Executive / Board Briefing One-Pager
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
A briefing for a board or leadership team that has heard 'Brilliant at the Basics' and needs to know what it is, what it obliges, and what to ask for.
How to use it
Read the first two sections aloud if you need to settle a room. Use the questions section as the agenda for a thirty-minute review with whoever runs IT and operations.
What it is
Brilliant at the Basics is a U.S. Department of War CIO campaign that names ten information-technology and ten operational-technology cybersecurity practices as priorities for the Defense Industrial Base. It is a statement of priority and emphasis — a clear signal about where the department believes attention belongs.
It is not, by itself, a contract clause, a certification, or a substitute for NIST SP 800-171, DFARS 252.204-7012, or CMMC obligations. Implementing the twenty practices does not make an organization compliant with any of those, and no part of this briefing should be represented as saying otherwise. Your obligations come from your contracts.
| Question | Honest answer |
|---|---|
| Is this contractually required? | Not in itself. Verify what your contracts and flowdowns actually require. |
| Does implementing it make us CMMC compliant? | No. It contributes to several requirements and provides evidence relevant to others. |
| Does it replace a System Security Plan? | No. An SSP describes your system and how each requirement is met; this is a priority list. |
| Is it still worth doing? | Yes. These are the practices that reduce the most risk for the least money in most DIB environments. |
The six-stage sequence
Official numbering is authoritative. This is the Resource Center's independent recommendation for the order in which resource-constrained teams should attempt the work.
| Stage | Name | Why it comes here | Practices |
|---|---|---|---|
| 1 | Know and control | See every identity and asset you defend. | IT-01, IT-02, OT-01, OT-02 |
| 2 | Contain compromise | Keep one breached device from becoming ten. | IT-05, OT-03, OT-06 |
| 3 | Reduce exposure | Close the gaps attackers reach first. | IT-03, IT-06, OT-05 |
| 4 | Recover operations | Prove you can restore before you need to. | IT-09, OT-04, OT-08 |
| 5 | Engineer securely | Build new capability without new risk. | IT-04, IT-07, IT-08, OT-09, OT-10 |
| 6 | Sustain performance | Keep your people and monitoring sharp. | IT-10, OT-07 |
Questions worth asking
- Which of the twenty practices do we consider deployed, and what is the evidence?
- 'We bought the tool' is not an answer. 'Here is the coverage number and the last validation result' is.
- What is our phishing-resistant MFA coverage for privileged accounts, as a number?
- When did we last restore a critical system from backup, and how long did it take?
- Can a compromised laptop on the office network reach production or our sensitive data?
- Who is accountable for each practice — by name, not by department?
- Which of these are we paying a service provider to do, and who retains the evidence?
- What would we not be able to recover from today?
Limitations
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-executive-briefing-one-pager to keep filenames consistent across your team.