Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
HIGH-LEVEL CROSSWALK

The IT Top 10, mapped to NIST 800-171 & CMMC

A high-level view of how each Brilliant at the Basics IT practice lines up with the NIST SP 800-171 control families and CMMC domains. Use it to orient — then open each practice guide for the specifics.

PracticePrimary NIST SP 800-171 familyCMMC domainAlso supports
IT-01 Phishing-Resistant MFAIdentification & Authentication (3.5)IAAccess ControlGuide →
IT-02 Asset InventoryConfiguration Management (3.4)CMRisk AssessmentGuide →
IT-03 Technical Debt ReductionSystem & Information Integrity (3.14)SI, CMRisk AssessmentGuide →
IT-04 Flexible Technology StackConfiguration Management (3.4)CMSystem & Comms ProtectionGuide →
IT-05 Logical SegmentationSystem & Communications Protection (3.13)SCAccess ControlGuide →
IT-06 Vulnerability ManagementRisk Assessment (3.11)RA, SISystem & Info IntegrityGuide →
IT-07 Security in the SDLCSystem & Information Integrity (3.14)SI, CMSecurity AssessmentGuide →
IT-08 Secure AI & Data ProtectionAccess Control (3.1) · SC Protection (3.13)AC, SCMedia ProtectionGuide →
IT-09 Backup & Disaster RecoveryMedia Protection (3.8)MPRecoveryGuide →
IT-10 Workforce ReadinessAwareness & Training (3.2)ATGuide →
Working the OT side too?

The OT Top 10 maps against NIST SP 800-82 and the CSF. See the OT Top 10 and the full framework mappings on each practice guide.