Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPGoogle Cloud
Cloud Infrastructure

Security Setup Checklist

70 steps across the ten Brilliant at the Basics requirements. Check each box as you complete it. Confirm every step against Google Cloud’s own documentation before you rely on it.

Where you work
Google Cloud console (console.cloud.google.com)
Content reviewed
2026-07-21
Prepared for
________________________________
Date started
________________________________
Before you store CUI here

For CUI, deploy inside Assured Workloads with the correct US government / Impact Level compliance regime.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Evidence to keep: Screenshot of 2-Step Verification enforcement setting · List of users with security keys enrolled · Admin console audit log of the policy change

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Evidence to keep: Export of IAM policy bindings per project · IAM Recommender history showing applied changes · Organization policy report on service account key constraints

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Evidence to keep: Exported asset list from Asset Inventory · Resource Manager hierarchy diagram or screenshot · List of all user and service accounts

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Evidence to keep: Screenshot of enabled Data Access audit log config · Log Router sink pointing to retained storage · Security Command Center findings report

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Evidence to keep: VPC and subnet configuration export · Firewall rule list showing default-deny · VPC Service Controls perimeter configuration

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Evidence to keep: VM Manager vulnerability report export · Patch deployment job history · Security Command Center findings list with remediation status

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Evidence to keep: Cloud KMS key ring and key configuration · Resource settings showing CMEK enabled · Key rotation schedule record

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Evidence to keep: Backup plan and vault configuration · Snapshot schedule showing recent successful backups · Documented restore test results

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Evidence to keep: Security posture definition and compliance report · Organization policy constraint settings · Security Health Analytics findings showing resolved items

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Evidence to keep: Sensitive Data Protection scan results and de-id templates · VPC Service Controls perimeter covering Vertex AI · Vertex AI audit logs and written AI use policy

This checklist is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each step against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/

Back to the guide