CSF Building a Metrics Program – Identify Part 2 of 6

This is a continuation of my CSF Actionable Metrics series. If you missed the first one, here’s the link to it. So with identify, its about Asset Management, Risk Assessments, and Improvement. This is part of my bigger series of Building a Metrics Program.

Identify within the CSF is about knowing your inventory, just like the CIS top 2 controls. What are those assets you have, what risks do they pose, and be thorough about the risks, like identify the threats to those assets, and then what do we do about it.

Using NIST CSF 2.0, Identify has three categories:

  • ID.AM — Asset Management
  • ID.RA — Risk Assessment
  • ID.IM — Improvement

Identify’s Asset Management is to know what we have, who owns it, how important it is, and what it depends on. This does go well with Govern’s Roles, Responsibilities & Authorities (GV.RR).

Control / OutcomeLeading indicatorsLagging indicators
ID.AM-01 Inventories of hardware managed by the organization are maintained% assets discovered; asset inventory reconciliation frequency; % assets with assigned ownerUnknown/rogue assets discovered; inventory inaccuracies discovered during incidents
ID.AM-02 Inventories of software, services and systems are maintained% applications/services inventoried; % with assigned business and technical ownersUnknown applications discovered; incidents involving unregistered systems
ID.AM-03 Communication and data flows are mapped% critical services with documented data flows; % critical integrations mappedIncidents involving unknown data flows; unidentified dependencies discovered during incidents
ID.AM-04 Inventories of services provided by suppliers are maintained% critical suppliers mapped to business services; % supplier services with ownersCritical service disruption caused by unknown supplier dependency
ID.AM-05 Assets are prioritized based on classification, criticality, resources and mission% assets classified by criticality/data sensitivity; % critical assets with validated ownersCritical assets discovered without appropriate classification/protection
ID.AM-06 Assets are managed throughout their lifecycle% assets receiving security review during acquisition/change/retirement; % retired assets properly decommissionedRetired assets retaining access/data; systems deployed without required security controls

An actionable metric would be % of critical assets with a validated business owner, technical owner, business criticality, data classification, and documented dependencies. This data is usually discovered through direct means of knowing what is getting built, assets created and put into the CMDB so tickets can be created to include them; there is also an alternative by using vulnerability assessment, scanning the network, finding assets/devices and reporting them to IT to also add to the CMDB. Make sure when you are building out your vulnerability management program that you have this as a defined workstream with a person who needs to figure out who owns the asset as per GV.RR.

Identity’s Risk Assessment helps us understand what can hurt the organization, how likely it is, what it could cost, and which risks actually matter

Control / OutcomeLeading indicatorsLagging indicators
ID.RA-01 Vulnerabilities in assets are identified and recorded% assets covered by vulnerability scanning; authenticated scan coverage; vulnerability discovery latencyExploited vulnerabilities; vulnerabilities discovered outside normal scanning; missed critical vulnerabilities
ID.RA-02 Cyber threat intelligence is received from information-sharing forums and sources% relevant intelligence sources monitored; intelligence processing time; % actionable intelligence translated into security actionsIncidents involving known threats that were not incorporated into defenses
ID.RA-03 Internal and external threats to the organization are identified and recorded% critical assets/business services with documented threat scenarios; threat-modeling coverageMaterial incidents involving previously unidentified threat scenarios
ID.RA-04 Potential impacts and likelihoods of threats and vulnerabilities are identified and recorded% material risks with quantified likelihood and impact; % critical scenarios with validated business impactActual incident impact materially differs from risk assessment; material risks discovered without prior assessment
ID.RA-05 Threats, vulnerabilities, likelihoods and impacts are used to understand risk% material risks with documented threat → vulnerability → impact relationships; % risks with current residual-risk assessmentsMaterial incidents involving previously misassessed risks; unexpected material risk exposure
ID.RA-06 Risk responses are identified, prioritized and communicated% material risks with documented treatment strategy; % risks with owner and target date; treatment prioritization based on quantified exposureRisks remaining untreated beyond tolerance; expired risk acceptances; overdue risk treatments
ID.RA-07 Changes and exceptions are identified and managed% material changes receiving risk assessment; % exceptions reviewed before expirationIncidents caused by unassessed changes; expired exceptions; unauthorized risk acceptance
ID.RA-08 Supplier-related cybersecurity risks are identified and managed% critical suppliers risk-assessed; assessment freshness; % critical suppliers mapped to critical business servicesSupplier-related incidents; critical supplier risks discovered after onboarding; supplier-caused business disruption

The goal of of Risk Assessment is to know what % of material cyber risks for which likelihood, financial impact, business impact, and residual risk have been quantified.

Identify’s Improvement is about figuring if we learning from what we discover, and are those lessons actually changing the organization’s risk.

Control / OutcomeLeading indicatorsLagging indicators
ID.IM-01 Improvements are identified from evaluations% assessments producing improvement actions; % actions with owners and target datesRepeat findings; recurring control deficiencies
ID.IM-02 Improvements are identified from security tests and exercises% test findings with remediation plans; remediation completion rate; retest coverageRepeat penetration-test findings; failed retests
ID.IM-03 Improvements are identified from operational activities% operational findings converted into improvement actions; lessons-learned completion rateRepeat operational failures; recurring root causes
ID.IM-04 Incident and exercise lessons are incorporated into cybersecurity improvements% incidents/exercises producing documented lessons learned; % lessons implemented within target timeframeRepeat incidents caused by previously identified weaknesses; same failure recurring in subsequent exercises

This helps determine the % of previously identified material weaknesses that recur after corrective action was implemented.

You will want to know how to answer the following about leading and lagging indicators regarding your metrics of Identify.

MetricExecutive question
1. Asset Visibility CoverageDo we know what we have?
2. Critical Asset Classification CoverageDo we know what matters?
3. Critical Service Dependency CoverageDo we know what those assets support?
4. Threat Scenario CoverageDo we understand what could attack us?
5. Vulnerability Risk CoverageDo we know which vulnerabilities actually create material risk?
6. Quantified Risk CoverageDo we understand the potential business/financial impact?
7. Material Risk Treatment CoverageAre identified material risks being addressed?
8. Critical Supplier Risk CoverageDo we understand our third-party exposure?
9. Risk Assessment AccuracyHow well did our assumptions match reality?
10. Repeat Failure RateAre we actually learning?

Related Posts