Govern The Ungovernable - NIST CSF Govern Function

Alan Raveling

S4x24 - ICS Security Conference · Day 3 · Stage 3

Overview

Alan Raveling's S4 conference talk, "Govern The Ungovernable - NIST CSF Govern Function," delivers a pragmatic and timely exploration of the newly introduced Govern function within the NIST Cybersecurity Framework (CSF) 2.0. Released as a final version on February 26th, NIST CSF 2.0 significantly expands its scope by embedding governance as a foundational element that underpins and integrates all other cybersecurity functions. Raveling’s presentation specifically targets smaller organizations, offering actionable strategies for establishing sustainable cybersecurity governance programs from the ground up, a concept he describes as "grassroots governance."

Watch on YouTube

Visual summary for Govern The Ungovernable - NIST CSF Govern Function by Alan Raveling
Visual summary for Govern The Ungovernable - NIST CSF Govern Function by Alan Raveling

Key moments

  1. 0:00 Introduction to NIST CSF 2.0 and Govern function
  2. 1:00 Foundational quotes on cybersecurity and action
  3. 2:00 Overview of NIST CSF 2.0 Govern function
  4. 4:00 Governance differences: large vs. small organizations
  5. 6:00 Common governance challenges for smaller organizations
  6. 7:00 Practical 'do's and don'ts' for effective governance
  7. 7:50 The critical IT/OT collaboration for governance success

Govern The Ungovernable - NIST CSF Govern Function

Speakers: Alan Raveling

Conference: S4

YouTube: https://www.youtube.com/watch?v=gT7gC4wrJtA

Overview

Alan Raveling's S4 conference talk, "Govern The Ungovernable - NIST CSF Govern Function," delivers a pragmatic and timely exploration of the newly introduced Govern function within the NIST Cybersecurity Framework (CSF) 2.0. Released as a final version on February 26th, NIST CSF 2.0 significantly expands its scope by embedding governance as a foundational element that underpins and integrates all other cybersecurity functions. Raveling’s presentation specifically targets smaller organizations, offering actionable strategies for establishing sustainable cybersecurity governance programs from the ground up, a concept he describes as "grassroots governance."

The talk stands out by acknowledging that while large enterprises often possess established governance bodies, budgets, and enforcement capabilities, smaller entities frequently struggle with undefined risk appetites, fluctuating strategies, lack of high-level accountability, and resource constraints. Raveling emphasizes that effective cybersecurity is not merely about products but a consistent set of practices, advocating for proactive, collaborative efforts that build internal support and leverage external peer networks. His insights are crucial for any organization grappling with the complexities of formalizing cybersecurity risk management, particularly those in Operational Technology (OT) environments where the convergence of IT and OT demands a unified, yet specialized, governance approach.

This article delves into Raveling's analysis of the Govern function, dissecting its core components and highlighting the unique challenges faced by small to medium-sized organizations. It provides a detailed look at the strategic and practical considerations necessary to embed governance effectively, ensuring cybersecurity efforts are cohesive, sustainable, and aligned with organizational objectives. By focusing on the practical application of NIST CSF 2.0's Govern function, Raveling offers a roadmap for turning theoretical frameworks into tangible security improvements.

Background

▶ Watch: Introduction to NIST CSF 2.0 and Govern function (0:00)

The evolution of cybersecurity frameworks reached a significant milestone with the final release of NIST CSF 2.0 on February 26th, marking a pivotal shift in how organizations are encouraged to approach cybersecurity risk management. The most profound change in this iteration is the introduction of the Govern function. Previously, the CSF comprised five core functions: Identify, Protect, Detect, Respond, and Recover. With CSF 2.0, Govern now encircles and integrates these existing functions, serving as the overarching strategic component that establishes and monitors an organization's cybersecurity risk management strategy, expectations, and policy. This re-framing underscores the principle that effective cybersecurity is not a series of disparate technical actions but a cohesive, strategically managed endeavor.

The Govern function, as outlined by NIST CSF 2.0, aims to address several critical areas: defining organizational context, establishing a risk management strategy, delineating roles and responsibilities, and developing comprehensive policies, processes, and procedures. It recognizes that without a clear governance structure, cybersecurity efforts can become fragmented, inconsistent, and ultimately ineffective. Raveling notes that while large, often publicly traded, organizations typically have well-established governance bodies with defined accountability, enforcement capabilities (both "sticks" like swaying bonuses and "carrots" like incentives), dedicated budgets, headcount, and empowering technologies, smaller organizations face a starkly different reality.

For many smaller organizations, cybersecurity governance either exists only on paper or is entirely absent. They contend with an unknown or undefined risk appetite, meaning there's no clear understanding of how much risk the organization is willing to tolerate. Their cybersecurity strategy is often in a constant state of flux, characterized by conflicting priorities, a lack of alignment, and frequent shifts in focus driven by the latest "hot" trend rather than a long-term vision. This instability leads to projects being delayed or abandoned before full implementation. A significant hurdle is the lack of accountability and ownership at higher management levels; if the board or investors aren't actively inquiring about cybersecurity, there's little impetus for action. Additionally, smaller organizations often suffer from boom-bust budgeting cycles, making it challenging to fund multi-year cybersecurity initiatives consistently. High turnover among cybersecurity professionals further exacerbates delays, as organizations are constantly onboarding new talent. Finally, Raveling highlights the issue of products not living up to OT-compatible claims, where solutions purchased with the expectation of solving problems in operational technology environments prove inadequate or require significant unforeseen modifications, leading to wasted resources and delayed progress. This backdrop of resource constraints, strategic instability, and lack of top-level engagement makes the implementation of the NIST CSF 2.0 Govern function a unique challenge for smaller entities, necessitating a tailored "grassroots" approach.

Key Findings

▶ Watch: Overview of NIST CSF 2.0 Govern function (2:00)

Raveling's talk illuminates several critical findings regarding cybersecurity governance in smaller organizations, particularly when contrasted with their larger counterparts. The fundamental insight is that governance for these entities requires a distinct approach, moving away from top-down mandates to a more iterative, collaborative, and sustainable model.

A primary finding is the prevalent absence of a defined risk appetite within smaller organizations. Without a clear understanding of what level of risk is acceptable, cybersecurity strategies lack direction and prioritization. This often leads to a cybersecurity strategy in a constant state of flux, where efforts are reactive, inconsistent, and prone to abandonment due to changing priorities or perceived "hot" new trends. This fluidity makes it nearly impossible to build long-term, impactful security programs.

Another significant issue is the lack of high-level accountability and ownership. Unlike large organizations where governance bodies have direct influence over bonuses and resource allocation, smaller companies often lack senior leadership engagement in cybersecurity. This absence of executive sponsorship means that cybersecurity initiatives struggle to gain traction, funding, or cross-departmental buy-in. Raveling notes that if the board or investors aren't asking about cybersecurity, there's little prompt for action.

Resource constraints manifest in several ways. Boom-bust budgeting, common in industries with fluctuating revenue, makes it difficult to plan and fund multi-year cybersecurity strategies, leading to inconsistent investment. Furthermore, a high turnover rate among cybersecurity professionals in smaller organizations means constant onboarding and delays in project implementation, further hindering progress.

Raveling also identifies a critical disconnect between IT-led security mindsets and OT operational realities. While IT personnel are adept at the formalities of governance (recording, assessing), they often lack the contextual understanding to evaluate Programmable Logic Controllers (PLCs) or other Industrial Control Systems (ICS) components effectively. Conversely, OT personnel possess the domain knowledge of what to evaluate and how, but may lack the formal governance expertise. This highlights the necessity of a collaborative effort between IT and OT to build effective governance in convergence environments.

Finally, a practical challenge is the frequent failure of products to live up to OT-compatible claims. Organizations invest in solutions marketed for OT environments, only to find they come with "17 asterisks" and don't perform as expected, leading to wasted resources and frustration. This underscores the need for careful evaluation and realistic expectations when adopting new technologies for critical infrastructure.

These findings collectively paint a picture of an environment where traditional governance models are ill-suited. Raveling's emphasis on "grassroots governance" directly addresses these challenges by advocating for pragmatic, relatable, and collaborative efforts that build support from within and leverage external networks to overcome inherent limitations.

Technical Deep Dive

▶ Watch: Governance differences: large vs. small organizations (4:00)

The core of Alan Raveling's talk revolves around the NIST Cybersecurity Framework (CSF) 2.0 and its new Govern function, which he describes as the "glue that pulls it all together" for a cohesive cybersecurity strategy. This function is not merely an add-on but an overarching umbrella that integrates the existing five functions (Identify, Protect, Detect, Respond, Recover), ensuring they operate within a defined strategic context.

Within the Govern category, NIST CSF 2.0 outlines six sub-categories, though Raveling focuses on those most pertinent to smaller organizations and the practical challenges they face. These include:

  1. Organizational Context: This involves understanding the organization's mission, objectives, stakeholders, and the environment in which it operates. For smaller organizations, this often means explicitly defining what their critical assets are, what business processes rely on them, and what the potential impact of a cyber incident would be. Without this foundational understanding, cybersecurity efforts can be misdirected or misaligned with business priorities.
  2. Risk Management Strategy: This sub-category requires establishing and communicating the organization's approach to identifying, assessing, managing, and monitoring cybersecurity risk. Crucially, it involves defining the organization's risk appetite – how much risk it is willing to accept. Raveling highlights that for many smaller entities, this appetite is "unknown or undefined," leading to inconsistent decision-making. A clear strategy provides a framework for prioritizing controls and investments.
  3. Roles and Responsibilities: This area focuses on clearly defining and communicating cybersecurity roles, responsibilities, and authorities across the organization. It's about figuring out "who's actually going to do what and how we're going to gauge that they're actually getting those things done consistently." Raveling notes that in larger organizations, dedicated governance bodies ensure accountability, often through incentive structures (carrots) and penalties (sticks). Smaller organizations must find ways to embed these responsibilities, even without a formal governance department, ensuring that cybersecurity tasks are not left to chance or assumed by overburdened staff.
  4. Policy: This involves establishing and communicating cybersecurity policies that align with the organization's risk management strategy and legal/regulatory requirements. Raveling humorously points out that this often falls into the category of "fun documentation that no one bothers to write that is asked for year after year." However, these policies are crucial for providing a consistent framework for behavior and decision-making. They translate the high-level strategy into actionable guidelines for employees and systems.

Raveling explicitly mentions excluding Supply Chain Risk Management from his detailed discussion, acknowledging it as a complex area that warrants its own dedicated talk, especially for organizations dealing with numerous third parties in sectors like consumer goods and packaging.

A central technical and organizational challenge Raveling addresses is the necessary collaboration between IT and OT personnel in industrial environments. He emphasizes that while IT professionals are essential for the "formalities of a governance program," such as "how to do the recording, how to do the assessing," they often lack the domain-specific knowledge of Operational Technology (OT) systems. Raveling uses the example of an IT person trying to evaluate a Programmable Logic Controller (PLC), noting, "They don't even know what to do." Conversely, OT personnel possess the critical understanding of "what to evaluate and how to evaluate it," but may not be familiar with the structured approach of a formal governance program. Therefore, effective governance in OT environments necessitates a true partnership, bridging these two distinct knowledge domains to create a program that is both formally sound and contextually relevant. This integration ensures that the controls and assessments derived from the Govern function are applicable and effective across the entire technological landscape, from corporate IT networks to critical industrial control systems.

Demo / Proof of Concept

▶ Watch: Practical 'do's and don'ts' for effective governance (7:00)

Alan Raveling's talk, "Govern The Ungovernable - NIST CSF Govern Function," is a strategic and conceptual discussion focused on the principles and practical implementation challenges of cybersecurity governance, particularly for smaller organizations adopting NIST CSF 2.0. As such, the presentation did not include a technical demonstration or a live proof of concept of any specific tools, exploits, or defensive measures. The focus remained on outlining a framework for organizational change and strategic alignment rather than showcasing technical capabilities.

Defensive Implications

▶ Watch: The critical IT/OT collaboration for governance success (7:50)

Raveling's insights offer crucial defensive implications for organizations, especially smaller ones, seeking to mature their cybersecurity posture through effective governance. The core message for defenders is to shift from reactive, product-centric security to a proactive, practice-based, and strategically governed approach.

  1. Prioritize and Align Controls: Defenders should establish a prioritized set of aligned security controls that will form the foundation of their governance program. This means moving beyond a scattergun approach to security solutions and instead focusing on controls that directly address the organization's defined risks and align with its business objectives. This helps prevent being "overwhelmed and panic[ked]" by the sheer volume of potential security measures.
  2. Secure Leadership Buy-in: It is paramount to "get engagement and buy-in from your leadership and management teams as soon as possible." Without high-level ownership, cybersecurity initiatives will lack the necessary resources, authority, and cross-departmental support. Defenders must translate technical risks into business terms that resonate with executives, demonstrating the long-range costs of "comfortable inaction" versus the benefits of proactive investment.
  3. Emphasize Sustainable Efforts: Focus on "sustainable efforts over one-time efforts." Cybersecurity is an ongoing journey, not a destination. This means establishing repeatable processes, continuous monitoring, and regular reviews rather than implementing a solution once and considering the problem solved. For smaller organizations, this also means recognizing that propagating new changes across sites can be a "more than a 12-month journey," requiring patience and persistence.
  4. Foster IT/OT Collaboration: In environments with both IT and OT, defenders must actively build bridges between these traditionally siloed departments. IT personnel can provide expertise in program formalities (recording, assessing), while OT personnel offer critical domain knowledge on "what to evaluate and how to evaluate it" for industrial systems like PLCs. This collaborative effort is essential to ensure that governance programs are both structured and contextually relevant, avoiding the pitfalls of IT-centric approaches that fail in OT.
  5. Communicate for Understanding and Alignment: Defenders should "communicate to seek understanding, alignment, and agreement." This involves making cybersecurity events and information "more relatable" to non-technical stakeholders. Clear, consistent communication helps in building "ground support" and multiplying the security team's voice, fostering a culture of shared responsibility.
  6. Define Risk Appetite and Strategy: Actively work to define the organization's risk appetite and formalize its cybersecurity strategy. An "unknown or undefined" risk appetite leads to inconsistent security decisions. A clear strategy, even if initially simple, provides direction, helps prioritize efforts, and ensures that cybersecurity investments are aligned with the organization's tolerance for risk.
  7. Leverage Peer Networks: "Seek out peers, join industry associations to learn what others are doing or are concerned about." For smaller organizations lacking extensive internal resources, external peer groups offer invaluable insights, shared experiences, and best practices. This can help validate strategies, discover effective solutions, and avoid common pitfalls, making cybersecurity efforts more efficient and effective.

By adopting these principles, defenders in smaller organizations can navigate the complexities of governance, transform their cybersecurity from a series of reactive actions into a strategic imperative, and build a more resilient defense against evolving threats.

Key Takeaways

  • NIST CSF 2.0's Govern function is foundational: The new Govern function is not an optional add-on but an essential, overarching component that integrates and enables all other cybersecurity functions, providing strategic direction and cohesion.
  • Small organizations need a "grassroots" approach to governance: Traditional top-down governance models are often unfeasible for smaller entities due to limited resources, undefined risk appetites, fluctuating strategies, and lack of high-level accountability. A collaborative, sustainable, and pragmatic approach is required.
  • IT/OT collaboration is critical for industrial security governance: Effective governance in OT environments demands a partnership between IT (for program formalities like recording and assessment) and OT (for domain-specific knowledge on what and how to evaluate industrial systems like PLCs).
  • Leadership buy-in and sustainable efforts are paramount: Gaining early engagement from leadership and focusing on consistent, long-term practices rather than one-off initiatives is crucial for establishing and maintaining an effective cybersecurity program.
  • Clear communication and peer networking amplify impact: Making cybersecurity relatable to all stakeholders and actively participating in industry peer groups can build internal support, multiply the security team's voice, and provide valuable external insights for resource-constrained organizations.
  • Define risk appetite and strategy to guide actions: Without a clearly defined risk appetite and a stable cybersecurity strategy, efforts can become fragmented and misaligned. Establishing these foundational elements is key to prioritizing controls and making informed security investments.

About the Speaker(s)

Alan Raveling is a cybersecurity expert who brings a pragmatic and refreshing approach to the complex world of Operational Technology (OT) security. While specific titles or company affiliations were not detailed in the provided transcript, it is evident from his talk that he has extensive experience as a consultant, particularly with clients in the consumer goods and packaging space, dealing with numerous third parties and their associated supply chain risks. His background clearly stems from the OT side of the world, providing him with a deep understanding of industrial control systems and the unique challenges they present. He advocates for bridging the gap between traditional IT security mindsets and OT operational realities, emphasizing collaborative efforts to build effective and sustainable cybersecurity governance programs. His insights are particularly valuable for smaller organizations seeking to implement robust security frameworks.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Alan Raveling's talk on the NIST CSF 2.0 Govern function provides a brutally honest and highly pragmatic roadmap for smaller organizations struggling with cybersecurity governance, especially in OT environments. He meticulously breaks down the challenges of undefined risk appetite, fluctuating strategies, and the critical IT/OT disconnect, offering actionable, 'grassroots' solutions. This isn't theoretical fluff; it's a direct, experience-driven guide to establishing sustainable governance where it's most needed but often overlooked.

Heather Calloway (CISO) — STRONG ACCEPT

Alan Raveling's session on the NIST CSF 2.0 Govern function offers a critical roadmap for smaller organizations to establish sustainable cybersecurity governance. He adeptly translates the framework's strategic intent into actionable, 'grassroots' approaches, acknowledging the unique challenges of resource constraints and the crucial need to bridge IT and OT perspectives. This is not just theoretical; it provides a clear path for defining risk appetite, securing leadership buy-in, and implementing consistent practices that matter for business resilience.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference