Mission and audience
Reduce exploitable exposure through complete coverage, defensible prioritization, accountable remediation, and verified closure.
A scan result is not a risk decision. This playbook connects vulnerabilities to assets, threats, business impact, change control, remediation ownership, and evidence that the weakness is actually closed.
Guided phase
Establish asset context
Know the assets, software, business priority, and ownership needed to interpret findings.
Actions to take
- Normalize asset identity across discovery and ownership systems.
- Prioritize assets by mission, exposure, data, and dependency.
- Track unsupported, unmanaged, ephemeral, and externally exposed assets.
Hardware Inventories
Inventories of hardware managed by the organization are maintained
Software, Service, and System Inventories
Inventories of software, services, and systems managed by the organization are maintained
Asset Prioritization
Assets are prioritized based on classification, criticality, resources, and impact on the mission
Guided phase
Discover and validate weaknesses
Identify vulnerabilities and maintain a process for receiving and analyzing disclosures.
Actions to take
- Combine scanning, testing, code analysis, configuration review, and disclosure channels.
- Validate findings and remove duplicates or false positives.
- Cover development, build, deployment, and runtime environments.
Identify and Record Vulnerabilities
Vulnerabilities in assets are identified, validated, and recorded
Vulnerability Disclosure Processes
Processes are established for receiving, analyzing, and responding to vulnerability disclosures
Secure Software Development
Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
Guided phase
Prioritize real risk
Use threats, likelihood, impact, exploitability, and asset context to understand inherent risk.
Actions to take
- Incorporate threat intelligence and observed exploitation.
- Account for compensating controls and attack paths.
- Document why priorities differ from raw severity scores.
Identify Internal and External Threats
Internal and external threats to the organization are identified and recorded
Estimate Threat Likelihood and Impact
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
Understand Inherent Risk
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Guided phase
Remediate and track exceptions
Choose, prioritize, plan, and track remediation or other risk responses through controlled change.
Actions to take
- Assign accountable owners and risk-based deadlines.
- Manage exceptions with expiration, evidence, and approval.
- Coordinate patching, configuration, replacement, and removal.
Select and Track Risk Responses
Risk responses are chosen, prioritized, planned, tracked, and communicated
Manage Changes and Exceptions
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
Configuration Management
Configuration management practices are established and applied
Software Maintenance and Removal
Software is maintained, replaced, and removed commensurate with risk
Guided phase
Verify closure and improve
Prove remediation worked and improve the process from evaluations and operations.
Actions to take
- Rescan or retest after remediation.
- Measure recurrence, aging, exception debt, and coverage gaps.
- Improve discovery and remediation using operational feedback.
Improvements from Evaluations
Improvements are identified from evaluations
Improvements from Operations
Improvements are identified from execution of operational processes, procedures, and activities
Monitor Computing and Runtime Environments
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Completion evidence
What should exist when this playbook is working?
- Authoritative asset, software, ownership, and criticality context.
- Documented discovery coverage and vulnerability intake process.
- Risk-based prioritization rationale beyond severity score alone.
- Remediation ownership, deadlines, exceptions, and approvals.
- Retest or rescan evidence for closure.
- Metrics for coverage, age, recurrence, exceptions, and time to verified remediation.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.