Get Demo

NIST CSF 2.0 Identify Function: Assets, Risk & Improvement

CSF 2.0 Identify (ID) — Asset Management, Risk Assessment, and Improvement — and how CyberSilo turns inventories and risk into Profile priorities.

Published: September 2026 Compliance · NIST CSF 2.0 8-10 min read

NIST's Identify outcome statement (CSWP 29): "The organization's current cybersecurity risks are understood." Identify builds the asset and risk picture so Protect and Detect investments follow Govern priorities — not the loudest vendor. See also the CSF 2.0 pillar guide and NIST hub.

What the Identify Function Covers

Knowing what you have (assets, data, suppliers' services), understanding cybersecurity risk to the organization, assets, and individuals, and feeding improvements across all six Functions from evaluations, tests, and operations.

Identify Categories (Official CSF 2.0)

Source: NIST CSWP 29, Table 1 / Appendix A — 3 Categories.

ID
Category
Outcome (brief)
ID.AM
Asset Management
Data, hardware, software, systems, facilities, services, and people identified and managed by relative importance
ID.RA
Risk Assessment
Cybersecurity risk to the organization, assets, and individuals is understood
ID.IM
Improvement
Improvements to risk management processes and activities identified across all CSF Functions

Why Identify Matters

Broken asset inventory breaks every downstream Function. ID.RA is where threat intelligence, vulnerabilities, likelihood/impact, and risk response live. ID.IM is the formal path from lessons learned (tests, exercises, incidents) into the backlog — including improvements that CSF 1.1 sometimes parked under Recover.

How CyberSilo Helps Operationalize Identify

Build an Identify-Ready Profile

Inventory gaps and risk assessments mapped to ID.AM, ID.RA, and ID.IM — with evidence you can reuse across frameworks.

Frequently Asked Questions

Where did Business Environment (ID.BE) go in CSF 2.0?

Organizational context outcomes were largely restructured under Govern as GV.OC. Use CSF 2.0 Category IDs (ID.AM, ID.RA, ID.IM) for Identify — not CSF 1.1 labels such as ID.BE.

Is ID.SC still an Identify Category?

No. In CSF 2.0, cybersecurity supply chain risk management is primarily under Govern as GV.SC. Identify has three Categories: ID.AM, ID.RA, and ID.IM.

How many Identify Categories are in CSF 2.0?

Three: Asset Management (ID.AM), Risk Assessment (ID.RA), and Improvement (ID.IM), per NIST CSWP 29 Table 1.

Govern · Protect · Detect · Respond · Recover

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!