Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPGoogle Workspace
Productivity Suite

Security Setup Checklist

70 steps across the ten Brilliant at the Basics requirements. Check each box as you complete it. Confirm every step against Google Workspace’s own documentation before you rely on it.

Where you work
Google Admin console (admin.google.com)
Content reviewed
2026-07-21
Prepared for
________________________________
Date started
________________________________
Before you store CUI here

Handling CUI in Workspace requires Assured Controls and careful scoping. Confirm an authorization path before you store CUI.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Evidence to keep: 2-Step Verification enrollment report · Screenshot of 'Only security key' policy on Admins OU · List of issued security keys/passkeys

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Evidence to keep: List of admin role assignments · Custom role definitions with privileges · Quarterly access review record

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Evidence to keep: Exported device inventory (dated) · User account list · Connected/third-party app report

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Evidence to keep: BigQuery log export configuration · Alert center rules and history · Weekly log-review records

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Evidence to keep: Context-Aware Access level definitions · App assignment screenshots · Blocked-access log entries

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Evidence to keep: Chrome/ChromeOS update policy settings · Managed browser version report · Security health page results

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Evidence to keep: CSE key service configuration · List of OUs/apps with CSE enabled · Sample encrypted Drive file

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Evidence to keep: Vault retention rule configuration · Successful test export record · Multi-party approval setting screenshot

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Evidence to keep: Security health page screenshot · Written configuration baseline document · Change/drift alert settings

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Evidence to keep: DLP rule definitions for Drive and Gmail · Gemini data-access configuration · DLP incident/audit report

This checklist is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each step against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/

Back to the guide