What are the six Functions of the NIST Cybersecurity Framework 2.0, and what does the new Govern Function add?
answer
- verbs, not a sequence
- a wheel with one hub
- strategy, policy, oversight, supply chain
- GV.OC to GV.SC
basics
~20 sNIST CSF 2.0 organizes outcomes under six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern, new in 2.0, covers risk strategy, roles, policy, oversight and supply chain risk, and informs how the other five are implemented.
solid answer
~40 sNIST CSF 2.0 (CSWP 29, February 2024) arranges its Core as Functions, then Categories, then Subcategories. The six Functions are **Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS) and Recover (RC)**, split into 22 Categories. **Govern** is the addition: organizational context, risk management strategy, roles and authorities, policy, oversight and cybersecurity supply chain risk management (`GV.OC`, `GV.RM`, `GV.RR`, `GV.PO`, `GV.OV`, `GV.SC`). NIST draws the Functions as a wheel with Govern at the centre, because it informs how the other five are carried out. The Functions are meant to run concurrently, and the Core describes outcomes, not a checklist of actions or a required order.
go deeper
Recall the six Functions in order and that Govern is the one CSF 2.0 added. Know the hierarchy of Function, Category and Subcategory.
Explain what the Govern Categories cover, why Govern sits at the centre of the wheel, and why the Functions run concurrently rather than as phases.
Show how you would use the Core as a mapping layer: tie your control set and policies to Subcategories so gaps and overlaps become visible across frameworks.
Argue how Govern changes the conversation with leadership: cybersecurity outcomes placed inside enterprise risk management, with supply chain risk owned at governance level.
## What the CSF is The **NIST Cybersecurity Framework (CSF) 2.0** is NIST Cybersecurity White Paper 29, published on 26 February 2024. It is an outcome-based framework for managing cybersecurity risk in organizations of any size or sector. Before version 2.0 it was titled the *Framework for Improving Critical Infrastructure Cybersecurity*; NIST states that this title is not used for CSF 2.0, which reflects its wider audience. The CSF is popular in interviews for a practical reason: its outcomes are sector-, country- and technology-neutral, and NIST publishes **Informative References** that map each outcome to other standards and control catalogs. That makes it a common vocabulary for saying "our SP 800-53 controls, our ISO 27001 controls and our policies all serve outcome X". ## The Core: Functions, Categories, Subcategories The **CSF Core** is a three-level hierarchy: 1. **Functions** - the six highest-level groupings, each named after a verb. 2. **Categories** - related outcomes that together make up a Function (22 in CSF 2.0). 3. **Subcategories** - more specific outcomes of technical and management activities, such as `GV.OC-03` on legal, regulatory and contractual requirements. | Function | ID | What its outcomes say | |---|---|---| | Govern | GV | Risk management strategy, expectations and policy are established, communicated and monitored | | Identify | ID | Current cybersecurity risks are understood (assets, suppliers, improvement) | | Protect | PR | Safeguards to manage risk are used (access control, training, data and platform security, resilience) | | Detect | DE | Possible attacks and compromises are found and analyzed | | Respond | RS | Actions regarding a detected incident are taken | | Recover | RC | Assets and operations affected by an incident are restored | The numbering of Subcategories is deliberately not sequential: gaps mark CSF 1.1 Subcategories that were relocated in 2.0. ## What Govern adds Govern gathers the outcomes that decide *how* the rest of the programme is run. Its six Categories are: - **Organizational Context (`GV.OC`)** - mission, stakeholder expectations, and legal, regulatory and contractual requirements. - **Risk Management Strategy (`GV.RM`)** - priorities, risk appetite and tolerance statements. - **Roles, Responsibilities, and Authorities (`GV.RR`)** - who is accountable, including leadership. - **Policy (`GV.PO`)** - cybersecurity policy established, communicated and enforced. - **Oversight (`GV.OV`)** - results of risk management activities inform and adjust strategy. - **Cybersecurity Supply Chain Risk Management (`GV.SC`)** - supplier risk managed as part of governance. NIST's own summary is that CSF 2.0 contains new features that highlight the importance of **governance and supply chains**, and that governance activities are critical for incorporating cybersecurity into the organization's broader **enterprise risk management (ERM)**. In the CSF's Functions figure, Govern sits at the centre of the wheel because it informs how the organization implements the other five. ## How the Functions relate A common weak answer treats the Functions as phases. The CSF says otherwise: - The order and size of Functions, Categories and Subcategories does **not** imply the sequence or importance of achieving them. - The Functions should be addressed **concurrently**: Govern, Identify, Protect and Detect happen continuously, while Respond and Recover must be ready at all times and act when incidents occur. - Govern, Identify and Protect help prevent and prepare for incidents; Govern, Detect, Respond and Recover help discover and manage them. - The outcomes are **not a checklist of actions**: what an organization does to achieve an outcome varies by organization and use case. ## What the CSF is not - It is not a control catalog. It points at catalogs such as SP 800-53 through Informative References and at online **Implementation Examples**. - It defines no certification scheme of its own: an organization uses it to describe and prioritize outcomes, not to obtain a certificate against it. - It is not a federal-only document: NIST addresses industry, government, academia and nonprofits. - It is not one-size-fits-all: NIST says each organization has common and unique risks, different risk appetites and missions, so implementations will vary. In an interview, name the six Functions, say that Govern is the 2.0 addition and what it covers, and add that the Core is outcomes, not ordered steps. That is the answer most panels are listening for.
- Is the CSF Core a checklist an organization completes in order?No. NIST CSF 2.0 says its outcomes are not a checklist of actions, and that the order and size of Functions, Categories and Subcategories does not imply sequence or importance. Functions are addressed concurrently; which actions achieve an outcome is left to the organization.
- Why is the CSF used to map other frameworks onto each other?Its outcomes are sector-, country- and technology-neutral, and NIST publishes Informative References that map each outcome to standards, guidelines and control catalogs such as SP 800-53. Two frameworks mapped to the same Subcategory can then be compared through it.
- Where does supplier risk sit in CSF 2.0?Under Govern, as the Category Cybersecurity Supply Chain Risk Management (`GV.SC`). CSF 2.0 treats supply chain risk as a governance outcome, alongside strategy, roles, policy and oversight.
saying these in an interview costs you the question
- Lists only five Functions and omits Govern
- Treats the Functions as sequential phases from Govern to Recover
- Calls the CSF Core a mandatory checklist of actions
- Claims organizations get certified against the NIST CSF
- Describes the CSF as a control catalog replacing SP 800-53