Mission and audience
Make cloud risk visible, owned, configured, monitored, and resilient across providers and services.
Cloud security failures usually cross identity, configuration, data, provider, logging, and ownership boundaries. This playbook keeps those decisions connected.
Guided phase
Govern providers and services
Prioritize cloud providers and services, establish requirements, and monitor third-party risk.
Actions to take
- Maintain an approved cloud-service inventory.
- Define shared-responsibility, logging, incident, exit, and evidence requirements.
- Monitor provider changes and inherited-service risk.
Prioritize Suppliers by Criticality
Suppliers are known and prioritized by criticality
Supply Chain Requirements in Agreements
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Monitor Supplier and Third-Party Risk
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
Supplier-Provided Service Inventories
Inventories of services provided by suppliers are maintained
Guided phase
Map the cloud estate
Inventory cloud resources, services, identities, data, and flows and manage change risk.
Actions to take
- Discover accounts, subscriptions, projects, regions, services, and external exposure.
- Map data movement and cross-account trust.
- Track exceptions, ephemeral resources, and infrastructure-as-code changes.
Software, Service, and System Inventories
Inventories of software, services, and systems managed by the organization are maintained
Network Communication and Data Flow Representations
Representations of the organization’s authorized network communication and internal and external network data flows are maintained
Data and Metadata Inventories
Inventories of data and corresponding metadata for designated data types are maintained
Manage Changes and Exceptions
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
Guided phase
Secure identity and configuration
Control cloud identities, authentication, authorization, and configuration baselines.
Actions to take
- Separate human, service, workload, and break-glass identities.
- Apply least privilege to control planes and automation.
- Detect configuration drift and prevent insecure defaults.
Manage Identities and Credentials
Identities and credentials for authorized users, services, and hardware are managed by the organization
Authenticate Users, Services, and Hardware
Users, services, and hardware are authenticated
Manage Permissions and Authorizations
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Configuration Management
Configuration management practices are established and applied
Guided phase
Protect data and telemetry
Protect cloud data and generate the records needed for accountability and detection.
Actions to take
- Define encryption, key, secret, and data-residency requirements.
- Enable control-plane, identity, network, data, and workload logging.
- Protect logs from tenant compromise and deletion.
Protect Data at Rest
The confidentiality, integrity, and availability of data-at-rest are protected
Protect Data in Transit
The confidentiality, integrity, and availability of data-in-transit are protected
Generate and Provide Log Records
Log records are generated and made available for continuous monitoring
Guided phase
Monitor and sustain resilience
Monitor providers and runtime environments and maintain capacity for adverse conditions.
Actions to take
- Correlate provider, identity, network, workload, and application telemetry.
- Test regional, account, identity-provider, and service dependency failures.
- Define capacity, quota, and recovery thresholds.
Monitor External Service Providers
External service provider activities and services are monitored to find potentially adverse events
Monitor Computing and Runtime Environments
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Maintain Resource Capacity
Adequate resource capacity to ensure availability is maintained
Completion evidence
What should exist when this playbook is working?
- Approved cloud provider and service inventory.
- Shared-responsibility and contractual security requirements.
- Cloud resource, identity, data, and flow inventory.
- Configuration baseline and drift-remediation evidence.
- Protected centralized logging and cloud detection coverage.
- Resilience tests for region, provider, identity, and capacity failures.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.