Know and control
See every identity and asset you defend.
Practical playbooks, checklists, crosswalks, and 30/60/90-day plans to strengthen IT, protect operational technology, and secure sensitive defense information.
Independent resource. Official titles and source guidance remain authoritative.Official numbering remains authoritative. This sequence is our independent recommendation for resource-constrained teams.
See every identity and asset you defend.
Keep one breached device from becoming ten.
Close the gaps attackers reach first.
Prove you can restore before you need to.
Build new capability without new risk.
Keep your people and monitoring sharp.
Recommended implementation sequence by the Brilliant at the Basics Resource Center — not an official DoW ordering.
Both tracks are complete: ten practices each, every one with a published implementation guide, a maturity ladder, validation checks, and evidence guidance. The OT track is written for production, not adapted from IT.
Identity, inventory, segmentation, patching, backup, and the people who run them — for the business systems and cloud services that hold your contract data.
Asset inventory, access, segmentation, remote pathways, monitoring, and recovery — written for production uptime, maintenance windows, and process safety rather than adapted from IT.
Every practice starts from an authoritative source. What we add is an independent implementation layer.
24-hour, 14-day, 30-day, and 90-day work with named owners.
Seven levels that separate owning a tool from operating and governing it.
Governance, configuration, operational, and validation records.
Caveated mappings to NIST, CMMC, CIS, and CSF — with the caveat on every row.
Stop credential phishing from becoming account takeover.
A walked-down, verified list of every OT asset.
Contain a compromised account or device to one zone.
Checklists, crosswalks, and templates generated from the same practice guidance you read here — so they cannot drift out of date.
Working against requirements, not just priorities? The NIST SP 800-171 mapping covers both revisions requirement by requirement, and the artifact library holds the registers, trackers, and worksheets to document the work.
What the campaign asks for, and how this site helps you carry it out. The clip is captions-only by design — it plays fine with the sound off, and the full text of it is below.
The wordmark assembles from four modules against a datum line. Sub-line: an independent DIB implementation resource, not affiliated with or endorsed by the U.S. Department of War.
Ten IT practices and ten OT practices appear as a numbered grid, IT in cyan and OT in amber.
The twenty practices regroup into the six recommended stages: know and control, contain compromise, reduce exposure, recover operations, engineer securely, sustain performance.
One practice expands into its four action horizons — 24 hours, 14 days, 30 days, 90 days — with an owner attached to each.
A validation check passes, then a maturity ladder fills from Absent to Governed, showing the difference between owning a tool and governing it.
Checklists, crosswalks, and templates fan out, then the closing card: brilliantatthebasics.us, published by inDirectIT.
No narration and no audio track. Everything the clip shows is also written on this page and linked from it.
Turning on the right settings is where most teams get stuck. These plain-language guides walk you through it — with diagrams and click-by-click checklists — for the ten requirements that matter most.
Each record identifies its publisher, provenance, and our most recent verification date.
The authoritative campaign page and source for the IT and OT Top 10 practices.
The department-level target architecture that the IT Top 10 supports.
The foundational reference for securing industrial control systems.
No. It is an independent resource published by inDirectIT. The official campaign page remains authoritative; everything else here is labeled independent analysis.
Read the full answer →Not in itself. It is a statement of priority. Your obligations come from your contracts and their flowdowns — read the clause to find out what binds you.
Read the full answer →Phishing-resistant MFA on admins, one reconciled inventory, and a timed restore test. Days of work, and they close the exposures behind most real incidents.
Read the full answer →