Mission and audience
Know where CUI exists, which requirements apply, how safeguards are implemented, and what evidence supports the claim.
CUI protection starts with contractual scope and data understanding, then depends on access, data safeguards, monitoring, incident evidence, recovery, and disciplined assessment.
Guided phase
Scope and govern CUI
Understand governing obligations, assign responsibility, and establish enforceable policy.
Actions to take
- Identify contracts, clauses, agency direction, and assessment expectations.
- Define the CUI system boundary, owners, and decision authorities.
- Document selected enhanced requirements separately from baseline CUI requirements.
Legal, Regulatory, and Contractual Requirements
Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
Roles, Responsibilities, and Authorities
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Establish and Enforce Cybersecurity Policy
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Guided phase
Identify CUI and critical assets
Maintain data inventories, classifications, priorities, and lifecycle responsibilities.
Actions to take
- Inventory CUI types, repositories, flows, users, and external services.
- Prioritize assets by mission and impact.
- Define retention, sharing, transfer, archival, and disposal rules.
Asset Prioritization
Assets are prioritized based on classification, criticality, resources, and impact on the mission
Data and Metadata Inventories
Inventories of data and corresponding metadata for designated data types are maintained
Asset Life-Cycle Management
Systems, hardware, software, services, and data are managed throughout their life cycles
Guided phase
Protect access and data
Limit access and protect CUI at rest, in transit, and in use.
Actions to take
- Enforce least privilege and separation of duties.
- Apply approved cryptography and key management.
- Control copy, export, remote access, collaboration, and removable media.
Manage Permissions and Authorizations
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Protect Data at Rest
The confidentiality, integrity, and availability of data-at-rest are protected
Protect Data in Transit
The confidentiality, integrity, and availability of data-in-transit are protected
Protect Data in Use
The confidentiality, integrity, and availability of data-in-use are protected
Guided phase
Monitor and preserve evidence
Generate logs, monitor the environment, and preserve incident data and provenance.
Actions to take
- Map each requirement to implementation and evidence.
- Protect logs and assessment evidence from alteration.
- Prepare for incident reporting and investigation obligations.
Generate and Provide Log Records
Log records are generated and made available for continuous monitoring
Monitor Computing and Runtime Environments
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Preserve Incident Data and Metadata
Incident data and metadata are collected, and their integrity and provenance are preserved
Guided phase
Recover and assess
Protect recovery assets and use assessments to improve the CUI program.
Actions to take
- Test restoration of CUI systems and data.
- Verify recovery assets before use.
- Track plans of action, evidence gaps, and completed improvements.
Create, Protect, Maintain, and Test Backups
Backups of data are created, protected, maintained, and tested
Verify Backups and Restoration Assets
The integrity of backups and other restoration assets is verified before using them for restoration
Improvements from Evaluations
Improvements are identified from evaluations
Completion evidence
What should exist when this playbook is working?
- Documented contractual and regulatory CUI scope.
- Current CUI asset, data, user, service, and flow inventory.
- Requirement-to-implementation and requirement-to-evidence traceability.
- System security plan, assessment records, and managed plans of action.
- Access, encryption, logging, incident, and recovery evidence.
- Agency-selected SP 800-172 enhanced-requirement decisions where applicable.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.