Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
IT SYSTEMSOFFICIAL TITLES & ORDER

The IT Top 10

Ten information-technology practices from the official campaign, translated into sequenced work, validation checks, and defensible evidence.

Official campaign ↗
10 PRACTICES
IT-01IT

Phishing-Resistant Multi-Factor Authentication (MFA)

Stop credential phishing from becoming account takeover.

STAGE
1 · Know and control
EFFORT
Medium
OWNER
Identity admin
Implementation guide availableReview the guide
IT-02IT

Comprehensive Asset Inventory Management

Know every device, identity, and application you defend.

STAGE
1 · Know and control
EFFORT
Medium
OWNER
IT leader
Practice overviewReview the practice
IT-03IT

Strategic Technical Debt Reduction

Retire the systems attackers count on you keeping.

STAGE
3 · Reduce exposure
EFFORT
High
OWNER
IT leader
Practice overviewReview the practice
IT-04IT

Flexible Technology Stack

Adopt and swap capabilities without security regressions.

STAGE
5 · Engineer securely
EFFORT
Medium
OWNER
IT leader
Practice overviewReview the practice
IT-05IT

Logical Segmentation to Limit Adversary Lateral Movement

Contain a compromised account or device to one zone.

STAGE
2 · Contain compromise
EFFORT
High
OWNER
Network admin
Practice overviewReview the practice
IT-06IT

Risk-Based Vulnerability Management

Fix the exposures most likely to be exploited first.

STAGE
3 · Reduce exposure
EFFORT
Medium
OWNER
IT leader / MSP
Practice overviewReview the practice
IT-07IT

Integrate Security Early in the Development Lifecycle

Catch weaknesses in the pipeline, not in production.

STAGE
5 · Engineer securely
EFFORT
Medium
OWNER
Engineering lead
Practice overviewReview the practice
IT-08IT

Secure AI Adoption and Data Protection

Use AI without leaking sensitive defense information.

STAGE
5 · Engineer securely
EFFORT
Medium
OWNER
Engineering lead
Practice overviewReview the practice
IT-09IT

Resilient Backup and Disaster Recovery Architecture

Restore operations from an attack you could not prevent.

STAGE
4 · Recover operations
EFFORT
Medium
OWNER
IT leader
Practice overviewReview the practice
IT-10IT

Continuous Technical Workforce Readiness

Keep the people running your defenses current and practiced.

STAGE
6 · Sustain performance
EFFORT
Low
OWNER
Executive sponsor
Practice overviewReview the practice