The Identify function
The Identify function requires an organization to develop a comprehensive understanding of its cybersecurity risk landscape. It focuses on identifying the assets, systems, data, and capabilities that must be protected, as well as the business context and governance structures used to manage those risks.
What it means
In practice, the Identify function serves as the foundation for all other NIST CSF functions. You cannot protect or detect threats against assets you do not know exist; therefore, this function is primarily about visibility and documentation. It shifts security from a reactive "firefighting" mode to a proactive risk-management strategy.
The scope extends beyond just hardware. It includes software applications, cloud services, third-party dependencies (supply chain), and the people who operate these systems. It also requires defining the organizational "risk appetite"—deciding which risks are acceptable and which must be mitigated immediately based on business impact.
Finally, this function integrates governance into security. This means establishing clear policies, assigning accountability for specific assets, and ensuring that cybersecurity goals are aligned with the overall mission of the organization.
How to meet it
- Maintain a centralized inventory of all physical and virtual hardware, software licenses, and cloud instances.
- Classify data based on sensitivity and criticality to ensure protection efforts are prioritized correctly.
- Document business processes and map them to the specific technical assets that support those functions.
- Establish a formal risk management process to identify threats, assess vulnerabilities, and determine potential impacts.
- Define clear cybersecurity roles and responsibilities within an organizational chart or governance charter.
- Create a registry of third-party vendors and service providers, including the data they access and their security requirements.
Evidence an auditor asks for
- An Asset Inventory (CMDB) showing hardware, software, and ownership details.
- A Risk Register documenting identified risks, likelihood/impact scores, and planned mitigation actions.
- Documented cybersecurity policies and governance frameworks approved by senior management.
- Network diagrams or data flow maps that illustrate how critical information moves through the environment.
Common pitfalls
- Relying on static spreadsheets for asset tracking that are outdated as soon as they are saved.
- Treating risk assessment as a one-time annual event rather than a continuous process integrated into change management.
- Overlooking "Shadow IT," such as unauthorized cloud applications or personal devices used for business purposes.