What CSF 2.0's new Govern function actually requires
The Govern (GV) function - added in CSF 2.0 - is the biggest structural change to the framework since 2014. It elevates cybersecurity governance, risk management strategy, organizational context, policy, oversight, and cybersecurity supply-chain risk management to first-class concerns alongside the technical functions. Boards and senior leaders are now explicitly named as accountable parties, with defined responsibilities and reporting expectations.
We implement Govern as a real operating model: written organizational context, documented risk appetite and tolerance, a maintained risk register, a supply-chain risk management program (vendor tiering, security questionnaires, continuous monitoring, contractual security clauses), a policy library, and a quarterly governance cadence with the executive team and the board.
- Organizational Context (GV.OC)
- Risk Management Strategy (GV.RM)
- Roles, Responsibilities & Authorities (GV.RR)
- Policy (GV.PO)
- Oversight (GV.OV)
- Cybersecurity Supply Chain Risk Management (GV.SC)

