The NIST Cybersecurity Framework had five functions for a long time: identify, protect, detect, respond and recover. Version 2.0 added a sixth - Govern - and did not place it alongside the others but above them.
What Govern covers
The function covers what used to be assumed and was therefore rarely done:
- Organizational context - mission, stakeholders, legal and regulatory obligations.
- Risk management strategy - risk appetite and tolerance, expressed so decisions can actually be made against them.
- Roles and responsibilities - who decides, who implements, who reports.
- Policy - established, communicated and maintained.
- Oversight - reviewing outcomes and adjusting the strategy.
- Supply chain risk management - raised to governance level rather than procurement.
In version 1.1 risk appetite was implicit. That meant decisions to accept risk were being taken by people not accountable for them - usually IT, because IT was the only function with the data. Govern puts that back with the board, explicitly.
How it relates to Croatian obligations
The framework is not law and nobody in Croatia requires it. It is useful for a different reason: it is a common language. A board that does not understand sub-measure 1.3 does understand the question "how capable are we of detecting an attack?"
The mapping is more direct than it appears:
| CSF 2.0 function | Corresponds to measures |
|---|---|
| Govern | 1 (commitment and accountability), 3 (risk management), 8 (supply chain) |
| Identify | 2 (assets), 3 (risk) |
| Protect | 4, 5, 6, 7, 9, 10, 13 |
| Detect | 6 (network monitoring), 11 (incident detection) |
| Respond | 11 (incident handling) |
| Recover | 12 (continuity and crisis) |
The same mapping exists towards ISO/IEC 27002:2022, because its control attributes use exactly the identify, protect, detect, respond and recover concepts. Three frameworks, one evidence base.
Where the framework genuinely helps
Not as a substitute for compliance, but as a tool for three things:
- Board reporting. Six functions fit on one slide. Ninety-nine sub-measures do not.
- Setting a target profile. The framework distinguishes current and target profiles, which is a better way to discuss budget than a list of deficiencies.
- Comparison over time. A profile, once set, produces a trend - and a trend is the only thing a board cares about more than the current state.
The trap to avoid
The framework describes outcomes, not controls. "Supply chain risks are identified and recorded" is an outcome - how you achieve it is not prescribed. That is its strength when used for governance, and its weakness when someone tries to use it as a task list.
Organisations that attempt to implement CSF instead of the Regulation end up with a good overview and no evidence base. The order that works is the reverse: implement the measures, then present the result through the six functions.
NIST published implementation examples alongside version 2.0, attaching concrete activities to each outcome. That is the most useful part of the documentation for a first-time user, and the most commonly skipped.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.