Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Security Frameworks

CSF Core Functions (Govern, Identify, Protect, Detect, Respond, Recover)

Also known as: NIST CSF Functions, Cybersecurity Framework Core Functions, Five Functions (CSF 1.1), Six Functions (CSF 2.0)
Simply put

The Core Functions are the highest-level categories used to organize cybersecurity outcomes within the NIST Cybersecurity Framework (CSF), a voluntary framework rather than a law. They describe broad activities an organization can undertake to manage cyber risk, spanning setting direction, understanding assets and risks, protecting them, detecting problems, responding to incidents, and recovering afterward. They are meant to be a common language for discussing and improving cybersecurity, not a mandatory checklist.

Formal definition

Within the NIST Cybersecurity Framework, the Core Functions are the top tier of the Framework Core, under which sit Categories and Subcategories that express desired cybersecurity outcomes. CSF 1.1 defined five Functions: Identify, Protect, Detect, Respond, and Recover. CSF 2.0 (published February 26, 2024) added GOVERN, yielding six Functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER; per NIST, GOVERN, IDENTIFY, and PROTECT outcomes help prevent and prepare for incidents, while GOVERN, DETECT, RESPOND, and RECOVER outcomes help discover and manage them. The Functions are organizational constructs for cyber risk management rather than a sequential process, and adoption of the CSF is voluntary unless made binding by contract, sector rule, or other authority. This entry describes the Functions at a conceptual level and does not enumerate their constituent Categories, Subcategories, or Informative References; readers should verify structure and current version against the authoritative NIST publication, since the framework is periodically revised.

Why it matters

The Core Functions give organizations a shared vocabulary for describing cybersecurity outcomes, which matters because cyber risk conversations otherwise fragment across technical, legal, and executive audiences. By grouping desired outcomes under a small number of headings, the Functions let a board member, a security engineer, and an auditor discuss the same risk posture without each imposing their own taxonomy. This common language is one of the central reasons the NIST Cybersecurity Framework has been adopted well beyond its original U.S. critical-infrastructure audience.

The Functions also structure how organizations think about the full lifecycle of cyber risk rather than treating security as a single control set. Per NIST, GOVERN, IDENTIFY, and PROTECT outcomes help prevent and prepare for incidents, while GOVERN, DETECT, RESPOND, and RECOVER outcomes help discover and manage them. Framing outcomes this way discourages the common failure of investing heavily in prevention while neglecting detection, response, and recovery capabilities that determine how much damage an incident actually causes.

It is important to keep the Functions in perspective: the CSF is a voluntary framework, not a law, and the Functions are organizational constructs rather than a mandatory checklist or a sequential procedure. They become binding only where a contract, sector-specific rule, or other authority incorporates the framework. Readers should treat the Functions as a structure for organizing and communicating cybersecurity work, and should verify the current version and detailed structure against the authoritative NIST publication, since the framework is periodically revised.

Who it's relevant to

Information security leaders and CISOs
Security leaders use the Core Functions to organize their programs, communicate posture to executives and boards, and identify gaps across the full risk lifecycle rather than concentrating solely on prevention. The GOVERN Function introduced in CSF 2.0 is particularly relevant to those responsible for setting risk-management direction and oversight.
Compliance officers and auditors
Where a contract, sector rule, or other authority incorporates the CSF, compliance and audit professionals may map obligations or assess maturity against the Functions. It is worth remembering that adoption of the CSF is voluntary unless made binding, so alignment with the Functions is not the same as certification against a mandatory standard, and any assessment should reference the framework version actually in scope.
Executives and boards
Because the Functions provide a common, non-technical vocabulary, senior leaders can use them to understand and question the organization's cybersecurity posture. The GOVERN Function speaks directly to leadership's role in establishing expectations and oversight for cyber risk management.
Legal counsel and risk managers
Counsel and risk managers may encounter the Functions when contracts or sector-specific rules reference the CSF, or when assessing how prevention, detection, response, and recovery capabilities affect exposure. They should confirm which version and which specific outcomes any obligation refers to, since the framework is periodically revised and the Functions differ between CSF 1.1 and CSF 2.0.

Inside CSF Core Functions (Govern, Identify, Protect, Detect, Respond, Recover)

Govern
The function addressing how an organization establishes, communicates, and monitors its cybersecurity risk management strategy, expectations, and policy. It was elevated as a distinct function in the CSF 2.0 revision to emphasize organizational context, roles and responsibilities, and oversight, and it cuts across the other functions rather than operating in isolation.
Identify
The function covering activities that help an organization understand its assets, systems, data, suppliers, and the associated cybersecurity risks. It generally underpins the other functions by informing risk-based prioritization.
Protect
The function encompassing safeguards used to manage or reduce identified cybersecurity risks, such as access management, awareness and training, data security, and protective technology measures.
Detect
The function addressing the timely discovery and analysis of possible cybersecurity events, including monitoring and anomaly identification, so that potential incidents can be recognized.
Respond
The function covering actions taken once a detected cybersecurity incident occurs, including incident management, analysis, mitigation, and communications aimed at containing impact.
Recover
The function addressing the restoration of assets and operations affected by a cybersecurity incident, supporting resilience and a return to normal operations.

Common questions

Answers to the questions practitioners most commonly ask about CSF Core Functions (Govern, Identify, Protect, Detect, Respond, Recover).

Does implementing the CSF Core Functions make my organization legally compliant with cybersecurity regulations?
No. The NIST Cybersecurity Framework is a voluntary framework, not a regulation, and adopting its Core Functions does not by itself establish legal compliance with any binding law. Certain regulators, contracts, or sector-specific requirements may reference or incorporate the framework, which can give it force in that specific context, but the framework itself carries no independent legal authority. Compliance obligations under regimes such as the GDPR, HIPAA, or state-level requirements are determined by those instruments, not by the CSF. Organizations should map the framework to their actual legal obligations rather than treating alignment with the Core Functions as a substitute for them, and should verify applicable requirements against the current official text.
Are the Core Functions meant to be performed one after another as sequential steps?
Generally, no. The Core Functions are best understood as concurrent and continuous categories of activity rather than a linear sequence with a defined start and finish. An organization typically carries out governance, identification, protection, detection, response, and recovery activities in parallel and on an ongoing basis, with outputs from one function informing others. Treating them as a checklist to complete in order tends to misrepresent how the framework is intended to support continuous risk management. The functions organize outcomes; they are not a project timeline.
How does the Govern function relate to the other five Core Functions in practice?
The Govern function is generally positioned as informing and being informed by the other functions rather than sitting alongside them as an equal, parallel activity. In most implementations it addresses how cybersecurity risk decisions are made, how roles and responsibilities are assigned, and how strategy, policy, and oversight are set—context that shapes how Identify, Protect, Detect, Respond, and Recover are prioritized and resourced. In practice, organizations often use governance outcomes to establish risk appetite and accountability, then reflect those decisions across the remaining functions. The precise emphasis will depend on organizational size, risk profile, and structure.
Where should an organization begin when adopting the Core Functions for the first time?
There is no single mandated starting point, but many organizations begin by establishing an understanding of their context, assets, and risks—activities associated with the Identify function—and by setting governance expectations before investing heavily in specific controls. This ordering is a common practical approach rather than a requirement of the framework. The appropriate entry point is fact-specific and may depend on existing maturity, resources, and the outcome of any current-state assessment. Because the framework is outcome-oriented, organizations generally prioritize functions and categories according to their own risk assessment rather than adopting everything at once.
How do the Core Functions fit with an assessment of our current cybersecurity posture?
The Core Functions are commonly used as an organizing structure for assessing current-state practices and identifying gaps relative to a desired target state. An assessment of this kind evaluates existing activities against the outcomes described in the functions and their subordinate categories; it is distinct from any formal certification, which the framework does not itself confer. Organizations often document current and target profiles across the functions to prioritize improvements. Note that an assessment describes posture at a point in time and depends on the accuracy of the information reviewed.
Do we need to address every Core Function to use the framework effectively?
The framework is generally intended to be applied flexibly according to an organization's risk, resources, and obligations rather than requiring uniform, exhaustive coverage of every function and category. In most cases organizations tailor their use of the Core Functions—emphasizing the outcomes most relevant to their risk profile—rather than treating each element as mandatory. That said, where a contract, regulator, or sector requirement references specific outcomes, those particular expectations may effectively become binding in that context. Scope decisions require professional judgment and should be documented against the organization's own risk determinations.

Common misconceptions

The CSF Core Functions are a mandatory legal requirement that organizations must comply with.
The NIST Cybersecurity Framework is a voluntary framework, not a binding regulation. It carries no legal force in itself. It may become effectively obligatory only where it is incorporated by contract, referenced by a sector regulator, or adopted through internal policy. Organizations should verify whether any specific legal or contractual obligation references it in their jurisdiction and sector.
The six functions are performed in a fixed sequence, one after another.
The functions are generally intended to be treated as concurrent and continuous rather than as a linear checklist. In particular, Govern is described as spanning and informing the other functions rather than being a step that precedes them.
Adopting the Core Functions results in a certification demonstrating compliance.
Using the framework is a self-directed practice, not a certification scheme. It differs from standards with formal certification pathways. Aligning with the functions does not by itself produce an accredited certificate, and readers should not conflate framework adoption with third-party certification.

Best practices

Treat the six functions as an ongoing, integrated program rather than a one-time or sequential exercise, revisiting each as risks and organizational context change.
Use the Govern function to define clear roles, responsibilities, and oversight, and to align cybersecurity risk management with broader organizational strategy.
Ground Protect, Detect, Respond, and Recover activities in the asset and risk understanding developed through the Identify function, prioritizing by risk.
Confirm whether any applicable regulation, contract, or customer requirement references the framework, since obligations differ by jurisdiction and sector and are fact-specific.
Verify function and category details against the current official NIST publication, as the framework has been revised over time and may be updated again.
Engage qualified professionals to interpret how the functions apply to your specific environment, treating the framework as informational guidance rather than a substitute for professional judgment.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.