Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPAmazon Web Services
Cloud Infrastructure

Security Setup Checklist

70 steps across the ten Brilliant at the Basics requirements. Check each box as you complete it. Confirm every step against Amazon Web Services’s own documentation before you rely on it.

Where you work
AWS Management Console
Content reviewed
2026-07-21
Prepared for
________________________________
Date started
________________________________
Before you store CUI here

For CUI and ITAR data, use AWS GovCloud (US) with FedRAMP High and DoD Impact Level 4–5 authorized services.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Evidence to keep: Identity Center authentication settings screenshot · List of users with registered FIDO2 devices · Root account MFA-enabled proof

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Evidence to keep: IAM role and policy list · Service control policy documents · Access Analyzer unused-access report

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Evidence to keep: AWS Config recorder status · Resource Explorer aggregator index confirmation · Exported resource inventory list

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Evidence to keep: CloudTrail 'all Regions' trail configuration · GuardDuty enabled status · Security Hub CSPM findings and alarm history

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Evidence to keep: VPC and subnet diagram · Security group and NACL rule export · WAF web ACL configuration

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Evidence to keep: Inspector findings report by severity · Patch Manager compliance dashboard · Maintenance window and patch policy settings

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Evidence to keep: KMS key list with rotation enabled · S3 default-encryption settings · Load balancer TLS/HTTPS configuration

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Evidence to keep: AWS Backup plan and schedule · Cross-Region copy job history · Successful restore test record

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Evidence to keep: Security Hub CSPM standards and score · AWS Config conformance pack results · Control Tower landing zone summary

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Evidence to keep: Bedrock guardrail policy configuration · Macie sensitive-data findings report · IAM policies limiting Bedrock access

This checklist is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each step against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/

Back to the guide