and tolerance statement, because everything downstream routes through it. Appetite is directional and set by the board; tolerance is numeric and tells an operator when to escalate without calling a meeting. Programmes that skip it end up escalating everything or nothing. For what the rest of the Function needs on paper, see our guide to NIST CSF policy templates.

How the NIST CSF GOVERN function changes the other five

The NIST CSF GOVERN function is not something you complete and set aside. It is the one that gives the other five their priorities. A Target Profile with no drivers behind it is a wish list; a Target Profile where every selected outcome traces to a risk, an obligation, a stakeholder expectation or a mission objective is a plan somebody will fund.

That linkage is also what makes an assessment defensible. If the same controls would be appropriate for a completely different organisation, the context work in GV.OC has not been done — and an assessor will notice. For how the Framework’s components fit together, our NIST Cybersecurity Framework overview covers the Core, Profiles and Tiers; the Organizational Profile guide covers the mechanism GOVERN feeds.

Common questions about the NIST CSF GOVERN function

Is GOVERN new in CSF 2.0?

Yes. CSF 1.1 had five Functions — Identify, Protect, Detect, Respond, Recover. CSF 2.0 added GOVERN as a sixth, and moved governance outcomes into it from ID.GV, ID.BE, ID.RM and ID.SC, all of which were withdrawn as Categories. It is the single largest structural change between the two versions.

How many Subcategories does GOVERN have?

Thirty-one, across six Categories: GV.OC (5), GV.RM (7), GV.RR (4), GV.PO (2), GV.OV (3) and GV.SC (10). That is more than PROTECT, which has 22, and nearly three times DETECT, which has 11.

Can we skip GOVERN if we already have an ISMS?

Partly, and the crosswalk will show you where. NIST maps every CSF outcome to ISO/IEC 27001, so much of GV.PO and GV.RM will have evidence you already hold. What an ISMS does not usually give you is GV.SC at ten-Subcategory depth, or the GV.OV oversight outcomes as three distinct reviews. Treat the mapping as orientation, not as coverage.

Who should own the NIST CSF GOVERN function?

The accountable executive owns the Function; the board owns appetite. GV.RR-01 requires leadership to be responsible and accountable, and accountability that is not attached to a named person does not satisfy the outcome. The security team can draft everything in GOVERN, but it cannot own it.

What is the quickest win inside GOVERN?

Writing down who may accept a residual risk, and up to what level. It takes an afternoon, it is evidence for GV.RR-02 and GV.RM-04, and it removes the most common source of stalled remediation — nobody being sure whether they are allowed to say yes.

Getting the NIST CSF GOVERN function documented

The Framework is free and worth reading in full before you start: NIST publishes CSF 2.0 at nist.gov/cyberframework. What it does not give you is the 30-odd documents that turn the NIST CSF GOVERN function into something an assessor can inspect.

Our NIST CSF Toolkit devotes 32 of its 164 documents to GOVERN alone — the context statement, the risk management strategy, appetite and tolerance, the roles and authorities allocation, the policy set, the three-part oversight review, and eleven documents covering GV.SC from programme through due diligence to supplier exit. Every one of them opens with the Subcategories it answers, in NIST’s own wording.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.