Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
Everything, in one place

Search the resource center

Practice guides, knowledge base articles, cloud setup steps, downloads, framework mappings, official sources, and policy updates — 224 records, filtered in your browser.

224 RESULTS
  1. PRACTICE GUIDEReviewed

    IT-01 — Phishing-Resistant Multi-Factor Authentication (MFA)

    Passwords alone are not enough. Phishing-resistant MFA — FIDO2 security keys, platform passkeys, or PIV — removes the shared secret an attacker can steal. Start with privileged and remote-access accounts, then expand…

    IT-01
  2. PRACTICE GUIDEReviewed

    IT-02 — Comprehensive Asset Inventory Management

    You defend what you can see. A comprehensive inventory covers hardware, cloud and on-prem software, and — increasingly — identities and service accounts. Build it from authoritative sources, reconcile the sources…

    IT-02
  3. PRACTICE GUIDEReviewed

    IT-03 — Strategic Technical Debt Reduction

    Technical debt is a security liability. End-of-life operating systems, unpatched appliances, and legacy protocols are the footholds adversaries count on you keeping. Treat retirement as a planned program: find the…

    IT-03
  4. PRACTICE GUIDEReviewed

    IT-04 — Flexible Technology Stack

    Lock-in is a risk multiplier. A flexible stack — built on documented baselines, standard interfaces, and portable data — lets you replace a weak or end-of-life component without re-architecting the business. The goal…

    IT-04
  5. PRACTICE GUIDEReviewed

    IT-05 — Logical Segmentation to Limit Adversary Lateral Movement

    A flat network turns one compromised laptop into access to everything. Logical segmentation — VLANs, host firewalls, identity-based access, and separated management planes — breaks the network into zones so an…

    IT-05
  6. PRACTICE GUIDEReviewed

    IT-06 — Risk-Based Vulnerability Management

    You will never fix every vulnerability, so fix the ones that matter first. Risk-based vulnerability management pairs regular scanning with prioritization by exploitability and exposure — known-exploited…

    IT-06
  7. PRACTICE GUIDEReviewed

    IT-07 — Integrate Security Early in the Development Lifecycle

    Security bolted on at the end is expensive and leaky. Building it in — threat modeling, secure coding standards, automated testing in the pipeline, dependency and secret scanning, and reviewed changes — catches…

    IT-07
  8. PRACTICE GUIDEReviewed

    IT-08 — Secure AI Adoption and Data Protection

    AI is entering the workplace whether you plan for it or not. Secure adoption means deciding — before staff paste data into a chatbot — which tools are approved, what data may and may not go into them, and how AI use…

    IT-08
  9. PRACTICE GUIDEReviewed

    IT-09 — Resilient Backup and Disaster Recovery Architecture

    Ransomware assumes your backups fail. A resilient architecture keeps at least one copy offline or immutable, protects backups with separate credentials and MFA, and — most importantly — proves recovery by testing…

    IT-09
  10. PRACTICE GUIDEReviewed

    IT-10 — Continuous Technical Workforce Readiness

    Tools do not defend anything on their own — people operate them. Continuous readiness means role-based training for the staff who run identity, endpoints, cloud, and response; hands-on exercises that build muscle…

    IT-10
  11. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-01 — Identity and Access Control

    OT access is often shared logins, default passwords, and standing vendor accounts nobody tracks. Bringing identity and access control to production means unique accountability, least privilege, controlled use of…

    OT-01
  12. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-02 — Validated Asset Inventory

    You cannot protect equipment you have not counted. A validated OT inventory is built passively, confirmed by physical walk-downs, and maintained through change control — not by scanning fragile devices.

    OT-02
  13. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-03 — Strict Network Segmentation

    The single most valuable OT control is keeping the plant network separate from the business network. Strict segmentation uses zones and conduits, a controlled boundary (ideally a DMZ) between IT and OT, and…

    OT-03
  14. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-04 — OT-Specific Incident Response and Recovery Plan

    An IT incident-response plan does not fit the plant. OT response has to weigh safety and physical process first, involve engineers and operators alongside IT, and account for the reality that you may run degraded or…

    OT-04
  15. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-05 — Manage Known Vulnerabilities

    You cannot patch OT like IT. Many devices can only be updated during rare maintenance windows, run vendor-certified firmware, or cannot be taken down at all. Managing known vulnerabilities in OT means knowing what…

    OT-05
  16. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-06 — Remote Access Pathways

    Remote access is how vendors keep equipment running — and how attackers get to the plant floor. The safe pattern is brokered access: connections pass through a controlled jump host in a DMZ, require strong…

    OT-06
  17. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-07 — Continuous Monitoring

    You cannot respond to what you cannot see. OT monitoring is built passively — from network taps and SPAN ports, not agents on fragile devices — to baseline normal traffic and flag the abnormal: new devices,…

    OT-07
  18. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-08 — System Resiliency

    Resiliency is the ability to keep operating, or return quickly, when something fails — whether a disk, a controller, or an attack. In OT that means backups of controller logic and configurations, spares and…

    OT-08
  19. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-09 — Supply Chain Security

    Every vendor, integrator, and component is a path into your environment. OT supply-chain security means knowing who your critical suppliers are, setting security expectations in agreements, checking equipment and…

    OT-09
  20. PRACTICE GUIDEReviewed — pending SME sign-off

    OT-10 — Review Processes

    In OT, an unreviewed change can trip a process or open a security hole — and the two concerns are inseparable. A change-review process ensures every modification to control systems, network, or configuration is…

    OT-10
  21. KNOWLEDGE BASE

    Replay-Resistant vs. Phishing-Resistant Authentication

    Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04);…

    IT-01
  22. KNOWLEDGE BASE

    CMMC vs. NIST SP 800-171: What’s the Difference?

    NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who…

  23. KNOWLEDGE BASE

    DFARS 7012’s 72-Hour Rule: What It Actually Requires

    DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the…

  24. KNOWLEDGE BASE

    GCC High vs. Commercial Microsoft 365: Do You Actually Need It?

    GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for…

  25. KNOWLEDGE BASE

    The Top Mistakes DIB Teams Make When Starting the Basics

    Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams…

  26. KNOWLEDGE BASE

    What Good Looks Like: The IT Top 10 at a Glance

    A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the…

  27. KNOWLEDGE BASE

    Scoping Your CUI Boundary: Discovery Methods, Remediation Paths, and the Numbers That Decide

    Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down…

  28. KNOWLEDGE BASE

    What Should a GCC High Migration Cost?

    A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and…

  29. KNOWLEDGE BASE

    Windows Pro vs. Enterprise for NIST 800-171 Rev 3: The Endpoint Parity Gap

    For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise…

  30. KNOWLEDGE BASE

    Your SPRS Score, Explained: How the DoD Assessment Methodology Works

    Your SPRS score is a self-reported number from 110 down to -203 that tells the DoD how much of NIST SP 800-171 you have actually implemented. It starts at 110, and every unmet requirement subtracts a weighted value…

  31. KNOWLEDGE BASE

    CMMC Phase II Is Suspended — What You Still Have to Do

    On July 13, 2026 the Department of War suspended the CMMC Phase II transition during a 60-day program review. Third-party (C3PAO) and Level 3 designations are paused and November 10, 2026 is no longer an operative…

  32. KNOWLEDGE BASE

    FCI, CUI, CDI — How the Rules Stack Together

    The security stack is driven first by the information involved, then by the clauses, assessment level, and contract-specific requirements that apply to the system handling it. FCI, CUI, and CDI are overlapping…

    IT-02
  33. KNOWLEDGE BASE

    The Foundation Clauses — FAR 52.204-21 and the DFARS 7012 Family

    FAR 52.204-21 and DFARS 252.204-7012, -7019, -7020 and -7021 form the contractual backbone of defense cybersecurity. Each has a distinct trigger, obligation, and flowdown. Alongside them sits an independent…

  34. KNOWLEDGE BASE

    CUI Is Not an Export License — ITAR and EAR as a Separate Overlay

    Export control is a separate legal overlay from CUI safeguarding. The controlling authority, classification, destination, end user, nationality, access path, license or exemption, and technical facts determine…

    IT-08
  35. CLOUD SETUP

    Microsoft 365 security setup guide

    Email, files, Teams, and identity for the whole company. Commercial Microsoft 365 is generally NOT authorized to store CUI. Most ITAR / CUI contractors need Microsoft 365 GCC High.

    IT-01IT-02IT-05IT-06IT-09IT-08
  36. CLOUD SETUP

    M365 — Phishing-Resistant Multi-Factor Authentication

    Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…

    IT-01
  37. CLOUD SETUP

    M365 — Least-Privilege Access Control

    Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…

  38. CLOUD SETUP

    M365 — Asset & Account Inventory

    Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…

    IT-02
  39. CLOUD SETUP

    M365 — Logging, Monitoring & Audit

    Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…

  40. CLOUD SETUP

    M365 — Network Segmentation & Boundary Protection

    Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…

    IT-05
  41. CLOUD SETUP

    M365 — Vulnerability & Patch Management

    Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…

    IT-06
  42. CLOUD SETUP

    M365 — Data Protection & Encryption

    Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…

  43. CLOUD SETUP

    M365 — Backup & Recovery

    Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…

    IT-09
  44. CLOUD SETUP

    M365 — Secure Configuration Baseline

    Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…

  45. CLOUD SETUP

    M365 — Secure AI Adoption & Data Loss Prevention

    Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…

    IT-08
  46. CLOUD SETUP

    Amazon Web Services security setup guide

    Servers, storage, databases, and networking you rent by the hour. For CUI and ITAR data, use AWS GovCloud (US) with FedRAMP High and DoD Impact Level 4–5 authorized services.

    IT-01IT-02IT-05IT-06IT-09IT-08
  47. CLOUD SETUP

    AWS — Phishing-Resistant Multi-Factor Authentication

    Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…

    IT-01
  48. CLOUD SETUP

    AWS — Least-Privilege Access Control

    Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…

  49. CLOUD SETUP

    AWS — Asset & Account Inventory

    Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…

    IT-02
  50. CLOUD SETUP

    AWS — Logging, Monitoring & Audit

    Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…

  51. CLOUD SETUP

    AWS — Network Segmentation & Boundary Protection

    Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…

    IT-05
  52. CLOUD SETUP

    AWS — Vulnerability & Patch Management

    Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…

    IT-06
  53. CLOUD SETUP

    AWS — Data Protection & Encryption

    Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…

  54. CLOUD SETUP

    AWS — Backup & Recovery

    Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…

    IT-09
  55. CLOUD SETUP

    AWS — Secure Configuration Baseline

    Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…

  56. CLOUD SETUP

    AWS — Secure AI Adoption & Data Loss Prevention

    Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…

    IT-08
  57. CLOUD SETUP

    Google Workspace security setup guide

    Gmail, Drive, Docs, and Meet with a single admin console. Handling CUI in Workspace requires Assured Controls and careful scoping. Confirm an authorization path before you store CUI.

    IT-01IT-02IT-05IT-06IT-09IT-08
  58. CLOUD SETUP

    Workspace — Phishing-Resistant Multi-Factor Authentication

    Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…

    IT-01
  59. CLOUD SETUP

    Workspace — Least-Privilege Access Control

    Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…

  60. CLOUD SETUP

    Workspace — Asset & Account Inventory

    Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…

    IT-02
  61. CLOUD SETUP

    Workspace — Logging, Monitoring & Audit

    Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…

  62. CLOUD SETUP

    Workspace — Network Segmentation & Boundary Protection

    Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…

    IT-05
  63. CLOUD SETUP

    Workspace — Vulnerability & Patch Management

    Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…

    IT-06
  64. CLOUD SETUP

    Workspace — Data Protection & Encryption

    Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…

  65. CLOUD SETUP

    Workspace — Backup & Recovery

    Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…

    IT-09
  66. CLOUD SETUP

    Workspace — Secure Configuration Baseline

    Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…

  67. CLOUD SETUP

    Workspace — Secure AI Adoption & Data Loss Prevention

    Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…

    IT-08
  68. CLOUD SETUP

    Google Cloud security setup guide

    Google's rent-by-the-hour compute, storage, and networking. For CUI, deploy inside Assured Workloads with the correct US government / Impact Level compliance regime.

    IT-01IT-02IT-05IT-06IT-09IT-08
  69. CLOUD SETUP

    GCP — Phishing-Resistant Multi-Factor Authentication

    Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…

    IT-01
  70. CLOUD SETUP

    GCP — Least-Privilege Access Control

    Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…

  71. CLOUD SETUP

    GCP — Asset & Account Inventory

    Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…

    IT-02
  72. CLOUD SETUP

    GCP — Logging, Monitoring & Audit

    Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…

  73. CLOUD SETUP

    GCP — Network Segmentation & Boundary Protection

    Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…

    IT-05
  74. CLOUD SETUP

    GCP — Vulnerability & Patch Management

    Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…

    IT-06
  75. CLOUD SETUP

    GCP — Data Protection & Encryption

    Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…

  76. CLOUD SETUP

    GCP — Backup & Recovery

    Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…

    IT-09
  77. CLOUD SETUP

    GCP — Secure Configuration Baseline

    Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…

  78. CLOUD SETUP

    GCP — Secure AI Adoption & Data Loss Prevention

    Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…

    IT-08
  79. CLOUD SETUP

    Azure Government security setup guide

    A separate, sovereign Azure cloud built for U.S. government data. Azure Government, paired with GCC High identity, is a purpose-built home for CUI: FedRAMP High and DoD Impact Level 4/5, with data kept in the U.S.…

    IT-01IT-02IT-05IT-06IT-09IT-08
  80. CLOUD SETUP

    Azure Gov — Phishing-Resistant Multi-Factor Authentication

    Make a stolen password useless on its own. A password can be phished or guessed. Multi-factor authentication (MFA) adds a second proof of identity. 'Phishing-resistant' means the second proof — like a security key or…

    IT-01
  81. CLOUD SETUP

    Azure Gov — Least-Privilege Access Control

    Give each person only the access their job needs — and no more. 'Least privilege' means everyone gets the smallest set of permissions that lets them do their work. Powerful admin rights are handed out carefully, and…

  82. CLOUD SETUP

    Azure Gov — Asset & Account Inventory

    Keep a live list of every device, identity, and app you defend. You cannot protect what you do not know you have. An inventory is an always-current list of your accounts, devices, and cloud services, so nothing is…

    IT-02
  83. CLOUD SETUP

    Azure Gov — Logging, Monitoring & Audit

    Record important events and watch for trouble. Logs are the security camera footage of your cloud. Turning them on — and keeping them — lets you see who did what, get alerted to attacks, and prove what happened after…

  84. CLOUD SETUP

    Azure Gov — Network Segmentation & Boundary Protection

    Keep one compromised thing from reaching everything else. Segmentation splits your environment into zones with locked doors between them, so a break-in one place cannot spread everywhere. A boundary controls exactly…

    IT-05
  85. CLOUD SETUP

    Azure Gov — Vulnerability & Patch Management

    Find weak spots and fix the risky ones first. Software has flaws that attackers exploit. Vulnerability management scans for those flaws, ranks them by real risk, and makes sure the important fixes (patches) actually…

    IT-06
  86. CLOUD SETUP

    Azure Gov — Data Protection & Encryption

    Scramble sensitive data so only the right people can read it. Encryption turns readable data into a locked code. Only someone with the key can unlock it. Protect data both while it sits in storage (at rest) and while…

  87. CLOUD SETUP

    Azure Gov — Backup & Recovery

    Be able to restore your data after an attack or outage. A backup is a safe, separate copy of your data. Recovery is proving you can actually bring it back. Ransomware and mistakes are survivable only if your backups…

    IT-09
  88. CLOUD SETUP

    Azure Gov — Secure Configuration Baseline

    Start every service from a known-good, hardened setting. A baseline is a checklist of safe settings for your cloud. Instead of leaving things on the risky defaults, you turn on protections, measure your score, and…

  89. CLOUD SETUP

    Azure Gov — Secure AI Adoption & Data Loss Prevention

    Use AI and share files without leaking sensitive information. AI assistants and easy file sharing are powerful — and easy to misuse. Data Loss Prevention (DLP) watches for sensitive data leaving where it should not,…

    IT-08
  90. DOWNLOAD

    Brilliant at the Basics 20-Practice Executive Checklist

    One page per track covering all twenty practices with owner, effort, stage, and the single question an executive should ask about each. All 20 practices in recommended sequence. Suggested owner and effort band. The…

  91. DOWNLOAD

    First 14 Days Action Plan

    The first two weeks, sequenced — the 24-hour and 14-day actions from every practice in the first three stages, with space for owner and date. 24-hour actions. 14-day actions. Owner and target-date columns. First…

  92. DOWNLOAD

    IT Top 10 Implementation Checklist

    Every implementation step and validation check for the ten IT practices, in the site's recommended sequence. Implementation steps per practice. Validation checks. Operating metrics. Maturity ladder for scoring

  93. DOWNLOAD

    OT Top 10 Implementation Checklist

    Every implementation step and validation check for the ten OT practices, with the safety and change-control considerations attached to each. Implementation steps per practice. Validation checks. Safety…

  94. DOWNLOAD

    IT Evidence Collection Checklist

    The governance, configuration, operations, and validation artifacts worth retaining for each IT practice, with a column for where yours lives. Evidence by practice and category. Location and owner columns. Retention…

  95. DOWNLOAD

    OT Evidence Collection Checklist

    The governance, configuration, operations, and validation artifacts worth retaining for each OT practice, including maintenance-window and safety-review records. Evidence by practice and category. Location and owner…

  96. DOWNLOAD

    NIST SP 800-171 Rev. 2 Crosswalk

    Every practice mapped to Rev. 2 requirement identifiers with relationship type, confidence, and an explicit caveat for each row. Practice-to-requirement rows. Relationship type and confidence. Per-row caveat. Mapping…

  97. DOWNLOAD

    NIST SP 800-171 Rev. 3 Crosswalk

    Practices mapped to Rev. 3 requirement identifiers where a reviewed mapping exists, with the same relationship, confidence, and caveat structure. Rev. 3 identifiers. Relationship type and confidence. Per-row caveat.…

  98. DOWNLOAD

    CMMC Level 2 Influence Matrix

    Which practices influence which CMMC Level 2 practice identifiers — stated as influence, not as coverage or readiness. Practice-to-CMMC identifier rows. Influence strength and confidence. Explicit non-coverage…

  99. DOWNLOAD

    NIST Cybersecurity Framework 2.0 Crosswalk

    Practices mapped to CSF 2.0 outcome identifiers, useful for reporting the campaign against a framework leadership already recognizes. Practice-to-CSF outcome rows. Relationship type and confidence. Per-row caveat.…

  100. DOWNLOAD

    CIS Controls v8.1 Crosswalk

    Practices mapped to CIS Controls v8.1 safeguards — the most operationally concrete of the crosswalks, and a useful bridge for MSP conversations. Practice-to-safeguard rows. Relationship type and confidence. Per-row…

  101. DOWNLOAD

    MSP / MSSP Responsibility Matrix

    A blank-by-design matrix for agreeing, in writing, who implements, who operates, who evidences, and who is accountable for each practice. All 20 practices. Implement / operate / evidence / accountable columns.…

  102. DOWNLOAD

    Executive / Board Briefing One-Pager

    What the campaign is, what it is not, the six-stage sequence, the questions a board should ask, and the honest statement of what implementation does and does not do for contractual obligations. What Brilliant at the…

  103. DOWNLOAD

    30-Day Implementation Plan Template

    A structured template for a first-month plan: the 24-hour, 14-day, and 30-day actions with owner, date, validation check, and evidence to retain. Three action horizons. Owner and date columns. First validation check.…

  104. DOWNLOAD

    90-Day Improvement Roadmap Template

    A quarter-length roadmap organized by the six-stage sequence, with a current-and-target maturity column for each practice. Six-stage roadmap. Current and target maturity columns. Dependency prompts. Quarterly review…

  105. FRAMEWORK MAPPINGReviewed

    NIST SP 800-171 Rev. 2 3.5.3 → IT-01

    Direct relationship, high confidence. The requirement calls for multifactor authentication for local and network access to privileged accounts and network access to non-privileged accounts — the same population this…

    IT-01
  106. FRAMEWORK MAPPINGReviewed

    NIST SP 800-171 Rev. 3 03.05.03 → IT-01

    Direct relationship, high confidence. Rev 3 restates the multifactor requirement with the same scope; phishing resistance is a stronger method choice within it, not a separate control.

    IT-01
  107. FRAMEWORK MAPPINGReviewed

    CMMC Level 2 IA.L2-3.5.3 → IT-01

    Direct relationship, high confidence. The CMMC practice inherits the 800-171 requirement text directly.

    IT-01
  108. FRAMEWORK MAPPINGReviewed

    NIST SP 800-63B AAL2 / AAL3 authenticators → IT-01

    Contextual relationship, high confidence. 800-63B is where 'phishing resistance' is actually defined; it tells you which authenticator types qualify.

    IT-01
  109. FRAMEWORK MAPPINGReviewed

    CIS Controls v8.1 6.3 / 6.4 / 6.5 → IT-01

    Direct relationship, moderate confidence. CIS separates MFA for externally-exposed applications, remote access, and administrative access — the same prioritization this practice recommends.

    IT-01
  110. FRAMEWORK MAPPINGReviewed

    NIST SP 800-171 Rev. 2 3.4.1 → IT-02

    Direct relationship, high confidence. The requirement is to establish and maintain baseline configurations and inventories of organizational systems throughout the development life cycle.

    IT-02
  111. FRAMEWORK MAPPINGReviewed

    NIST SP 800-171 Rev. 3 03.04.01 → IT-02

    Direct relationship, high confidence. Rev 3 retains the baseline-configuration and inventory requirement with equivalent scope.

    IT-02
  112. FRAMEWORK MAPPINGReviewed

    CMMC Level 2 CM.L2-3.4.1 → IT-02

    Direct relationship, high confidence. The CMMC practice inherits the 800-171 requirement text directly.

    IT-02
  113. FRAMEWORK MAPPINGReviewed

    NIST CSF 2.0 ID.AM-01 / ID.AM-02 → IT-02

    Direct relationship, high confidence. The CSF asset-management outcomes cover hardware and software inventories explicitly.

    IT-02
  114. FRAMEWORK MAPPINGReviewed

    CIS Controls v8.1 1.1 / 2.1 → IT-02

    Direct relationship, high confidence. Enterprise and software asset inventories are the first two CIS controls and describe the same activity.

    IT-02
  115. FRAMEWORK MAPPINGReviewed

    NIST SP 800-171 Rev. 2 3.4.1 / 3.14.1 → IT-03

    Supporting relationship, moderate confidence. Retiring unsupported systems is how organizations keep baseline configurations maintainable and flaws remediable; neither requirement names end-of-life management directly.

    IT-03
  116. FRAMEWORK MAPPINGReviewed

    CMMC Level 2 CM.L2-3.4.1 / SI.L2-3.14.1 → IT-03

    Supporting relationship, moderate confidence. The same reasoning carries to the inherited CMMC practices.

    IT-03
  117. FRAMEWORK MAPPINGReviewed

    NIST CSF 2.0 ID.AM-08 → IT-03

    Supporting relationship, moderate confidence. The CSF asset lifecycle outcome covers systems through decommissioning, which is exactly this practice.

    IT-03
  118. FRAMEWORK MAPPINGReviewed

    CIS Controls v8.1 2.2 / 2.3 → IT-03

    Direct relationship, moderate confidence. CIS requires that unsupported software be addressed or documented with a mitigation, which is the substance of this practice.

    IT-03
  119. FRAMEWORK MAPPINGReviewed

    NIST SP 800-171 Rev. 2 3.4.2 → IT-04

    Supporting relationship, moderate confidence. Establishing and enforcing security configuration settings is the requirement; documented, portable baselines are how you make that maintainable.

    IT-04
  120. FRAMEWORK MAPPINGReviewed

    CMMC Level 2 CM.L2-3.4.2 → IT-04

    Supporting relationship, moderate confidence. The same reasoning carries to the inherited CMMC practice.

    IT-04

Showing the first 120 of 224 results. Add a filter or a search term to narrow it.