What should teams do first with the NIST CSF 2.0 GOVERN function before mapping controls?
Start by documenting the organizational context that should later control choices: mission, internal and external stakeholders, legal, regulatory, and contractual requirements, critical services, and external dependencies. Then establish the risk-management strategy, including objectives, and tolerance, response options, communication paths, and a consistent method for prioritizing risk.
Assign and communicate leadership accountability, operational roles, authorities, and resources. Establish policy from the approved context and strategy, set oversight that uses performance results to adjust direction, and define the cybersecurity supply-chain risk management program. Controls can then be selected and mapped to specific outcomes and priorities.
The Core does not prescribe a step-by-step implementation sequence, and all six Functions should be addressed concurrently. sits at the center because it informs how the other five Functions are implemented and prioritized.
NIST published on February 26, 2024 as voluntary, sector-, country-, and technology-neutral guidance. does not itself create a legal duty, board mandate, certification, control set, or universal review deadline. Applicable laws, regulations, contracts, and internal policies remain separate inputs under GV.OC-03 and may make particular actions or dates mandatory.
- Organizational Context (GV.OC): record mission, stakeholder expectations, applicable requirements, critical services, and dependencies.
- Risk Management Strategy (GV.RM): approve objectives, appetite and tolerance, response options, communication paths, prioritization method, and integration with enterprise risk management.
- Roles, Responsibilities, and Authorities (GV.RR): name accountable leadership, working roles, decision rights, escalation paths, resources, and relevant workforce practices.
- Policy (GV.PO): establish, communicate, enforce, review, and update policy when requirements, threats, technology, or mission change.
- Oversight (GV.OV): review strategy outcomes, coverage of requirements and risks, and organization-wide performance; adjust strategy and direction where needed.
- Cybersecurity Supply Chain Risk Management (GV.SC): establish the program, prioritize suppliers, set agreement requirements, perform due diligence, monitor relationship risk, coordinate incidents, and plan for relationship exit.
Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.
NIST resource center for CSF 2.0 quick-start guides, examples, profiles, and informative references.
NIST risk assessment guidance used as adjacent support for risk analysis and prioritization.