The NIST CSF Identify function
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · NIST CSF
You cannot protect what you have not identified. The Identify function is the inventory-and-understanding work the rest of the CSF builds on.
Where the framework begins
The NIST Cybersecurity Framework organises security into functions, and Identify is the natural starting point. It is about understanding: what assets and data you have, what risks they face, and the business and supply-chain context you operate in. Everything the other functions do depends on this understanding.
What it covers
Identify spans asset management (knowing your systems, data, and software), risk assessment (understanding the threats and vulnerabilities to them), and — emphasised in CSF 2.0 — supply-chain risk and the business context that sets your priorities. It is the map before the journey.
Asset management is the keystone
The single most useful Identify outcome is a current asset and data inventory. Programs that struggle almost always skipped it — you cannot protect, monitor, or recover systems you have not catalogued. Build the inventory first and the rest of the CSF has something to act on.
Risk-driven
Identify ties assets to risk, which then drives where you invest in the Protect, Detect, and Respond functions. Done well, it makes your whole program risk-based rather than uniform. SentinelPanda builds the asset and risk picture that anchors a CSF program.