Guided Defense Playbooks
Turn the knowledge graph into an action path.
Choose a real defensive objective, follow the most relevant NIST CSF outcomes into the Cross-Framework Defense Map, and use the linked controls, CUI requirements, D3FEND techniques, ATT&CK context, books, podcasts, and Academy lessons to deepen the work.
Bare Metal Cyber editorial guidance · Built on the source-controlled v0.2.16 Defense Map
Open the complete Defense Map →Choose a mission
Start with the outcome you need—not the framework you already know.
Each playbook is a curated educational route. Official NIST and MITRE relationships remain labeled separately from Bare Metal Cyber editorial sequencing.
Protect systems and information
5 playbooksIdentity defense playbook
Identity and Privileged Access
- Phases
- 5
- Outcomes
- 10
- Controls
- 75
Architecture playbook
Zero Trust
- Phases
- 5
- Outcomes
- 16
- Controls
- 112
Cloud operating model playbook
Cloud Security
- Phases
- 5
- Outcomes
- 18
- Controls
- 92
Information protection playbook
Data Protection
- Phases
- 5
- Outcomes
- 12
- Controls
- 77
Exposure reduction playbook
Vulnerability Management
- Phases
- 5
- Outcomes
- 16
- Controls
- 81
Detect, respond, and recover
4 playbooksDetection engineering playbook
Logging and Detection
- Phases
- 5
- Outcomes
- 14
- Controls
- 76
Resilience playbook
Ransomware Resilience
- Phases
- 5
- Outcomes
- 14
- Controls
- 64
Incident operations playbook
Incident Response
- Phases
- 5
- Outcomes
- 20
- Controls
- 54
Operational resilience playbook
Continuity and Recovery
- Phases
- 5
- Outcomes
- 18
- Controls
- 67
Govern risk and resilience
3 playbooksControlled information playbook
CUI Protection
- Phases
- 5
- Outcomes
- 16
- Controls
- 111
Third-party risk playbook
Supply Chain Risk
- Phases
- 5
- Outcomes
- 15
- Controls
- 61
AI risk playbook
AI Security and Governance
- Phases
- 5
- Outcomes
- 22
- Controls
- 124
Relationship boundaries
Guidance without overclaiming.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.