ID 21 subcategories · 3 categories

NIST CSF 2.0 Identify (ID)

Identify covers asset management, risk assessment and improvement — the understanding that everything downstream depends on. These outcomes are prerequisites rather than protections, and an incomplete inventory silently caps how well every Protect and Detect outcome can score. In CSF 2.0 the supply chain content that used to live here moved into Govern.

ID.AM — Asset Management

ID.AM-01 Hardware inventory
Inventories of hardware managed by the organization are maintained.
ID.AM-02 Software and service inventory
Inventories of software, services, and systems managed by the organization are maintained.
ID.AM-03 Network communication and data flows
Representations of the organization's authorized network communication and internal and external network data flows are maintained.
ID.AM-04 Supplier-provided asset inventory
Inventories of services provided by suppliers are maintained.
ID.AM-05 Asset prioritization
Assets are prioritized based on classification, criticality, resources, and impact on the mission.
ID.AM-07 Data inventory and classification
Inventories of data and corresponding metadata for designated data types are maintained.
ID.AM-08 Asset lifecycle management
Systems, hardware, software, services, and data are managed throughout their life cycles.

ID.RA — Risk Assessment

ID.RA-01 Vulnerability identification
Vulnerabilities in assets are identified, validated, and recorded.
ID.RA-02 Threat intelligence received
Cyber threat intelligence is received from information sharing forums and sources.
ID.RA-03 Internal and external threats identified
Internal and external threats to the organization are identified and recorded.
ID.RA-04 Threat impact and likelihood
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.
ID.RA-05 Risk prioritization from threats, vulnerabilities, impacts
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
ID.RA-06 Risk responses chosen and tracked
Risk responses are chosen, prioritized, planned, tracked, and communicated.
ID.RA-07 Changes and exceptions risk-assessed
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked.
ID.RA-08 Vulnerability disclosure handling
Processes for receiving, analyzing, and responding to vulnerability disclosures are established.
ID.RA-09 Hardware and software integrity verified pre-use
The authenticity and integrity of hardware and software are assessed prior to acquisition and use.
ID.RA-10 Critical supplier assessment
Critical suppliers are assessed prior to acquisition.

ID.IM — Improvement

ID.IM-01 Improvements from evaluations
Improvements are identified from evaluations.
ID.IM-02 Improvements from tests and exercises
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties.
ID.IM-03 Improvements from operations
Improvements are identified from execution of operational processes, procedures, and activities.
ID.IM-04 Plans established and maintained
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved.

Other CSF 2.0 functions

GV PR DE RS RC
Crosswalk to ISO 27001 & SOC 2 →
Map these outcomes across frameworks in the Control Mapper.
Search all 106 subcategories →
Filter the CSF 2.0 Core by keyword, function or category.

Frequently asked questions

How many subcategories are in the NIST CSF Identify function?

Identify (ID) contains 21 subcategories across 3 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.

Is the Identify function mandatory?

No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

What changed in the Identify function in CSF 2.0?

Identify lost its supply chain category to the new Govern function and gained an Improvement category covering lessons learned, evaluations and testing.