Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Zero Trust

Build explicit trust decisions around identity, devices, workloads, networks, data, policy enforcement, telemetry, and continuous adaptation.

5Guided phases
16CSF outcomes
112Mapped controls
34D3FEND techniques

Architecture playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Replace implicit trust with verified, least-privilege, context-aware access decisions that remain observable and revisable.

Zero Trust is an architecture and operating model, not a product. This playbook organizes the asset, identity, data, policy, enforcement, and telemetry decisions needed to make it real.

Built forEnterprise architects · Identity teams · Network teams · Cloud teams · Security leaders
01

Guided phase

Map resources and flows

Know the users, devices, workloads, data, services, and communication paths involved in each trust decision.

Actions to take

  • Inventory protected resources and data flows.
  • Identify trust boundaries and legacy implicit trust.
  • Prioritize high-value access paths for redesign.
ID.AM-02Identify · Asset Management

Software, Service, and System Inventories

Inventories of software, services, and systems managed by the organization are maintained

5 controls3 800-1714 800-172
ID.AM-03Identify · Asset Management

Network Communication and Data Flow Representations

Representations of the organization’s authorized network communication and internal and external network data flows are maintained

6 controls3 800-17111 800-1724 D3FEND6 mitigations
02

Guided phase

Verify identities and context

Authenticate users, services, and hardware and protect the assertions used in access decisions.

Actions to take

  • Strengthen identity lifecycle and authentication assurance.
  • Protect tokens, federation, device identity, and recovery paths.
  • Use context without making opaque or discriminatory decisions.
PR.AA-01Protect · Identity Management, Authentication, and Access Control

Manage Identities and Credentials

Identities and credentials for authorized users, services, and hardware are managed by the organization

14 controls10 800-1717 800-1725 D3FEND5 mitigations
PR.AA-03Protect · Identity Management, Authentication, and Access Control

Authenticate Users, Services, and Hardware

Users, services, and hardware are authenticated

10 controls8 800-1715 800-1723 D3FEND4 mitigations
03

Guided phase

Enforce least privilege

Authorize each access based on policy, risk, and current context while limiting lateral movement.

Actions to take

  • Define policy decision and enforcement points.
  • Reduce standing privilege and broad network reachability.
  • Test deny, fail-safe, emergency, and degraded modes.
PR.AA-05Protect · Identity Management, Authentication, and Access Control

Manage Permissions and Authorizations

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

12 controls10 800-1719 800-17212 D3FEND17 mitigations
PR.IR-01Protect · Technology Infrastructure Resilience

Protect Networks and Environments

Networks and environments are protected from unauthorized logical access and usage

5 controls5 800-17115 800-1727 D3FEND15 mitigations
04

Guided phase

Protect data and workloads

Apply safeguards to data at rest, in transit, and in use and maintain secure configurations.

Actions to take

  • Bind protection to data sensitivity and workload context.
  • Harden workload identities, configurations, and secrets.
  • Protect management planes and policy infrastructure.
05

Guided phase

Observe and adapt decisions

Monitor runtime behavior, manage exceptions, and improve policy using operational evidence.

Actions to take

  • Log access decisions, enforcement outcomes, and policy changes.
  • Review exceptions and failed trust decisions.
  • Tune policy based on incidents, tests, and user impact.
DE.CM-09Detect · Continuous Monitoring

Monitor Computing and Runtime Environments

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

12 controls6 800-17119 800-1727 D3FEND10 mitigations
ID.IM-03Identify · Improvement

Improvements from Operations

Improvements are identified from execution of operational processes, procedures, and activities

39 controls14 800-17113 800-17221 D3FEND17 mitigations

Completion evidence

What should exist when this playbook is working?

  • Protected-resource and data-flow inventory.
  • Defined policy decision, policy administration, and enforcement architecture.
  • Identity, device, workload, and data assurance requirements.
  • Least-privilege and segmentation implementation evidence.
  • Access-decision and policy-change telemetry.
  • Documented exception, degraded-mode, and continuous-improvement processes.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.