# ID — Identify

- **Function ID:** ID

## Subcategories

- [ID.AM-01](/md/csf/ID.AM-01.md) — Inventories of hardware managed by the organization are maintained
- [ID.AM-02](/md/csf/ID.AM-02.md) — Inventories of software, services, and systems managed by the organization are maintained
- [ID.AM-03](/md/csf/ID.AM-03.md) — Representations of the organization's authorized network communication and internal and external network data flows are maintained
- [ID.AM-04](/md/csf/ID.AM-04.md) — Inventories of services provided by suppliers are maintained
- [ID.AM-05](/md/csf/ID.AM-05.md) — Assets are prioritized based on classification, criticality, resources, and impact on the mission
- [ID.AM-07](/md/csf/ID.AM-07.md) — Inventories of data and corresponding metadata for designated data types are maintained
- [ID.AM-08](/md/csf/ID.AM-08.md) — Systems, hardware, software, services, and data are managed throughout their life cycles
- [ID.IM-01](/md/csf/ID.IM-01.md) — Improvements are identified from evaluations
- [ID.IM-02](/md/csf/ID.IM-02.md) — ID.IM-02
- [ID.IM-03](/md/csf/ID.IM-03.md) — Improvements are identified from execution of operational processes, procedures, and activities
- [ID.IM-04](/md/csf/ID.IM-04.md) — Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
- [ID.RA-01](/md/csf/ID.RA-01.md) — Vulnerabilities in assets are identified, validated, and recorded
- [ID.RA-02](/md/csf/ID.RA-02.md) — Cyber threat intelligence is received from information sharing forums and sources
- [ID.RA-03](/md/csf/ID.RA-03.md) — Internal and external threats to the organization are identified and recorded
- [ID.RA-04](/md/csf/ID.RA-04.md) — Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
- [ID.RA-05](/md/csf/ID.RA-05.md) — Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
- [ID.RA-06](/md/csf/ID.RA-06.md) — Risk responses are chosen, prioritized, planned, tracked, and communicated
- [ID.RA-07](/md/csf/ID.RA-07.md) — Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
- [ID.RA-08](/md/csf/ID.RA-08.md) — Processes for receiving, analyzing, and responding to vulnerability disclosures are established
- [ID.RA-09](/md/csf/ID.RA-09.md) — The authenticity and integrity of hardware and software are assessed prior to acquisition and use
- [ID.RA-10](/md/csf/ID.RA-10.md) — Critical suppliers are assessed prior to acquisition

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
