Mission and audience
Replace implicit trust with verified, least-privilege, context-aware access decisions that remain observable and revisable.
Zero Trust is an architecture and operating model, not a product. This playbook organizes the asset, identity, data, policy, enforcement, and telemetry decisions needed to make it real.
Guided phase
Map resources and flows
Know the users, devices, workloads, data, services, and communication paths involved in each trust decision.
Actions to take
- Inventory protected resources and data flows.
- Identify trust boundaries and legacy implicit trust.
- Prioritize high-value access paths for redesign.
Hardware Inventories
Inventories of hardware managed by the organization are maintained
Software, Service, and System Inventories
Inventories of software, services, and systems managed by the organization are maintained
Network Communication and Data Flow Representations
Representations of the organization’s authorized network communication and internal and external network data flows are maintained
Data and Metadata Inventories
Inventories of data and corresponding metadata for designated data types are maintained
Guided phase
Verify identities and context
Authenticate users, services, and hardware and protect the assertions used in access decisions.
Actions to take
- Strengthen identity lifecycle and authentication assurance.
- Protect tokens, federation, device identity, and recovery paths.
- Use context without making opaque or discriminatory decisions.
Manage Identities and Credentials
Identities and credentials for authorized users, services, and hardware are managed by the organization
Authenticate Users, Services, and Hardware
Users, services, and hardware are authenticated
Protect and Verify Identity Assertions
Identity assertions are protected, conveyed, and verified
Guided phase
Enforce least privilege
Authorize each access based on policy, risk, and current context while limiting lateral movement.
Actions to take
- Define policy decision and enforcement points.
- Reduce standing privilege and broad network reachability.
- Test deny, fail-safe, emergency, and degraded modes.
Manage Permissions and Authorizations
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Protect Networks and Environments
Networks and environments are protected from unauthorized logical access and usage
Guided phase
Protect data and workloads
Apply safeguards to data at rest, in transit, and in use and maintain secure configurations.
Actions to take
- Bind protection to data sensitivity and workload context.
- Harden workload identities, configurations, and secrets.
- Protect management planes and policy infrastructure.
Protect Data at Rest
The confidentiality, integrity, and availability of data-at-rest are protected
Protect Data in Transit
The confidentiality, integrity, and availability of data-in-transit are protected
Protect Data in Use
The confidentiality, integrity, and availability of data-in-use are protected
Configuration Management
Configuration management practices are established and applied
Guided phase
Observe and adapt decisions
Monitor runtime behavior, manage exceptions, and improve policy using operational evidence.
Actions to take
- Log access decisions, enforcement outcomes, and policy changes.
- Review exceptions and failed trust decisions.
- Tune policy based on incidents, tests, and user impact.
Monitor Computing and Runtime Environments
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Manage Changes and Exceptions
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
Improvements from Operations
Improvements are identified from execution of operational processes, procedures, and activities
Completion evidence
What should exist when this playbook is working?
- Protected-resource and data-flow inventory.
- Defined policy decision, policy administration, and enforcement architecture.
- Identity, device, workload, and data assurance requirements.
- Least-privilege and segmentation implementation evidence.
- Access-decision and policy-change telemetry.
- Documented exception, degraded-mode, and continuous-improvement processes.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.