NIST CSF · Domain 6
Govern
About 10% of the exam
The six GOVERN categories
- GV.OC
- organizational context
- GV.RM
- risk management strategy
- GV.RR
- roles, responsibilities and authorities
- GV.PO
- cybersecurity policy
- GV.OV
- strategy oversight
- GV.SC
- cybersecurity supply chain risk management
- Status
- new function added in 2.0
GOVERN is where the other five functions get their mandate, their money and their accountability
What GOVERN changed
- Cybersecurity treated as enterprise risk
- Executives accountable rather than merely informed
- Risk appetite stated before controls chosen
- Supply chain raised to its own category
- Policy tied to outcomes and reviewed
- Oversight loops results back to strategy
The framework now assumes a board level conversation, not only a security team conversation
GV.OC, organizational context
- Mission and stakeholder expectations understood
- Legal and regulatory requirements known
- Critical objectives and dependencies mapped
- Context reviewed as the business changes
- Sector obligations recognized explicitly
GV.RM, risk strategy
- Risk objectives agreed and communicated
- Appetite and tolerance stated in writing
- Risk response decisions recorded consistently
- Enterprise and cyber risk integrated
- Strategic direction reviewed periodically
- Positive risk and opportunity considered
GV.RR, roles and authority
- Leadership accountable and demonstrably engaged
- Roles defined across the organization
- Adequate resources allocated to security
- Security duties in performance expectations
- Hiring and leaving practices support outcomes
GV.PO, policy
- Policy established and communicated widely
- Enforced through monitoring and consequence
- Reviewed on a defined schedule
- Updated after incidents and change
- Exceptions approved and time limited
GV.OV, oversight
- Strategy outcomes reviewed for adjustment
- Performance measured against stated objectives
- Risk coverage reviewed by leadership
- Findings adjust the strategy itself
- Oversight is a loop, not a report
GV.SC, supply chain
- Program established and agreed by stakeholders
- Supplier roles defined inside the organization
- Requirements written into every contract
- Due diligence before and during engagement
- Suppliers included in incident planning
- Offboarding treated as a security event
Tiering suppliers
- Rank by access to sensitive systems
- Weigh criticality of the service supplied
- Consider how easily they are replaced
- Flow requirements down to subcontractors
- Reassess when the relationship changes
Governance in motion
- Set context and obligations
- Agree risk appetite
- Assign roles and resources
- Publish policy
- Delegate to the other functions
- Measure outcomes
- Adjust the strategy
- Every function reports into oversight
- An appetite breach forces a decision
- Blocking an initiative needs quantified risk
- Escalation route defined before disagreement
Governance failures
- Risk appetite never written down
- Policy published but never enforced
- Supplier signed with no security terms
- Subcontracting discovered after the incident
- Security spend decided without risk data
- Residual risk above tolerance, quietly accepted
- Board briefed once a year only
Supply chain evidence
- Supplier inventory with tiers recorded
- Contracts holding security and notification clauses
- Assessment results kept per supplier
- Software bill of materials collected
- Right to audit exercised occasionally
- Fourth party exposure documented
- Offboarding checklist with access revocation
Rapid recall: GOVERN codes
- GV.OC
- context and obligations
- GV.RM
- strategy, appetite, tolerance
- GV.RR
- roles and resourcing
- GV.PO
- policy and exceptions
- GV.OV
- oversight and adjustment
- GV.SC
- supply chain risk management
Governance next to other guidance
- ISO/IEC 27001
- clauses 4, 5 and 9.3
- SP 800-39
- organization wide risk management
- SP 800-161
- supply chain risk practices
- SP 800-37
- authorization and continuous monitoring
- Board duty
- oversight, never daily operation
Reference strip: context, strategy, roles, policy, suppliers
Context
- Mission, stakeholders, obligations
- Dependencies and critical objectives
- Reviewed as the business shifts
Strategy
- Appetite and tolerance written
- Cyber risk inside enterprise risk
- Responses recorded consistently
Roles
- Executive accountability named
- Resources actually allocated
- Duties in performance expectations
Policy
- Published, enforced, reviewed
- Exceptions approved and expiring
- Updated after incidents
Suppliers
- Tiered by access and criticality
- Requirements in the contract
- Monitored, then offboarded securely
Quick exam traps
- Trap: GOVERN replaces the Identify function
- Trap: Supply chain risk is still an Identify outcome in CSF 2.0
- Trap: A published policy is proof the policy outcome is met
- Trap: Risk tolerance can stay an unwritten understanding
- Trap: Oversight means receiving a report, with nothing following from it
- Trap: Fourth party subcontractors are the supplier's problem alone
- Trap: The board owns day to day cybersecurity operation
cybercertprep.com · original revision sheet written from the public body of knowledge