Knowledge Base
Plain-language, independently-written explainers on the standards, clauses, and controls behind the DoW Brilliant at the Basics priorities — for the IT lead who is technically capable but not a full-time compliance specialist.
Replay-Resistant vs. Phishing-Resistant Authentication
Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04); phishing-resistant is defined in SP 800-63B and mandated by OMB M-22-09, not by a base 800-171 control.
CMMC vs. NIST SP 800-171: What’s the Difference?
NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who checks, how often, and what proof is required.
DFARS 7012’s 72-Hour Rule: What It Actually Requires
DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the clause down to subcontractors. The report itself is only part of the obligation.
GCC High vs. Commercial Microsoft 365: Do You Actually Need It?
GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for lighter CUI — but confirm with your prime. It costs more and migration is a real project.
The Top Mistakes DIB Teams Make When Starting the Basics
Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams make starting out, and the simple fixes.
What Good Looks Like: The IT Top 10 at a Glance
A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the how-to.
Scoping Your CUI Boundary: Discovery Methods, Remediation Paths, and the Numbers That Decide
Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down traceability cascade, staff interviews, or automated digital discovery) determines how accurately you can size the boundary, and four remediation paths — surgical file cleanup, a user-account enclave, program segmentation, or enterprise migration — are chosen mostly by two ratios: what share of users touch CUI, and how sprawled it already is.
What Should a GCC High Migration Cost?
A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and roughly $250 per user to move and validate mail, files, and Teams. Total ≈ $15,500 + tooling + ($250 × users). The cost nobody quotes correctly is the risk in the mapping and cutover — get those wrong and you pay again in spillage, broken permissions, and downtime.
Windows Pro vs. Enterprise for NIST 800-171 Rev 3: The Endpoint Parity Gap
For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise E3/E5 or Education license; Pro isn't entitled. App Control for Business (WDAC) runs on Pro but is the harder engine and no substitute for the rest: Credential Guard (Enterprise-only), Defender for Endpoint EDR (E5), and more. In GCC High, getting those Enterprise licenses onto devices is partner-mediated and portal-fragmented.
These articles are independent education. They cite the standards and clauses they discuss, but do not by themselves establish compliance, satisfy a contract clause, or confer CMMC certification. Confirm against the official publication that applies to your contract.