CSF Core Functions (Govern, Identify, Protect, Detect, Respond, Recover)
The Core Functions are the highest-level categories used to organize cybersecurity outcomes within the NIST Cybersecurity Framework (CSF), a voluntary framework rather than a law. They describe broad activities an organization can undertake to manage cyber risk, spanning setting direction, understanding assets and risks, protecting them, detecting problems, responding to incidents, and recovering afterward. They are meant to be a common language for discussing and improving cybersecurity, not a mandatory checklist.
Within the NIST Cybersecurity Framework, the Core Functions are the top tier of the Framework Core, under which sit Categories and Subcategories that express desired cybersecurity outcomes. CSF 1.1 defined five Functions: Identify, Protect, Detect, Respond, and Recover. CSF 2.0 (published February 26, 2024) added GOVERN, yielding six Functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER; per NIST, GOVERN, IDENTIFY, and PROTECT outcomes help prevent and prepare for incidents, while GOVERN, DETECT, RESPOND, and RECOVER outcomes help discover and manage them. The Functions are organizational constructs for cyber risk management rather than a sequential process, and adoption of the CSF is voluntary unless made binding by contract, sector rule, or other authority. This entry describes the Functions at a conceptual level and does not enumerate their constituent Categories, Subcategories, or Informative References; readers should verify structure and current version against the authoritative NIST publication, since the framework is periodically revised.
Why it matters
The Core Functions give organizations a shared vocabulary for describing cybersecurity outcomes, which matters because cyber risk conversations otherwise fragment across technical, legal, and executive audiences. By grouping desired outcomes under a small number of headings, the Functions let a board member, a security engineer, and an auditor discuss the same risk posture without each imposing their own taxonomy. This common language is one of the central reasons the NIST Cybersecurity Framework has been adopted well beyond its original U.S. critical-infrastructure audience.
The Functions also structure how organizations think about the full lifecycle of cyber risk rather than treating security as a single control set. Per NIST, GOVERN, IDENTIFY, and PROTECT outcomes help prevent and prepare for incidents, while GOVERN, DETECT, RESPOND, and RECOVER outcomes help discover and manage them. Framing outcomes this way discourages the common failure of investing heavily in prevention while neglecting detection, response, and recovery capabilities that determine how much damage an incident actually causes.
It is important to keep the Functions in perspective: the CSF is a voluntary framework, not a law, and the Functions are organizational constructs rather than a mandatory checklist or a sequential procedure. They become binding only where a contract, sector-specific rule, or other authority incorporates the framework. Readers should treat the Functions as a structure for organizing and communicating cybersecurity work, and should verify the current version and detailed structure against the authoritative NIST publication, since the framework is periodically revised.
Who it's relevant to
Inside CSF Core Functions (Govern, Identify, Protect, Detect, Respond, Recover)
Common questions
Answers to the questions practitioners most commonly ask about CSF Core Functions (Govern, Identify, Protect, Detect, Respond, Recover).
