Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
INDEPENDENT IMPLEMENTATION LAYERPLAIN-LANGUAGE GUIDES

Cloud Setup Guides

Step-by-step, plain-language instructions for turning on the security settings that matter — in Microsoft 365, AWS, Google Workspace, Google Cloud, and Azure Government. Every guide is written to be understood by a beginner, with a diagram and a checklist you can actually follow.

How to use these guides

Pick your cloud, then work through the ten requirements in order. Each requirement is explained in everyday words, shows a process-flow diagram, and gives you a click-by-click checklist. Your checklist progress is saved only in this browser. The official campaign remains the authoritative source.

Read the official campaign ↗
Choose your cloud

Five platforms, one playbook

What you will set up

Ten requirements, every cloud

Each maps to the Brilliant at the Basics IT Top 10 and to the NIST SP 800-171 / CMMC Level 2 controls behind DFARS 252.204-7012.

01

Phishing-Resistant Multi-Factor Authentication

Make a stolen password useless on its own.

IT-013.5.3IA.L2-3.5.3
02

Least-Privilege Access Control

Give each person only the access their job needs — and no more.

3.1.5AC.L2-3.1.5
03

Asset & Account Inventory

Keep a live list of every device, identity, and app you defend.

IT-023.4.1CM.L2-3.4.1
04

Logging, Monitoring & Audit

Record important events and watch for trouble.

3.3.1AU.L2-3.3.1
05

Network Segmentation & Boundary Protection

Keep one compromised thing from reaching everything else.

IT-053.13.5SC.L2-3.13.5
06

Vulnerability & Patch Management

Find weak spots and fix the risky ones first.

IT-063.11.2RA.L2-3.11.2
07

Data Protection & Encryption

Scramble sensitive data so only the right people can read it.

3.13.11SC.L2-3.13.11
08

Backup & Recovery

Be able to restore your data after an attack or outage.

IT-093.8.9MP.L2-3.8.9
09

Secure Configuration Baseline

Start every service from a known-good, hardened setting.

3.4.2CM.L2-3.4.2
10

Secure AI Adoption & Data Loss Prevention

Use AI and share files without leaking sensitive information.

IT-083.1.3AC.L2-3.1.3
Coverage at a glance

Every requirement is covered for every cloud

Click any cell to jump straight to that guide.

RequirementM365AWSWorkspaceGCPAzure Gov
01Phishing-Resistant Multi-Factor Authentication
02Least-Privilege Access Control
03Asset & Account Inventory
04Logging, Monitoring & Audit
05Network Segmentation & Boundary Protection
06Vulnerability & Patch Management
07Data Protection & Encryption
08Backup & Recovery
09Secure Configuration Baseline
10Secure AI Adoption & Data Loss Prevention