Identify NIST Cybersecurity Framework 2.0

NIST Cybersecurity Framework: Identify Security Controls

Understand the organization's assets, suppliers, and related cybersecurity risks.

21 controls
3 critical
92h est. effort
3 categories

Asset Management

Improvement

Risk Assessment

id-ra-1

Vulnerabilities in assets are identified, validated, and recorded

Unpatched vulnerabilities are the most common initial access vector in breaches. Regular scanning tu...

id-ra-10

Critical suppliers are assessed prior to acquisition

Bringing a new critical supplier into your environment is a risk event that deserves the same scruti...

id-ra-2

Cyber threat intelligence is received from information sharing forums and sources

Staying ahead of attackers means consuming intelligence about what they are doing, not just reacting...

id-ra-3

Internal and external threats to the organization are identified and recorded

A vulnerability scan tells you about weaknesses in your assets, but threat identification tells you ...

id-ra-4

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

Knowing that a vulnerability exists is not the same as knowing how much it matters. A critical CVE i...

id-ra-5

Risk information is used to understand inherent risk and prioritize responses

Risk data is only valuable if it drives decisions. Organizations that maintain a risk register but n...

id-ra-6

Risk responses are chosen, prioritized, planned, tracked, and communicated

Identifying a risk without deciding what to do about it is just a longer list of problems. Every ris...

id-ra-7

Changes and exceptions are managed, assessed for risk impact, and tracked

Every change to your environment, whether a new service, a configuration update, or a policy excepti...

id-ra-8

Processes for receiving, analyzing, and responding to vulnerability disclosures are established

Security researchers, customers, and employees regularly discover vulnerabilities in your products o...

id-ra-9

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

Compromised hardware and software can be introduced into your environment during the acquisition pro...