Mission and audience
Protect information according to its value, sensitivity, lifecycle, use, movement, and recovery needs.
Data protection is more than encryption. It depends on knowing the data, controlling access, safeguarding each state, monitoring use, managing lifecycle, and proving recoverability.
Guided phase
Inventory and classify data
Know what data exists, why it matters, where it moves, and how long it should remain.
Actions to take
- Inventory data types, stores, flows, owners, and processors.
- Prioritize data based on mission, legal, privacy, and contractual impact.
- Define lifecycle and disposal requirements.
Asset Prioritization
Assets are prioritized based on classification, criticality, resources, and impact on the mission
Data and Metadata Inventories
Inventories of data and corresponding metadata for designated data types are maintained
Asset Life-Cycle Management
Systems, hardware, software, services, and data are managed throughout their life cycles
Guided phase
Control access and use
Define and enforce permissions, entitlements, and authorizations around sensitive data.
Actions to take
- Map roles and services to permitted data actions.
- Review broad access, shared repositories, exports, and service identities.
- Separate administrative, data, and key-management privileges.
Manage Permissions and Authorizations
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Guided phase
Protect data in every state
Apply appropriate safeguards at rest, in transit, and in use.
Actions to take
- Define cryptographic, tokenization, masking, isolation, and integrity requirements.
- Protect keys, secrets, certificates, and trust anchors.
- Validate application and workflow handling of sensitive data.
Protect Data at Rest
The confidentiality, integrity, and availability of data-at-rest are protected
Protect Data in Transit
The confidentiality, integrity, and availability of data-in-transit are protected
Protect Data in Use
The confidentiality, integrity, and availability of data-in-use are protected
Guided phase
Protect recovery and resilience
Create and test backups and resilience mechanisms that preserve confidentiality and integrity.
Actions to take
- Align backup design to data criticality and recovery objectives.
- Protect backups from unauthorized access, deletion, and corruption.
- Test data restoration and integrity validation.
Create, Protect, Maintain, and Test Backups
Backups of data are created, protected, maintained, and tested
Resilience Mechanisms
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Guided phase
Monitor and preserve evidence
Observe data use, preserve incident data, and verify restoration assets before recovery.
Actions to take
- Monitor sensitive data access, movement, and abnormal use.
- Preserve data and metadata provenance during investigations.
- Verify recovery assets before restoring production.
Monitor Computing and Runtime Environments
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Preserve Incident Data and Metadata
Incident data and metadata are collected, and their integrity and provenance are preserved
Verify Backups and Restoration Assets
The integrity of backups and other restoration assets is verified before using them for restoration
Completion evidence
What should exist when this playbook is working?
- Data and metadata inventory with owners and classifications.
- Data-flow and external-sharing documentation.
- Access model and periodic authorization reviews.
- Encryption, key, integrity, masking, and disposal evidence.
- Backup and restoration test results.
- Monitoring, investigation, and provenance records.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.