When MME sends "Identity Request" NAS message to UE, first it is received by eNodeB RRC layer. Until th e Initial context setup request message is received by eNodeB, it can't impose any integrity or ciphering for signalling as well as user data.
Now come to your question - Does "Identity Request" should be ASN.1 ecoded ? Answer is "Yes".
RRC layer at eNodeB receives S1-AP "Downlink NAS Transport" and it picksthe "Initial UE message" from there and prepare RRC "DL Information transfer" and finally send to UE. DL Information transfer is always ASN.1 encoded, it doesn't matter whether security is enabled or not.