Quick answer

The IDENTIFY Function helps an organization build and maintain an accurate understanding of its assets, suppliers, dependencies, vulnerabilities, threats, and current cybersecurity risk. In NIST CSF 2.0, it follows GOVERN and contains three Categories: Asset Management (ID.AM), Risk Assessment (ID.RA), and Improvement (ID.IM). Its purpose is to turn visibility into risk-based priorities across the other CSF Functions.

Who should read this

This guide is for CISOs, IT leaders, risk and compliance teams, business continuity professionals, and executives who need to understand what the IDENTIFY Function asks an organization to know before it can make defensible cybersecurity decisions.

In this guide

What IDENTIFY means Asset Management Risk Assessment Improvement 2026 update Checklist FAQs

What is the IDENTIFY Function?

IDENTIFY is the second of the six Functions in the NIST Cybersecurity Framework 2.0. It follows GOVERN, which establishes organizational context, strategy, accountability, policy, and risk oversight.

If GOVERN defines how the organization will make cybersecurity decisions, IDENTIFY provides the information those decisions require. It asks the organization to understand what it has, what matters most, what could threaten it, where meaningful weaknesses exist, and what needs to improve.

Cybersecurity teams often say, “You cannot protect what you do not know you have.” That is true, but IDENTIFY goes further. An inventory is only the starting point. The organization must connect each important asset to its business purpose, owner, data, dependencies, criticality, threats, vulnerabilities, and potential operational impact.

The three Categories of IDENTIFY

ID.AM

Asset Management

Primary question: What do we have, where is it, who owns it, and why does it matter?

Practical outcome: A current, risk-ranked view of assets, services, data, and dependencies.

ID.RA

Risk Assessment

Primary question: What could happen, how likely is it, and what would the impact be?

Practical outcome: Risk decisions based on threats, vulnerabilities, likelihood, and business impact.

ID.IM

Improvement

Primary question: What have we learned, and what needs to change?

Practical outcome: A repeatable process for turning assessments, tests, incidents, and operations into measurable improvements.

ID.AM

Asset Management: know the environment that supports the business

Asset Management covers the hardware, software, systems, services, facilities, people, and data that enable the organization to operate. Those assets must be identified and managed according to their importance to organizational objectives and the organization’s risk strategy.

This Category goes well beyond maintaining a device spreadsheet. A useful asset record should explain what the asset does, who is responsible for it, what information it stores or processes, which business service it supports, what it depends on, and how damaging its loss or compromise would be.

A defensible asset-management program should account for:

  • Company-managed and externally hosted hardware, including endpoints, servers, mobile devices, network equipment, operational technology, and connected devices.
  • Software, applications, platforms, cloud infrastructure, SaaS products, and other technology services.
  • Authorized network communications and internal and external data flows.
  • Services delivered by suppliers, managed service providers, cloud providers, and other third parties.
  • Designated data types and their associated metadata, location, ownership, sensitivity, retention, and movement.
  • Asset classification, business criticality, dependencies, mission impact, and lifecycle status.

Where organizations commonly fall short

Our experience is that most organizations perform some parts of asset management well, but few perform all of them consistently. We may see a reliable hardware inventory with no corresponding software inventory, or a server list that never explains the business purpose of each system. Cloud services may be tracked by procurement but not by security. Supplier dependencies may live only in contracts. Data inventories and current data-flow diagrams remain an especially common gap.

Discovery is another problem. If an organization relies only on manually entered records, the inventory begins aging as soon as it is completed. Remote devices, temporary cloud resources, abandoned systems, unauthorized SaaS, and shadow IT can all create blind spots.

NIST’s updated incident-response guidance reinforces the value of current, preferably automatically maintained inventories. The purpose is not merely administrative accuracy. Responders need reliable asset and dependency information to scope incidents, find related exposure, understand business impact, and prioritize containment and recovery.

ID.RA

Risk Assessment: turn technical findings into business decisions

Risk Assessment is where the organization develops an informed view of cybersecurity risk to the business, its assets, and affected individuals. It includes identifying and validating vulnerabilities, receiving threat intelligence, documenting relevant internal and external threats, analyzing likelihood and impact, selecting risk responses, and tracking those decisions.

NIST CSF 2.0 separates Risk Management Strategy, which sits under GOVERN, from Risk Assessment, which remains under IDENTIFY. The distinction is useful: GOVERN establishes how the organization defines, communicates, and oversees risk, while IDENTIFY applies that direction to actual threats, vulnerabilities, assets, suppliers, changes, and exceptions.

Important distinction

A vulnerability is not the same thing as risk

A vulnerability scan can identify a technical weakness. Risk analysis asks whether that weakness is realistically exploitable, what asset and business process it affects, what existing controls reduce the exposure, how likely exploitation is, and what the resulting operational, financial, legal, safety, or reputational impact could be. Without that context, a long list of findings is not a risk-management program.

Does NIST CSF 2.0 require a Business Impact Analysis?

ID.RA-04 calls for potential impacts and the likelihood of threats exploiting vulnerabilities to be identified and recorded. It does not prescribe a specific Business Impact Analysis methodology. However, a BIA is one effective way to identify critical processes, high-value assets, recovery dependencies, and the potential impact of disruption.

NIST’s 2026 guidance explicitly positions the BIA as an input to scoping an Organizational Profile and prioritizing assets. In practice, the BIA and cybersecurity risk assessment should inform each other. The BIA identifies what the business cannot afford to lose; the risk assessment evaluates what could cause that loss and how the organization should respond.

Risk Assessment also extends beyond vulnerability management. Organizations should account for changes and exceptions, processes for receiving vulnerability disclosures, the authenticity and integrity of hardware and software before acquisition, and the risk presented by critical suppliers before entering the relationship.

ID.IM

Improvement: make lessons learned produce change

Improvement ensures that evaluations, testing, exercises, incidents, third-party activity, and everyday operations lead to changes across the cybersecurity program. It is the feedback loop connecting IDENTIFY to all six CSF Functions.

Useful improvement opportunities may come from framework assessments, internal audits, penetration tests, tabletop exercises, control testing, incident reviews, supplier exercises, vulnerability trends, operational failures, and changes to the business or threat landscape.

Improvement is not complete until the organization:

  1. Documents the lesson, deficiency, or changed condition.
  2. Evaluates its risk and business significance.
  3. Assigns an accountable owner and target date.
  4. Updates the relevant plan, process, architecture, or control.
  5. Validates that the change produced the intended result.
  6. Feeds the result back into the organization’s risk view and CSF Profile.

ID.IM-04 also calls for incident response and other cybersecurity plans affecting operations to be established, communicated, maintained, and improved. That may initially feel more appropriate under RESPOND, but the placement makes sense: an organization cannot systematically improve a plan that has never been defined, exercised, or owned.

Continuous improvement takes sustained attention. Organizations that treat an assessment as a one-time event often recreate the same gaps the following year. Mature programs maintain a living backlog, prioritize changes according to risk, and verify that completed work actually reduced exposure.

Current guidance

What IDENTIFY means in practice in 2026

The CSF 2.0 Core has not changed the three IDENTIFY Categories, but NIST’s newer supporting publications add useful implementation context. The message is clear: IDENTIFY should operate as a continuously refreshed business capability, not an annual inventory exercise.

Modern inventories need to include cloud and SaaS services, supplier-provided services, remote assets, temporary infrastructure, shadow IT, and emerging technologies such as AI platforms, models, datasets, and automation services when they are used within the organization. Visibility should be reconciled across technical discovery tools, procurement records, identity platforms, contracts, configuration repositories, and data-governance processes.

NIST also continues to strengthen the connection between cybersecurity risk management and enterprise risk management. Cybersecurity risk should be described in terms business leaders can compare with other enterprise risks, including operational disruption, financial loss, legal or regulatory exposure, safety, customer impact, and strategic consequences.

Workforce capability belongs in that discussion as well. If an organization identifies a critical outcome but lacks the people, skills, authority, or third-party support required to achieve it, that capability gap is itself a risk requiring a decision.

Practical IDENTIFY checklist

Use these questions to pressure-test whether the Function is operating effectively:

01. Can we automatically discover and reconcile the assets operating across our internal, remote, cloud, and externally hosted environments?

02. Does each important asset have a business owner, technical owner, purpose, classification, criticality, and lifecycle status?

03. Do we know which sensitive data types we hold, where they reside, how they move, and who can access them?

04. Are cloud, SaaS, managed services, and critical supplier dependencies represented in our inventory and risk process?

05. Can we connect vulnerabilities and threats to actual business services, data, dependencies, likelihood, and impact?

06. Are risk responses documented, prioritized, assigned, tracked, and communicated to the right decision-makers?

07. Do assessments, incidents, tests, exercises, and operational experience generate owned and measurable improvements?

08. Could incident responders use our inventories and dependency maps today without first rebuilding them?

The bottom line

IDENTIFY creates the operational picture that the rest of the cybersecurity program depends on. If the organization does not know what it has, what matters, where data moves, which suppliers it relies on, and how threats could affect the business, its security investments will be driven by assumptions.

A strong IDENTIFY capability replaces those assumptions with evidence. That evidence allows the organization to apply safeguards under PROTECT, focus monitoring under DETECT, make faster decisions during RESPOND, and restore the right operations first under RECOVER.

Frequently asked questions

NIST CSF 2.0 IDENTIFY FAQs

What is the IDENTIFY Function in NIST CSF 2.0?

IDENTIFY is the Function used to understand the organization’s current cybersecurity risks. It connects knowledge of assets, data, services, suppliers, threats, vulnerabilities, likelihood, impact, and improvement opportunities to risk-based decisions.

What are the three Categories within IDENTIFY?

The three Categories are Asset Management (ID.AM), Risk Assessment (ID.RA), and Improvement (ID.IM).

Does IDENTIFY include cloud services and third parties?

Yes. Asset Management includes services provided by suppliers, while Risk Assessment includes evaluating critical suppliers before acquisition. Cloud infrastructure, SaaS products, managed services, and external data flows should be represented when they support the organization.

Does NIST CSF 2.0 require a Business Impact Analysis?

The IDENTIFY Function requires organizations to understand and record potential impact and likelihood, but it does not prescribe one specific BIA methodology. A Business Impact Analysis is a strong supporting practice for identifying critical processes, high-value assets, dependencies, and the consequences of disruption.

How often should asset inventories and risk assessments be updated?

They should be updated whenever the environment or risk context changes and reviewed on a defined schedule. High-change environments should use automated discovery and continuous reconciliation rather than depending on an annual manual inventory.

What is the difference between vulnerability management and Risk Assessment?

Vulnerability management identifies and addresses weaknesses. Risk Assessment adds threat relevance, exploitability, business criticality, existing controls, likelihood, impact, and available response options so the organization can decide what deserves priority.

Achieve Better Cybersecurity

Know what matters before it becomes an incident.

SEVN-X Framework Assessments turn NIST CSF 2.0 outcomes into a clear view of your current posture, prioritized risk, and a practical remediation roadmap built for your organization.

Explore Framework Assessments

You may also like

NIST Cybersecurity Framework 2.0: Govern | 2026 Updated
NIST Cybersecurity Framework 2.0: Govern | 2026 Updated
21 January, 2025

Quick answer The GOVERN Function establishes how an organization makes, communicates, and oversees cybersecurity risk de...

NIST Cybersecurity Framework 2.0: Protect | 2026 Update
NIST Cybersecurity Framework 2.0: Protect | 2026 Update
21 January, 2025

Quick answer The PROTECT Function applies safeguards to reduce the likelihood and impact of cybersecurity events. In NIS...