Kuwait NCF Identify function. Asset Identification and Classification: comprehensive Configuration Management Database (CMDB) covering hardware + software + data + cloud assets + IoT + OT/ICS + virtual + container + identity + business processes + suppliers. Asset classification by criticality (Crown Jewels + business-critical + standard + low risk) + sensitivity (Top Secret + Secret + Confidential + Internal + Public) + Kuwait NCSC Critical National Infrastructure (CNI) sectoral designation (energy + oil + gas + water + electricity + telecommunications + ICT + banking + finance + healthcare + government + transportation + defense). Risk Assessment and Treatment: ISO 27005 + NIST SP 800-30/37 + FAIR + structured taxonomy of threats (cyber + insider + supply chain + nation-state APT + ransomware + DDoS + social engineering + physical) + vulnerabilities + impact + likelihood + risk register + treatment plan (Avoid + Reduce + Transfer + Accept) + residual risk acceptance + executive sign-off + risk-based prioritisation of controls + GCC threat landscape considerations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.