CSF Building a Metrics Program – Identify Part 2 of 6
This is a continuation of my CSF Actionable Metrics series. If you missed the first one, here’s the link to it. So with identify, its about Asset Management, Risk Assessments, and Improvement. This is part of my bigger series of Building a Metrics Program.
Identify within the CSF is about knowing your inventory, just like the CIS top 2 controls. What are those assets you have, what risks do they pose, and be thorough about the risks, like identify the threats to those assets, and then what do we do about it.

Using NIST CSF 2.0, Identify has three categories:
- ID.AM — Asset Management
- ID.RA — Risk Assessment
- ID.IM — Improvement
Identify’s Asset Management is to know what we have, who owns it, how important it is, and what it depends on. This does go well with Govern’s Roles, Responsibilities & Authorities (GV.RR).
| Control / Outcome | Leading indicators | Lagging indicators |
|---|---|---|
| ID.AM-01 Inventories of hardware managed by the organization are maintained | % assets discovered; asset inventory reconciliation frequency; % assets with assigned owner | Unknown/rogue assets discovered; inventory inaccuracies discovered during incidents |
| ID.AM-02 Inventories of software, services and systems are maintained | % applications/services inventoried; % with assigned business and technical owners | Unknown applications discovered; incidents involving unregistered systems |
| ID.AM-03 Communication and data flows are mapped | % critical services with documented data flows; % critical integrations mapped | Incidents involving unknown data flows; unidentified dependencies discovered during incidents |
| ID.AM-04 Inventories of services provided by suppliers are maintained | % critical suppliers mapped to business services; % supplier services with owners | Critical service disruption caused by unknown supplier dependency |
| ID.AM-05 Assets are prioritized based on classification, criticality, resources and mission | % assets classified by criticality/data sensitivity; % critical assets with validated owners | Critical assets discovered without appropriate classification/protection |
| ID.AM-06 Assets are managed throughout their lifecycle | % assets receiving security review during acquisition/change/retirement; % retired assets properly decommissioned | Retired assets retaining access/data; systems deployed without required security controls |
An actionable metric would be % of critical assets with a validated business owner, technical owner, business criticality, data classification, and documented dependencies. This data is usually discovered through direct means of knowing what is getting built, assets created and put into the CMDB so tickets can be created to include them; there is also an alternative by using vulnerability assessment, scanning the network, finding assets/devices and reporting them to IT to also add to the CMDB. Make sure when you are building out your vulnerability management program that you have this as a defined workstream with a person who needs to figure out who owns the asset as per GV.RR.
Identity’s Risk Assessment helps us understand what can hurt the organization, how likely it is, what it could cost, and which risks actually matter
| Control / Outcome | Leading indicators | Lagging indicators |
|---|---|---|
| ID.RA-01 Vulnerabilities in assets are identified and recorded | % assets covered by vulnerability scanning; authenticated scan coverage; vulnerability discovery latency | Exploited vulnerabilities; vulnerabilities discovered outside normal scanning; missed critical vulnerabilities |
| ID.RA-02 Cyber threat intelligence is received from information-sharing forums and sources | % relevant intelligence sources monitored; intelligence processing time; % actionable intelligence translated into security actions | Incidents involving known threats that were not incorporated into defenses |
| ID.RA-03 Internal and external threats to the organization are identified and recorded | % critical assets/business services with documented threat scenarios; threat-modeling coverage | Material incidents involving previously unidentified threat scenarios |
| ID.RA-04 Potential impacts and likelihoods of threats and vulnerabilities are identified and recorded | % material risks with quantified likelihood and impact; % critical scenarios with validated business impact | Actual incident impact materially differs from risk assessment; material risks discovered without prior assessment |
| ID.RA-05 Threats, vulnerabilities, likelihoods and impacts are used to understand risk | % material risks with documented threat → vulnerability → impact relationships; % risks with current residual-risk assessments | Material incidents involving previously misassessed risks; unexpected material risk exposure |
| ID.RA-06 Risk responses are identified, prioritized and communicated | % material risks with documented treatment strategy; % risks with owner and target date; treatment prioritization based on quantified exposure | Risks remaining untreated beyond tolerance; expired risk acceptances; overdue risk treatments |
| ID.RA-07 Changes and exceptions are identified and managed | % material changes receiving risk assessment; % exceptions reviewed before expiration | Incidents caused by unassessed changes; expired exceptions; unauthorized risk acceptance |
| ID.RA-08 Supplier-related cybersecurity risks are identified and managed | % critical suppliers risk-assessed; assessment freshness; % critical suppliers mapped to critical business services | Supplier-related incidents; critical supplier risks discovered after onboarding; supplier-caused business disruption |
The goal of of Risk Assessment is to know what % of material cyber risks for which likelihood, financial impact, business impact, and residual risk have been quantified.
Identify’s Improvement is about figuring if we learning from what we discover, and are those lessons actually changing the organization’s risk.
| Control / Outcome | Leading indicators | Lagging indicators |
|---|---|---|
| ID.IM-01 Improvements are identified from evaluations | % assessments producing improvement actions; % actions with owners and target dates | Repeat findings; recurring control deficiencies |
| ID.IM-02 Improvements are identified from security tests and exercises | % test findings with remediation plans; remediation completion rate; retest coverage | Repeat penetration-test findings; failed retests |
| ID.IM-03 Improvements are identified from operational activities | % operational findings converted into improvement actions; lessons-learned completion rate | Repeat operational failures; recurring root causes |
| ID.IM-04 Incident and exercise lessons are incorporated into cybersecurity improvements | % incidents/exercises producing documented lessons learned; % lessons implemented within target timeframe | Repeat incidents caused by previously identified weaknesses; same failure recurring in subsequent exercises |
This helps determine the % of previously identified material weaknesses that recur after corrective action was implemented.
You will want to know how to answer the following about leading and lagging indicators regarding your metrics of Identify.
| Metric | Executive question |
|---|---|
| 1. Asset Visibility Coverage | Do we know what we have? |
| 2. Critical Asset Classification Coverage | Do we know what matters? |
| 3. Critical Service Dependency Coverage | Do we know what those assets support? |
| 4. Threat Scenario Coverage | Do we understand what could attack us? |
| 5. Vulnerability Risk Coverage | Do we know which vulnerabilities actually create material risk? |
| 6. Quantified Risk Coverage | Do we understand the potential business/financial impact? |
| 7. Material Risk Treatment Coverage | Are identified material risks being addressed? |
| 8. Critical Supplier Risk Coverage | Do we understand our third-party exposure? |
| 9. Risk Assessment Accuracy | How well did our assumptions match reality? |
| 10. Repeat Failure Rate | Are we actually learning? |
