Governance: The Function Boards Keep Skipping in NIST's CSF 2.0
NIST rewrote its Cybersecurity Framework in 2024 to add a function most boards still have not noticed, and the one they have not noticed is the one written specifically for them.
The original Cybersecurity Framework organized a security program around five functions: Identify, Protect, Detect, Respond, Recover. Version 2.0 added a sixth, Govern, and NIST did not slot it in alongside the others. It sits above them in NIST's own published guide to the update, structured as the function that establishes organizational context, risk management strategy, policy, oversight, and the roles and authorities the other five functions operate under. That is not a technical control category. It is a description of what a board is supposed to be doing, written into a federal cybersecurity standard for the first time.
Most boards I sit with have not adjusted their questions to match. They still ask the security team how detection is going, how incident response testing went last quarter, whether recovery time objectives are being met. Those are good questions. They are also all questions about functions four, five, and six, at least under the old framework, and none of them touch the function that NIST just told every organization using this standard is now the board's own responsibility to own.

Why Governance got added, and why it changed the framework's shape
The five original functions describe what a security team executes. Govern describes who decided the strategy those functions execute, who has the authority to accept a given level of risk, and who is accountable when that risk materializes. Putting it structurally above the other five was a deliberate signal. A security team can be excellent at detection and response and still be operating without any board level decision about how much risk the organization is actually willing to carry, which categories of risk get escalated, or who signs off when a tradeoff between security and speed comes up.
Gartner's research on governance platform adoption points at the same gap from a different angle. Large enterprises are now deploying an average of eight governance, risk, and compliance technologies, a number Gartner expects to reach ten by 2028. That is a lot of tooling accumulating underneath a function that, in most organizations, still has no single accountable owner at the board level. Tools without a governing decision behind them tend to produce dashboards nobody is actually required to act on.
What the Govern function actually asks a board to do
Establish and periodically revisit the organization's actual risk appetite, in specific enough terms that a security team can operationalize it, not a general statement that risk should be minimized.
Assign named roles, responsibilities, and authorities for cybersecurity decisions, so it is clear in advance who accepts a risk, who escalates one, and who has final sign off.
Extend that same oversight to cybersecurity supply chain risk, meaning the vendors and third parties who sit inside the organization's own risk posture whether anyone
reviewed them that way or not.
None of this is a document to file once. It is a standing responsibility, and treating it as a one time policy exercise is exactly the mistake NIST restructured the framework to correct. I have sat with boards that could recite their detection metrics in detail and could not answer a much simpler question: who at this table actually owns the decision about how much cyber risk we are willing to carry this year. That answer should not require a meeting to produce. If it does, the Govern function has not actually been implemented, regardless of how mature the other five look on paper. Our team walks boards through exactly this gap as part of BetterWorld Technology's cybersecurity risk assessments.




Comments