What you’ll be able to do
- Say what each CSF 2.0 Govern category is for, in one plain sentence, with one Riverstone example.
- Describe ISO/IEC 27001:2022 with Amd 1:2024 as a scoped ISMS, not as product safety or a promise about one incident.
- Keep a 30-day cadence of three rituals, each mapped to one Govern category.
- Sort a risk sentence, a control, and an evidence record without treating a GRC module as the work.
Six jobs, not a module
F8 named Govern as the function that assigns owners. NIST CSWP 29, final 26 February 2024, states the function this way: the organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored. The same publication puts Govern at the center of the wheel because it informs how the other five Functions are done. Buying a GRC module does not establish that function.
Table 1 of CSWP 29 names six Govern categories. The sentences below are plain-language jobs for this lesson, plus one Riverstone example each. They are not quotations of Subcategory outcome text, and this lesson does not recite Subcategory identifiers. Read the CSF card when you want the edition pin and the limits.
- GV.OC Organizational Context: know the mission, who depends on it, and which requirements wrap the decision. Riverstone’s context is the Oakland morning dock wave and TrackPort delivery windows.
- GV.RM Risk Management Strategy: write the priorities, constraints, and what you will accept, then use that note on the live decision. KEV-listed internet appliances outrank the lunch wiki. The unchecked geofence stays a guess.
- GV.RR Roles, Responsibilities, and Authorities: name who decides, who operates, and who keeps the record. Priya accepts the VPN risk, Devon changes the admin group, and Maya files the enrollment report.
- GV.PO Policy: write the rule, tell the people who must follow it, and apply it. VPN-Admin accounts use phishing-resistant MFA. A shared clipboard password is not a second rule.
- GV.OV Oversight: read the results and change the strategy when they disagree with the plan. On 9 April, Priya reads expired exceptions and the missing factor before anyone calls the row green.
- GV.SC Cybersecurity Supply Chain Risk Management: know the suppliers that can stall the mission, and keep watching them while the contract runs. The VPN vendor’s broken image is a dated constraint. The TrackPort SaaS provider is a different supplier, on a different system.
A profile for one system, and a scoped ISMS
CSWP 29 describes an Organizational Profile as the current and target cybersecurity posture in the Core’s outcomes, for a scope you choose. You may keep more than one profile. A Current Profile says what you achieve now. A Target Profile says the outcomes you have selected. This month’s target is the VPN only: every VPN-Admin account on phishing-resistant MFA, or a dated exception. It is not a profile of the whole company, and it is not a Tier used as a score.
ISO/IEC 27001:2022 is Edition 3 of the requirements for an information security management system. Amendment 1:2024, climate action changes, was published on 23 February 2024. When a certification body has issued a certificate, that certificate is scoped evidence of an ISMS audit. It is not a product-safety mark for TrackPort, and it does not mean the VPN cannot be exploited. A Statement of Applicability records which controls the ISMS includes and the reason for any exclusion. Annex A is not a list you must implement in full because someone said “27001.” This lesson does not copy Annex A, and it does not teach accredited auditor skills. Use the ISO card for the edition and the boundaries.
Three rituals in thirty days
The month from 10 March to 9 April is the cadence. Maya does not open a new spreadsheet of every category identifier. She brings three things Priya can finish in one sitting. Each ritual practices one Govern category. The other categories stay visible in the list above so nobody pretends three rows are the whole function.
At work, pick one live system and write, privately, who owns its risk and the date of the last evidence. Do not paste employer records into Atlas. If you cannot name the owner or the date, that gap is the finding.
| Ritual | What Maya brings | Govern category |
|---|---|---|
| Read every open exception and close any date that has passed. | The jump-host compensating control, owner Priya Shah, expiry 9 April 2026. | GV.OV Oversight |
| Refresh the target for the VPN only. | Target: every VPN-Admin account on phishing-resistant MFA, or a new dated exception. | GV.RM Risk Management Strategy |
| File the evidence the control already produces. | Devon’s enrollment report for VPN-Admin, with the account that still has no factor named on the page. | GV.PO Policy |
CHECK YOUR JUDGMENT