The establishes, communicates, and monitors cybersecurity risk strategy, expectations, and policy. Its Categories cover organizational context, risk-management strategy, roles and authorities, policy, oversight, and cybersecurity supply-chain risk management. Metrics should inform those governance decisions, not reduce the entire Core to one maturity score. The examples and thresholds on this page are Sorena's operating guidance, not NIST requirements.
1
Section 1
What GOVERN covers and what metrics must do
The covers organizational context (GV.OC), risk management strategy (GV.RM), roles, responsibilities, and authorities (GV.RR), policy (GV.PO), oversight (GV.OV), and cybersecurity supply chain risk management (GV.SC). Its outcomes address the strategy, expectations, and policy used to manage cybersecurity risk.
NIST discusses key performance indicators and key risk indicators as information practitioners provide to managers and executives. It does not prescribe a universal metric catalog, formula, dashboard, threshold, or aggregate CSF score. Each organization chooses measures that fit its objectives, risks, , and decision process.
A useful measure tells a named decision owner whether to continue, investigate, fund, adjust, accept, or escalate. If no action can follow from the result, the measure may be descriptive, but it is not a governance control by itself. An external law, contract, or policy may prescribe a separate measure or threshold; preserve that authority instead of labeling it a NIST threshold.
Executive view | Changes in major risks, or tolerance, priority gaps, resource choices, supplier dependencies, and decisions requiring direction.
Management view | Action-plan progress, overdue or blocked gaps, policy and control-performance trends, exceptions, supplier-risk treatment, and changed requirements or threats.
Metric record | Decision question, CSF outcome, owner, formula or rule, numerator and denominator where applicable, population, period, source, collection method, threshold, limitation, and escalation path.
Start with a specific GOVERN outcome and decision. The measures below are Sorena's operating examples, not NIST-required metrics or thresholds. Adapt the formula, population, timing, and escalation rule to the organization.
GV.OC | Decision: has context changed enough to revise risk priorities? | Examples: confirmed requirement changes awaiting disposition; critical service dependencies without a current owner; stakeholder expectations not mapped to a decision.
GV.RM | Decision: are operational choices within approved risk direction? | Examples: risk decisions outside stated tolerance; risk records using an unapproved method; elapsed time for out-of-tolerance escalation.
GV.RR and GV.PO | Decision: are accountability, resources, and policy operating as intended? | Examples: priority outcomes without an accountable owner; overdue policy reviews triggered by change; exceptions without active approval.
GV.OV | Decision: should strategy or direction change? | Examples: priority gaps by status and risk; repeated threshold breaches; accepted risks due for review; action plans blocked by resources or dependencies.
GV.SC | Decision: which supplier risks require treatment or escalation? | Examples: critical suppliers without an assigned risk owner; agreed actions overdue; material supplier changes awaiting reassessment.
Define a metric before using its trend or threshold in a governance decision. Preserve the underlying records so a reviewer can reproduce the result and understand exclusions or changes in method.
Identity | Metric name, linked GOVERN outcome, decision question, decision owner, data owner, and reporting audience.
Calculation | Unit, formula or classification rule, numerator, denominator, population, exclusions, period, cutoff time, source systems, and treatment of missing or duplicate records.
Interpretation | Baseline, trend direction, threshold or tolerance, uncertainty, known bias, comparability with prior periods, and conditions that invalidate the result.
Response | Review frequency or event trigger, required action at each threshold, escalation authority, decision record, and follow-up owner.
Evidence | Query or extraction method, source snapshot or record IDs, approvals, exception list, calculation version, reviewer, and correction history.
A favorable count can hide a critical exception, and a rising count can reflect better detection rather than worsening control. Pair the number with its scope, trend explanation, exceptions, and decision record.
Do not average unrelated Subcategory judgments into a single 'NIST compliance' or maturity percentage that the CSF does not define.
Do not call a metric a key performance indicator or key risk indicator without stating the objective or risk and the decision it changes.
Do not compare periods after changing scope, source, formula, threshold, or data quality without marking the break in comparability.
Do not treat activity volume, such as reviews completed, as proof that risk fell or the outcome was achieved.
Do not present an internally chosen threshold as a NIST requirement.
Run the review at the organization's chosen cadence and after material events. Keep the dashboard small enough that each measure receives an owner decision or a recorded reason for no action.
Step 1 | Frame | Name the decision, authority, linked GOVERN outcome, Profile scope, appetite or tolerance, and stakeholder need.
Step 2 | Validate | Confirm the metric definition, covered period and population, source completeness, exceptions, comparability, and known limitations.
Step 3 | Interpret | Compare the result with the approved threshold, trend, priority, open gaps, incidents, and contextual changes.
Step 4 | Decide | Continue, investigate, fund, reprioritize, accept, adjust strategy or policy, or escalate; record rationale and conditions.
Step 5 | Follow through | Assign the action and evidence, update the Profile or risk record when appropriate, and set the next review or event trigger.
Defines the GOVERN Function and Categories, their outcome statements, the executive-manager-practitioner communication cycle, and the use of performance and risk indicators to inform risk decisions.
"does not prescribe how outcomes should be achieved"