NIST CSF 2.0 core functions: Govern, Identify, Protect, Detect, Respond, Recover
By Sam Rivera, Founder, SentinelPanda · March 10, 2026 · 3 min read · NIST CSF
The Cybersecurity Framework is a conceptual map, not a control checklist. Knowing the six functions cold is how you have a useful conversation with executives, customers, and procurement.
Six functions, not five
The original 2014 framework had five functions: Identify, Protect, Detect, Respond, Recover. NIST CSF 2.0 (published 2024) added a sixth — Govern — which wraps and informs the other five. The change reflects how cybersecurity has shifted from a technical checklist to an enterprise-risk discipline that boards and executives are accountable for.
Each function decomposes into categories (high-level outcomes) and subcategories (specific outcomes). Subcategories are the leaf-level statements you use to assess yourself; there are about 100 of them across the six functions in 2.0.
Govern (GV)
The strategic context for cybersecurity. Establish the organisation's cybersecurity risk management strategy, expectations, and policy. Categories include Organisational Context, Risk Management Strategy, Roles, Responsibilities, and Authorities, Policy, Oversight, and Cybersecurity Supply Chain Risk Management.
Govern is the function most CISOs and executives spend more time on with CSF 2.0 than they did with 1.1. It is also the one most likely to involve the board.
Identify (ID)
Understand the cybersecurity risks to systems, people, assets, data, and capabilities. Categories: Asset Management, Risk Assessment, and Improvement (the continuous improvement loop). Identify is where the asset inventory, the data inventory, and the risk register live.
Protect (PR)
Develop and implement appropriate safeguards. Categories: Identity Management, Authentication, and Access Control; Awareness and Training; Data Security; Platform Security; Technology Infrastructure Resilience. Most of the operational security investment in any program shows up here.
Detect (DE)
Develop and implement appropriate activities to identify the occurrence of a cybersecurity event. Categories: Continuous Monitoring; Adverse Event Analysis. Detect is where logging, SIEM, EDR, and security monitoring live.
Respond (RS)
Take action regarding a detected cybersecurity incident. Categories: Incident Management; Incident Analysis; Incident Response Reporting and Communication; Incident Mitigation. Respond is the runbook and the tabletop exercise. A program that has never run a real incident, even a simulated one, has a Respond function on paper only.
Recover (RC)
Restore assets and operations affected by a cybersecurity incident. Categories: Incident Recovery Plan Execution; Incident Recovery Communication. Recover is business continuity and disaster recovery, scoped specifically to cyber. Backups, runbooks, and a tested recovery time objective live here.
How to use the six functions
CSF is descriptive, not prescriptive — it does not tell you which controls to implement, only which outcomes you should be achieving. The intended workflow is: pick a Target Profile (which subcategories you want to achieve, at what implementation tier), assess your Current Profile, identify gaps, and prioritise. The framework is a structure for that conversation, not a checklist.
Most organisations use CSF as a lingua franca with executives and customers (who recognise the six functions) while running their actual control program against ISO 27001 Annex A or SOC 2 — the framework's informative references make that mapping mechanical.