Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Cloud Security

Govern cloud providers, inventory services and data, secure identities and configurations, protect telemetry, and maintain resilience across shared-responsibility boundaries.

5Guided phases
18CSF outcomes
92Mapped controls
23D3FEND techniques

Cloud operating model playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Make cloud risk visible, owned, configured, monitored, and resilient across providers and services.

Cloud security failures usually cross identity, configuration, data, provider, logging, and ownership boundaries. This playbook keeps those decisions connected.

Built forCloud teams · Security architects · Platform engineers · Risk teams · Application owners
01

Guided phase

Govern providers and services

Prioritize cloud providers and services, establish requirements, and monitor third-party risk.

Actions to take

  • Maintain an approved cloud-service inventory.
  • Define shared-responsibility, logging, incident, exit, and evidence requirements.
  • Monitor provider changes and inherited-service risk.
GV.SC-05Govern · Cybersecurity Supply Chain Risk Management

Supply Chain Requirements in Agreements

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

6 controls4 800-1711 800-172
GV.SC-07Govern · Cybersecurity Supply Chain Risk Management

Monitor Supplier and Third-Party Risk

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

5 controls3 800-1711 800-172
02

Guided phase

Map the cloud estate

Inventory cloud resources, services, identities, data, and flows and manage change risk.

Actions to take

  • Discover accounts, subscriptions, projects, regions, services, and external exposure.
  • Map data movement and cross-account trust.
  • Track exceptions, ephemeral resources, and infrastructure-as-code changes.
ID.AM-02Identify · Asset Management

Software, Service, and System Inventories

Inventories of software, services, and systems managed by the organization are maintained

5 controls3 800-1714 800-172
ID.AM-03Identify · Asset Management

Network Communication and Data Flow Representations

Representations of the organization’s authorized network communication and internal and external network data flows are maintained

6 controls3 800-17111 800-1724 D3FEND6 mitigations
03

Guided phase

Secure identity and configuration

Control cloud identities, authentication, authorization, and configuration baselines.

Actions to take

  • Separate human, service, workload, and break-glass identities.
  • Apply least privilege to control planes and automation.
  • Detect configuration drift and prevent insecure defaults.
PR.AA-01Protect · Identity Management, Authentication, and Access Control

Manage Identities and Credentials

Identities and credentials for authorized users, services, and hardware are managed by the organization

14 controls10 800-1717 800-1725 D3FEND5 mitigations
PR.AA-03Protect · Identity Management, Authentication, and Access Control

Authenticate Users, Services, and Hardware

Users, services, and hardware are authenticated

10 controls8 800-1715 800-1723 D3FEND4 mitigations
PR.AA-05Protect · Identity Management, Authentication, and Access Control

Manage Permissions and Authorizations

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

12 controls10 800-1719 800-17212 D3FEND17 mitigations
04

Guided phase

Protect data and telemetry

Protect cloud data and generate the records needed for accountability and detection.

Actions to take

  • Define encryption, key, secret, and data-residency requirements.
  • Enable control-plane, identity, network, data, and workload logging.
  • Protect logs from tenant compromise and deletion.
05

Guided phase

Monitor and sustain resilience

Monitor providers and runtime environments and maintain capacity for adverse conditions.

Actions to take

  • Correlate provider, identity, network, workload, and application telemetry.
  • Test regional, account, identity-provider, and service dependency failures.
  • Define capacity, quota, and recovery thresholds.
DE.CM-06Detect · Continuous Monitoring

Monitor External Service Providers

External service provider activities and services are monitored to find potentially adverse events

5 controls3 800-1715 800-1722 D3FEND3 mitigations
DE.CM-09Detect · Continuous Monitoring

Monitor Computing and Runtime Environments

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

12 controls6 800-17119 800-1727 D3FEND10 mitigations

Completion evidence

What should exist when this playbook is working?

  • Approved cloud provider and service inventory.
  • Shared-responsibility and contractual security requirements.
  • Cloud resource, identity, data, and flow inventory.
  • Configuration baseline and drift-remediation evidence.
  • Protected centralized logging and cloud detection coverage.
  • Resilience tests for region, provider, identity, and capacity failures.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.