This is Part 3 of our series on NIST CSF 2.0. Part 2 covered the Govern function and establishing security leadership.
The Identify function answers fundamental questions that every security program must address: What do we have? What's it worth? What could go wrong? Without these answers, security efforts become unfocused—protecting everything equally (which means protecting nothing adequately) or protecting the wrong things.
What Identify Covers
In CSF 2.0, the Identify function has three categories:
Asset Management (ID.AM) — Inventorying hardware, software, data, and systems. Understanding what exists before trying to protect it.
Risk Assessment (ID.RA) — Evaluating threats, vulnerabilities, and potential impacts. Understanding what could go wrong and how likely it is.
Improvement (ID.IM) — Identifying gaps and opportunities to strengthen your security program based on assessments, incidents, and lessons learned. This category is new in CSF 2.0.
Note: Business Environment, Risk Management Strategy, and Supply Chain Risk Management all moved to the Govern function in CSF 2.0 — covered in Part 2 of this series.
Asset Management: The Foundation
Organizations consistently underestimate how difficult asset management is. The typical environment includes:
- Known, managed devices (relatively easy)
- Shadow IT—devices and applications IT doesn't know about
- Cloud resources spun up by developers and never decommissioned
- Legacy systems that everyone forgot about
- Third-party integrations with access to internal systems
- Data spread across managed and unmanaged locations
Effective asset management requires:
Automated discovery. Manual inventory can't keep up with dynamic environments. Use tools that continuously scan for assets:
- Network scanning (Nmap, Nessus)
- Endpoint detection platforms (CrowdStrike, SentinelOne)
- Cloud security posture management (AWS Config, Azure Policy)
- Configuration management databases (ServiceNow, similar)
Classification. Not all assets are equal. Classify by:
- Criticality to business operations
- Sensitivity of data processed or stored
- Regulatory requirements
- Exposure to threats
Ownership. Every asset should have a designated owner responsible for its security and lifecycle management.
Risk Assessment
Risk assessment connects assets to potential negative outcomes. Key elements:
Threat identification. What could threaten your assets? Consider:
- External attackers (criminals, nation-states, hacktivists)
- Insider threats (malicious or accidental)
- Natural disasters and environmental factors
- Technology failures
Vulnerability analysis. Where are the weaknesses that threats could exploit?
- Technical vulnerabilities (unpatched systems, misconfigurations)
- Process gaps (inadequate access controls, missing monitoring)
- Human factors (susceptibility to social engineering)
Impact assessment. What happens if a threat exploits a vulnerability?
- Financial impact (direct costs, lost revenue, regulatory penalties)
- Operational impact (downtime, disruption)
- Reputational impact (customer trust, brand damage)
- Legal and compliance impact
Likelihood estimation. How probable is the risk scenario? Consider:
- Threat actor motivation and capability
- Vulnerability exploitability
- Existing controls and their effectiveness
Risk prioritization. Combine impact and likelihood to prioritize risks. Focus resources on high-impact, high-likelihood scenarios first.
Practical Risk Assessment Approaches
Qualitative assessment uses categories (High/Medium/Low) rather than precise numbers. It's faster and easier to communicate but less precise.
Quantitative assessment uses numerical estimates for likelihood and impact. Frameworks like FAIR (Factor Analysis of Information Risk) provide structured approaches. More precise but requires more data and expertise.
For most organizations, a hybrid approach works best—qualitative for initial prioritization, with quantitative analysis for major decisions or high-stakes risks.
Supply Chain Risk Management sits in the Govern function (GV.SC) in CSF 2.0, not Identify—covered in Part 2 of this series. The vendor questions above (access scope, security posture, compromise impact, continuity) belong in that context.
Common Failures in Identify
Incomplete asset inventory. Focusing only on IT-managed assets while ignoring shadow IT, cloud resources, and third-party integrations.
Static assessment. Treating risk assessment as a one-time exercise rather than continuous activity. Environments change; assessments must keep pace.
Ignoring business context. Technical risk assessment without understanding business impact leads to misallocated resources.
Analysis paralysis. Spending so much time on assessment that action never happens. Good enough now is better than perfect never.
Isolated effort. Risk assessment without input from business units misses critical context about asset importance and risk tolerance.
Getting Started
Start with your crown jewels—most critical assets and sensitive data first, then expand. Get automated discovery running so you're not maintaining a spreadsheet. Assign an owner to every critical asset. Use a simple risk framework to begin; add sophistication once you're actually using it. Most importantly: make it continuous. Annual risk assessments are snapshots of a world that changed eleven months ago.
Next in the Series
Part 4 covers the Protect function—implementing controls to safeguard critical assets based on what you've identified.
Need help with asset discovery, risk assessment, or building an Identify program? Our security assessments and GRC Advisory services provide the foundation for effective security programs. Let's talk.
