Skip to content

The NIST CSF Identify function

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · NIST CSF

You cannot protect what you have not identified. The Identify function is the inventory-and-understanding work the rest of the CSF builds on.

Where the framework begins

The NIST Cybersecurity Framework organises security into functions, and Identify is the natural starting point. It is about understanding: what assets and data you have, what risks they face, and the business and supply-chain context you operate in. Everything the other functions do depends on this understanding.

What it covers

Identify spans asset management (knowing your systems, data, and software), risk assessment (understanding the threats and vulnerabilities to them), and — emphasised in CSF 2.0 — supply-chain risk and the business context that sets your priorities. It is the map before the journey.

Asset management is the keystone

The single most useful Identify outcome is a current asset and data inventory. Programs that struggle almost always skipped it — you cannot protect, monitor, or recover systems you have not catalogued. Build the inventory first and the rest of the CSF has something to act on.

Risk-driven

Identify ties assets to risk, which then drives where you invest in the Protect, Detect, and Respond functions. Done well, it makes your whole program risk-based rather than uniform. SentinelPanda builds the asset and risk picture that anchors a CSF program.

NIST CSF 2.0 core functions Building an asset inventory auditors trust The NIST CSF Protect function

Run your compliance program in one workspace.