Understand what you are defending and what threatens it. Every downstream capability — detection coverage, response prioritisation, recovery ordering — depends on the quality of this function. An unknown asset cannot be monitored, patched, or restored.
Continuously maintained inventory of hardware, software, cloud resources, data flows, and their owners. Includes shadow-IT discovery.
ID-2
Data classification
Data mapped and classified (e.g., public / internal / confidential / special-category personal data) with owners assigned.
ID-3
Crown-jewel analysis
Identification of business-critical services and the assets they depend on; drives detection and recovery priority.
ID-4
Vulnerability management (identification)
Regular authenticated scanning, cloud posture assessment, and external attack-surface monitoring.
ID-5
Threat landscape & intelligence
A documented threat profile: which actors, sectors, and techniques (MITRE ATT&CK) are relevant to your organisation. Consume national CSIRT and ENISA advisories. A-tier deep dive on building a full CTI capability: 15-cti-deep-dive.md.
NIS2 Art. 21(2)(d) — supply chain security requires knowing your suppliers and dependencies (asset/dependency inventory).
GDPR Art. 30 — records of processing activities: reuse as data-flow inventory.
DORA Art. 8 — identification of ICT-supported business functions and information assets.
CRA (Cyber Resilience Act, Regulation (EU) 2024/2847) — relevant when you produce or procure "products with digital elements"; feeds procurement requirements.
ENISA Threat Landscape (annual) — recommended baseline input for the threat profile.