Auditen
Home / Frameworks / NIST CSF 2.0 / The Identify function
NIST CSF 2.0 · ID

The Identify function

The Identify function requires an organization to develop a comprehensive understanding of its cybersecurity risk landscape. It focuses on identifying the assets, systems, data, and capabilities that must be protected, as well as the business context and governance structures used to manage those risks.

What it means

In practice, the Identify function serves as the foundation for all other NIST CSF functions. You cannot protect or detect threats against assets you do not know exist; therefore, this function is primarily about visibility and documentation. It shifts security from a reactive "firefighting" mode to a proactive risk-management strategy.

The scope extends beyond just hardware. It includes software applications, cloud services, third-party dependencies (supply chain), and the people who operate these systems. It also requires defining the organizational "risk appetite"—deciding which risks are acceptable and which must be mitigated immediately based on business impact.

Finally, this function integrates governance into security. This means establishing clear policies, assigning accountability for specific assets, and ensuring that cybersecurity goals are aligned with the overall mission of the organization.

How to meet it

Evidence an auditor asks for

  • An Asset Inventory (CMDB) showing hardware, software, and ownership details.
  • A Risk Register documenting identified risks, likelihood/impact scores, and planned mitigation actions.
  • Documented cybersecurity policies and governance frameworks approved by senior management.
  • Network diagrams or data flow maps that illustrate how critical information moves through the environment.

Common pitfalls

  • Relying on static spreadsheets for asset tracking that are outdated as soon as they are saved.
  • Treating risk assessment as a one-time annual event rather than a continuous process integrated into change management.
  • Overlooking "Shadow IT," such as unauthorized cloud applications or personal devices used for business purposes.