Identify (ID): what it demands and how it is evidenced
You cannot protect what you have not enumerated. Identify holds asset management, risk assessment and — new emphasis in 2.0 — improvement. Its quality decides whether every downstream function operates on reality or on an outdated spreadsheet.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the CSF 2.0 series · CSF is voluntary guidance — we build profiles, not certificates
The categories inside Identify
Category identifiers reference NIST CSF 2.0 (26 February 2024) — nist.gov/cyberframework.
Where profiles fall short
ID.AM evidence is a reconciled inventory — discovery scans vs records vs finance — not a stale export. Unknown assets void downstream controls.
ID.RA expects risks with owners, responses and review dates; a register whose entries have not changed in a year documents a process that stopped.
2.0 emphasises data and its flows (ID.AM); DPDP and sectoral rules ask for the same map — one exercise serves both.
Evidence that holds up
- Asset inventory with criticality and reconciliation evidence (ID.AM)
- Data-flow documentation for critical processes
- Risk assessment method, register with owners/responses/reviews (ID.RA)
- Improvement backlog traced from incidents/tests to completed change (ID.IM)
Identify FAQ
How detailed must the asset inventory be?
Proportional to risk: complete enough that protection, detection and response decisions can rely on it — hardware, software, services and data with owners and criticality, reconciled periodically against discovery.
Where did "Improvement" come from?
CSF 2.0 gave improvement its own category (ID.IM), consolidating lessons-learned expectations so that assessments and incidents demonstrably change the programme.
Does Identify cover third parties?
Third-party risk strategy lives in GV.SC; Identify covers knowing which suppliers, services and data flows exist and assessing the risks they create (ID.AM/ID.RA).
Your CSF 2.0 profile, built properly
Current and target profiles, gap analysis, and a prioritised roadmap that maps onto the ISO 27001, SOC 2 or SEBI CSCRF work you may already owe — kept current on SigmaTrust.
