Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Data Protection

Inventory and prioritize data, enforce access, protect data in every state, maintain trusted backups, and preserve evidence during incidents and recovery.

5Guided phases
12CSF outcomes
77Mapped controls
29D3FEND techniques

Information protection playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Protect information according to its value, sensitivity, lifecycle, use, movement, and recovery needs.

Data protection is more than encryption. It depends on knowing the data, controlling access, safeguarding each state, monitoring use, managing lifecycle, and proving recoverability.

Built forData owners · Security architects · Privacy teams · Cloud teams · Application teams
01

Guided phase

Inventory and classify data

Know what data exists, why it matters, where it moves, and how long it should remain.

Actions to take

  • Inventory data types, stores, flows, owners, and processors.
  • Prioritize data based on mission, legal, privacy, and contractual impact.
  • Define lifecycle and disposal requirements.
ID.AM-05Identify · Asset Management

Asset Prioritization

Assets are prioritized based on classification, criticality, resources, and impact on the mission

3 controls1 800-1713 800-1727 D3FEND4 mitigations
ID.AM-08Identify · Asset Management

Asset Life-Cycle Management

Systems, hardware, software, services, and data are managed throughout their life cycles

15 controls5 800-1713 D3FEND5 mitigations
02

Guided phase

Control access and use

Define and enforce permissions, entitlements, and authorizations around sensitive data.

Actions to take

  • Map roles and services to permitted data actions.
  • Review broad access, shared repositories, exports, and service identities.
  • Separate administrative, data, and key-management privileges.
PR.AA-05Protect · Identity Management, Authentication, and Access Control

Manage Permissions and Authorizations

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

12 controls10 800-1719 800-17212 D3FEND17 mitigations
03

Guided phase

Protect data in every state

Apply appropriate safeguards at rest, in transit, and in use.

Actions to take

  • Define cryptographic, tokenization, masking, isolation, and integrity requirements.
  • Protect keys, secrets, certificates, and trust anchors.
  • Validate application and workflow handling of sensitive data.
04

Guided phase

Protect recovery and resilience

Create and test backups and resilience mechanisms that preserve confidentiality and integrity.

Actions to take

  • Align backup design to data criticality and recovery objectives.
  • Protect backups from unauthorized access, deletion, and corruption.
  • Test data restoration and integrity validation.
PR.IR-03Protect · Technology Infrastructure Resilience

Resilience Mechanisms

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

9 controls1 800-1712 D3FEND4 mitigations
05

Guided phase

Monitor and preserve evidence

Observe data use, preserve incident data, and verify restoration assets before recovery.

Actions to take

  • Monitor sensitive data access, movement, and abnormal use.
  • Preserve data and metadata provenance during investigations.
  • Verify recovery assets before restoring production.
DE.CM-09Detect · Continuous Monitoring

Monitor Computing and Runtime Environments

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

12 controls6 800-17119 800-1727 D3FEND10 mitigations
RS.AN-07Respond · Incident Analysis

Preserve Incident Data and Metadata

Incident data and metadata are collected, and their integrity and provenance are preserved

3 controls3 800-1713 800-1723 D3FEND2 mitigations
RC.RP-03Recover · Incident Recovery Plan Execution

Verify Backups and Restoration Assets

The integrity of backups and other restoration assets is verified before using them for restoration

3 controls1 800-1712 800-172

Completion evidence

What should exist when this playbook is working?

  • Data and metadata inventory with owners and classifications.
  • Data-flow and external-sharing documentation.
  • Access model and periodic authorization reviews.
  • Encryption, key, integrity, masking, and disposal evidence.
  • Backup and restoration test results.
  • Monitoring, investigation, and provenance records.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.