Official stays official
Official titles, source links, and campaign intent are labeled. The original publisher remains authoritative.
This resource helps Defense Industrial Base companies turn the DoW Brilliant at the Basics initiative into practical work without blurring the line between official direction and independent interpretation.
Official titles, source links, and campaign intent are labeled. The original publisher remains authoritative.
Sequences, implementation steps, crosswalks, and evidence guidance are explicitly identified as independent work.
Every practice guide shows its technical and editorial review status, who reviewed it, and when the source was last verified.
This site provides education, not legal advice, certification, or a guarantee of cybersecurity or contractual compliance. Implementing the twenty practices does not make an organization compliant with NIST SP 800-171, DFARS 252.204-7012, CMMC, or export-control obligations, and does not satisfy a contract requirement on its own.
The most common failure in security programmes is not missing controls — it is mistaking one stage of a control for another. Owning a tool is not configuring it. Configuring it is not deploying it to the right scope. None of those is operating it, measuring it, or governing it. Every practice guide, scorecard, and downloadable checklist on this site scores against the same seven levels so those distinctions stay visible.
| Level | Name | What it means | The question that separates it from the level below |
|---|---|---|---|
| 0 | Absent | The capability does not exist in any form. | Is there anything at all — a tool, a document, a person who owns it? |
| 1 | Documented | Intent exists on paper. Deployment has not happened or is incomplete. | Is the intent written down, with a named owner and a scope? |
| 2 | Configured | The technology or process is configured, but not yet applied to the intended scope. | Is it switched on and set up somewhere — even if only in part of the estate? |
| 3 | Deployed | It is applied across the scope it was meant to cover. | Does it cover everything in scope, with the exceptions written down? |
| 4 | Operating | It functions consistently during normal operations, not only when someone is watching. | Does it keep working through a normal month without manual rescue? |
| 5 | Measured | Coverage and effectiveness are measured, monitored, and exception-handled. | Can you state a number for coverage or effectiveness, and show the trend? |
| 6 | Governed | Ownership, scheduled review, continuous improvement, and evidence retention are established. | Is there an accountable owner, a review cadence, and retained evidence? |
Read against the primary source text, then classified by relationship type and confidence. No automated mapping tool was used.
Each mapping records a relationship type (direct, supporting, enabling, or contextual), a confidence level, the reasoning behind it, and an explicit caveat stating what the mapping does not claim. If a caveat cannot be written honestly, the mapping is not published. A mapping is an aid to your own analysis — never an assertion of equivalence or a compliance determination.
Review the crosswalkPractice guides carry two independent statuses. Technical review covers whether the steps, validation checks, and safety guidance are sound for the environments described. Editorial review covers whether the wording is accurate, appropriately caveated, and clearly separated from official material. Both are shown on every guide, alongside the reviewer, the last review date, the date the official source was last verified, and a content version.
Resource records name the publisher, link to the original source, and display the date of the latest editorial verification. Corrections are traceable and time-stamped.
Review the source libraryBrilliant at the Basics is published and maintained by inDirectIT, Inc.— a federal CUI security and NIST SP 800-171 engineering firm that operates its own assessed CMMC Level 2 environment. The Resource Center is editorially independent of inDirectIT’s commercial services: guidance here is selected for the campaign’s priorities, not for any engagement. There is no paid placement, no vendor ranking, and no gated official-source material. Where a commercial tool appears in the resource library it is labeled as a vendor tool.
If your implementation questions outgrow an educational resource, the practitioners behind this site are at indirectit.com ↗.
Whether this is an official site, whether the Top 10 is contractually required, how it relates to CMMC and NIST SP 800-171, and what a small business should do first are all answered on the frequently asked questions page.