Auditen
Home / Frameworks / NIST CSF 2.0 / The Govern function
NIST CSF 2.0 · GV

The Govern function

The Govern function requires an organization to establish and monitor its cybersecurity risk management strategy, expectations, and policies. It ensures that cybersecurity is integrated into the broader enterprise risk management process and aligned with legal, regulatory, and organizational objectives.

What it means

Govern shifts cybersecurity from a purely technical implementation to a strategic governance requirement. Its intent is to create the structural framework—the "rules of engagement"—under which all other NIST CSF functions (Identify, Protect, Detect, Respond, Recover) operate.

In practice, this involves defining who holds authority over risk decisions and how those decisions are communicated across the organization. It requires a clear understanding of the organizational context, including mission objectives, stakeholders, and legal obligations, to ensure security efforts are proportional to the actual risks faced.

The scope extends beyond internal operations to include the supply chain. Governance ensures that third-party risks are managed through consistent standards and that executive leadership provides continuous oversight rather than occasional check-ins.

How to meet it

Evidence an auditor asks for

  • Approved cybersecurity policies, strategy documents, and charters with evidence of executive sign-off and version control.
  • Meeting minutes from governance committees or board reviews that demonstrate active oversight of cyber risks.
  • A Risk Register documenting identified threats, their associated business impact, ownership, and the chosen treatment (mitigate, transfer, avoid, or accept).
  • Third-party risk assessment reports or completed security questionnaires for critical suppliers.
  • Organizational charts and job descriptions that formally assign cybersecurity responsibilities.

Common pitfalls

  • Treating governance as a "paper exercise" where documents are written once but never enforced or updated to reflect current operations.
  • Creating policies that are too generic or aspirational, making them impossible to audit or measure for compliance.
  • A disconnect between technical staff and executive leadership, resulting in security controls that do not align with the organization's actual risk appetite.