agentsclimarketplace

Nist pf identify

Skill onfire7777/universal-ai-skills-library/skills/nist-pf-identify

Router-first AI skill system for Codex, Claude, Cursor, Hermes, Paperclip, OpenCode, and local AI stacks: search, preflight-route, and load 1,812 skills on demand without duplicating the corpus.

Install
npx -y skills add onfire7777/universal-ai-skills-library --skill nist-pf-identify

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 13 stars13 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Implement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Provides control mapping, gap analysis templates, and implementation workflows for privacy risk identification.

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

7.5 KB, as published. Nobody here has run it

NIST Privacy Framework — IDENTIFY Function

Overview

The IDENTIFY function in the NIST Privacy Framework (Version 1.0, January 2020) enables organizations to develop organizational understanding of privacy risk arising from data processing. This skill covers all four subcategories: Business Environment (ID.BE), Data Actions (ID.DA), Improvement (ID.IM), and Risk Assessment (ID.RA).

IDENTIFY Function Subcategories

ID.BE — Business Environment

Understanding the organization's mission, objectives, stakeholders, and activities to prioritize privacy risk management decisions.

SubcategoryDescriptionImplementation Guidance
ID.BE-P1The organization's role(s) in the data processing ecosystem are identified and communicatedDocument whether the organization acts as data controller, processor, or both. Map all data flows identifying organizational role at each stage.
ID.BE-P2Priorities for organizational mission, objectives, and activities are established and communicatedAlign privacy objectives with business strategy. Ensure executive leadership endorses privacy as a business priority.
ID.BE-P3Systems/products/services that process data are identified and prioritizedMaintain an inventory of all systems processing personal data. Classify by risk tier based on data sensitivity and volume.

ID.DA — Data Actions

Understanding the data actions the organization performs and associated privacy risks.

SubcategoryDescriptionImplementation Guidance
ID.DA-P1A data processing ecosystem inventory is created and maintainedCatalog all data processing activities including collection points, storage locations, sharing partners, and retention periods.
ID.DA-P2Owners of data actions are identifiedAssign clear ownership for each data processing activity. Document accountability chains from operational to executive level.
ID.DA-P3Problematic data actions are identified and prioritized for managementUse the NIST problematic data actions catalog to assess risk. Score based on likelihood and impact to individuals.

ID.IM — Improvement

Continuous improvement of privacy risk management.

SubcategoryDescriptionImplementation Guidance
ID.IM-P1A process for continuous improvement of the privacy risk assessment approach is establishedSchedule quarterly reviews of risk methodology. Incorporate lessons from incidents and regulatory developments.
ID.IM-P2Privacy risk assessment findings are incorporated into improvement plansTrack remediation actions in a centralized register. Assign deadlines and owners for each improvement item.

ID.RA — Risk Assessment

Understanding and evaluating privacy risks.

SubcategoryDescriptionImplementation Guidance
ID.RA-P1Data actions and their expected problematic data actions are identifiedMap each data action to potential problematic outcomes using NIST's catalog of problematic data actions.
ID.RA-P2Organizational systems, products, and services are monitored for problematic data actionsDeploy continuous monitoring for unauthorized access, unexpected data flows, and policy violations.
ID.RA-P3Risk responses are identified and prioritizedDefine response strategies: mitigate, transfer, avoid, or accept. Document rationale for each risk response decision.

Implementation Workflow

Phase 1: Inventory and Discovery (Weeks 1-4)

  1. Stakeholder Identification: Identify all internal and external stakeholders involved in data processing
  2. System Inventory: Catalog all systems, applications, and services that process personal data
  3. Data Flow Mapping: Document how data moves through the organization from collection to deletion
  4. Role Classification: Determine the organization's role (controller/processor) for each data processing activity

Phase 2: Data Action Analysis (Weeks 5-8)

  1. Data Action Catalog: Document all data actions (collection, retention, logging, generation, disclosure, transfer)
  2. Ownership Assignment: Assign data stewards for each data action category
  3. Problematic Data Action Screening: Evaluate each data action against NIST's problematic data actions list
  4. Impact Assessment: Score each problematic data action on likelihood and severity scales (1-5)

Phase 3: Risk Assessment (Weeks 9-12)

  1. Risk Scoring: Calculate risk scores as Likelihood x Impact for each identified problematic data action
  2. Risk Prioritization: Rank risks and identify those exceeding organizational risk tolerance
  3. Response Planning: Select and document risk response strategies for each high-priority risk
  4. Control Mapping: Map existing and planned controls to identified risks

Phase 4: Continuous Improvement (Ongoing)

  1. Quarterly Reviews: Reassess risk landscape and update risk register
  2. Incident Integration: Incorporate findings from privacy incidents into risk assessments
  3. Regulatory Monitoring: Track changes in applicable privacy regulations
  4. Metrics Tracking: Monitor key risk indicators and report to governance bodies

Control Mapping to Other Frameworks

NIST PF IDENTIFYISO 27701GDPR ArticleCCPA Section
ID.BE-P15.2.1Art. 24, 26, 281798.140(d),(v)
ID.BE-P25.2.2Art. 5(2)1798.100
ID.BE-P3A.7.2.1Art. 301798.110
ID.DA-P1A.7.2.8Art. 30(1)1798.110(c)
ID.DA-P25.3Art. 37-391798.130
ID.DA-P3A.7.2.5Art. 351798.185
ID.RA-P16.1.2Art. 35(7)1798.185(a)(15)
ID.RA-P29.1Art. 32(1)(d)1798.150
ID.RA-P36.1.3Art. 35(7)(d)1798.185(a)(15)

Maturity Assessment

Level 1 — Initial

  • Ad hoc privacy risk identification
  • No formal inventory of data processing activities
  • Reactive approach to privacy issues

Level 2 — Managed

  • Basic data inventory exists
  • Some data actions documented
  • Risk assessments conducted periodically

Level 3 — Defined

  • Comprehensive data processing inventory maintained
  • All data actions cataloged with owners
  • Structured risk assessment process in place

Level 4 — Quantitatively Managed

  • Metrics-driven risk assessment
  • Automated monitoring of data actions
  • Quantitative risk scoring methodology

Level 5 — Optimizing

  • Continuous improvement process embedded
  • Predictive risk analytics
  • Industry-leading privacy risk management practices

References

  • NIST Privacy Framework Version 1.0 (January 16, 2020)
  • NIST SP 800-37 Rev. 2 — Risk Management Framework
  • NIST IR 8062 — An Introduction to Privacy Engineering and Risk Management in Federal Systems
  • ISO/IEC 27701:2019 — Privacy Information Management

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.