Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPAmazon Web Services
Cloud Infrastructure

Key Settings One-Pager

The essential goal, the features that carry it, the mistake to avoid, and the proof to keep — for each of the ten Brilliant at the Basics requirements. A quick reference to pin up, not a substitute for the full step-by-step guide. Confirm every setting against Amazon Web Services’s own documentation.

Where you work
AWS Management Console
Content reviewed
2026-07-21
Before you store CUI here

For CUI and ITAR data, use AWS GovCloud (US) with FedRAMP High and DoD Impact Level 4–5 authorized services.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Make a stolen password useless on its own.

Configure in
AWS IAM Identity CenterAWS Identity and Access Management (IAM)AWS Organizations
Don’t miss

Give each admin a second backup security key and store it safely, or a lost key can lock you out.

Evidence to keep

Identity Center authentication settings screenshot · List of users with registered FIDO2 devices · Root account MFA-enabled proof

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Give each person only the access their job needs — and no more.

Configure in
AWS Identity and Access Management (IAM)AWS OrganizationsAWS IAM Identity Center
Don’t miss

Never attach the AdministratorAccess policy for day-to-day work; start with almost nothing and add only what breaks.

Evidence to keep

IAM role and policy list · Service control policy documents · Access Analyzer unused-access report

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Keep a live list of every device, identity, and app you defend.

Configure in
AWS ConfigAWS Systems ManagerAWS Resource ExplorerAWS Organizations
Don’t miss

Enable Config in every Region, not just your main one, because forgotten resources in unused Regions are a classic blind spot.

Evidence to keep

AWS Config recorder status · Resource Explorer aggregator index confirmation · Exported resource inventory list

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Record important events and watch for trouble.

Configure in
AWS CloudTrailAmazon CloudWatchAmazon GuardDutyAWS Security Hub CSPM
Don’t miss

Keep at least one year of CloudTrail logs; the default 90-day event history is not enough for most defense audits.

Evidence to keep

CloudTrail 'all Regions' trail configuration · GuardDuty enabled status · Security Hub CSPM findings and alarm history

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Keep one compromised thing from reaching everything else.

Configure in
Amazon VPCSecurity GroupsNetwork ACLsAWS WAF
Don’t miss

Avoid the '0.0.0.0/0 allow all' rule on security groups; open sources are the most common cloud misconfiguration.

Evidence to keep

VPC and subnet diagram · Security group and NACL rule export · WAF web ACL configuration

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Find weak spots and fix the risky ones first.

Configure in
Amazon InspectorAWS Systems ManagerAWS Systems Manager Patch Manager
Don’t miss

Test patches on a small group first; auto-patching everything at once can break a critical app during business hours.

Evidence to keep

Inspector findings report by severity · Patch Manager compliance dashboard · Maintenance window and patch policy settings

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Scramble sensitive data so only the right people can read it.

Configure in
AWS Key Management Service (KMS)Amazon S3Amazon EBSAWS Certificate Manager
Don’t miss

Use customer managed KMS keys instead of AWS-owned keys so you can prove control and revoke access if needed.

Evidence to keep

KMS key list with rotation enabled · S3 default-encryption settings · Load balancer TLS/HTTPS configuration

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Be able to restore your data after an attack or outage.

Configure in
AWS BackupAmazon EBSAmazon S3AWS Organizations
Don’t miss

A backup you have never restored is only a hope; schedule real restore drills so you know it works.

Evidence to keep

AWS Backup plan and schedule · Cross-Region copy job history · Successful restore test record

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Start every service from a known-good, hardened setting.

Configure in
AWS Security Hub CSPMAWS ConfigAWS Control TowerAWS Organizations
Don’t miss

Do not try to fix every finding at once; sort by severity and knock out Critical and High controls first.

Evidence to keep

Security Hub CSPM standards and score · AWS Config conformance pack results · Control Tower landing zone summary

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Use AI and share files without leaking sensitive information.

Configure in
Amazon Bedrock GuardrailsAmazon MacieAmazon S3AWS Identity and Access Management (IAM)
Don’t miss

Never paste CUI into a public AI tool; keep AI use inside Bedrock with guardrails so your data stays in your account.

Evidence to keep

Bedrock guardrail policy configuration · Macie sensitive-data findings report · IAM policies limiting Bedrock access

This one-pager is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It is a condensed reference — the full guide has the click-by-click steps. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each setting against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/