---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Identify the core framework

# Identify the framework core {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Within the NIST CSF
application, the Framework Core section is used to identify categories and
subcategories as cybersecurity policies and their statement policies.

The application uses categories to define cybersecurity activities for targets and uses
subcategories to evaluate cybersecurity requirements to provide additional details on compliance.  
With NIST CSF guidance, the application groups categories and subcategories into functions and represent them as activities. The NIST CSF uses the following five modules to designate individual functions:

* Identify
* Protect
* Detect
* Respond
* Recover
* Govern
{#identify-framework-core__ul_ghd_2r5_phb}

Each module points to a grouping of policy and control objectives that relates to that
function.
* **[Review the framework core](https://servicenow-prod.fluidtopics.net/i2wJcdT6WQzw0UOLBlz58w)**   
  Review the Framework Core that's activated with the NIST CSF application.

