Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
headphones
Bare Metal Cyber Presents: Framework

Bare Metal Cyber Presents: Framework

Jason Edwards

Bare Metal Cyber Presents: Framework is your go-to podcast for mastering cybersecurity frameworks, with a special focus on the NIST Cybersecurity Framework (CSF) and NIST 800-53. This series breaks down each function, category, and subcategory to help professionals, educators, and organizations understand their structure and real-world applications. Each episode delivers clear, practical insights with examples that make cybersecurity frameworks more accessible and actionable. Whether you're new to cybersecurity or looking to refine your expertise, Framework equips you with the knowledge to strengthen security strategies and compliance efforts. Tune in and build your framework for success!
Share icon

All episodes

Best episodes

Top 10 Bare Metal Cyber Presents: Framework Episodes

Goodpods has curated a list of the 10 best Bare Metal Cyber Presents: Framework episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to Bare Metal Cyber Presents: Framework for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite Bare Metal Cyber Presents: Framework episode by adding your comments to the episode page.

Bare Metal Cyber Presents: Framework - RS.AN-08 - Assessing Incident Magnitude

RS.AN-08 - Assessing Incident Magnitude

Bare Metal Cyber Presents: Framework

play

02/25/25 • 19 min

RS.AN-08 estimates and validates an incident’s magnitude by assessing its scope and impact, searching other targets for indicators of compromise or persistence. This involves manual reviews or automated tools to confirm the extent of damage or spread, refining initial assessments. It quantifies the incident’s true reach.

This subcategory aligns analysis with risk priorities, ensuring resources target the full breadth of an incident, from isolated to systemic effects. It supports effective mitigation by clarifying the scale of response needed. RS.AN-08 ensures a comprehensive grasp of incident consequences.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - RS.AN-06 - Recording Investigation Actions

RS.AN-06 - Recording Investigation Actions

Bare Metal Cyber Presents: Framework

play

02/25/25 • 18 min

RS.AN-06 ensures that all investigative actions during an incident—like system checks or containment steps—are meticulously recorded, with integrity and provenance preserved. This involves immutable logs by responders and detailed documentation by the incident lead, safeguarding evidence for legal or audit purposes. It maintains a reliable investigation trail.

This subcategory supports accountability and forensics by ensuring records are tamper-proof and traceable, aligning with risk management needs. It enables accurate post-incident reviews and lessons learned, enhancing future responses. RS.AN-06 upholds the credibility of incident investigations.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - RS.AN-03 - Investigating Incident Causes

RS.AN-03 - Investigating Incident Causes

Bare Metal Cyber Presents: Framework

play

02/25/25 • 18 min

RS.AN-03 conducts detailed analysis to reconstruct incident events, identify involved assets, and pinpoint root causes, such as exploited vulnerabilities or threat actors. This includes examining deception technologies for attacker behavior insights, aiming to understand both immediate triggers and systemic issues. It provides the foundation for effective response and prevention.

This subcategory enhances response by delivering actionable findings, aligning analysis with risk priorities to address critical weaknesses. It supports forensics and recovery by uncovering underlying causes, reducing recurrence risks. RS.AN-03 drives a thorough understanding of incident dynamics.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - DE.CM-06 - Monitoring External Service Providers

DE.CM-06 - Monitoring External Service Providers

Bare Metal Cyber Presents: Framework

play

02/25/25 • 19 min

DE.CM-06 requires monitoring the activities and services of external providers—like cloud platforms or ISPs—to detect adverse events that could impact the organization. This includes tracking remote administration or onsite maintenance by third parties for deviations from expected behavior. It ensures external dependencies don’t become blind spots.

This subcategory mitigates risks from outsourced services by maintaining oversight, aligning monitoring with contractual security expectations. It supports a comprehensive security posture by extending vigilance beyond organizational boundaries. DE.CM-06 safeguards against threats originating in the supply chain.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - DE.CM-02 - Watching the Physical Environment for Threats
play

02/25/25 • 18 min

DE.CM-02 involves monitoring the physical environment housing technology assets to detect adverse events, such as unauthorized access or tampering with controls like locks and alarms. This includes reviewing logs from badge readers and visitor records for unusual patterns, supplemented by tools like cameras and security guards. It protects the physical layer of cybersecurity.

This subcategory ensures that physical breaches, which could enable logical attacks, are identified quickly, aligning monitoring with risk levels for critical areas. It supports a holistic security approach by integrating physical oversight with digital defenses. DE.CM-02 safeguards assets from tangible threats that could compromise operations.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - DE.CM-01 - Monitoring Networks for Adverse Events

DE.CM-01 - Monitoring Networks for Adverse Events

Bare Metal Cyber Presents: Framework

play

02/25/25 • 18 min

DE.CM-01 focuses on continuously monitoring networks and network services, such as DNS and BGP, to detect potentially adverse events like unauthorized connections or traffic anomalies. This involves comparing real-time network flows against established baselines to identify deviations that could signal a security threat. It ensures visibility into network activity to catch issues early.

This subcategory strengthens proactive defense by monitoring both wired and wireless networks, including facilities for rogue access points, aligning efforts with risk priorities. It supports rapid detection of compromises by maintaining a comprehensive view of network behavior. DE.CM-01 is a cornerstone of network security vigilance.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - PR.PS-06 - Securing the Software Development Process

PR.PS-06 - Securing the Software Development Process

Bare Metal Cyber Presents: Framework

play

02/25/25 • 17 min

PR.PS-06 integrates secure development practices into the software lifecycle, protecting code from tampering and ensuring releases have minimal vulnerabilities. This includes monitoring performance to maintain security in production and securely disposing of software when obsolete. It ensures organization-developed software meets high security standards.

This subcategory enhances software integrity by embedding cybersecurity from design to deployment, reducing exploitable flaws. It aligns development with risk management goals, supporting ongoing improvement through performance tracking. PR.PS-06 fosters secure, reliable software outputs.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - PR.PS-03 - Managing Hardware Lifecycles

PR.PS-03 - Managing Hardware Lifecycles

Bare Metal Cyber Presents: Framework

play

02/25/25 • 16 min

PR.PS-03 ensures hardware is maintained, replaced, or securely removed based on its security capabilities and risk profile, such as replacing devices unable to support modern software protections. This includes planning for end-of-life support and disposing of hardware responsibly to prevent data leakage. It keeps the physical infrastructure secure and functional.

This subcategory reduces risks by ensuring hardware meets evolving security needs, with auditable disposal processes to maintain accountability. It aligns hardware management with organizational risk strategies, prioritizing critical systems. PR.PS-03 sustains a secure hardware lifecycle.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - PR.PS-02 - Maintaining Software Security

PR.PS-02 - Maintaining Software Security

Bare Metal Cyber Presents: Framework

play

02/25/25 • 16 min

PR.PS-02 focuses on maintaining, replacing, or removing software based on risk, including timely patching, updating container images, and phasing out end-of-life versions. This ensures software remains supported and secure, reducing vulnerabilities from outdated or unauthorized applications. It includes plans for obsolescence to manage lifecycle risks.

This subcategory strengthens resilience by uninstalling unnecessary or risky software components that could be exploited, aligning updates with vulnerability management timelines. It balances security with operational needs, ensuring only current, necessary software persists. PR.PS-02 keeps the software environment lean and protected.

bookmark
plus icon
share episode
Bare Metal Cyber Presents: Framework - RS.MI-02 - Eradicating Incident Threats

RS.MI-02 - Eradicating Incident Threats

Bare Metal Cyber Presents: Framework

play

02/25/25 • 18 min

RS.MI-02 ensures incidents are fully eradicated, removing threats like malware or unauthorized access through automated system features or manual responder actions. This can involve third-party support, such as MSSPs, to eliminate root causes and residual risks. It restores systems to a secure state.

This subcategory aligns eradication with risk goals, ensuring complete threat removal to prevent recurrence, balancing speed with thoroughness. It supports recovery by clearing the path for safe restoration. RS.MI-02 finalizes the mitigation process with decisive action.

bookmark
plus icon
share episode

Show more best episodes

Toggle view more icon

FAQ

How many episodes does Bare Metal Cyber Presents: Framework have?

Bare Metal Cyber Presents: Framework currently has 114 episodes available.

What topics does Bare Metal Cyber Presents: Framework cover?

The podcast is about Educational, Hacking, Podcasts, Technology, Education and Cybersecurity.

What is the most popular episode on Bare Metal Cyber Presents: Framework?

The episode title 'RC.CO-03 - Communicating Recovery Progress' is the most popular.

What is the average episode length on Bare Metal Cyber Presents: Framework?

The average episode length on Bare Metal Cyber Presents: Framework is 20 minutes.

When was the first episode of Bare Metal Cyber Presents: Framework?

The first episode of Bare Metal Cyber Presents: Framework was released on Feb 4, 2025.

Show more FAQ

Toggle view more icon

Comments