| name | nist-pf-identify |
| title | NIST Privacy Framework — IDENTIFY Function |
| description | Implement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Provides control mapping, gap analysis templates, and implementation workflows for privacy risk identification. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/nist-pf-identify |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
NIST Privacy Framework — IDENTIFY Function
Overview
The IDENTIFY function in the NIST Privacy Framework (Version 1.0, January 2020) enables organizations to develop organizational understanding of privacy risk arising from data processing. This skill covers all four subcategories: Business Environment (ID.BE), Data Actions (ID.DA), Improvement (ID.IM), and Risk Assessment (ID.RA).
IDENTIFY Function Subcategories
ID.BE — Business Environment
Understanding the organization's mission, objectives, stakeholders, and activities to prioritize privacy risk management decisions.
| Subcategory | Description | Implementation Guidance |
|---|
| ID.BE-P1 | The organization's role(s) in the data processing ecosystem are identified and communicated | Document whether the organization acts as data controller, processor, or both. Map all data flows identifying organizational role at each stage. |
| ID.BE-P2 | Priorities for organizational mission, objectives, and activities are established and communicated | Align privacy objectives with business strategy. Ensure executive leadership endorses privacy as a business priority. |
| ID.BE-P3 | Systems/products/services that process data are identified and prioritized | Maintain an inventory of all systems processing personal data. Classify by risk tier based on data sensitivity and volume. |
ID.DA — Data Actions
Understanding the data actions the organization performs and associated privacy risks.
| Subcategory | Description | Implementation Guidance |
|---|
| ID.DA-P1 | A data processing ecosystem inventory is created and maintained | Catalog all data processing activities including collection points, storage locations, sharing partners, and retention periods. |
| ID.DA-P2 | Owners of data actions are identified | Assign clear ownership for each data processing activity. Document accountability chains from operational to executive level. |
| ID.DA-P3 | Problematic data actions are identified and prioritized for management | Use the NIST problematic data actions catalog to assess risk. Score based on likelihood and impact to individuals. |
ID.IM — Improvement
Continuous improvement of privacy risk management.