NIST CSF Govern Function
The Govern Function is one of the Functions in the NIST Cybersecurity Framework (CSF) 2.0, added to emphasize the role of governance in managing cybersecurity risk. It focuses on establishing and maintaining the structures, policies, and processes an organization uses to make decisions about cybersecurity. In practice, it helps organizations set direction and priorities that inform how the other Functions are carried out.
In NIST CSF 2.0 (published February 26, 2024), GOVERN (GV) is one of the framework's six Functions, introduced as an overarching addition to emphasize governance's importance in effectively managing cybersecurity risk. Per NIST, the GOVERN Function provides outcomes to inform what an organization may do to achieve and prioritize the outcomes of the other Functions (Identify, Protect, Detect, Respond, and Recover). It centers on establishing and maintaining governance structures and processes, such as organizational context, risk management strategy, roles and responsibilities, policy, and oversight, used to manage cybersecurity risk. It should be noted that GOVERN was not present in CSF 1.1, whose learning materials described five Functions (Identify, Protect, Detect, Respond, Recover); the Govern Function is specific to CSF 2.0. The evidence provided does not detail the individual Categories or Subcategories within GOVERN, so those specifics are outside the scope of this definition.
Why it matters
The introduction of the GOVERN Function in NIST CSF 2.0, published February 26, 2024, formalized what many security leaders had long argued: that cybersecurity is fundamentally a matter of organizational governance and business risk, not solely a technical discipline. By establishing GOVERN as one of the framework's six Functions, NIST signaled that the structures, policies, and decision-making processes an organization uses to manage cybersecurity risk deserve the same explicit attention as the operational activities of identifying, protecting, detecting, responding, and recovering. This matters because even well-resourced technical controls can fail to reduce risk if there is no clear direction, defined accountability, or oversight guiding their use.
GOVERN is particularly significant because it provides outcomes intended to inform what an organization may do to achieve and prioritize the outcomes of the other Functions. In other words, governance sets the direction and priorities that shape how the rest of the framework is carried out. For organizations that treat cybersecurity as a checklist of tools rather than a business risk to be managed at the leadership level, the GOVERN Function reframes the conversation around organizational context, risk management strategy, roles and responsibilities, policy, and oversight.
A common expert correction is worth noting here: the GOVERN Function was not present in CSF 1.1, whose materials described five Functions. Treating governance as an implicit or optional layer, rather than as a defined element of the framework, understates the emphasis CSF 2.0 places on leadership-level accountability for cybersecurity risk decisions.
Who it's relevant to
Inside GV
Common questions
Answers to the questions practitioners most commonly ask about GV.