Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

CUI Protection

Scope Controlled Unclassified Information, establish responsibility, apply SP 800-171 and selected SP 800-172 safeguards, preserve evidence, and sustain protection.

5Guided phases
16CSF outcomes
111Mapped controls
34D3FEND techniques

Controlled information playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Know where CUI exists, which requirements apply, how safeguards are implemented, and what evidence supports the claim.

CUI protection starts with contractual scope and data understanding, then depends on access, data safeguards, monitoring, incident evidence, recovery, and disciplined assessment.

Built forDefense contractors · System owners · CUI program leaders · Assessors · Security teams
01

Guided phase

Scope and govern CUI

Understand governing obligations, assign responsibility, and establish enforceable policy.

Actions to take

  • Identify contracts, clauses, agency direction, and assessment expectations.
  • Define the CUI system boundary, owners, and decision authorities.
  • Document selected enhanced requirements separately from baseline CUI requirements.
GV.OC-03Govern · Organizational Context

Legal, Regulatory, and Contractual Requirements

Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed

22 controls1 800-171
GV.RR-02Govern · Roles, Responsibilities, and Authorities

Roles, Responsibilities, and Authorities

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

6 controls
GV.PO-01Govern · Policy

Establish and Enforce Cybersecurity Policy

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

20 controls1 800-171
02

Guided phase

Identify CUI and critical assets

Maintain data inventories, classifications, priorities, and lifecycle responsibilities.

Actions to take

  • Inventory CUI types, repositories, flows, users, and external services.
  • Prioritize assets by mission and impact.
  • Define retention, sharing, transfer, archival, and disposal rules.
ID.AM-05Identify · Asset Management

Asset Prioritization

Assets are prioritized based on classification, criticality, resources, and impact on the mission

3 controls1 800-1713 800-1727 D3FEND4 mitigations
ID.AM-08Identify · Asset Management

Asset Life-Cycle Management

Systems, hardware, software, services, and data are managed throughout their life cycles

15 controls5 800-1713 D3FEND5 mitigations
03

Guided phase

Protect access and data

Limit access and protect CUI at rest, in transit, and in use.

Actions to take

  • Enforce least privilege and separation of duties.
  • Apply approved cryptography and key management.
  • Control copy, export, remote access, collaboration, and removable media.
PR.AA-05Protect · Identity Management, Authentication, and Access Control

Manage Permissions and Authorizations

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

12 controls10 800-1719 800-17212 D3FEND17 mitigations
04

Guided phase

Monitor and preserve evidence

Generate logs, monitor the environment, and preserve incident data and provenance.

Actions to take

  • Map each requirement to implementation and evidence.
  • Protect logs and assessment evidence from alteration.
  • Prepare for incident reporting and investigation obligations.
DE.CM-09Detect · Continuous Monitoring

Monitor Computing and Runtime Environments

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

12 controls6 800-17119 800-1727 D3FEND10 mitigations
RS.AN-07Respond · Incident Analysis

Preserve Incident Data and Metadata

Incident data and metadata are collected, and their integrity and provenance are preserved

3 controls3 800-1713 800-1723 D3FEND2 mitigations
05

Guided phase

Recover and assess

Protect recovery assets and use assessments to improve the CUI program.

Actions to take

  • Test restoration of CUI systems and data.
  • Verify recovery assets before use.
  • Track plans of action, evidence gaps, and completed improvements.
RC.RP-03Recover · Incident Recovery Plan Execution

Verify Backups and Restoration Assets

The integrity of backups and other restoration assets is verified before using them for restoration

3 controls1 800-1712 800-172

Completion evidence

What should exist when this playbook is working?

  • Documented contractual and regulatory CUI scope.
  • Current CUI asset, data, user, service, and flow inventory.
  • Requirement-to-implementation and requirement-to-evidence traceability.
  • System security plan, assessment records, and managed plans of action.
  • Access, encryption, logging, incident, and recovery evidence.
  • Agency-selected SP 800-172 enhanced-requirement decisions where applicable.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.