Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Vulnerability Management

Connect asset context, vulnerability discovery, threat and impact analysis, risk-based prioritization, remediation, verification, and continuous improvement.

5Guided phases
16CSF outcomes
81Mapped controls
28D3FEND techniques

Exposure reduction playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Reduce exploitable exposure through complete coverage, defensible prioritization, accountable remediation, and verified closure.

A scan result is not a risk decision. This playbook connects vulnerabilities to assets, threats, business impact, change control, remediation ownership, and evidence that the weakness is actually closed.

Built forVulnerability teams · System owners · Platform teams · Application teams · Risk leaders
01

Guided phase

Establish asset context

Know the assets, software, business priority, and ownership needed to interpret findings.

Actions to take

  • Normalize asset identity across discovery and ownership systems.
  • Prioritize assets by mission, exposure, data, and dependency.
  • Track unsupported, unmanaged, ephemeral, and externally exposed assets.
ID.AM-02Identify · Asset Management

Software, Service, and System Inventories

Inventories of software, services, and systems managed by the organization are maintained

5 controls3 800-1714 800-172
ID.AM-05Identify · Asset Management

Asset Prioritization

Assets are prioritized based on classification, criticality, resources, and impact on the mission

3 controls1 800-1713 800-1727 D3FEND4 mitigations
02

Guided phase

Discover and validate weaknesses

Identify vulnerabilities and maintain a process for receiving and analyzing disclosures.

Actions to take

  • Combine scanning, testing, code analysis, configuration review, and disclosure channels.
  • Validate findings and remove duplicates or false positives.
  • Cover development, build, deployment, and runtime environments.
ID.RA-08Identify · Risk Assessment

Vulnerability Disclosure Processes

Processes are established for receiving, analyzing, and responding to vulnerability disclosures

1 controls1 800-1711 800-1726 D3FEND9 mitigations
PR.PS-06Protect · Platform Security

Secure Software Development

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

7 controls1 800-1715 D3FEND6 mitigations
03

Guided phase

Prioritize real risk

Use threats, likelihood, impact, exploitability, and asset context to understand inherent risk.

Actions to take

  • Incorporate threat intelligence and observed exploitation.
  • Account for compensating controls and attack paths.
  • Document why priorities differ from raw severity scores.
ID.RA-03Identify · Risk Assessment

Identify Internal and External Threats

Internal and external threats to the organization are identified and recorded

4 controls2 800-1714 800-1727 D3FEND4 mitigations
ID.RA-04Identify · Risk Assessment

Estimate Threat Likelihood and Impact

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

6 controls1 800-1713 800-1727 D3FEND4 mitigations
ID.RA-05Identify · Risk Assessment

Understand Inherent Risk

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

4 controls2 800-1714 800-1727 D3FEND4 mitigations
04

Guided phase

Remediate and track exceptions

Choose, prioritize, plan, and track remediation or other risk responses through controlled change.

Actions to take

  • Assign accountable owners and risk-based deadlines.
  • Manage exceptions with expiration, evidence, and approval.
  • Coordinate patching, configuration, replacement, and removal.
05

Guided phase

Verify closure and improve

Prove remediation worked and improve the process from evaluations and operations.

Actions to take

  • Rescan or retest after remediation.
  • Measure recurrence, aging, exception debt, and coverage gaps.
  • Improve discovery and remediation using operational feedback.
ID.IM-03Identify · Improvement

Improvements from Operations

Improvements are identified from execution of operational processes, procedures, and activities

39 controls14 800-17113 800-17221 D3FEND17 mitigations
DE.CM-09Detect · Continuous Monitoring

Monitor Computing and Runtime Environments

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

12 controls6 800-17119 800-1727 D3FEND10 mitigations

Completion evidence

What should exist when this playbook is working?

  • Authoritative asset, software, ownership, and criticality context.
  • Documented discovery coverage and vulnerability intake process.
  • Risk-based prioritization rationale beyond severity score alone.
  • Remediation ownership, deadlines, exceptions, and approvals.
  • Retest or rescan evidence for closure.
  • Metrics for coverage, age, recurrence, exceptions, and time to verified remediation.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.