---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Process overview

# NIST CSF process overview {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The NIST CSF navigation structure facilitates the management of the NIST cybersecurity through activities of identification and prioritization, as described in the NIST Framework for Improving Critical
Infrastructure Cybersecurity version 1.1 and version 2.0 special publications.

## NIST CSF process
overview {#nist-csf-process__section_hvl_3gd_qhb}

1. The risk executives and/or the security officers identify categories and subcategories as cybersecurity policies.
2. The risk executives and/or the security officers prioritize cybersecurity activities.
3. Monitor the NIST CSF Overview dashboard
{#nist-csf-process__ol_pgf_jgd_qhb}
* **[Identify the framework core](https://servicenow-prod.fluidtopics.net/oBMaKAERFn4W9QS31SxEow)**   
  Within the NIST CSF application, the Framework Core section is used to identify categories and subcategories as cybersecurity policies and their statement policies.
* **[Align and prioritize cybersecurity activities](https://servicenow-prod.fluidtopics.net/hKF1cC_4p8FzgBg0hbUO9w)**   
  Within the NIST CSF application, the Framework Profiling section is used to help an organization to align and prioritize its cybersecurity activities with its requirements, risk tolerances, and resources.

