Govern Function
The Govern Function is one of the functions in the NIST Cybersecurity Framework (CSF) 2.0, focused on establishing and maintaining the governance structures and processes an organization uses to manage cybersecurity risk. It addresses policy, oversight, and accountability at the program level, and helps inform and prioritize the outcomes of the framework's other functions. It was added in the 2.0 version of the framework to reflect the growing importance of risk management and governance for IT and security teams.
In the NIST Cybersecurity Framework (CSF) 2.0, published by NIST in February 2024, the GOVERN Function provides outcomes intended to inform and prioritize the outcomes of the framework's other functions. As commonly described, it concerns establishing and maintaining organizational governance structures and processes for managing cybersecurity risk, making cybersecurity accountability explicit at the program level across policy, oversight, and risk management. Note that as scoped here, the Govern Function is a component of a cybersecurity framework rather than an AI-specific governance instrument; the NIST CSF is issued as voluntary guidance rather than binding law, and the evidence provided addresses cybersecurity governance specifically and does not establish its application to AI model governance. Characterizations of its relative importance within the framework (for example, as the 'glue' holding the framework together) reflect practitioner opinion in the evidence rather than a definitional claim.
Why it matters
The Govern Function marks a structural shift in how the NIST Cybersecurity Framework treats governance. In CSF 2.0, published by NIST in February 2024, GOVERN was added to the framework's set of functions and is positioned to inform and prioritize the outcomes of the other functions. This reflects a recognition, as described in the evidence, that risk management and governance have become essential tasks for IT and security teams rather than peripheral concerns handled only after technical controls are in place.
For practitioners, the significance is that the Govern Function makes cybersecurity accountability explicit at the program level, covering policy, oversight, and risk management. Rather than leaving governance implicit across scattered activities, it provides a defined place in the framework for establishing who is accountable and how cybersecurity risk decisions are made and maintained. One practitioner cited in the evidence characterizes it as the 'glue that holds the entire framework together,' though this is an opinion about its relative importance rather than a definitional claim.
It is important to scope the Govern Function correctly. The NIST CSF is issued as voluntary guidance, not binding law, and the Govern Function is a component of a cybersecurity framework specifically. The evidence provided addresses cybersecurity governance and does not establish the function's application to AI model governance or model risk management. Readers should not assume that adopting the Govern Function satisfies AI-specific governance obligations, nor that it is interchangeable with instruments such as the NIST AI Risk Management Framework, ISO/IEC 42001, or model risk guidance such as SR 11-7.
Who it's relevant to
Inside Govern Function
Common questions
Answers to the questions practitioners most commonly ask about Govern Function.