Skip to main content
Language Translation
  Close Menu

Identify is the first and most important function of NIST. Each category in NIST deals with various cybersecurity subcategories. We are not going to go into detail here on all the subcategories, instead we tackle the function as a whole. The questions in the Identify category will range from: why cybersecurity is important to every organization; how to identify the different assets in the organization; helping you understand the various risks involved if you have not identified everything; the importance of identifying all the smart devices connected to your network.

Businesses need to understand that it is the top priority to take the time to find every system and service within their infrastructure, and the risks involved if not done correctly. It is very important to know the criticality of each asset, meaning what is the level of importance of each system, service, data, personnel, and facility to your organization. Similarly, it is imperative to find all the “Smart devices” connecting or interacting with your organization, as each one of these devices can be an opportunity for a cybercriminal to use against you.

Low – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Low to Medium will be to 1) begin integrating cybersecurity into your daily business decisions because small and medium businesses are easy targets for cybercriminals, 2) Understand your top priority is that if you don’t know what you have, you can’t protect it. Therefore, create a list / inventory of all your digital assets, systems, services, and data. Ensure the inventory includes “smart” devices such as wearables, smart locks, connected cameras, mobile credit card readers/point of sale (POS), inventory & stock control, shipping trackers, supply-chain data monitoring, temperature / climate control / water leak sensors, voice assistants, smart lights, smart thermostats and HVAC, connected alarm systems / smoke / carbon monoxide, smart televisions, etc… 3) Determine your businesses priority for each of the assets in your inventory. The higher the priority something is to your business, the better the protections need to be.

The following are additional resources to help you level up your game from Low to Medium:

Medium - Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Medium to High will be to 1) Ensure you update your inventory of all of your digital assets such as cloud services, upstream and downstream systems, data, and smart devices very frequently, and begin researching asset management services to automate the process, 2) Determine which structured, formalized risk model you will use to measure, manage, and remediate your business’ cybersecurity risks, examples are "NIST 800-30", "Fair Institute", etc… to ensure all risks are properly assessed, and 3) Determine the roles & responsibilities that everyone will play in cybersecurity for your business, so you spread out the workload and begin building a security first culture.

The following are additional resources to help you level up your game from Medium to High:

High - Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score and keep it at High will be to 1) Implement a formal risk management framework, examples are "NIST 800-30", "Fair Institute", etc… and make sure you include identification of the threats to your organization’s critical physical and digital assets, 2) All cybersecurity decisions are in alignment with your organizations mission, goals, stakeholders, and processes, 3) understand the regulatory, operational, legal, environmental, and risk requirements, and 4) understand the organization’s top priorities, concerns, risk appetite, and assumptions to better inform cyber decisions.

The following are additional resources to help you level up your game and keep it at High: