Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Identity and Privileged Access

Build a governed identity lifecycle, strengthen authentication, enforce least privilege, and monitor how human, service, and device identities are used.

5Guided phases
10CSF outcomes
75Mapped controls
29D3FEND techniques

Identity defense playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Make every identity known, appropriately trusted, narrowly authorized, observable, and removable.

Identity is both a control plane and a common attack path. This playbook turns identity governance, authentication, authorization, and monitoring into one connected operating model.

Built forIdentity teams · Security architects · Cloud teams · System owners · Auditors
01

Guided phase

Inventory and proof identities

Establish authoritative records for people, services, devices, and credentials before granting access.

Actions to take

  • Define authoritative identity sources and owners.
  • Inventory service, workload, device, and emergency accounts.
  • Document proofing, credential binding, joiner, mover, and leaver rules.
PR.AA-01Protect · Identity Management, Authentication, and Access Control

Manage Identities and Credentials

Identities and credentials for authorized users, services, and hardware are managed by the organization

14 controls10 800-1717 800-1725 D3FEND5 mitigations
PR.AA-02Protect · Identity Management, Authentication, and Access Control

Identity Proofing and Credential Binding

Identities are proofed and bound to credentials based on the context of interactions

1 controls1 800-172
02

Guided phase

Authenticate and protect assertions

Use context-appropriate authentication and protect the assertions that systems rely on.

Actions to take

  • Require phishing-resistant or stronger authentication where risk justifies it.
  • Protect tokens, assertions, federation paths, and recovery channels.
  • Test reauthentication and step-up conditions.
PR.AA-03Protect · Identity Management, Authentication, and Access Control

Authenticate Users, Services, and Hardware

Users, services, and hardware are authenticated

10 controls8 800-1715 800-1723 D3FEND4 mitigations
03

Guided phase

Authorize and limit privilege

Define, enforce, and review permissions using least privilege and separation of duties.

Actions to take

  • Assign accountable owners for privileged roles.
  • Remove standing access where time-bound access is feasible.
  • Review entitlements, toxic combinations, and emergency access.
PR.AA-05Protect · Identity Management, Authentication, and Access Control

Manage Permissions and Authorizations

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

12 controls10 800-1719 800-17212 D3FEND17 mitigations
GV.RR-02Govern · Roles, Responsibilities, and Authorities

Roles, Responsibilities, and Authorities

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

6 controls
04

Guided phase

Monitor identity use

Detect misuse, drift, anomalous authentication, and inappropriate privilege use.

Actions to take

  • Correlate authentication, authorization, directory, and workload telemetry.
  • Define high-value identity alerts and investigation paths.
  • Measure dormant, orphaned, overprivileged, and shared identities.
DE.CM-03Detect · Continuous Monitoring

Monitor Personnel Activity and Technology Use

Personnel activity and technology usage are monitored to find potentially adverse events

6 controls3 800-1713 800-1724 D3FEND5 mitigations
DE.AE-02Detect · Adverse Event Analysis

Analyze Potentially Adverse Events

Potentially adverse events are analyzed to better understand associated activities

4 controls4 800-1719 800-1725 D3FEND5 mitigations
05

Guided phase

Improve the identity program

Use operations, incidents, reviews, and policy changes to continuously improve identity controls.

Actions to take

  • Track recurring access exceptions and control failures.
  • Update policy when technology, risk, or business dependencies change.
  • Retire identity debt through measurable improvement work.
ID.IM-03Identify · Improvement

Improvements from Operations

Improvements are identified from execution of operational processes, procedures, and activities

39 controls14 800-17113 800-17221 D3FEND17 mitigations
GV.PO-02Govern · Policy

Review and Update Cybersecurity Policy

Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission

20 controls1 800-171

Completion evidence

What should exist when this playbook is working?

  • Current identity and privileged-account inventories with accountable owners.
  • Documented authentication and credential-binding standards.
  • Approved role, entitlement, and separation-of-duties model.
  • Evidence of periodic access reviews and timely deprovisioning.
  • Identity telemetry, alert logic, investigation runbooks, and test results.
  • Metrics for orphaned, dormant, shared, and overprivileged accounts.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.