Compliance Glossary

What is Identify Function?

Definition

The Identify function in NIST CSF focuses on developing organizational understanding of cybersecurity risks to systems, assets, data, and capabilities. It encompasses asset management, business environment understanding, governance, risk assessment, risk management strategy, and supply chain risk management.

In Depth

The Identify function establishes the foundation for all other cybersecurity activities by ensuring the organization understands its environment, the resources that support critical functions, and the cybersecurity risks it faces. Key categories within this function include asset management (inventorying hardware, software, data, and external information systems), business environment (understanding the organization's mission, objectives, and stakeholders), governance (establishing cybersecurity policies, roles, and legal requirements), risk assessment (identifying and evaluating cybersecurity risks), and supply chain risk management (understanding and managing risks associated with the supply chain). Without the Identify function, organizations cannot effectively prioritize their security investments or determine which assets require the most protection. In practice, implementing the Identify function involves creating comprehensive asset inventories, conducting regular risk assessments, mapping data flows, understanding regulatory obligations, and establishing a governance structure with clear accountability for cybersecurity decisions. Organizations at higher implementation tiers integrate the Identify function into their overall enterprise risk management processes.

Related Frameworks

Generate compliance docs with PoliWriter

Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.

Get Started Free