OpenFrame Gen1 is Here

Cyber insurers renewing policies in 2026 are asking applicants to map their controls to NIST CSF 2.0 or an equivalent, and the section they read hardest is governance. That's awkward if your IT governance framework lives in a slide deck nobody has opened since the last audit. The standard guidance on this topic hands you a roster of seven frameworks and leaves the picking to you. This goes the other way: choose the governance layer first, then fit the operational frameworks underneath it. That layer is the Govern function in NIST CSF 2.0, and it's the shortest route from nothing to something an underwriter will accept.

TL;DR

QuestionShort answer
What is an IT governance framework?A documented structure that assigns decision rights, policy ownership, and oversight for technology, kept separate from the day to day management of it.
Which one should you start with?The Govern function in NIST CSF 2.0. Six categories, plain language, and the vocabulary auditors and underwriters already use.
What do COBIT and ITIL do then?They sit underneath. COBIT supplies auditable process detail, ITIL 4 runs service delivery, ISO/IEC 38500 handles board level direction.
What's the first artifact?A one page decision rights table naming who approves risk acceptance, policy exceptions, and vendor onboarding.
Why does this matter commercially?Carriers, prime contractors, and enterprise buyers increasingly ask for governance evidence before they ask for control evidence.
How long to something usable?90 days to a defensible v1 if you write artifacts instead of strategy documents.

What an IT Governance Framework Is

An IT governance framework answers one question in writing: who gets to decide what about technology, and how does anyone know the decisions are being followed. It's a structure of decision rights, policies, and oversight loops. It is not a project plan, a control checklist, or a tool.

The cleanest statement of the split comes from ISO/IEC 38500, the international standard for board level governance of information technology. Governance evaluates, directs, and monitors. Management plans, builds, runs, and reports. A CIO deciding to migrate to Intune is management. The written rule that says migrations above a certain spend need executive sign off, and the quarterly review that checks whether that rule was followed, is governance.

That distinction is where most governance work falls apart in smaller organizations. A 40 seat accounting firm has no board, no CIO, and no governance committee. Its IT decisions get made in a hallway by whoever noticed the problem first. The framework's job is not to invent a bureaucracy that company can't staff. It's to write down the three or four decisions that carry real consequence and name a human for each one.

For anyone running IT on behalf of clients, the framework does a second job. It draws the line between what the provider decides and what the client decides. Ambiguity there is the most common failure mode in co-managed arrangements: alerts go unacknowledged because both sides assumed the other owned them.

Why NIST CSF 2.0 Changed the Starting Point

NIST published Cybersecurity Framework 2.0 on February 26, 2024. The headline change was structural. Where version 1.1 had five functions, 2.0 has six: Govern, Identify, Protect, Detect, Respond, Recover, spread across 22 categories and 106 subcategories. Govern is the new one, and it doesn't sit alongside the other five. It sits underneath them and feeds them.

The scope also widened. Version 1.1 was written for critical infrastructure. Version 2.0 is written for everyone, which is why it reads more plainly than COBIT and costs nothing to obtain.

Cherilyn Pascoe, director of NIST's National Cybersecurity Center of Excellence, framed the shift this way in NIST's release announcement: "The CSF has always been intended to be used from the server room to the boardroom, and as server rooms are now no longer on-prem, the boardroom becomes even more important." Kevin Stine, chief of NIST's Applied Cybersecurity Division, described the 2.0 update as an effort to make the framework relevant to a much wider set of users in the United States and abroad.

Cybersecurity Dive's coverage put the practical consequence bluntly: NIST made governance a formal, first class part of cybersecurity rather than an assumed prerequisite. That matters for procurement. Once governance has its own function identifier, a questionnaire can ask for it by name.

The reason to start here rather than with COBIT is availability and vocabulary. CSF 2.0 is free, it's roughly 30 pages of readable outcomes rather than several hundred pages of process reference, and the six function names are already the shared language on insurance applications and vendor security questionnaires. Building governance in a vocabulary your counterparties don't recognize means translating it later.

The Six Govern Categories, Translated

Govern breaks into six categories. Each one maps to a question a client executive can answer and an artifact you can produce.

CategoryThe question it answersFirst artifact to produce
GV.OC, Organizational ContextWhat does this business do, who depends on it, and which laws and contracts bind it?A one page context statement listing regulated data types, contractual security obligations, and critical services.
GV.RM, Risk Management StrategyHow much risk is acceptable, and who says so?A written risk appetite statement with named thresholds for downtime, data loss, and unpatched exposure.
GV.RR, Roles, Responsibilities, AuthoritiesWho owns each cybersecurity outcome, from the top down?A decision rights table naming an accountable person per outcome, not a department.
GV.PO, PolicyWhich policies exist, who approves them, and when are they reviewed?A policy register with owner, approval date, and next review date per policy.
GV.OV, OversightIs the program producing the outcomes it promised, and how do we know?A quarterly review agenda with three to five metrics tied to the risk appetite statement.
GV.SC, Supply Chain Risk ManagementWhich third parties can hurt us, and what do we require of them?A tiered vendor inventory with security requirements attached per tier.

Read down the artifact column and you have the deliverable list for a first governance build. Six documents, none longer than two pages. That's a very different scope from what "roll out an IT governance framework" usually implies.

GV.SC deserves extra attention because it's the category most often skipped and the one auditors probe hardest. A tiered vendor inventory is the entry point, and the mechanics of building one are covered in more depth in our guide to vendor risk management for MSPs.

How the Major Frameworks Fit Together

Framework selection gets presented as a competition. It isn't. These things stack, and the useful question is which layer each one occupies.

FrameworkWhat it governsWhere it plugs into GovernEffort to adopt
NIST CSF 2.0Cyber risk outcomes across six functionsIs the governance layer. Start here.Low. Free, ~30 pages, no certification body.
ISO/IEC 38500Board level direction of IT, via evaluate, direct, monitorSharpens GV.OV and GV.RR for organizations that have a boardLow, but abstract. Principles, no controls.
COBIT 2019End to end enterprise IT, governance and management objectivesSupplies auditable process detail under every GV categoryHigh. Large reference model, training oriented.
ITIL 4Service delivery, incident, change, problemOperationalizes policy set in GV.POMedium. Well known to service desk teams.
ISO/IEC 27001Information security management systemProvides certifiable evidence for GV.PO and GV.OVHigh. Audit, surveillance, real cost.
COSOEnterprise risk and internal control, finance ledAligns GV.RM with the language finance and audit committees useMedium. Familiar to CFOs, less so to IT.
FAIRQuantified cyber risk in financial termsTurns GV.RM's risk appetite into dollar figuresMedium to high. Needs data and a trained analyst.

The pattern: CSF 2.0 sets direction, ITIL 4 and COBIT do the work, ISO 27001 supplies the certificate when a contract demands one, and FAIR converts the whole thing into numbers a CFO will argue with. Picking all of them at once is how governance projects die. Picking CSF 2.0 and one operational partner is how they ship.

For a wider survey of the frameworks in this table, including the compliance regimes that sit next to them, see our cybersecurity frameworks list. That post catalogs the landscape. This one is about the decision layer, so treat them as companions rather than substitutes.

Who Decides What in a Co-Managed Setup

Governance in a provider relationship fails on ambiguity, not on absence. Both parties usually have opinions about security. Neither has written down who signs.

A decision rights table fixes that in one page. The version below maps to GV.RR and covers the decisions that carry consequence in a typical co-managed arrangement.

DecisionClient executiveProvider vCIOProvider technicianEvidence produced
Accept a documented riskAccountable, signsRecommends and quantifiesReports the findingSigned risk acceptance record
Grant a policy exceptionApproves above thresholdApproves routine exceptionsRequestsDated exception with expiry
Onboard a new SaaS vendorApproves for tier 1 and 2Reviews and tiersFlags discoveryVendor tier record
Emergency change during an incidentInformed afterConsulted if reachableExecutes, documents within 24 hoursChange record with justification
Deviate from the patch windowApproves for production serversApproves for endpointsRequestsPatch deviation log

The point of the evidence column is that governance is only real if it leaves a trail. An underwriter reviewing a claim, or an auditor sampling controls, doesn't want to hear that risk acceptance happens. They want five signed records from the last twelve months.

The other thing this table exposes is discovery. Nobody can approve vendor onboarding for tools they can't see, which is why unsanctioned SaaS quietly breaks GV.OC and GV.SC at the same time. Our write up on how providers find, price, and fix shadow IT covers the discovery side of that problem.

The Insurance and Procurement Payoff

Governance work is hard to fund because the benefit sounds abstract. In 2026 it stopped being abstract.

Carriers writing and renewing cyber policies now commonly ask applicants to map controls against CSF 2.0 or an equivalent framework. The six function names give underwriters and brokers a structure they recognize, which makes a submission faster to evaluate. Govern specifically gives finance and security leaders a way to show board level ownership, and that's the evidence carriers look for on larger or higher limit applications.

Procurement follows the same pattern. Enterprise buyers and prime contractors increasingly send security questionnaires organized around framework functions. Answering "we follow NIST CSF 2.0, here is our Govern evidence pack" beats assembling ad hoc responses for every questionnaire that arrives.

There's a defensive angle too. After an incident, the question shifts from what controls existed to who was responsible for deciding they were sufficient. A dated risk acceptance record signed by a named executive is a materially different position than a shrug.

Your First 90 Days

Sequence matters more than completeness. Build in this order and each artifact feeds the next.

  1. Days 1 to 30, context and roles. Write the GV.OC context statement and the GV.RR decision rights table. These two are prerequisites for everything else, and both are interviews rather than research. Two hours with the client executive gets you most of the way.
  2. Days 31 to 60, risk and policy. Convert the context statement into a GV.RM risk appetite statement with numeric thresholds, then build the GV.PO policy register. Register existing policies as they are, including gaps. An honest register beats an aspirational one.
  3. Days 61 to 90, oversight and supply chain. Set the GV.OV quarterly review agenda with three to five metrics, run the first review, and produce the GV.SC tiered vendor inventory. The first review is the point where governance becomes a habit instead of a document.

Anything not on that list, including maturity tier assessments, control mappings, and framework crosswalks, waits until v1 exists and has survived one oversight cycle.

Where Governance Programs Stall

Three patterns account for most of the failures.

The first is writing strategy instead of artifacts. A 30 page governance charter that names no individuals and produces no records satisfies nobody. If a document doesn't create evidence, it isn't governance.

The second is oversight without data. GV.OV asks whether the program is delivering its promised outcomes. Answering that requires pulling patch compliance, backup verification, and identity hygiene numbers from wherever they live. When those numbers sit in six disconnected consoles with different reporting periods, the quarterly review turns into a data gathering exercise and gets skipped by the third quarter. This is a stack problem wearing a governance costume.

The third is treating the framework as a one time project. CSF 2.0 profiles are meant to be revisited as the business changes. A governance package built once and never reopened is a snapshot of a company that no longer exists.

Picking the Framework That Fits

If you need a defensible governance layer and don't have one, start with CSF 2.0 Govern. If a contract requires a certificate, add ISO/IEC 27001 and keep CSF as the internal structure. If auditors need process level detail, layer COBIT 2019 beneath the categories you've already defined. If the service desk is the weak point, ITIL 4 addresses delivery, not governance, so it complements rather than replaces this work.

The tooling question is separate but connected. Govern's oversight category is only as good as the reporting underneath it, and a fragmented stack makes quarterly metrics expensive to produce. That's part of the argument for consolidation: OpenFrame is an AI-native all-in-one MSP and IT platform with native PSA included, built to keep RMM, ticketing, and reporting in one place without vendor lock-in, which makes the GV.OV numbers a query rather than a scavenger hunt. It won't write your risk appetite statement. It will stop the quarterly review from being the reason governance dies.

Governance isn't a document you produce. It's the record you can hand someone twelve months later when they ask who decided, and when, and on what basis. Start with the six artifacts. Everything else is commentary.

Kristina Shkriabina

Marketing Manager

Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

IT Governance

An IT governance framework is a documented structure that assigns decision rights, policy ownership, and oversight for technology. It defines who approves risk acceptance, exceptions, and vendor onboarding, and how those decisions get recorded. Governance directs and monitors; management plans, builds, and runs.
Govern contains GV.OC organizational context, GV.RM risk management strategy, GV.RR roles and responsibilities, GV.PO policy, GV.OV oversight, and GV.SC cybersecurity supply chain risk management. Each maps to one artifact: a context statement, risk appetite statement, decision rights table, policy register, review agenda, and vendor inventory.
Governance evaluates, directs, and monitors; management plans, builds, runs, and reports. Deciding to migrate to Intune is management. The written rule requiring executive sign off above a spend threshold, plus the quarterly review checking that rule was followed, is governance. ISO/IEC 38500 draws this line.
Start with the Govern function in NIST CSF 2.0. It is free, roughly 30 pages, and written in plain outcomes rather than process reference. Its six function names are already the vocabulary on cyber insurance applications and vendor security questionnaires, so nothing needs translating later.
No. They stack underneath it. COBIT 2019 supplies auditable process detail beneath each Govern category, and ITIL 4 operationalizes the policies set in GV.PO. ISO/IEC 27001 adds a certificate when a contract requires one. CSF 2.0 stays the direction setting layer.
About 90 days to a defensible first version. Days 1 to 30 cover organizational context and decision rights, days 31 to 60 cover risk appetite and the policy register, days 61 to 90 cover the first oversight review and a tiered vendor inventory.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.