Mission and audience
Make every identity known, appropriately trusted, narrowly authorized, observable, and removable.
Identity is both a control plane and a common attack path. This playbook turns identity governance, authentication, authorization, and monitoring into one connected operating model.
Guided phase
Inventory and proof identities
Establish authoritative records for people, services, devices, and credentials before granting access.
Actions to take
- Define authoritative identity sources and owners.
- Inventory service, workload, device, and emergency accounts.
- Document proofing, credential binding, joiner, mover, and leaver rules.
Manage Identities and Credentials
Identities and credentials for authorized users, services, and hardware are managed by the organization
Identity Proofing and Credential Binding
Identities are proofed and bound to credentials based on the context of interactions
Guided phase
Authenticate and protect assertions
Use context-appropriate authentication and protect the assertions that systems rely on.
Actions to take
- Require phishing-resistant or stronger authentication where risk justifies it.
- Protect tokens, assertions, federation paths, and recovery channels.
- Test reauthentication and step-up conditions.
Authenticate Users, Services, and Hardware
Users, services, and hardware are authenticated
Protect and Verify Identity Assertions
Identity assertions are protected, conveyed, and verified
Guided phase
Authorize and limit privilege
Define, enforce, and review permissions using least privilege and separation of duties.
Actions to take
- Assign accountable owners for privileged roles.
- Remove standing access where time-bound access is feasible.
- Review entitlements, toxic combinations, and emergency access.
Manage Permissions and Authorizations
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Roles, Responsibilities, and Authorities
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Guided phase
Monitor identity use
Detect misuse, drift, anomalous authentication, and inappropriate privilege use.
Actions to take
- Correlate authentication, authorization, directory, and workload telemetry.
- Define high-value identity alerts and investigation paths.
- Measure dormant, orphaned, overprivileged, and shared identities.
Monitor Personnel Activity and Technology Use
Personnel activity and technology usage are monitored to find potentially adverse events
Analyze Potentially Adverse Events
Potentially adverse events are analyzed to better understand associated activities
Guided phase
Improve the identity program
Use operations, incidents, reviews, and policy changes to continuously improve identity controls.
Actions to take
- Track recurring access exceptions and control failures.
- Update policy when technology, risk, or business dependencies change.
- Retire identity debt through measurable improvement work.
Improvements from Operations
Improvements are identified from execution of operational processes, procedures, and activities
Review and Update Cybersecurity Policy
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
Completion evidence
What should exist when this playbook is working?
- Current identity and privileged-account inventories with accountable owners.
- Documented authentication and credential-binding standards.
- Approved role, entitlement, and separation-of-duties model.
- Evidence of periodic access reviews and timely deprovisioning.
- Identity telemetry, alert logic, investigation runbooks, and test results.
- Metrics for orphaned, dormant, shared, and overprivileged accounts.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.