“GOVERN is in the center of the wheel because it informs how an organization will implement the other five Functions.”National Institute of Standards and Technology (NIST) · The NIST Cybersecurity Framework (CSF) 2.0 · 2024 · NIST CSWP 29, «The NIST Cybersecurity Framework (CSF) 2.0» (26 februarie 2024), secțiunea 1 «CSF Core», explicația figurii 2
Governance is not an extra heading but the function that decides how all the others are applied.
Until 2024 the NIST framework had five functions: identify, protect, detect, respond, recover. Version 2.0, published on 26 February 2024, added a sixth — GOVERN — and moved it to the centre of the wheel. It is not an extra heading but an admission: risk strategy, executive expectations, policy, roles and authorities, supply chain risk and oversight are not technical activities, yet they decide how well the technical ones get done. The consequence is unwelcome for teams that start with tools. If nobody has decided which objectives the organisation defends, who decides, and with what budget, then detection and response are optimised in a vacuum. The same idea underpins clause 5 of ISO/IEC 27001, leadership: top management does not support the system, it is accountable for it. An auditor hunting for governance evidence reads written management decisions with a date and an author, not monitoring screens.
Why it matters At audit, governance evidence is a written management decision with a date and an author, not a technical dashboard.