NIST Identify
IDENTIFY:
This function focuses on understanding risks to systems, people, assets, data, and capabilities. Thus, enabling effective risk management and decision-making.
Categories in the Identify Function
- Asset Management:
Identify and inventory organizational assets (hardware, software, data, etc.).
- Business Environment:
Understand the organization’s mission, role in the supply chain, and critical functions.
- Governance:
Establish cybersecurity policies, roles, and responsibilities aligned with legal and regulatory requirements.
- Risk Assessment:
Identify potential threats, vulnerabilities, and impacts to assets.
- Risk Management Strategy:
Establish the organization’s approach to managing cybersecurity risk.