Jason Edwards

Framework: The NIST Cybersecurity Framework (CSF)

**Framework** is your go-to podcast for mastering the **NIST Cybersecurity Framework (CSF)**—the foundational model for building and improving organizational security programs. This series breaks down every function, category, and subcategory within the CSF, helping professionals, educators, and leaders understand how to apply the framework in real-world environments. Each episode delivers clear, practical explanations that connect framework concepts to daily security operations, governance, and risk management practices. Whether you’re new to cybersecurity or refining an established program,...

Author

Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

PR.AA-05 - Enforcing Access Control Policies 25.02.2025

PR.AA-05 establishes a policy-driven approach to managing access permissions, ensuring they are granted based on need (least privilege) and distinct roles (separation of duties). This includes regular reviews to revoke unnecessary privileges, such as when roles change, and enforcement through technical controls. It minimizes the risk of excessive or conflicting access rights. This subcategory supp...

PR.AA-04 - Securing Identity Assertions 25.02.2025

PR.AA-04 focuses on securing identity assertions—digital statements used to convey authentication and user information—across systems like single sign-on or federated environments. This involves protecting assertions with encryption or digital signatures and verifying their integrity to prevent tampering or spoofing. It ensures trust in identity data as it moves between systems. This subcategory e...

PR.AA-03 - Authenticating Users and Devices 25.02.2025

PR.AA-03 mandates the authentication of users, services, and hardware to verify their identity before granting access to organizational assets. This can include multifactor authentication (MFA), strong password policies, or periodic re-authentication, particularly in high-risk environments like zero trust architectures. It ensures that only verified entities can operate within the system. This sub...

PR.AA-02 - Verifying Identities for Credential Issuance 25.02.2025

PR.AA-02 requires verifying the identities of individuals or entities before binding them to credentials, tailoring the proofing process to the context of their intended interactions. This might involve checking government-issued IDs for personnel or ensuring unique credentials are issued without sharing, confirming legitimacy at enrollment. It ensures that credentials accurately represent authori...

PR.AA-01 - Managing Identities and Credentials 25.02.2025

PR.AA-01 focuses on the management of identities and credentials for all authorized entities—users, services, and hardware—within the organization’s control. This involves issuing, tracking, and revoking access credentials, such as cryptographic certificates or device identifiers, to ensure only legitimate entities can interact with systems and assets. Proper management reduces the risk of unautho...

ID.IM-04 - Strengthening Incident Response Plans 25.02.2025

ID.IM-04 involves establishing, sharing, and maintaining cybersecurity plans—like incident response or disaster recovery—that impact operations, with a focus on continuous improvement. These plans include clear processes, contacts, and escalation criteria to manage adverse events effectively. Regular updates ensure they address evolving threats and organizational needs. This subcategory enhances r...

ID.IM-03 - Enhancing Processes from Operational Insights 25.02.2025

ID.IM-03 seeks improvements from the day-to-day execution of cybersecurity processes, procedures, and activities, capturing lessons learned in real-world operations. This includes reviewing metrics or conducting supplier collaboration sessions to assess performance over time. It ensures that operational experience informs security enhancements. This subcategory promotes a feedback loop where pract...

ID.IM-02 - Improving Through Security Tests and Exercises 25.02.2025

ID.IM-02 identifies improvements from security tests and exercises, like penetration testing or incident response simulations, often involving suppliers and third parties. These activities reveal vulnerabilities and response gaps, providing actionable insights for enhancement. Collaboration with external partners ensures a comprehensive view of shared risks. This subcategory strengthens preparedne...

ID.IM-01 - Learning from Cybersecurity Evaluations 25.02.2025

ID.IM-01 focuses on identifying improvements to cybersecurity risk management through evaluations, such as self-assessments or third-party audits. These reviews consider current threats and compliance requirements, pinpointing gaps in processes or controls. It drives continuous enhancement of the organization’s security posture. This subcategory supports a culture of learning by using evaluation f...

ID.RA-10 - Assessing Critical Suppliers Before Acquisition 25.02.2025

ID.RA-10 involves conducting risk assessments of critical suppliers before engaging them, evaluating their cybersecurity practices and supply chain risks. This ensures that suppliers handling sensitive data or vital services meet organizational security requirements. It’s a proactive step to mitigate third-party vulnerabilities. This subcategory aligns procurement with risk priorities, focusing on...

ID.RA-09 - Verifying Hardware and Software Integrity 25.02.2025

ID.RA-09 requires assessing the authenticity and integrity of hardware and software before purchase or deployment, ensuring they are free from tampering or vulnerabilities. This due diligence verifies that critical technology meets security standards, reducing the risk of compromised assets entering the environment. It’s a preventive measure against supply chain threats. This subcategory supports...

ID.RA-08 - Handling Vulnerability Disclosures 25.02.2025

ID.RA-08 establishes processes for handling vulnerability disclosures from suppliers, customers, or government sources, ensuring timely analysis and response. This includes assigning responsibilities to assess impacts and coordinate with stakeholders under defined protocols, often outlined in contracts. It keeps the organization responsive to external vulnerability reports. This subcategory enhanc...

ID.RA-07 - Managing Changes and Exceptions in Risk 25.02.2025

ID.RA-07 focuses on managing changes to systems or processes and exceptions to policies, assessing their risk impacts, and documenting them for oversight. This includes formal procedures for reviewing proposed changes, evaluating risks, and planning rollbacks if needed. Tracking ensures that accepted risks or exceptions are revisited over time. This subcategory prevents unintended vulnerabilities...

ID.RA-06 - Prioritizing Risk Response Strategies 25.02.2025

ID.RA-06 involves selecting, prioritizing, and planning risk responses—such as mitigation, acceptance, or transfer—based on assessed risks, then tracking and sharing progress. This structured process uses vulnerability management criteria to decide actions and monitor implementation through tools like risk registers. Communication ensures stakeholders are informed of planned responses. This subcat...

ID.RA-05 - Understanding Inherent Cybersecurity Risks 25.02.2025

ID.RA-05 uses data on threats, vulnerabilities, likelihoods, and impacts to assess inherent risk—the risk before controls are applied—and prioritize responses. This involves developing threat models to understand risks to critical assets and guide mitigation strategies. It ensures that risk management focuses on the most pressing dangers. This subcategory supports strategic decision-making by link...

ID.RA-04 - Assessing Threat Impact and Likelihood 25.02.2025

ID.RA-04 requires assessing and documenting the likelihood and potential impacts of threats exploiting identified vulnerabilities, such as data breaches or system failures. This collaborative effort between business and cybersecurity teams estimates risk scenarios and their consequences, recorded in tools like risk registers. It provides a clear picture of risk severity and scope. This subcategory...

ID.RA-03 - Recognizing Internal and External Threats 25.02.2025

ID.RA-03 involves identifying and documenting threats—both internal, like insider risks, and external, like cyberattacks—that could impact the organization. This process uses threat intelligence and hunting techniques to pinpoint actors and tactics likely to target operations or assets. Recording these threats ensures a comprehensive threat profile for risk planning. This subcategory enhances situ...

ID.RA-02 - Leveraging Cyber Threat Intelligence 25.02.2025

ID.RA-02 focuses on gathering cyber threat intelligence from forums, advisories, and reputable sources to stay informed about current and emerging threats. This intelligence includes details on threat actors, tactics, and vulnerabilities relevant to the organization’s assets. It ensures that cybersecurity tools and teams have up-to-date information to enhance detection and response. This subcatego...

ID.RA-01 - Identifying and Recording Asset Vulnerabilities 25.02.2025

ID.RA-01 involves identifying, validating, and documenting vulnerabilities in organizational assets, including software, hardware, and facilities. This process uses tools and assessments to pinpoint weaknesses—like unpatched software or physical security gaps—that could be exploited. Recording these vulnerabilities ensures a clear record for tracking and remediation. This subcategory supports risk...

ID.AM-08 - Managing Assets Across Their Lifecycle 25.02.2025

ID.AM-08 focuses on managing all assets—systems, hardware, software, services, and data—across their entire life cycles, from deployment to disposal. This includes integrating cybersecurity considerations into acquisition, use, and retirement phases, ensuring consistent protection. It addresses risks like shadow IT or redundant systems that expand the attack surface. This subcategory promotes secu...

ID.AM-07 - Inventorying Sensitive Data and Metadata 25.02.2025

ID.AM-07 requires maintaining inventories of designated data types—like PII, health information, or intellectual property—along with metadata such as provenance and ownership. This ongoing effort ensures organizations know where sensitive data resides and how it’s classified, critical for compliance and security. It supports tracking data across systems and locations. This subcategory enhances dat...

ID.AM-05 - Prioritizing Assets by Importance 25.02.2025

ID.AM-05 involves prioritizing assets—data, hardware, software, and services—based on their classification, criticality, resource needs, and mission impact. This process defines criteria to rank assets, ensuring that those most vital to organizational objectives receive focused protection. Regular updates keep priorities aligned with changing conditions. This subcategory enables efficient resource...

ID.AM-04 - Cataloging Supplier-Provided Services 25.02.2025

ID.AM-04 requires organizations to keep inventories of supplier-provided services, such as IaaS, PaaS, SaaS, and APIs, used in their operations. This tracking ensures awareness of external dependencies that could introduce risks if not properly managed. It provides a basis for monitoring and securing third-party service usage. This subcategory enhances oversight by updating inventories whenever ne...

ID.AM-03 - Mapping Network Communication Flows 25.02.2025

ID.AM-03 involves maintaining up-to-date representations of authorized network communications and data flows, both within the organization and with external entities. This includes documenting baselines for wired, wireless, and cloud-based interactions, as well as expected protocols and ports. It ensures visibility into how data moves, critical for detecting anomalies or unauthorized access. This...

ID.AM-02 - Managing Software and Service Inventories 25.02.2025

ID.AM-02 focuses on maintaining detailed inventories of software, services, and systems, covering everything from commercial applications to cloud-based offerings and custom solutions. This comprehensive tracking ensures organizations know what digital assets they manage, aiding in vulnerability identification and compliance efforts. It provides a clear picture of the software landscape supporting...

Listen to the Framework: The NIST Cybersecurity Framework (CSF) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.