home / frameworks / nist-csf / functions-and-categories

// NIST CSF hub

NIST CSF 2.0 functions and categories explained

How the 6 functions, 22 categories, and 106 subcategories of the CSF 2.0 Core fit together.

How the Core is built

The CSF Core is a list of outcomes, not a list of controls. NIST arranges those outcomes in three levels. At the top are 6 functions, below them are 22 categories, and under those sit 106 subcategories. Each subcategory has an identifier such as GV.OC-01 or PR.AA-05, which makes it easy to cite in policies, audit findings, and mappings.

The functions aren't sequential. NIST describes them as concurrent activities, with Govern placed at the centre of its wheel graphic because it informs the other five. An organization can work on detection and recovery at the same time, for example, while its board refines risk appetite.

Govern

Govern is the main addition. It pulls together outcomes that were scattered across Identify in version 1.1 and adds new ones. Its 6 categories are organizational context (GV.OC), risk management strategy (GV.RM), roles, responsibilities, and authorities (GV.RR), policy (GV.PO), oversight (GV.OV), and cybersecurity supply chain risk management (GV.SC).

Supply chain risk received its own category with 10 subcategories. They cover supplier due diligence, contract requirements, monitoring suppliers over the relationship, and planning for the end of a supplier relationship. This is the category Canadian suppliers often see reflected in questionnaires from U.S. customers.

Identify and Protect

Identify has 3 categories in 2.0: asset management (ID.AM), risk assessment (ID.RA), and improvement (ID.IM). Improvement is new. It asks organizations to learn from assessments, exercises, real incidents, and the day-to-day running of their security program, then feed those lessons back into every function. Asset management now covers data inventories as well as hardware, software, and services.

Protect has 5 categories. They are identity management, authentication, and access control (PR.AA), awareness and training (PR.AT), data security (PR.DS), platform security (PR.PS), and technology infrastructure resilience (PR.IR). Platform security replaced older categories on protective technology and maintenance. It groups configuration management, software maintenance, logging, and secure development practices in one place.

Detect, Respond, and Recover

Detect has 2 categories, continuous monitoring (DE.CM) and adverse event analysis (DE.AE), which together cover watching networks, people, and services and deciding when an event becomes an incident. Respond has 4: incident management (RS.MA), incident analysis (RS.AN), incident response reporting and communication (RS.CO), and incident mitigation (RS.MI). Recover has 2: incident recovery plan execution (RC.RP) and incident recovery communication (RC.CO). That's 8 in all.

Short and practical. That's how most of these outcomes read, even in the more technical functions where a reader might expect detailed control language. RC.RP, for instance, includes checking the integrity of backups before using them to restore assets, and declaring the end of recovery based on criteria agreed in advance.

Implementation examples and informative references

Version 2.0 moved supporting detail online so NIST can update it without reissuing the framework. Implementation examples give short, action-oriented illustrations of how to achieve each subcategory, such as reviewing logs for unusual activity or keeping offline backups of important data. They're suggestions. NIST says they aren't a complete list, and organizations can meet an outcome in other ways.

Informative references map subcategories to other documents, including SP 800-53, the CIS Critical Security Controls, and ISO/IEC 27001:2022. The CSF 2.0 Reference Tool lets users browse and export the Core along with these references in spreadsheet or JSON form.

  • Govern: 6 categories
  • Identify: 3 categories
  • Protect: 5 categories
  • Detect: 2 categories
  • Respond: 4 categories
  • Recover: 2 categories

Resources

All NIST CSF resources

References

  1. The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29), NIST
  2. CSF 2.0 Reference Tool, NIST
  3. CSF 2.0 Informative References, NIST