Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
Built for the Defense Industrial Base

Turn the Top 10 into action.

Practical playbooks, checklists, crosswalks, and 30/60/90-day plans to strengthen IT, protect operational technology, and secure sensitive defense information.

Independent resource. Official titles and source guidance remain authoritative.
The recommended sequence

Six stages. Twenty practices. One practical order.

Official numbering remains authoritative. This sequence is our independent recommendation for resource-constrained teams.

2

Contain compromise

Keep one breached device from becoming ten.

4

Recover operations

Prove you can restore before you need to.

6

Sustain performance

Keep your people and monitoring sharp.

Recommended implementation sequence by the Brilliant at the Basics Resource Center — not an official DoW ordering.

Two tracks, twenty practices

Pick the track you actually run.

Both tracks are complete: ten practices each, every one with a published implementation guide, a maturity ladder, validation checks, and evidence guidance. The OT track is written for production, not adapted from IT.

IT SYSTEMS10 PRACTICES

The IT Top 10

Identity, inventory, segmentation, patching, backup, and the people who run them — for the business systems and cloud services that hold your contract data.

Typical owners
Identity administrator, IT leader, Network administrator
All ten guides
Published, with review status on every page
Open the IT Top 10 →Implementation checklistSelf-assessment
OPERATIONAL TECHNOLOGY10 PRACTICES

The OT Top 10

Asset inventory, access, segmentation, remote pathways, monitoring, and recovery — written for production uptime, maintenance windows, and process safety rather than adapted from IT.

Typical owners
Plant / OT leader, OT / network administrator, OT engineer
All ten guides
Published, with review status on every page
Open the OT Top 10 →Implementation checklistSelf-assessment
Beyond the official campaign

The campaign sets priorities. We help carry them out.

Every practice starts from an authoritative source. What we add is an independent implementation layer.

01

Sequenced action

24-hour, 14-day, 30-day, and 90-day work with named owners.

02

A maturity ladder

Seven levels that separate owning a tool from operating and governing it.

03

Evidence guidance

Governance, configuration, operational, and validation records.

04

Framework crosswalks

Caveated mappings to NIST, CMMC, CIS, and CSF — with the caveat on every row.

Take it off the screen

Print-ready implementation assets

Checklists, crosswalks, and templates generated from the same practice guidance you read here — so they cannot drift out of date.

Browse all 15 downloads →

Working against requirements, not just priorities? The NIST SP 800-171 mapping covers both revisions requirement by requirement, and the artifact library holds the registers, trackers, and worksheets to document the work.

Watch

The resource center in 30 seconds

What the campaign asks for, and how this site helps you carry it out. The clip is captions-only by design — it plays fine with the sound off, and the full text of it is below.

Text version of the clip — every frame, in order
  1. 0:00
    Brilliant at the Basics

    The wordmark assembles from four modules against a datum line. Sub-line: an independent DIB implementation resource, not affiliated with or endorsed by the U.S. Department of War.

  2. 0:04
    Twenty practices, two tracks

    Ten IT practices and ten OT practices appear as a numbered grid, IT in cyan and OT in amber.

  3. 0:10
    Six stages, one order

    The twenty practices regroup into the six recommended stages: know and control, contain compromise, reduce exposure, recover operations, engineer securely, sustain performance.

  4. 0:16
    From priority to action

    One practice expands into its four action horizons — 24 hours, 14 days, 30 days, 90 days — with an owner attached to each.

  5. 0:22
    Prove it operates

    A validation check passes, then a maturity ladder fills from Absent to Governed, showing the difference between owning a tool and governing it.

  6. 0:27
    Take it with you

    Checklists, crosswalks, and templates fan out, then the closing card: brilliantatthebasics.us, published by inDirectIT.

No narration and no audio track. Everything the clip shows is also written on this page and linked from it.

Written for beginners

Cloud setup guides for every major platform

Turning on the right settings is where most teams get stuck. These plain-language guides walk you through it — with diagrams and click-by-click checklists — for the ten requirements that matter most.

Open the cloud guides →
The resource library

Curated authoritative sources

Each record identifies its publisher, provenance, and our most recent verification date.

DoD Zero Trust Strategy

The department-level target architecture that the IT Top 10 supports.

OFFICIAL SOURCEITDoD CIO · Strategy · IT-01 IT-05
Explore the full library →