Annex I · Objective 02
Identify
Identifying creates a common vision of the assets, dependencies and risks that support the entity's services.
Complete structure
Categories and controls.
Select each category to see all the codes and titles that make up it.
ID.GAAsset Management9 checks
- ID.GA-1
Equipment and other physical resources managed or held by the entity are inventoried.
- ID.GA-2
The logical resources that support the processes of the entity's services are inventoried.
- ID.GA-3
Networks and communication flows are mapped.
- ID.GA-4
The services provided by suppliers are inventoried.
- ID.GA-5
The assets are classified according to their criticality.
- ID.GA-6
Data and metadata thereof shall be identified and recorded.
- ID.GA-7
Systems, hardware, software, services and data are managed throughout your life cycles.
- ID.GA-8
Data are destroyed according to the Data Classification and Management Policy.
- ID.GA-9
The entity implements a change management process.
ID.ARRisk Assessment7 checks
- ID.AR-1
Asset vulnerabilities are identified and documented on the basis of the defined methodology.
- ID.AR-2
The entity shares information on cybersecurity threats with stakeholders.
- ID.AR-3
Internal and external threats are identified and documented on the basis of the defined methodology.
- ID.AR-4
Potential impacts and their likelihood of threats are identified and recorded.
- ID.AR-5
The entity shall assess the identified risks.
- ID.AR-6
The entity shall ensure that risk responses are identified and prioritized.
- ID.AR-7
The entity defines processes to receive information, analyze and respond to internal and external vulnerabilities.
ID.MCContinuous Improvement3 checks
- ID.MC-1
Improvements are identified through assessments and information is shared with stakeholders.
- ID.MC-2
Improvements are identified from cybersecurity testing and exercises.
- ID.MC-3
The improvements are identified from the execution of operational processes, procedures and activities.
Application
How to work every control.
- Confirm full description in Annex I
- Set scope and responsibility
- Relating control with risk and critical services
- Associate implementation and evidence
- Record gaps, priority and deadline
- Review implementation and effectiveness
Primary source
Regulation No. 756/2026, of 22 June — Annex I
The codes and titles reproduce the structure of Annex I. Please refer to the official act for the full description and normative references of each control.