---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Identify the core framework

# Identify the framework core {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Within the NIST CSF
application, the Framework Core section is used to identify categories and
subcategories as cybersecurity policies and their statement policies.

The application uses categories to define cybersecurity activities for targets and uses
subcategories to evaluate cybersecurity requirements to provide additional details on compliance.  
With NIST CSF guidance, the application groups categories and subcategories into functions and represent them as activities. The NIST CSF uses the following five modules to designate individual functions:

* Identify
* Protect
* Detect
* Respond
* Recover
* Govern
{#identify-framework-core__ul_ghd_2r5_phb}

Each module points to a grouping of policy and control objectives that relates to that
function.
* **[Review the framework core](https://servicenow-prod.fluidtopics.net/l1OVnk6jLf1VbSuedqcuuA)**   
  Review the Framework Core that's activated with the NIST CSF application.

