We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

NIST CSF 2.0 · Function 2 of 6

Identify (ID): what it demands and how it is evidenced

You cannot protect what you have not enumerated. Identify holds asset management, risk assessment and — new emphasis in 2.0 — improvement. Its quality decides whether every downstream function operates on reality or on an outdated spreadsheet.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the CSF 2.0 series · CSF is voluntary guidance — we build profiles, not certificates

The categories inside Identify

ID.AM
Asset management

Hardware, software, services, data and their flows inventoried and prioritised by criticality — including the cloud and SaaS estate that shadow IT grows.

ID.RA
Risk assessment

Vulnerabilities and threats identified, likelihood and impact analysed, risk responses chosen and tracked — with intelligence feeding it.

ID.IM
Improvement

Lessons from assessments, tests, incidents and exercises drive improvement plans — the category that turns findings into change.

Category identifiers reference NIST CSF 2.0 (26 February 2024) — nist.gov/cyberframework.

Where profiles fall short

The inventory is the CMDB nobody trusts

ID.AM evidence is a reconciled inventory — discovery scans vs records vs finance — not a stale export. Unknown assets void downstream controls.

Risk register without owners or movement

ID.RA expects risks with owners, responses and review dates; a register whose entries have not changed in a year documents a process that stopped.

Data flows undocumented

2.0 emphasises data and its flows (ID.AM); DPDP and sectoral rules ask for the same map — one exercise serves both.

Evidence that holds up

  • Asset inventory with criticality and reconciliation evidence (ID.AM)
  • Data-flow documentation for critical processes
  • Risk assessment method, register with owners/responses/reviews (ID.RA)
  • Improvement backlog traced from incidents/tests to completed change (ID.IM)

Identify FAQ

How detailed must the asset inventory be?

Proportional to risk: complete enough that protection, detection and response decisions can rely on it — hardware, software, services and data with owners and criticality, reconciled periodically against discovery.

Where did "Improvement" come from?

CSF 2.0 gave improvement its own category (ID.IM), consolidating lessons-learned expectations so that assessments and incidents demonstrably change the programme.

Does Identify cover third parties?

Third-party risk strategy lives in GV.SC; Identify covers knowing which suppliers, services and data flows exist and assessing the risks they create (ID.AM/ID.RA).

Govern (GV)Protect (PR)

Your CSF 2.0 profile, built properly

Current and target profiles, gap analysis, and a prioritised roadmap that maps onto the ISO 27001, SOC 2 or SEBI CSCRF work you may already owe — kept current on SigmaTrust.